Skip to content

chore(keycloak): bump KMS proxy to 0.2.2 - #3995

Merged
myasnikovdaniil merged 1 commit into
mainfrom
chore/keycloak-kms-proxy-0.2.2
Aug 31, 2026
Merged

myasnikovdaniil merged 1 commit into
mainfrom
chore/keycloak-kms-proxy-0.2.2

Conversation

@myasnikovdaniil

@myasnikovdaniil myasnikovdaniil commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

This PR updates keycloak-kms-proxy to v0.2.2 and pins image to published digest. New version fixes decryption for reads whose result set spans a join.

Screenshots

Not applicable.

Downstream repositories

Release note

chore(keycloak): update keycloak-kms-proxy to v0.2.2 with a fix for decrypting reads whose result set spans a join

Summary by CodeRabbit

  • Chores
    • Updated the Keycloak encryption component to a newer verified image version.
    • Improved deployment reliability by pinning the image to a specific integrity digest.

Pin the released image by digest so package rendering is reproducible.

Assisted-By: GPT-5 <[email protected]>
Signed-off-by: Myasnikov Daniil <[email protected]>
@github-actions github-actions Bot added area/keycloak Issues or PRs related to Keycloak (SSO / identity) kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt size/XS This PR changes 0-9 lines, ignoring generated files labels Aug 31, 2026
@coderabbitai

coderabbitai Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 2fab702b-7aad-4b85-8e0d-ab6a65abdded

📥 Commits

Reviewing files that changed from the base of the PR and between b9a95a0 and 6d94440.

📒 Files selected for processing (1)
  • packages/system/keycloak/values.yaml

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The Keycloak chart updates the encryption image from version 0.2.1 to version 0.2.2 and pins the image to a specific digest.

Changes

Keycloak image update

Layer / File(s) Summary
Update encryption image reference
packages/system/keycloak/values.yaml
The encryption.image value now uses keycloak-kms-proxy:0.2.2 with a pinned SHA-256 digest.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 6d944

This narrowly scoped update selects the Keycloak encryption proxy version 0.2.2 by immutable digest without changing routing, permissions, or deployment behavior. No actionable merge-blocking risk remains beyond normal checks and review.

Suggested reviewers: ivanhunters

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating the Keycloak KMS proxy to version 0.2.2.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/keycloak-kms-proxy-0.2.2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@myasnikovdaniil
myasnikovdaniil merged commit e84a446 into main Aug 31, 2026
11 of 15 checks passed
@myasnikovdaniil
myasnikovdaniil deleted the chore/keycloak-kms-proxy-0.2.2 branch August 31, 2026 07:07
@myasnikovdaniil myasnikovdaniil added the kind/backport Categorizes issue or PR as requiring a backport to the current release line label Aug 31, 2026
@github-actions

Copy link
Copy Markdown

Successfully created backport PR for release-1.6:

myasnikovdaniil added a commit that referenced this pull request Aug 31, 2026
Andrei Kvapil (kvaps) pushed a commit that referenced this pull request Sep 7, 2026
## What this PR does

This PR updates keycloak-kms-proxy to v0.2.2 and pins image to published
digest. New version fixes decryption for reads whose result set spans a
join.

### Screenshots

Not applicable.

### Downstream repositories

- [x] No downstream repository is affected by this change
- [ ] [cozystack/website](https://github.com/cozystack/website) -
follow-up:
- [ ]
[cozystack/terraform-provider-cozystack](https://github.com/cozystack/terraform-provider-cozystack)
- follow-up:
- [ ]
[cozystack/ansible-cozystack](https://github.com/cozystack/ansible-cozystack)
- follow-up:
- [ ] [cozystack/ccp](https://github.com/cozystack/ccp) - follow-up:
- [ ] [cozystack/talm](https://github.com/cozystack/talm) - follow-up:
- [ ] [cozystack/cozyhr](https://github.com/cozystack/cozyhr) -
follow-up:
- [ ] [cozystack/cozy-proxy](https://github.com/cozystack/cozy-proxy) -
follow-up:
- [ ]
[cozystack/cozystack-telemetry-server](https://github.com/cozystack/cozystack-telemetry-server)
- follow-up:
- [ ]
[cozystack/external-apps-example](https://github.com/cozystack/external-apps-example)
- follow-up:
- [ ] [cozystack/examples](https://github.com/cozystack/examples) -
follow-up:

### Release note

```release-note
chore(keycloak): update keycloak-kms-proxy to v0.2.2 with a fix for decrypting reads whose result set spans a join
```


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated the Keycloak encryption component to a newer verified image
version.
* Improved deployment reliability by pinning the image to a specific
integrity digest.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/keycloak Issues or PRs related to Keycloak (SSO / identity) kind/backport Categorizes issue or PR as requiring a backport to the current release line kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt size/XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants