16 Commits
Author SHA1 Message Date
Philip LaineandGitHub f8186877fc Update kube forwarder version (#381)
This new version comes with two important fixes. The first is that it
resolves failures when the same target is set in many egress resources.
The second is that it ensures that the output rules are sorted by name,
this way the config map is not updated if nothing has changed.

<!-- codesmith:footer -->
---
<a
href="https://app.blacksmith.sh/netbirdio/codesmith/kubernetes-operator/pr/381"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img
alt="View with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a>
<a
href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787315777&installation_model_id=427504&pr_number=381&repository=netbirdio%2Fkubernetes-operator&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fkubernetes-operator%2Fpull%2F381&signature=b892e51abec537fc5e78a4b27ad397e7e2f649162885c48952e0b7fec760d7a3"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img
alt="Autofix with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a>
<sup>Need help on this PR? Tag <code>/codesmith</code> with what you
need. Autofix is disabled.</sup>

<!-- codesmith:autofix:disabled -->
<!-- /codesmith:footer -->
2026-07-23 12:04:50 +02:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
e752d1587f Bump github.com/netbirdio/netbird from 0.72.4 to 0.74.7 (#376)
Bumps
[github.com/netbirdio/netbird](https://github.com/netbirdio/netbird)
from 0.72.4 to 0.74.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/netbirdio/netbird/releases">github.com/netbirdio/netbird's
releases</a>.</em></p>
<blockquote>
<h2>v0.74.7</h2>
<h2>What's Changed</h2>
<ul>
<li>[relay] Handle QUIC connections concurrently to prevent handshake
head-of-line blocking by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6784">netbirdio/netbird#6784</a></li>
<li>[client] Reject leading hyphen in getent input to prevent flag
injection by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6787">netbirdio/netbird#6787</a></li>
<li>[client] Sanitize peer FQDN/hostname in generated SSH config by <a
href="https://github.com/riccardomanfrin"><code>@​riccardomanfrin</code></a>
in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6805">netbirdio/netbird#6805</a></li>
<li>[client] Disable gVisor TCP RACK loss detection on Windows by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6808">netbirdio/netbird#6808</a></li>
<li>[client] Rename isValidAccessToken to reflect audience-only check by
<a
href="https://github.com/riccardomanfrin"><code>@​riccardomanfrin</code></a>
in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6806">netbirdio/netbird#6806</a></li>
<li>[client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default by <a
href="https://github.com/riccardomanfrin"><code>@​riccardomanfrin</code></a>
in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6812">netbirdio/netbird#6812</a></li>
<li>[client] Evaluate IP fragments against firewall ACLs by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6781">netbirdio/netbird#6781</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7">https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7</a></p>
<h2>v0.74.6</h2>
<h2>What's Changed</h2>
<ul>
<li>[client] ios: preserve WireGuard key on interactive re-login (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6777">#6777</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/netbirdio/netbird/compare/v0.74.5...v0.74.6">https://github.com/netbirdio/netbird/compare/v0.74.5...v0.74.6</a></p>
<h2>v0.74.5</h2>
<h2>What's Changed</h2>
<ul>
<li>[proxy] enforce model allowlist for URL-routed providers
(Bedrock/Vertex) by <a
href="https://github.com/mlsmaycon"><code>@​mlsmaycon</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6764">netbirdio/netbird#6764</a></li>
<li>[management] Remove proxy peer stale deduplication logic by <a
href="https://github.com/mlsmaycon"><code>@​mlsmaycon</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6768">netbirdio/netbird#6768</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/netbirdio/netbird/compare/v0.74.4...v0.74.5">https://github.com/netbirdio/netbird/compare/v0.74.4...v0.74.5</a></p>
<h2>v0.74.4</h2>
<h2>What's Changed</h2>
<ul>
<li>[management] fix: prevent reverse proxy domain from being pushed as
DNS search domain by <a
href="https://github.com/blaugrau90"><code>@​blaugrau90</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6498">netbirdio/netbird#6498</a></li>
