Changelog
Notable changes to Egret Nest Dashboard, following Keep a Changelog and Semantic Versioning.
[0.2.0] - Security hardening (pentest remediation)
Changed (upgrade impact)
- The server refuses to start without
EGRET_NEST_SECRET_KEYwhen TOTP data would otherwise be stored unencrypted. Set the key, or explicitly opt into the old behavior withEGRET_NEST_ALLOW_PLAINTEXT_TOTP=1. This was previously a warning that silently continued with plaintext TOTP seeds at rest. - SSO login is refused until first-run setup is complete. A brand-new SSO account can no longer be auto-provisioned before the instance is bootstrapped, closing a race where an early SSO login could permanently lock the operator out of the admin console.
- The Helm chart now defaults
networkPolicy.enabled: true(default-deny egress). It degrades gracefully on a CNI that doesn’t enforce NetworkPolicy. - Default deployment examples pin a released image tag instead of
latest(compose,.env.example, docs); floating tags are noted as convenience-only.
Security
- First-run bootstrap is race-safe. The
bootstrappedstate is claimed atomically alongside admin creation, and SSO provisioning + the/setupgate both key off it, so exactly one admin is ever created (verified under concurrent load). - Login no longer leaks account existence via timing. The unknown-user / SSO-only path now runs a dummy argon2id verification so it costs the same as a real wrong-password attempt.
- Container images are vulnerability-scanned before publish. The release workflow runs Trivy (fail on HIGH/CRITICAL) between build and push.
- CI/CD hardening:
concurrencycancellation on PR workflows. - The one-time setup token is accessed atomically (
atomic.Pointer), fixing a data race under concurrent/setuprequests.
Changed
- Ingress TLS enforcement is configurable (
ingress.sslRedirect), and the docs recommendexistingSecret(SOPS / External Secrets / Vault) as the primary way to supply secrets rather than plaintextvalues.yaml.
0.1.1 - Brand, distribution, and hardening
Added
- Docker Hub distribution. The container image is mirrored to
nx1x/egret-nestalongside GHCR, with floatinglatest/v0/v0.1tags, and the Docker Hub repo overview is kept in sync with the README. - Go fuzzing over the untrusted-input parsing paths, plus contributor onboarding docs.
Changed
- New visual identity - an egret-in-flight mark across the icon, app-icon, logo (a self-contained dark-card lockup), favicon, and social preview; the README now leads with the logo.
- Wider security policy in SECURITY.md - explicit safe harbor for good-faith research, response-time targets, coordinated disclosure, and reporter credit (plain email, no PGP required).
Security
- Go toolchain 1.26.5 and refreshed digest-pinned Actions and base images (clears the stdlib advisories).
0.1.0 - first release
The optional self-hosted dashboard for Egret: ingest CI/CD runs and view egress over time, endpoint drift, and violations across your fleet, with multi-tenant access control. Ships as a single Go binary with embedded SQLite - no external services required.
Added
- Run ingest + history. The Egret agent/Action POSTs each run; stored in embedded SQLite. Run list/detail, per-repo egress-over-time, org fleet view, and new-endpoint drift (inline-SVG sparklines, no JavaScript).
- Authentication - one core, three providers. Local accounts (argon2id) with self-service TOTP 2FA, GitHub OAuth, and generic OIDC (Okta / Entra / Google), configurable via env or an admin UI (client secrets encrypted at rest, env always wins).
- Authorization (multi-tenant RBAC). Organizations → repositories → runs, with fail-closed org membership (SSO authenticates identity; an admin grants access), per-org roles (owner/admin/member/viewer), and scoped, revocable ingest tokens.
- Admin console. Settings, connect-a-repo, user management, audit log, live access log, and retention controls.
- Deploy. Dockerfile, hardened
docker-compose(+ optional nginx TLS), a Helm chart,healthcheck+backupcommands, and a deployment guide.
Security
- Hardened for crown-jewel data: native TLS (or behind a proxy),
__Host-cookies, CSRF on every mutation, a strict CSP (script-src 'none'), argon2id password hashing, AES-256-GCM secrets at rest, HMAC-verified webhooks, token-gated metrics, and an audit trail. - SSRF-guarded OIDC: every OIDC fetch for a UI-configured issuer refuses internal addresses at dial time (closes DNS-rebinding and attacker-declared-endpoint holes).
- Supply chain: digest-pinned base images, SHA-pinned Actions, container CVE
scanning (Trivy),
govulncheck, and CodeQL.