From 12ba004c1d2b0edbec07df9bf4438ddc7bb659b3 Mon Sep 17 00:00:00 2001
From: chen21019 <19357113+chen21019@users.noreply.github.com>
Date: Tue, 22 Sep 2026 18:25:05 +0800
Subject: [PATCH] Reconcile accounts into shared Default environment
---
COMPATIBILITY.md | 20 ++-
README.md | 16 +-
code/framework/api-pub-sub-jetty/pom.xml | 2 +-
code/framework/api-pub-sub/pom.xml | 2 +-
code/framework/api/pom.xml | 2 +-
code/framework/archaius/pom.xml | 2 +-
code/framework/async/pom.xml | 2 +-
code/framework/auditing/pom.xml | 2 +-
code/framework/db-loader/pom.xml | 2 +-
code/framework/deferred/pom.xml | 2 +-
code/framework/encryption/pom.xml | 2 +-
code/framework/engine/pom.xml | 2 +-
code/framework/eventing/pom.xml | 2 +-
code/framework/events/pom.xml | 2 +-
code/framework/extension-spring/pom.xml | 2 +-
code/framework/extension/pom.xml | 2 +-
code/framework/java-server/pom.xml | 2 +-
code/framework/jmx/pom.xml | 2 +-
code/framework/jooq/pom.xml | 2 +-
code/framework/json/pom.xml | 2 +-
code/framework/launcher/pom.xml | 2 +-
code/framework/lock/pom.xml | 2 +-
code/framework/logback/pom.xml | 2 +-
code/framework/managed-context/pom.xml | 2 +-
code/framework/metrics/pom.xml | 2 +-
code/framework/module/pom.xml | 2 +-
code/framework/object/pom.xml | 2 +-
code/framework/pool/pom.xml | 2 +-
code/framework/resource-monitor/pom.xml | 2 +-
code/framework/schema/pom.xml | 2 +-
code/framework/server/pom.xml | 2 +-
code/framework/spring/pom.xml | 2 +-
code/framework/system-task/pom.xml | 2 +-
code/framework/token/pom.xml | 2 +-
code/framework/utils/pom.xml | 2 +-
code/iaas/agent-instance/pom.xml | 2 +-
code/iaas/agent-server/pom.xml | 2 +-
code/iaas/agent/pom.xml | 2 +-
code/iaas/allocator/pom.xml | 2 +-
code/iaas/api-logic/pom.xml | 2 +-
code/iaas/archaius-management/pom.xml | 2 +-
code/iaas/auth-logic/pom.xml | 2 +-
.../iaas/api/auth/AbstractTokenUtil.java | 24 ++-
.../platform/iaas/api/auth/dao/AuthDao.java | 2 +
.../iaas/api/auth/dao/impl/AuthDaoImpl.java | 20 +++
.../auth/projects/ProjectResourceManager.java | 17 ++
...jectResourceManagerDefaultProjectTest.java | 152 ++++++++++++++++++
code/iaas/bootstrap/pom.xml | 2 +-
code/iaas/config-item/api/pom.xml | 2 +-
code/iaas/config-item/common/pom.xml | 2 +-
code/iaas/config-item/server/pom.xml | 2 +-
code/iaas/engine-jooq/pom.xml | 2 +-
code/iaas/events/pom.xml | 2 +-
code/iaas/external-handler/pom.xml | 2 +-
code/iaas/ha/pom.xml | 2 +-
code/iaas/healthcheck/pom.xml | 2 +-
code/iaas/labels/pom.xml | 2 +-
code/iaas/logic-common/pom.xml | 2 +-
code/iaas/logic/pom.xml | 2 +-
code/iaas/metadata/pom.xml | 2 +-
code/iaas/model/pom.xml | 2 +-
.../core/constants/ProjectConstants.java | 2 +
code/iaas/resource-pool/pom.xml | 2 +-
code/iaas/service-discovery/api/pom.xml | 2 +-
code/iaas/service-discovery/server/pom.xml | 2 +-
code/iaas/ssh-common/pom.xml | 2 +-
code/iaas/storage-service/pom.xml | 2 +-
code/iaas/task-jooq/pom.xml | 2 +-
code/implementation/activity-log/pom.xml | 2 +-
.../agent-instance-impl/pom.xml | 2 +-
code/implementation/docker/api/pom.xml | 2 +-
code/implementation/docker/common/pom.xml | 2 +-
code/implementation/docker/compute/pom.xml | 2 +-
code/implementation/docker/machine/pom.xml | 2 +-
code/implementation/docker/storage/pom.xml | 6 +-
