Fixed
- (deps) Update module github.com/giantswarm/mcp-oauth to v0.2.200 in #829 by @renovate[bot]
Full Changelog: https://github.com/giantswarm/muster/compare/v0.3.13...v0.3.14
Full Changelog: https://github.com/giantswarm/muster/compare/v0.3.13...v0.3.14
Full Changelog: https://github.com/giantswarm/klausctl/compare/v0.2.1...v0.2.2
Full Changelog: https://github.com/giantswarm/klaus-operator/compare/v0.0.93...v0.0.94
Full Changelog: https://github.com/giantswarm/muster/compare/v0.3.12...v0.3.13
muster-windows-<arch>.exe.resource parameter now carry an aud claim defaulting to the server’s resource identifier (RFC 9068 §2.2), instead of an empty audience that JWT-validating gateways (e.g. agentgateway) reject with 401 InvalidAudience. Existing grants self-heal on their next token refresh.muster.oauth.server.dex.allowPrivateIPOIDC: allows Dex OIDC discovery to reach issuer URLs that resolve to private/loopback IPs (e.g. Azure internal load balancers). Requires mcp-oauth#427. Emits a CWE-918 startup warning.networkPolicy.cilium.ingressGateway rule allows egress to the gateway backend endpoints on their target ports (default: 10080/10443, selector: app.kubernetes.io/name=envoy in envoy-gateway-system).Full Changelog: https://github.com/giantswarm/klaus-operator/compare/v0.0.92...v0.0.93
Full Changelog: https://github.com/giantswarm/klaus-oci/compare/v0.0.47...v0.0.48
Full Changelog: https://github.com/giantswarm/klaus/compare/v0.0.196...v0.0.197
Full Changelog: https://github.com/giantswarm/klausctl/compare/v0.2.0...v0.2.1
Full Changelog: https://github.com/giantswarm/muster/compare/v0.3.10...v0.3.11