<li>[client] Recover from rosenpass key desync by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6714">netbirdio/netbird#6714</a></li>
<li>[client] Bump golang.org/x/crypto to v0.54.0 by <a
href="https://github.com/lixmal"><code>@​lixmal</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6709">netbirdio/netbird#6709</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/blaugrau90"><code>@​blaugrau90</code></a> made
their first contribution in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6498">netbirdio/netbird#6498</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/netbirdio/netbird/compare/v0.74.3...v0.74.4">https://github.com/netbirdio/netbird/compare/v0.74.3...v0.74.4</a></p>
<h2>v0.74.3</h2>
<h2>What's Changed</h2>
<ul>
<li>[client] fix MDM managementURL conflict on default-port URL echo by
<a
href="https://github.com/riccardomanfrin"><code>@​riccardomanfrin</code></a>
in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6672">netbirdio/netbird#6672</a></li>
<li>[client] Update gopsutil to v4 by <a
href="https://github.com/mlsmaycon"><code>@​mlsmaycon</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6688">netbirdio/netbird#6688</a></li>
<li>[client] Fix hanging status command during relay dial by <a
href="https://github.com/theodorsm"><code>@​theodorsm</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6694">netbirdio/netbird#6694</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/netbirdio/netbird/compare/v0.74.2...v0.74.3">https://github.com/netbirdio/netbird/compare/v0.74.2...v0.74.3</a></p>
<h2>v0.74.2</h2>
<h2>What's Changed</h2>
<ul>
<li>[management] Add vLLM e2e test by <a
href="https://github.com/braginini"><code>@​braginini</code></a> in <a
href="https://redirect.github.com/netbirdio/netbird/pull/6649">netbirdio/netbird#6649</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/netbirdio/netbird/commit/a1c9427d8004576e2cbb9e546d409847fa9df318"><code>a1c9427</code></a>
[client] Evaluate IP fragments against firewall ACLs (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6781">#6781</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/b7b0d5796e988ac5f369d51d3a16b162d5fb9522"><code>b7b0d57</code></a>
[client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6812">#6812</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/3f8c4473783424e1642d2991b896add973249d97"><code>3f8c447</code></a>
[client] Rename isValidAccessToken to reflect audience-only check (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6806">#6806</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/6e3f4d8722d1c3f4482c44aec725aaba80c4512c"><code>6e3f4d8</code></a>
[client] Disable gVisor TCP RACK loss detection on Windows (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6808">#6808</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/099ae4bc6cc8ab95ef16343acb87c33b8197711c"><code>099ae4b</code></a>
[client] Sanitize peer FQDN/hostname in generated SSH config (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6805">#6805</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/63d60ba490794eebd0ad5ce77e4d31269e9c793b"><code>63d60ba</code></a>
[client] Reject leading hyphen in getent input to prevent flag injection
(<a
href="https://redirect.github.com/netbirdio/netbird/issues/6787">#6787</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/62fc8d254e636c3053ae8a21c4ea075558a8273f"><code>62fc8d2</code></a>
[relay] Handle QUIC connections concurrently to prevent handshake
head-of-lin...</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/3a2f773d655d88d16ed953fc2a114a4e690a1b08"><code>3a2f773</code></a>
[client] preserve WireGuard key on interactive re-login (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6777">#6777</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/f0eed7564f3a9138962da1408986e4666d7137b5"><code>f0eed75</code></a>
[management] Remove proxy peer stale deduplication logic (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6768">#6768</a>)</li>
<li><a
href="https://github.com/netbirdio/netbird/commit/277d8e4c5352950e1ec4fbd21a3266f0412b09fe"><code>277d8e4</code></a>
[proxy] enforce model allowlist for URL-routed providers
(Bedrock/Vertex) (<a
href="https://redirect.github.com/netbirdio/netbird/issues/6">#6</a>...</li>
<li>Additional commits viewable in <a
href="https://github.com/netbirdio/netbird/compare/v0.72.4...v0.74.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/netbirdio/netbird&package-manager=go_modules&previous-version=0.72.4&new-version=0.74.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

