Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
40ccd18
Add v0.4 to version picker
ntnn Jul 8, 2026
f9ec1dd
update index,html and other setup docs to 0.4 (#237)
mengliwg Jul 9, 2026
23669f6
Audit GitHub Actions, fix issues, and add zizmor job (#238)
xmudrii Jul 13, 2026
505f65b
chore(deps): update all non-major dependencies (#242)
renovate[bot] Aug 3, 2026
646eb93
docs(how-to): add air-gapped installation guide (#243)
Perseus985 Aug 7, 2026
775ee58
chore(deps): update actions/checkout action to v7 (#234)
renovate[bot] Aug 9, 2026
cdb0753
chore(deps): update actions/setup-node action to v7 (#241)
renovate[bot] Aug 9, 2026
7043839
docs: add provider permissions documentation (#244)
OlegErshov Aug 12, 2026
d4283e7
fix: patch dependency vulnerabilities (8 → 4 dev-only) (#247)
gkrajniak Aug 13, 2026
5bc9acd
Restrict CODEOWNERS to maintainer teams
ntnn Aug 28, 2026
568d29b
chore(deps): lock file maintenance (#248)
renovate[bot] Aug 30, 2026
4154c19
Update the Platform Mesh Talks page (#250)
xmudrii Sep 1, 2026
b43124b
Update all non-major dependencies (#253)
renovate[bot] Sep 13, 2026
f6c0b1c
docs: document uiConfig.filters catalog filter configuration (#254)
gkrajniak Sep 15, 2026
88f2634
fix(deps): override vite to resolve vite and esbuild vulnerabilities …
gkrajniak Sep 16, 2026
39d20c7
docs: document portal UI and server libraries (#255)
gkrajniak Sep 17, 2026
5f31baf
add 0.5 to the release dropdown
xrstf Sep 24, 2026
01584aa
Merge pull request #258 from xrstf/add-0.5
xrstf Sep 24, 2026
4c26181
fix: use publisher app to deploy to branch to work with current branc…
aaronschweig Sep 24, 2026
755f0bd
chore: adress zizimor findings
aaronschweig Sep 24, 2026
8ab8651
chore: dont try to generate app token for forks as secrets are not sh…
aaronschweig Sep 24, 2026
399383f
Merge remote-tracking branch 'upstream/main' into ci/update
akafazov Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 17 additions & 5 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ on:
- closed

permissions:
contents: read
contents: read # Baseline for actions/checkout; elevated scopes are granted per-job

concurrency:
group: pages-preview-${{ github.event.pull_request.number }}
Expand All @@ -22,13 +22,24 @@ jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
contents: read # Only reads for checkout; gh-pages push and PR comment use the platform-mesh-publisher app token
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
persist-credentials: false

- id: app-token
name: Generate platform-mesh-publisher app token
if: ${{ !github.event.pull_request.head.repo.fork }} # Secrets are unavailable on fork PRs; preview deploy below is likewise skipped
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: "1415820" # platform-mesh-publisher
private-key: ${{ secrets.PM_PUBLISHER_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 24
cache: npm
Expand All @@ -49,4 +60,5 @@ jobs:
- uses: rossjrw/pr-preview-action@ffa7509e91a3ec8dfc2e5536c4d5c1acdf7a6de9 # v1
if: ${{ !github.event.pull_request.head.repo.fork }}
with:
token: ${{ steps.app-token.outputs.token }}
source-dir: .vitepress/dist
10 changes: 5 additions & 5 deletions .github/workflows/ossf-scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,9 @@ permissions:

jobs:
scorecard:
uses: platform-mesh/.github/.github/workflows/job-ossf-scorecard.yml@068efd5c6c7a6d0c4b28f5887de7ca156cb5f7b8 # main
uses: platform-mesh/.github/.github/workflows/job-ossf-scorecard.yml@ab6caea57060a3eba5fc58cadbb2aaa1b06da18a # main
permissions:
security-events: write
id-token: write
contents: read
actions: read
security-events: write # Needed to upload Scorecard results to the GitHub Security tab
id-token: write # Needed for keyless publishing of Scorecard results
contents: read # Needed to read repository contents
actions: read # Needed to read GitHub Actions workflows
30 changes: 21 additions & 9 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ on:
workflow_dispatch:

permissions:
contents: read
contents: read # Baseline for actions/checkout; elevated scopes are granted per-job

concurrency:
group: pages-${{ github.ref_name }}
Expand All @@ -18,25 +18,35 @@ jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: write
contents: read # Only reads for checkout; pushes to gh-pages use the platform-mesh-publisher app token
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
persist-credentials: false

- id: app-token
name: Generate platform-mesh-publisher app token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: "1415820" # platform-mesh-publisher
private-key: ${{ secrets.PM_PUBLISHER_PRIVATE_KEY }}
permission-contents: write

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 24
cache: npm
cache: npm # zizmor: ignore[cache-poisoning]

