diff --git a/CHANGELOG.md b/CHANGELOG.md index c59a936e..ff989702 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -316,6 +316,11 @@ Skeleton (copy what you need): and compose pins, one grouped PR per plugin. #### Services +- **order v2.10.2 and checkout v0.13.2 on Kind** (Temporal Go SDK 1.49.0; + order-worker and checkout-worker too). Both tags passed the full + local-stack release audit (A/B/C + C22) from scratch on their merged SHAs; + the first run's C22 found the SDK's new `failure_reason` attribute missing + from the semconv registry, which pkg#117 declared before the rerun. - **The fleet runs on Go 1.27.1** ([#1107](https://github.com/duynhlab/homelab/issues/1107) G2): user 2.5.1, product 1.16.1, inventory 0.9.1, cart 2.4.1, order 2.10.1, review 2.4.1, shipping 1.9.1, notification 2.4.1, payment 2.6.1, checkout diff --git a/kubernetes/apps/checkout-worker.yaml b/kubernetes/apps/checkout-worker.yaml index 6988862c..0bb44804 100644 --- a/kubernetes/apps/checkout-worker.yaml +++ b/kubernetes/apps/checkout-worker.yaml @@ -92,7 +92,7 @@ spec: # one shared binary, two subcommands, one CVE surface. # # THE ONE LINE a release edits. - image: ghcr.io/duynhlab/checkout-service/checkout-service:0.13.1 + image: ghcr.io/duynhlab/checkout-service/checkout-service:0.13.2 imagePullPolicy: IfNotPresent args: ["worker"] ports: diff --git a/kubernetes/apps/order-worker.yaml b/kubernetes/apps/order-worker.yaml index 43c238f8..fa4dc5f3 100644 --- a/kubernetes/apps/order-worker.yaml +++ b/kubernetes/apps/order-worker.yaml @@ -144,7 +144,7 @@ spec: # skew is a real (if narrow) coupling -- widen it only when the replay # corpus and the migrations both say it is safe. The retired per-build # manifest carried this caveat and it was worth keeping. - image: ghcr.io/duynhlab/order-service/order-service:2.10.1 + image: ghcr.io/duynhlab/order-service/order-service:2.10.2 imagePullPolicy: IfNotPresent args: ["worker"] ports: diff --git a/kubernetes/apps/services/checkout.yaml b/kubernetes/apps/services/checkout.yaml index f0ddd0ce..933b36ed 100644 --- a/kubernetes/apps/services/checkout.yaml +++ b/kubernetes/apps/services/checkout.yaml @@ -77,7 +77,7 @@ spec: # released, no Retry-After); transient 503 arms unchanged; httpx v0.37.0. # Lands in the same train as frontend 3.2.0 — the SPA must never meet a # code it cannot word. Compose gate 2026-08-19 (A21 asserts the new wire). - image_tag: "0.13.1" # {"$imagepolicy": "flux-system:checkout:tag"} + image_tag: "0.13.2" # {"$imagepolicy": "flux-system:checkout:tag"} # 0.7.1: a promo code whose cap is already spent answers 409 PROMO_EXHAUSTED # at apply, matching the confirm gate; it answered 500 before, which the # storefront could only render as "Service temporarily unavailable" diff --git a/kubernetes/apps/services/order.yaml b/kubernetes/apps/services/order.yaml index 633e6d59..986f56a1 100644 --- a/kubernetes/apps/services/order.yaml +++ b/kubernetes/apps/services/order.yaml @@ -69,7 +69,7 @@ spec: # registered is traced and logged as an ordinary 404 rather than vanishing. # Compose E2E audit passed on this code before the tag; measured 0 -> 15 spans # for /metrics and 0 for /health and /ready, unchanged. - image_tag: "2.10.1" # {"$imagepolicy": "flux-system:order:tag"} + image_tag: "2.10.2" # {"$imagepolicy": "flux-system:order:tag"} namespace: order # RFC-0024 P3: authmw consumer — the domain template injects the explicit # OIDC_ISSUER/OIDC_JWKS_URL pair (Keycloak realm; pkg v0.37.0 contract).