<!-- codesmith:footer -->
---
<a
href="https://app.blacksmith.sh/netbirdio/codesmith/kubernetes-operator/pr/376"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img
alt="View with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a>
<a
href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787085769&installation_id=146802194&pr_number=376&repository=netbirdio%2Fkubernetes-operator&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fkubernetes-operator%2Fpull%2F376&signature=2f50a4b5245bbba3f14f2249365f03c700d30db07e15709056766b6a716394dd"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img
alt="Autofix with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a>
<sup>Need help on this PR? Tag <code>/codesmith</code> with what you
need. Autofix is disabled.</sup>

<!-- codesmith:autofix:disabled -->
<!-- /codesmith:footer -->

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 11:04:59 +02:00
Philip LaineandGitHub ea2dafd5a3 Add network egress resource (#357)
This change adds a new import resource which enables exposing Netbird
resources as Kubernetes services. This remove the need to add sidecars
to every pod.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a new `NetworkEgress` custom resource (`netbird.io/v1alpha1`)
with CRD, schema validation, and status/conditions.
* Extended controller functionality to create egress services and
translate egress rules into import `EndpointSlice` resources; egress
pods now include a kube-egress-forwarder sidecar.
* **Bug Fixes**
* Added missing deep-copy and declarative apply support for the new
`NetworkEgress` API types.
* **Documentation**
* Updated README/API reference and added example manifests for
`NetworkEgress` (including IP/FQDN target usage).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-07-17 08:06:53 +02:00
Philip LaineandGitHub 10f40da0e7 Add NetBird server to test connections (#328)
This change adds a NetBird server to the e2e test and ensures that
cluster proxy peers can start and connect to the server.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Changes**
* Updated the `ClusterProxy` `spec.apiServer` default to include a
trailing `/` when omitted, aligning operator behavior with the
Kubernetes in-cluster API URL.
* **Documentation**
* Refreshed the `ClusterProxySpec.apiServer` API reference to reflect
the trailing `/` default.
* **Tests**
* Improved end-to-end coverage with a dynamically provisioned management
URL, more robust readiness polling, and enhanced `ClusterProxy`
validation.
* **Chores**
* Updated the end-to-end test Go configuration and CI to use the
e2e-specific Go settings/toolchain.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 14:50:47 +02:00
Philip LaineandGitHub da90b6ae42 Add groups option to cluster proxy (#297)
This change adds an option to specify groups a cluster proxy peer is a
member of.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added optional `spec.groups` to the ClusterProxy custom resource to
associate group references by `id`, `name`, or `localRef`.
* CRD schema includes OpenAPI validation to enforce that each group
reference specifies exactly one selector.

* **Bug Fixes**
* Improved deep-copy behavior for ClusterProxy spec so group references
are copied safely and don’t share underlying slices.

* **Documentation**
* Updated API reference docs and README API table to include the new
`groups` field.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-16 10:49:57 +02:00
Philip LaineandGitHub 5dd73dcc80 Add new resource for Kubernetes API proxy (#279)
This adds a new resource which deploys a Kubernetes API server proxy
that can be used to access the API server without tokens through
Netbird.

Part of #274 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added ClusterProxy custom resource for cluster API proxying
capabilities

* **Documentation**
  * Added ClusterProxy API reference documentation with schema details

* **Examples**
* Added example ClusterProxy configuration and RBAC setup for cluster
proxy targets

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/netbirdio/kubernetes-operator/pull/279?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-01 11:41:48 +02:00
pallieter-verhoeven-glbnxtandGitHub 3bb745de19 Add health probe overrides to sidecar (#278)
Add support for overriding the health probes.
This is useful, for example, when injecting NetBird as a sidecar. In
that setup, the main container could start before NetBird has
established the VPN connection, resulting in failing to connect to
peers.