code/implementation/extension-api/pom.xml | 2 +-
code/implementation/hazelcast/common/pom.xml | 2 +-
.../implementation/hazelcast/eventing/pom.xml | 2 +-
code/implementation/hazelcast/lock/pom.xml | 2 +-
code/implementation/host-api/pom.xml | 2 +-
code/implementation/host-stats/pom.xml | 2 +-
code/implementation/register/pom.xml | 2 +-
code/implementation/sample-setup/pom.xml | 2 +-
.../sample/data/SampleDataStartupV3.java | 2 +-
code/implementation/settings-api/pom.xml | 2 +-
.../simulator/agent-connection/pom.xml | 2 +-
code/implementation/simulator/storage/pom.xml | 2 +-
code/implementation/system-stack/pom.xml | 2 +-
code/implementation/vm/pom.xml | 2 +-
code/meta-parent/pom.xml | 2 +-
code/packaging/app-config/pom.xml | 2 +-
.../cattle/iaas-api/defaults.properties | 1 +
code/packaging/app/pom.xml | 2 +-
code/packaging/bundle/pom.xml | 2 +-
code/packaging/dev/pom.xml | 2 +-
code/packaging/meta/pom.xml | 2 +-
code/parent/pom.xml | 2 +-
.../orchestration-engine-0.183.317.md | 21 +++
pom.xml | 2 +-
resources/pom.xml | 2 +-
scripts/build | 2 +-
scripts/check-pasturestack-source | 9 +-
scripts/check-release-artifact | 2 +-
103 files changed, 366 insertions(+), 106 deletions(-)
create mode 100644 code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManagerDefaultProjectTest.java
create mode 100644 docs/releases/orchestration-engine-0.183.317.md
diff --git a/COMPATIBILITY.md b/COMPATIBILITY.md
index 584c51d8e7..e91d8b5ce5 100644
--- a/COMPATIBILITY.md
+++ b/COMPATIBILITY.md
@@ -6,7 +6,7 @@ New operator-facing names use PastureStack and `PASTURESTACK_*`. Compatibility i
## Docker host policy
-Release `0.183.316` preserves the Docker host policy introduced in `0.183.299`,
+Release `0.183.317` preserves the Docker host policy introduced in `0.183.299`,
which adds Docker Engine `29.8.0` as an exact supported
version alongside the preserved legacy ranges, `24.0.9`, and the existing
`29.4.1` through `29.7.2` interval. It does not widen the interval to admit
@@ -23,6 +23,24 @@ modifying another backend. Each of those modes needs runtime acceptance on
the relevant host before a Server release that consumes this Engine is
published as fully supported.
+## Shared Default environment
+
+Release `0.183.317` changes only the default-environment provisioning policy.
+When `project.create.default=true` and `project.default.provisioning=shared`, a
+successful external login reconciles the account into the project whose stable
+UUID is `adminProject`. The membership identity is the internal `rancher_id`
+for that exact account and the baseline role is `member`.
+
+Reconciliation is idempotent and serialized by the existing project lock. If
+any identity in the authenticated set already has an active direct or group
+membership, that role is authoritative and no baseline membership is added.
+This preserves explicit owner, restricted, read-only, or no-access decisions.
+The migration does not delete the personal environments made by older releases
+or move their stacks; returning accounts gain the shared Default on the next
+successful login. Operators can retain the former first-login behavior with
+`project.default.provisioning=personal`, or disable default provisioning with
+`none`.
