* feat: improve operator ConfigMap settings handling - Protect jwt_secret and min_keep_alive_version from deletion (add to PROTECTED_SETTINGS) - Expose jwt_secret in config exports (remove from HIDDEN_SETTINGS) - Reject empty/null jwt_secret values with warning - Clamp retention_period_secs to 30 days max on CE builds - Improve apply_settings_diff logging: distinguish Created/Updated/Deleted with from/to values and unchanged count summary - Add sensitive value masking in logs with partial redaction (prefix/suffix) for top-level secrets and nested sub-field masking for oauths, smtp, object_store_cache_config, custom_instance_pg_databases - Sort global_settings keys alphabetically in YAML export - Order worker_configs with "default" and "native" first in YAML export - Add tests for sorted YAML serializer Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: address PR review feedback - Fix redact_string panic on multi-byte UTF-8 by using chars() instead of byte-length slicing - Protect jwt_secret from deletion via direct API (set_global_setting_internal rejects empty/null with BadRequest) - Add code comment documenting jwt_secret visibility trade-off Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
33 KiB
33 KiB