-
Notifications
You must be signed in to change notification settings - Fork 92
Comparing changes
Open a pull request
base repository: parca-dev/parca-agent
base: main
head repository: parca-dev/parca-agent
compare: gcp
- 19 commits
- 10 files changed
- 1 contributor
Commits on Sep 7, 2026
-
Add GCP Marketplace deployment support
Add Jsonnet configuration and manifests to support deploying parca-agent to Google Cloud Marketplace. Includes DaemonSet, RBAC, ConfigMap, and Application definitions.
Configuration menu - View commit details
-
Copy full SHA for b920e96 - Browse repository at this point
Copy the full SHA b920e96View commit details -
Update GCP Marketplace deployer with proper image templating and sche…
…ma configuration
Configuration menu - View commit details
-
Copy full SHA for 9553da2 - Browse repository at this point
Copy the full SHA 9553da2View commit details -
Fix GCP Marketplace image requirements
- Use DOCKER_BUILDKIT=0 to produce Docker manifest v2 format instead of OCI - Add parca-agent Dockerfile with GCP Marketplace annotation - Fix image path in schema and manifest template to use named image reference
Configuration menu - View commit details
-
Copy full SHA for 4dddeaa - Browse repository at this point
Copy the full SHA 4dddeaaView commit details -
Configuration menu - View commit details
-
Copy full SHA for 98813f3 - Browse repository at this point
Copy the full SHA 98813f3View commit details -
Configuration menu - View commit details
-
Copy full SHA for ae17f1e - Browse repository at this point
Copy the full SHA ae17f1eView commit details -
Update GCP Marketplace deployment configuration
- Add VERSION_GCP variable to strip v prefix and patch version for GCP tags - Strip v prefix from version in jsonnet for proper version labeling - Remove Service from componentKinds (parca-agent doesn't expose one) - Fix image path template and add remoteStoreAddress config
Configuration menu - View commit details
-
Copy full SHA for fbcc8d7 - Browse repository at this point
Copy the full SHA fbcc8d7View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7a5b73f - Browse repository at this point
Copy the full SHA 7a5b73fView commit details -
Fix GCP Marketplace Application resource configuration
- Add addOwnerRef: true to application.yaml.template to enable proper ownership and lifecycle management - Add all componentKinds (ServiceAccount, ConfigMap, ClusterRole, ClusterRoleBinding, DaemonSet) to Application resource - Add offline mode storage path configuration with default value /tmp - Add remoteStoreAddress default value (empty string) to support offline-only deployments - Remove trailing YAML separator (---) from manifest.yaml.template that caused parser errors - Add offlineModeStoragePath support to parca-agent.libsonnet
Configuration menu - View commit details
-
Copy full SHA for 7c766a7 - Browse repository at this point
Copy the full SHA 7c766a7View commit details -
Fix GCP Marketplace Docker images for amd64 architecture
Specify --platform=linux/amd64 in Dockerfiles to ensure correct architecture when building on ARM machines (Apple Silicon). This prevents "exec format error" when deploying to GKE nodes which run on linux/amd64.
Configuration menu - View commit details
-
Copy full SHA for 4aadbe4 - Browse repository at this point
Copy the full SHA 4aadbe4View commit details -
Add bearer token support to GCP Marketplace deployment
Adds the token parameter to gcp.jsonnet to enable bearer token authentication for the remote store. The generated manifest now includes the --remote-store-bearer-token flag with the $bearerToken placeholder.
Configuration menu - View commit details
-
Copy full SHA for 0f734c2 - Browse repository at this point
Copy the full SHA 0f734c2View commit details -
Update GCP Marketplace to version 0.45.0
Updates all GCP Marketplace configuration files to use parca-agent v0.45.0. Also improves Makefile to use separate VERSION_GCP_MINOR and VERSION_GCP_PATCH variables for better version tagging, adds platform specification for amd64 architecture, and marks remoteStoreAddress as required in the schema.