+
## External identity type upgrades
`oidc_user` and `oidc_group` are built-in OpenID Connect identity types. An
diff --git a/README.md b/README.md
index 82e0c5aa0e..9b8ead21c0 100644
--- a/README.md
+++ b/README.md
@@ -9,8 +9,8 @@ PastureStack is an independent community effort to preserve, audit, and moderniz
## Project status
The current public GitHub Release
-[`v0.183.316`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.316)
-produces engine version `0.183.316`. It retains the existing Java 25, Ubuntu
+[`v0.183.317`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.317)
+produces engine version `0.183.317`. It retains the existing Java 25, Ubuntu
26.04, Maven, Liquibase, MariaDB/MySQL, WebSocket, dependency, concurrency, and
runtime-hardening work from the maintained compatibility line. Release builds
consume the exact `5.7.4` runtime JAR published by
@@ -21,6 +21,14 @@ product identity and provenance are carried by the artifact name, metadata,
SBOM, and release evidence. Provenance and scope are documented in
[`third-party/HAZELCAST.md`](third-party/HAZELCAST.md).
+Release `0.183.317` gives every eligible external account access to the one
+shared Default environment instead of creating a new personal environment on
+first login. Provisioning uses the stable platform account identity and is
+idempotent under the existing project lock. An existing direct or group role,
+including `noaccess`, is preserved and never replaced by the baseline `member`
+role; existing environments and workloads are not removed. Returning accounts
+created by earlier releases are reconciled on their next successful login.
+
Release `0.183.316` keeps the documented local-administrator recovery path
usable when OpenID Connect uses `required` site access. A completed local
password and MFA recovery login is represented by a server-encrypted local
@@ -169,7 +177,7 @@ dependency line. The existing platform JSON surface remains on
`com.fasterxml.jackson` 2.22. Packaging gates admit only the reviewed,
version-pinned pair and verify that their class namespaces are disjoint.
-Host compatibility is evidence-based. Release `0.183.316` preserves the legacy ranges and Docker Engine `24.0.9`, retains the bounded `29.4.1` through `29.7.2` interval, and supports exactly `29.8.0`. It does not admit unverified `29.7.3` or `29.8.1`, or Docker 25 through 28. The frontend marks versions above the configured newest version as *untested*, not *supported*. Every Server release that consumes this policy must still pass its Ubuntu 26.04 host and installed firewall-backend runtime acceptance gate.
+Host compatibility is evidence-based. Release `0.183.317` preserves the legacy ranges and Docker Engine `24.0.9`, retains the bounded `29.4.1` through `29.7.2` interval, and supports exactly `29.8.0`. It does not admit unverified `29.7.3` or `29.8.1`, or Docker 25 through 28. The frontend marks versions above the configured newest version as *untested*, not *supported*. Every Server release that consumes this policy must still pass its Ubuntu 26.04 host and installed firewall-backend runtime acceptance gate.
The build and Dapper images still compile the Docker `29.7.2` CLI from the pinned official tag commit with Go `1.27.0`; the CLI tool version is separate from the Docker daemon host support setting. They do not import Docker's precompiled Go `1.26.5` binary. The source archive SHA-256 and Go builder image digest are enforced by the source gate and the resulting images are scanned before release.
