From 5166e32f9d51d58b740c57282ecd99895eecbdfa Mon Sep 17 00:00:00 2001 From: Eric Hibbs Date: Mon, 10 Aug 2026 14:41:25 -0700 Subject: [PATCH] Bump firewall image to 2.1.1 (Helm + CloudFormation) Updates the Helm chart appVersion and every image tag pin to 2.1.1, and the chart version to 0.11.2, across the Helm chart and the CloudFormation templates and example values. Main was still pinned to 2.0.14, so this skips the 2.0.15 through 2.1.0 releases. --- cloudformation/README.md | 4 ++-- cloudformation/firewall-eks.yaml | 4 ++-- cloudformation/values/dns-override.values.yaml | 2 +- helm/Chart.yaml | 4 ++-- helm/README.md | 2 +- helm/values.yaml | 2 +- 6 files changed, 9 insertions(+), 9 deletions(-) diff --git a/cloudformation/README.md b/cloudformation/README.md index bb19429..3796995 100644 --- a/cloudformation/README.md +++ b/cloudformation/README.md @@ -14,7 +14,7 @@ On EKS the firewall is the **Helm chart** (`../helm`), which already supports DN |------|---------| | `eks-cluster.yaml` | **Greenfield wrapper** — VPC + EKS cluster + node group + OIDC provider. Skip if you already run a cluster. | | `firewall-eks.yaml` | **Shared base** — ElastiCache Redis + Socket token (Secrets Manager) + IRSA role; emits the `helm upgrade --install` command. | -| `values/dns-override.values.yaml` | Example Helm values (DNS-override + Redis + self-signed certs). Behavioral defaults stay synced with `helm/values.yaml`; image pinned to `2.0.14`. | +| `values/dns-override.values.yaml` | Example Helm values (DNS-override + Redis + self-signed certs). Behavioral defaults stay synced with `helm/values.yaml`; image pinned to `2.1.1`. | ## Cases @@ -29,7 +29,7 @@ The base template currently takes the **handoff** approach: CloudFormation provi ## Config model -On EKS the Helm chart renders the firewall config into a **ConfigMap**. The stack injects install-time values for the ElastiCache endpoint (`redis.host`), the Socket token (`socket.apiToken`, read from Secrets Manager), and the firewall image tag (`image.tag`, default `2.0.14`). Chart version defaults to `0.11.1`. +On EKS the Helm chart renders the firewall config into a **ConfigMap**. The stack injects install-time values for the ElastiCache endpoint (`redis.host`), the Socket token (`socket.apiToken`, read from Secrets Manager), and the firewall image tag (`image.tag`, default `2.1.1`). Chart version defaults to `0.11.2`. ## Known DRAFT caveats diff --git a/cloudformation/firewall-eks.yaml b/cloudformation/firewall-eks.yaml index 76c63fd..9d43679 100644 --- a/cloudformation/firewall-eks.yaml +++ b/cloudformation/firewall-eks.yaml @@ -54,12 +54,12 @@ Parameters: ChartVersion: Type: String - Default: "0.11.1" + Default: "0.11.2" Description: Socket Firewall Helm chart version to install. FirewallImageTag: Type: String - Default: "2.0.14" + Default: "2.1.1" Description: socketdev/socket-registry-firewall image tag (must match chart appVersion). Resources: diff --git a/cloudformation/values/dns-override.values.yaml b/cloudformation/values/dns-override.values.yaml index fd16446..1a49c83 100644 --- a/cloudformation/values/dns-override.values.yaml +++ b/cloudformation/values/dns-override.values.yaml @@ -17,7 +17,7 @@ image: repository: socketdev/socket-registry-firewall # Pin explicitly so CloudFormation installs don't drift if the chart # appVersion changes independently. Never use :latest for a security product. - tag: "2.0.14" + tag: "2.1.1" pullPolicy: Always socket: diff --git a/helm/Chart.yaml b/helm/Chart.yaml index 95c2fd3..a7220fd 100644 --- a/helm/Chart.yaml +++ b/helm/Chart.yaml @@ -2,10 +2,10 @@ apiVersion: v2 name: socket-firewall description: Socket.dev Registry Firewall - Block vulnerable packages before they reach your cluster type: application -version: 0.11.1 +version: 0.11.2 # appVersion is the single source of truth for the firewall image version. # image.tag in values.yaml defaults to this (see templates/_helpers.tpl). -appVersion: "2.0.14" +appVersion: "2.1.1" keywords: - security - supply-chain diff --git a/helm/README.md b/helm/README.md index 8da0c3e..e0b6441 100644 --- a/helm/README.md +++ b/helm/README.md @@ -90,7 +90,7 @@ registries: | Parameter | Description | Default | |-----------|-------------|---------| | `image.repository` | Docker image | `socketdev/socket-registry-firewall` | -| `image.tag` | Image tag. Keep in sync with chart `appVersion`. Empty falls back to `appVersion`. | `"2.0.14"` | +| `image.tag` | Image tag. Keep in sync with chart `appVersion`. Empty falls back to `appVersion`. | `"2.1.1"` | | `image.pullPolicy` | Image pull policy | `Always` | | `replicaCount` | Number of replicas (ignored if autoscaling enabled) | `1` | | `socket.apiToken` | Socket API token | `""` | diff --git a/helm/values.yaml b/helm/values.yaml index 099efba..af11273 100644 --- a/helm/values.yaml +++ b/helm/values.yaml @@ -5,7 +5,7 @@ image: repository: socketdev/socket-registry-firewall # Keep in sync with Chart.yaml appVersion. Leave empty only if you intentionally # want to track whatever appVersion the installed chart carries. - tag: "2.0.14" + tag: "2.1.1" pullPolicy: Always # Image pull secrets for private registries