ragleap-observability · release notes
2026-10-02 · ragleap-observability-v0.5.0
ragleap-observability v0.5.0
Added
- Dedicated zero-permission ServiceAccounts for Prometheus, Grafana, Loki, AlertManager and postgres-exporter (
serviceAccount.create), with no API token mounted.
- Configurable Grafana admin credentials:
grafana.admin.password, grafana.admin.existingSecret, plus a warning when the placeholder password is in use.
Changed
- Promtail's ClusterRole grants
pods only (the unused nodes permission was dropped).
Verified
- On a live
kind cluster: no token in the pods, Prometheus/Grafana/Loki/Promtail still working after rollout, Grafana 200/401 login test, can-i list nodes = no, grafana cli admin reset-admin-password procedure.
Known limitations
- The placeholder Grafana password is still the default when no option is set; upgrading does not change it on an existing release.
- No real Slack or email send has been confirmed yet.
Release notes mirrored from GitHub Releases.