- id: configure
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6

- id: set-version
name: Set documentation version
run: |
if [[ "${{ github.ref }}" == "refs/heads/main" ]]; then
if [[ "${GITHUB_REF}" == "refs/heads/main" ]]; then
echo "version=main" >> $GITHUB_OUTPUT
elif [[ "${{ github.ref }}" == refs/heads/release-* ]]; then
elif [[ "${GITHUB_REF}" == refs/heads/release-* ]]; then
echo "version=${GITHUB_REF#refs/heads/}" >> $GITHUB_OUTPUT
else
echo "version=" >> $GITHUB_OUTPUT
Expand All @@ -48,18 +58,20 @@ jobs:
DOCS_VERSION: ${{ steps.set-version.outputs.version }}
PAGES_BASE: ''

- uses: JamesIves/github-pages-deploy-action@d92aa235d04922e8f08b40ce78cc5442fcfbfa2f # v4
- uses: JamesIves/github-pages-deploy-action@fa24774553152dd7873cd16ebd8d959b010c5445 # v4
if: ${{ github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/heads/release-') }}
with:
token: ${{ steps.app-token.outputs.token }}
folder: .vitepress/dist
branch: gh-pages
target-folder: ${{ steps.set-version.outputs.version }}
clean-exclude: pr-preview
force: false

- uses: JamesIves/github-pages-deploy-action@d92aa235d04922e8f08b40ce78cc5442fcfbfa2f # v4
- uses: JamesIves/github-pages-deploy-action@fa24774553152dd7873cd16ebd8d959b010c5445 # v4
if: ${{ github.ref == 'refs/heads/main' }}
with:
token: ${{ steps.app-token.outputs.token }}
folder: .
branch: gh-pages
target-folder: .
Expand Down
26 changes: 26 additions & 0 deletions .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
name: Zizmor
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '30 4 * * 1'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
zizmor:
uses: platform-mesh/.github/.github/workflows/job-zizmor.yml@ab6caea57060a3eba5fc58cadbb2aaa1b06da18a # main
with:
persona: 'auditor'
permissions:
security-events: write # Needed to write to the GitHub Security tab
contents: read # Needed to read repository contents
actions: read # Needed to read GitHub Actions workflows
8 changes: 8 additions & 0 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# zizmor configuration for platform-mesh.github.io workflows.
# https://docs.zizmor.sh/configuration/
rules:
# Repo convention: jobs are identified by their key (e.g. `build`), not a
# separate display name. Adding `name:` to every job would fight the
# established style across the workflows here.
anonymous-definition:
disable: true
17 changes: 15 additions & 2 deletions .vitepress/config.mts
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,10 @@ export default withMermaid({
)
},
]
}
},
optimizeDeps: {
include: ['mermaid'],
},
},


Expand Down Expand Up @@ -121,6 +124,7 @@ export default withMermaid({
items: [
{ text: 'Set up Platform Mesh locally', link: '/how-to-guides/set-up-platform-mesh-locally' },
{ text: 'Set up remote deployment', link: '/how-to-guides/set-up-remote-deployment' },
{ text: 'Air-gapped deployment', link: '/how-to-guides/install-air-gapped' },
{ text: 'Speed up local rebuilds', link: '/how-to-guides/speed-up-local-rebuilds' },
]
},
Expand Down Expand Up @@ -223,7 +227,15 @@ export default withMermaid({
{ text: 'OpenFGA', link: '/reference/components/openfga' },
{ text: 'rebac-authz-webhook', link: '/reference/components/rebac-authz-webhook' },
{ text: 'Kubernetes GraphQL gateway', link: '/reference/components/kubernetes-graphql-gateway' },
{ text: 'Portal', link: '/reference/components/portal' },
{
text: 'Portal',
link: '/reference/components/portal',
collapsed: false,
items: [
{ text: 'Portal UI library', link: '/reference/components/portal/portal-ui-lib' },
{ text: 'Portal server library', link: '/reference/components/portal/portal-server-lib' },
],
},
{ text: 'Marketplace', link: '/reference/components/marketplace' },
{ text: 'virtual-workspaces', link: '/reference/components/virtual-workspaces' },
{ text: 'Observability', link: '/reference/components/observability' },
Expand All @@ -244,6 +256,7 @@ export default withMermaid({
{ text: 'IAM Store resource', link: '/reference/resources/iamstore-resource' },
{ text: 'ContentConfiguration', link: '/reference/resources/content-configuration' },
{ text: 'Metadata catalog', link: '/reference/resources/metadata-catalog' },
{ text: 'ProviderPermissions', link: '/reference/resources/provider-permissions-resource' },
]
},
{
Expand Down
1 change: 1 addition & 0 deletions .vitepress/theme/components/VersionSelector.vue
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ interface Version {
// Define available versions - update this list when adding new versions
const versions: Version[] = [
{ name: 'main', label: 'main (latest)' },
{ name: 'release-0.5', label: 'v0.5' },
{ name: 'release-0.4', label: 'v0.4' },
{ name: 'release-0.3', label: 'v0.3' },
{ name: 'release-0.2', label: 'v0.2' },
Expand Down
2 changes: 1 addition & 1 deletion CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1 +1 @@
* @platform-mesh/kube
* @platform-mesh/go-maintainers @platform-mesh/node-maintainers
42 changes: 32 additions & 10 deletions community/talks.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,33 +8,43 @@ This page lists Platform Mesh talks — upcoming conference sessions and recordi

