Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: parca-dev/parca-agent
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: parca-dev/parca-agent
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: gcp
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 19 commits
  • 10 files changed
  • 1 contributor

Commits on Sep 7, 2026

  1. Add GCP Marketplace deployment support

    Add Jsonnet configuration and manifests to support deploying parca-agent
    to Google Cloud Marketplace. Includes DaemonSet, RBAC, ConfigMap, and
    Application definitions.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    b920e96 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    9553da2 View commit details
    Browse the repository at this point in the history
  3. Fix GCP Marketplace image requirements

    - Use DOCKER_BUILDKIT=0 to produce Docker manifest v2 format instead of OCI
    - Add parca-agent Dockerfile with GCP Marketplace annotation
    - Fix image path in schema and manifest template to use named image reference
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    4dddeaa View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    98813f3 View commit details
    Browse the repository at this point in the history
  5. Update

    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    ae17f1e View commit details
    Browse the repository at this point in the history
  6. Update GCP Marketplace deployment configuration

    - Add VERSION_GCP variable to strip v prefix and patch version for GCP tags
    - Strip v prefix from version in jsonnet for proper version labeling
    - Remove Service from componentKinds (parca-agent doesn't expose one)
    - Fix image path template and add remoteStoreAddress config
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    fbcc8d7 View commit details
    Browse the repository at this point in the history
  7. Set correct deploy-info

    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    7a5b73f View commit details
    Browse the repository at this point in the history
  8. Fix GCP Marketplace Application resource configuration

    - Add addOwnerRef: true to application.yaml.template to enable proper ownership and lifecycle management
    - Add all componentKinds (ServiceAccount, ConfigMap, ClusterRole, ClusterRoleBinding, DaemonSet) to Application resource
    - Add offline mode storage path configuration with default value /tmp
    - Add remoteStoreAddress default value (empty string) to support offline-only deployments
    - Remove trailing YAML separator (---) from manifest.yaml.template that caused parser errors
    - Add offlineModeStoragePath support to parca-agent.libsonnet
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    7c766a7 View commit details
    Browse the repository at this point in the history
  9. Fix GCP Marketplace Docker images for amd64 architecture

    Specify --platform=linux/amd64 in Dockerfiles to ensure correct
    architecture when building on ARM machines (Apple Silicon). This
    prevents "exec format error" when deploying to GKE nodes which run
    on linux/amd64.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    4aadbe4 View commit details
    Browse the repository at this point in the history
  10. Add bearer token support to GCP Marketplace deployment

    Adds the token parameter to gcp.jsonnet to enable bearer token authentication for the remote store. The generated manifest now includes the --remote-store-bearer-token flag with the $bearerToken placeholder.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    0f734c2 View commit details
    Browse the repository at this point in the history
  11. Update GCP Marketplace to version 0.45.0

    Updates all GCP Marketplace configuration files to use parca-agent v0.45.0. Also improves Makefile to use separate VERSION_GCP_MINOR and VERSION_GCP_PATCH variables for better version tagging, adds platform specification for amd64 architecture, and marks remoteStoreAddress as required in the schema.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    82bc295 View commit details
    Browse the repository at this point in the history
  12. Configuration menu
    Copy the full SHA
    f16ae3f View commit details
    Browse the repository at this point in the history
  13. Store bearer token in Kubernetes Secret for GCP deployment

    Changes the bearer token handling to use Kubernetes Secrets instead of
    plaintext CLI arguments. The token is now stored in a Secret, mounted
    as a volume, and read via --remote-store-bearer-token-file, matching
    the Polar Signals Cloud security pattern.
    
    Changes:
    - Add Secret resource when token is configured
    - Replace --remote-store-bearer-token with --remote-store-bearer-token-file
    - Mount token Secret at /var/parca-agent in the DaemonSet
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    ce58893 View commit details
    Browse the repository at this point in the history
  14. deploy/gcp: also tag and annotate deployer image with patch version

    Also expose imageTag as a schema property so the deployed version
    is explicit and overridable without rebuilding the deployer image.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    b36354f View commit details
    Browse the repository at this point in the history
  15. deploy/gcp: bump to 0.47.1 and fix imageTag schema conflict

    Remove the duplicate imageTag property from schema.yaml — it is
    auto-generated by the marketplace deployer from the image reference
    and having a default value caused expand_config.py to fail.
    
    Also bump publishedVersion to 0.47.1 to match the new deployer image.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    d1d41e8 View commit details
    Browse the repository at this point in the history
  16. deploy/gcp: bump to 0.48.0

    Bump the GCP Marketplace deployer, parca-agent image, schema
    publishedVersion, and Application version to 0.48.0. The manifest
    templates were still pinned at 0.45.1, so this also realigns them with
    the schema/Dockerfile that had moved ahead to 0.47.1.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    ca268d3 View commit details
    Browse the repository at this point in the history
  17. deploy: pull fresh bases on build, create gcp/tmp on generate

    The Marketplace images are rebuilt to pick up CVE fixes in their base
    layers, but buildx was happy to reuse a cached base, so a "rebuild"
    could ship the exact same vulnerable layers. --pull matches what
    .goreleaser.yml already does for the upstream agent images.
    
    gcp/tmp is gitignored, so `make manifests` failed on a fresh checkout:
    generate.sh writes the GCP manifests there via `jsonnet -m`, which does
    not create the directory itself.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    020e243 View commit details
    Browse the repository at this point in the history
  18. deploy/gcp: bump to 0.49.1

    Google Marketplace flagged both listing images for CVE-2026-39821
    (GO-2026-5026), a Punycode validation flaw in golang.org/x/net/idna that
    lets an encoded label bypass a hostname privilege check.
    
    Bumping to 0.49.0 would not have been enough. Its x/net module is
    already v0.56.0, but idna is also vendored into the Go standard library,
    and v0.49.0 was built with go1.25.11 -- govulncheck on the shipped
    binary still reports GO-2026-5026 via net/http, plus seven other stdlib
    advisories. The fix landed in go1.25.13, so this needs a rebuild rather
    than a dependency bump. v0.49.1 is that rebuild.
    
    Also refreshes the release note, which still announced the initial
    Marketplace release.
    metalmatze committed Sep 7, 2026
    Configuration menu
    Copy the full SHA
    094eea7 View commit details
    Browse the repository at this point in the history

Commits on Sep 8, 2026

  1. deploy/gcp: overlay kubectl v1.37.0 in the deployer image

    Marketplace flagged the deployer for CVE-2026-39821 (GO_STDLIB, go1.26.5,
    fixed in go1.26.6). None of that is ours. The only Go binary in the whole
    image is /opt/kubectl/v1.36/kubectl, which comes from Google's
    deployer_envsubst base.
    
    Rebuilding does not help. onbuild:latest and public-image-13.0.10 are the
    same digest, built 2026-08-18, so there is no newer base to pull, and
    upstream's newest v1.36 patch (v1.36.4) is also built with go1.26.5.
    kubectl v1.37.0 is the first release built with go1.26.6, so overlay that
    binary in place.
    
    /usr/bin/kubectl selects a binary by server version and falls back to
    /opt/kubectl/default, a symlink to this directory, so replacing the file
    keeps that logic intact. The tradeoff is server skew support moving from
    1.35-1.37 to 1.36-1.38.
    
    Verified on the built image: kubectl is go1.26.6, it is the only Go binary
    present, and govulncheck reports no vulnerabilities.
    metalmatze committed Sep 8, 2026
    Configuration menu
    Copy the full SHA
    06481ec View commit details
    Browse the repository at this point in the history
Loading