Configuration menu - View commit details
-
Copy full SHA for 82bc295 - Browse repository at this point
Copy the full SHA 82bc295View commit details -
Configuration menu - View commit details
-
Copy full SHA for f16ae3f - Browse repository at this point
Copy the full SHA f16ae3fView commit details -
Store bearer token in Kubernetes Secret for GCP deployment
Changes the bearer token handling to use Kubernetes Secrets instead of plaintext CLI arguments. The token is now stored in a Secret, mounted as a volume, and read via --remote-store-bearer-token-file, matching the Polar Signals Cloud security pattern. Changes: - Add Secret resource when token is configured - Replace --remote-store-bearer-token with --remote-store-bearer-token-file - Mount token Secret at /var/parca-agent in the DaemonSet
Configuration menu - View commit details
-
Copy full SHA for ce58893 - Browse repository at this point
Copy the full SHA ce58893View commit details -
deploy/gcp: also tag and annotate deployer image with patch version
Also expose imageTag as a schema property so the deployed version is explicit and overridable without rebuilding the deployer image.
Configuration menu - View commit details
-
Copy full SHA for b36354f - Browse repository at this point
Copy the full SHA b36354fView commit details -
deploy/gcp: bump to 0.47.1 and fix imageTag schema conflict
Remove the duplicate imageTag property from schema.yaml — it is auto-generated by the marketplace deployer from the image reference and having a default value caused expand_config.py to fail. Also bump publishedVersion to 0.47.1 to match the new deployer image.
Configuration menu - View commit details
-
Copy full SHA for d1d41e8 - Browse repository at this point
Copy the full SHA d1d41e8View commit details -
Bump the GCP Marketplace deployer, parca-agent image, schema publishedVersion, and Application version to 0.48.0. The manifest templates were still pinned at 0.45.1, so this also realigns them with the schema/Dockerfile that had moved ahead to 0.47.1.
Configuration menu - View commit details
-
Copy full SHA for ca268d3 - Browse repository at this point
Copy the full SHA ca268d3View commit details -
deploy: pull fresh bases on build, create gcp/tmp on generate
The Marketplace images are rebuilt to pick up CVE fixes in their base layers, but buildx was happy to reuse a cached base, so a "rebuild" could ship the exact same vulnerable layers. --pull matches what .goreleaser.yml already does for the upstream agent images. gcp/tmp is gitignored, so `make manifests` failed on a fresh checkout: generate.sh writes the GCP manifests there via `jsonnet -m`, which does not create the directory itself.
Configuration menu - View commit details
-
Copy full SHA for 020e243 - Browse repository at this point
Copy the full SHA 020e243View commit details -
Google Marketplace flagged both listing images for CVE-2026-39821 (GO-2026-5026), a Punycode validation flaw in golang.org/x/net/idna that lets an encoded label bypass a hostname privilege check. Bumping to 0.49.0 would not have been enough. Its x/net module is already v0.56.0, but idna is also vendored into the Go standard library, and v0.49.0 was built with go1.25.11 -- govulncheck on the shipped binary still reports GO-2026-5026 via net/http, plus seven other stdlib advisories. The fix landed in go1.25.13, so this needs a rebuild rather than a dependency bump. v0.49.1 is that rebuild. Also refreshes the release note, which still announced the initial Marketplace release.
Configuration menu - View commit details
-
Copy full SHA for 094eea7 - Browse repository at this point
Copy the full SHA 094eea7View commit details
Commits on Sep 8, 2026
-
deploy/gcp: overlay kubectl v1.37.0 in the deployer image
Marketplace flagged the deployer for CVE-2026-39821 (GO_STDLIB, go1.26.5, fixed in go1.26.6). None of that is ours. The only Go binary in the whole image is /opt/kubectl/v1.36/kubectl, which comes from Google's deployer_envsubst base. Rebuilding does not help. onbuild:latest and public-image-13.0.10 are the same digest, built 2026-08-18, so there is no newer base to pull, and upstream's newest v1.36 patch (v1.36.4) is also built with go1.26.5. kubectl v1.37.0 is the first release built with go1.26.6, so overlay that binary in place. /usr/bin/kubectl selects a binary by server version and falls back to /opt/kubectl/default, a symlink to this directory, so replacing the file keeps that logic intact. The tradeoff is server skew support moving from 1.35-1.37 to 1.36-1.38. Verified on the built image: kubectl is go1.26.6, it is the only Go binary present, and govulncheck reports no vulnerabilities.
Configuration menu - View commit details
-
Copy full SHA for 06481ec - Browse repository at this point
Copy the full SHA 06481ecView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff main...gcp