Example usage:
```yaml
apiVersion: netbird.io/v1alpha1
kind: SidecarProfile
metadata:
  name: netbird-sidecar
  labels:
spec:
  injectionMode: Sidecar
  setupKeyRef:
    name: netbird-setup-key
  containerOverride:
    startupProbe:
      exec:
        command: ["netbird", "status", "--check", "startup"]
      initialDelaySeconds: 10
      failureThreshold: 10
      periodSeconds: 5
```

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* SidecarProfile now supports overriding container health check probes
(startup, liveness, and readiness) for sidecar containers, enabling
fine-grained control over probe configurations.

* **Documentation**
* Updated API reference documentation with new probe override
configuration options.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/netbirdio/kubernetes-operator/pull/278?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-29 10:58:28 +02:00
pallieter-verhoeven-glbnxtandGitHub dcd9dfdb4e Add AllowExtraDnsLabels to setupKey CRD (#277)
This option was hardcoded to false.
It is now configurable in the SetupKey CRD with a default false value.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* New allowExtraDnsLabels setting for Setup Keys to control whether
peers may include extra DNS labels (disabled by default, immutable after
creation).
* **Documentation**
* API reference updated to document the new allowExtraDnsLabels field
and its default/behavior.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/netbirdio/kubernetes-operator/pull/277?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-27 18:45:07 +02:00
Philip LaineandGitHub 69afe3aade Fix SPDX license header (#231)
This change adds SPDX license headers to all files and eforces it with
the linter.

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-05-05 12:59:36 +02:00
Philip LaineandGitHub 37d48b5ca8 Set best practice defaults for network router deployment (#214)
This change sets some Kubernetes best practices as defaults. Such as
topology spread and pod disruption budget.

It also exposes log level and image settings in the root struct to make
it easier to override commonly configured settings.

Fixes #77 
Fixes #162

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-28 15:18:15 +02:00
Philip LaineandGitHub 9838f0dccc Add sidecar profile (#192)
This change adds a new SidecarProfile resource which allows configuring
client sidecar injection into pods. It replaces the older annotation
based solution. This removes any pod specific configuration from the
setup key and puts it all in this side car configuration.

Fixes #188

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-23 19:17:53 +02:00
Philip LaineandGitHub 99ef70603f Allow references to groups by name (#195)
Group names are unique so we can safely use the name as a reference
method to groups. This makes assigning resources created in the cluster
to groups that already exist a lot easier.
2026-04-23 13:12:09 +02:00
Philip LaineandGitHub 6768a76c9c Add network router and resource (#189)
This change adds two new resources, NetworkRouter and NetworkResource,
which enable clusters to expose Kubernetes services to Netbird.

The NetworkRouter is responsible for creating the network, group, setup
key and routing peer all of which are unique to the isntance. Along with
the deployment of the client in the cluster.

The NetworkResource exposes a service by linking to the specific router
it wants to expose to. This makes coupling between the resource and
network easy to understand.

Routers also set a DNS zone which is used to give names to resources
based on the name and namespace of the service being exposed.

Part of #172

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-23 08:55:49 +02:00
Philip LaineandGitHub af11e31b28 Add ready conditon and cleanup finalizer and status patching (#186)
This change adds a ready condition. It also sets a standard for status
fields and documentation. It makes use of helper functions from FluxCD
to better manage patching of finalizers and status.

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-21 15:42:11 +02:00
Philip LaineandGitHub 9c4ca73712 Implement group resource (#181)
This change implements a new group resource. 

It also sets the standard for a resource reference will be done through
out the controller. A resource reference can either be done by ID or as
a local named reference to the actual resource. This allows end users to
chose if they want to manage things completely in the cluster or not.

Part of #172

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-15 10:16:10 +02:00
Philip LaineandGitHub 26479a19c0 Implement new setup key resource (#178)
This change implements a new resource called SetupKey that manages the
lifecycle of setup keys and stores them in secrets.

A major change here is that we are also switching to using SSA for
resource management.

Part of #172

Signed-off-by: Philip Laine <philip.laine@gmail.com>
2026-04-13 12:20:35 +02:00