## Upcoming

### Polymorphic interfaces in kcp: The three vendor problem
### Scaling Kube-Apiserver to Thousands of Tenants – Lessons Learned From kcp

[KCD Helsinki 2026](https://community2.cncf.io/events/details/cncf-kcd-helsinki-presents-kubernetes-community-days-helsinki-2026/) — May 20, 2026.
[ContainerDays Hamburg 2026](https://www.containerdays.io/containerdays-hamburg-2026/) — September 2–4, 2026.

### Platform Mesh: Breaking API Lock-In for True Multi-Cloud Service Portability
## 2026

[ContainerDays Hamburg 2026](https://www.containerdays.io/containerdays-hamburg-2026/) — September 2–4, 2026.
### Kubernetes Plane Aerodynamics: Breaking the Architectural Sound Barrier

## Recordings
[KubeCon + CloudNativeCon India 2026](https://events.linuxfoundation.org/kubecon-cloudnativecon-india/) — Mumbai, June 2026.

### Platform Mesh: Breaking API Lock-In for True Multi-Cloud Service Portability
[Watch on YouTube](https://youtu.be/oh24ueXj8cc)

[KubeCon + CloudNativeCon Europe 2026](https://kccnceu2026.sched.com/) — Amsterdam, March 2026.
### Polymorphic interfaces in kcp: The three vendor problem

[Watch on YouTube](https://www.youtube.com/watch?v=43X0_U3cc-Y)
[KCD Helsinki 2026](https://community2.cncf.io/events/details/cncf-kcd-helsinki-presents-kubernetes-community-days-helsinki-2026/) — Helsinki, May 2026.

No recording available, check out Cloud Native Suisse Romande 2025 talk.

### Sovereignty = func(Ecosystems, Interoperability)

Platform Mesh and [OCM](https://ocm.software/) in the context of sovereignty.

[ALASCA Tech-Talk #35](https://alasca.cloud/en/alasca-tech-talks/).
[ALASCA Tech-Talk #35](https://alasca.cloud/en/alasca-tech-talks/) — Online, April 2026.

[Watch on YouTube](https://www.youtube.com/watch?v=hzkrbW_J7U0)

### Platform Mesh: Breaking API Lock-In for True Multi-Cloud Service Portability

[KubeCon + CloudNativeCon Europe 2026](https://kccnceu2026.sched.com/) — Amsterdam, March 2026.

[Watch on YouTube](https://www.youtube.com/watch?v=43X0_U3cc-Y)

## 2025

### Polymorphic interfaces in kcp: The three vendor problem

[Cloud Native Suisse Romande](https://community.cncf.io/cloud-native-suisse-romande/).
[Cloud Native Suisse Romande 2025](https://community.cncf.io/cloud-native-suisse-romande/) — Geneva, December 2025.

[Watch on YouTube](https://www.youtube.com/watch?v=AG9-DdW32xg)

Expand All @@ -43,3 +53,15 @@ Platform Mesh and [OCM](https://ocm.software/) in the context of sovereignty.
[ContainerDays Conference 2025](https://www.containerdays.io/containerdays-conference-2025/) — Hamburg, September 2025.

[Watch on YouTube](https://www.youtube.com/watch?v=8GFDj_-scSQ)

### Building Europe's Cloud Future: NeoNephos' Platform Mesh

[Open Source Summit Europe 2025](https://events.linuxfoundation.org/archive/2025/open-source-summit-europe/) — Amsterdam, August 2025.

[Watch on YouTube](https://youtu.be/k7U2KT-rw7o)

### NeoNephos' OpenMFP and Platform Mesh: Building Composable Enterprise Arcitectures

[Open Source Summit Europe 2025](https://events.linuxfoundation.org/archive/2025/open-source-summit-europe/) — Amsterdam, August 2025.

[Watch on YouTube](https://youtu.be/vpDGQgCaLt8)
1 change: 1 addition & 0 deletions how-to-guides/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ How-to guides are task-focused. Use them when you already know what you want to

- [Set up Platform Mesh locally](./set-up-platform-mesh-locally.md)
- [Set up remote deployment](./set-up-remote-deployment.md)
- [Air-gapped deployment](./install-air-gapped.md)
- [Speed up local rebuilds](./speed-up-local-rebuilds.md)

## Platform operators
Expand Down
Loading
Loading