Added
- (oauth) Per-issuer acceptedTypHeaders for trustedIssuers in #837 by @QuentinBisson
Full Changelog: https://github.com/giantswarm/muster/compare/v0.4.4...v0.5.0
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
Full Changelog: https://github.com/giantswarm/muster/compare/v0.4.4...v0.5.0
Full Changelog: https://github.com/giantswarm/muster/compare/v0.4.3...v0.4.4
Full Changelog: https://github.com/giantswarm/muster/compare/v0.4.2...v0.4.3
Full Changelog: https://github.com/giantswarm/muster/compare/v0.4.1...v0.4.2
Full Changelog: https://github.com/giantswarm/klaus/compare/v0.0.202...v0.0.203
Full Changelog: https://github.com/giantswarm/klaus/compare/v0.0.201...v0.0.202
trustedAudiences) are no longer hard-rejected by the trusted-issuer Bearer branch when the same issuer is also configured in trustedIssuers — fixes Backstage AI-chat SSO token forwarding returning 401 (typ header is "", expected "at+jwt") on deployments with the token-exchange broker enabled. (#838)POST /api/auth/cluster-token/:installation backend route exchanges the user’s main Dex ID token for a short-lived cluster token (RFC 8693), cached per user and installation; the kubernetes auth connectors try this silent path before the cookie-based refresh, keeping the legacy popup as fallback for unmigrated clusters. Configured via gs.clusterTokenBroker; installations marked with gs.installations.<name>.clusterTokenAudience disappear from the provider settings page, collapsing it to the single main login.authProvider has no dedicated auth.providers entry, enabling single sign-on for muster. Deployments activate this by removing the mcp-muster provider from auth.providers, which also removes the separate PKCE login from the user settings page.
See ./docs/releases/v0.136.0-changelog.md for more information.coredns image to 1.14.4.