What openchoreo/openchoreo shipped
Written by FoxPlug from public releases; not affiliated with Openchoreo. An automatic summary of the public release, pull request and commit data of github.com/openchoreo/openchoreo. Openchoreo did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- v1.3.0 released with Audit Logs (beta) for recording state-modifying operations across REST API and MCP servers, readable from portal, occ command, or MCP tool. Release
- v1.3.0-rc.1 released with Audit Logs and Cost Insights features. Release
- v1.3.0-rc.2 released as follow-up to rc.1. Release
- Cluster hooks feature added to the project. Pull request #4829
- Audit events from service accounts now record real actor.id instead of unknown. Pull request #4814
- occ auditlogs command fixed to properly scope context and handle ascending paging. Pull request #4831
readable_id_claimmade optional in control plane Helm schema to fix upgrade failures. Pull request #4837- Observability service ingress restricted in release-v1.1 backport while preserving required platform communication. Pull request #4810
- CI workflow split to separate candidate publication from build-and-test validation. Pull request #4812
- Hook enable flag removed. Pull request #4839
Why it matters
v1.3.0 brings audit logging to beta, allowing users to track all state-modifying operations across the platform with multiple access methods. This week includes fixes for service account auditing, Helm schema compatibility, and CLI command scoping to ensure the audit feature works reliably.
Changelog entry
- v1.3.0: Audit Logs (beta) for REST API and MCP servers; Cost Insights feature Release
- feat: add cluster hooks feature Pull request #4829
- fix: record real actor.id for service accounts in audit events Pull request #4814
- fix(cli): fix occ auditlogs context scoping and ascending paging Pull request #4831
- fix(helm): make
readable_id_claimoptional in control plane schema Pull request #4837 - fix(helm): restrict observability service ingress (backport to release-v1.1) Pull request #4810
- ci: split publish workflow into separate reusable workflow Pull request #4812
- chore: pin observability modules on release-v20260924 Pull request #4833
- fix: remove hook enable flag Pull request #4839
Openchoreo v1.3.0 is here. Audit Logs (beta) now captures every state-modifying operation across REST API and MCP servers—readable from portal, occ command, or MCP tool.
Openchoreo v1.3.0 is available. Audit Logs (beta) brings full visibility into state-modifying operations across the platform. Every change is now recorded in a policy-driven audit trail, accessible through the portal, occ auditlogs command, or as an MCP tool. Fixes include service account auditing, Helm schema compatibility, and CLI improvements.
Week of September 14, 2026
What shipped
- v1.3.0 is now marked as a GA release in the changelog. Pull request #4803
- Delivery Insights read API and logs-adapter events source shipped, letting users query delivery metrics through the observer. Pull request #4248
- Identity provider upgraded from Thunder 0.28.0 to ThunderID 1.0.1. Pull request #4751
- New
occ auditlogsCLI command added to query audit logs with filtering support. Pull request #4754 - Audit actor identity claim is now configurable, allowing deployments to use readable identities like email instead of opaque token IDs. Pull request #4758
- Portal assistant auth config now derives from security.subjects configuration instead of requiring hand-written ConfigMaps. Pull request #4777
- SRE agent tooling broadened to include Kubernetes events and managed Resource state, with new extensions mechanism. Pull request #4743
- MCP HTTP servers upgraded to go-sdk v1.7.0 and now use stateless HTTP to support MCP 2026-07-28 protocol. Pull request #4721
- Audit logging now enabled by default in quick-start, k3d and e2e setups when observability plane is installed. Pull request #4763
- v1.2.6 released with WorkflowRun authorization fix and simplified git basic auth handling. Release
Why it matters
v1.3.0 moves to GA with significant new observability and audit capabilities. The Delivery Insights API lets users track deployment metrics, the new audit commands provide better visibility into system actions, and configuration improvements make deployments more flexible. Users upgrading get a modern identity provider, broader agent capabilities, and audit logging that works out of the box.
Changelog entry
- v1.3.0 GA release marking Pull request #4803
- Delivery Insights read API and logs-adapter events source Pull request #4248
- occ auditlogs command for querying audit logs Pull request #4754
- Configurable audit actor ID claim (defaults to 'sub') Pull request #4758
- Identity provider upgraded to ThunderID 1.0.1 Pull request #4751
- Portal assistant auth config derived from security.subjects Pull request #4777
- SRE agent tooling broadened with Kubernetes events and Resource state Pull request #4743
- MCP HTTP servers upgraded to go-sdk v1.7.0 with stateless HTTP support Pull request #4721
- Audit logging enabled by default in quick-start, k3d and e2e setups with observability Pull request #4763
- v1.2.6 patch release with WorkflowRun authorization fix Release
v1.3.0 is now GA. Delivery Insights, configurable audit actor claims, and improved SRE tooling ship this week.
OpenChoreo v1.3.0 reaches GA with major observability improvements. New Delivery Insights read API and logs-adapter events source let you track deployment metrics. Audit logging works out of the box in local setups. The SRE agent can now see Kubernetes events and Resource state. Identity provider upgraded to ThunderID 1.0.1. Audit actor claims are configurable for better identity tracking.