@@ -217,7 +225,7 @@ The gate performs dependency-hygiene checks, builds every Maven module with JDK
To create the complete release archive after the gate passes:
```sh
-ENGINE_VERSION=0.183.316 bash scripts/build --release
+ENGINE_VERSION=0.183.317 bash scripts/build --release
bash scripts/check-release-artifact dist/artifacts/cattle.jar
```
diff --git a/code/framework/api-pub-sub-jetty/pom.xml b/code/framework/api-pub-sub-jetty/pom.xml
index 33d8c5d333..1d62f0d1a1 100644
--- a/code/framework/api-pub-sub-jetty/pom.xml
+++ b/code/framework/api-pub-sub-jetty/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/api-pub-sub/pom.xml b/code/framework/api-pub-sub/pom.xml
index 165ffe7fa9..d0d845d3e7 100644
--- a/code/framework/api-pub-sub/pom.xml
+++ b/code/framework/api-pub-sub/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/api/pom.xml b/code/framework/api/pom.xml
index af0e55a1c6..842990859e 100644
--- a/code/framework/api/pom.xml
+++ b/code/framework/api/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/archaius/pom.xml b/code/framework/archaius/pom.xml
index 9c766d91a4..83c4e78298 100644
--- a/code/framework/archaius/pom.xml
+++ b/code/framework/archaius/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-meta-parent
- 0.183.316
+ 0.183.317
../../meta-parent/pom.xml
diff --git a/code/framework/async/pom.xml b/code/framework/async/pom.xml
index 470728bcdb..3869733983 100644
--- a/code/framework/async/pom.xml
+++ b/code/framework/async/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/auditing/pom.xml b/code/framework/auditing/pom.xml
index 425fc9310f..2f609e6b59 100644
--- a/code/framework/auditing/pom.xml
+++ b/code/framework/auditing/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/db-loader/pom.xml b/code/framework/db-loader/pom.xml
index 33c25bb1f0..8f1cc167e4 100644
--- a/code/framework/db-loader/pom.xml
+++ b/code/framework/db-loader/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/deferred/pom.xml b/code/framework/deferred/pom.xml
index 0b202977c7..92a45a633d 100644
--- a/code/framework/deferred/pom.xml
+++ b/code/framework/deferred/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/encryption/pom.xml b/code/framework/encryption/pom.xml
index e4715d5792..6c480a5ffa 100644
--- a/code/framework/encryption/pom.xml
+++ b/code/framework/encryption/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/engine/pom.xml b/code/framework/engine/pom.xml
index 464dfbd161..8457a31adf 100644
--- a/code/framework/engine/pom.xml
+++ b/code/framework/engine/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/eventing/pom.xml b/code/framework/eventing/pom.xml
index 23f1681da7..5065dc3b1b 100644
--- a/code/framework/eventing/pom.xml
+++ b/code/framework/eventing/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/events/pom.xml b/code/framework/events/pom.xml
index a70a9bf06d..6cddc5bad9 100644
--- a/code/framework/events/pom.xml
+++ b/code/framework/events/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/extension-spring/pom.xml b/code/framework/extension-spring/pom.xml
index 1e91eebd55..265f2e3f8c 100644
--- a/code/framework/extension-spring/pom.xml
+++ b/code/framework/extension-spring/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/extension/pom.xml b/code/framework/extension/pom.xml
index b1114560b5..518d734159 100644
--- a/code/framework/extension/pom.xml
+++ b/code/framework/extension/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/java-server/pom.xml b/code/framework/java-server/pom.xml
index 2cee45e366..2c57e4bc7d 100644
--- a/code/framework/java-server/pom.xml
+++ b/code/framework/java-server/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/jmx/pom.xml b/code/framework/jmx/pom.xml
index 1a22d8221f..713687712e 100644
--- a/code/framework/jmx/pom.xml
+++ b/code/framework/jmx/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/jooq/pom.xml b/code/framework/jooq/pom.xml
index de7e9b9eaa..4a9974dbe0 100644
--- a/code/framework/jooq/pom.xml
+++ b/code/framework/jooq/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/json/pom.xml b/code/framework/json/pom.xml
index 9e0eecf457..10aea7226e 100644
--- a/code/framework/json/pom.xml
+++ b/code/framework/json/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/launcher/pom.xml b/code/framework/launcher/pom.xml
index 5449ead04f..947709691e 100644
--- a/code/framework/launcher/pom.xml
+++ b/code/framework/launcher/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/lock/pom.xml b/code/framework/lock/pom.xml
index 591d644c44..64a1479016 100644
--- a/code/framework/lock/pom.xml
+++ b/code/framework/lock/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/logback/pom.xml b/code/framework/logback/pom.xml
index 7fc23ca332..864f26dbb8 100644
--- a/code/framework/logback/pom.xml
+++ b/code/framework/logback/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-meta-parent
- 0.183.316
+ 0.183.317
../../meta-parent/pom.xml
diff --git a/code/framework/managed-context/pom.xml b/code/framework/managed-context/pom.xml
index dce9135c23..4ae049d1f7 100644
--- a/code/framework/managed-context/pom.xml
+++ b/code/framework/managed-context/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/metrics/pom.xml b/code/framework/metrics/pom.xml
index 7833e8e8fa..99cff3325b 100644
--- a/code/framework/metrics/pom.xml
+++ b/code/framework/metrics/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/module/pom.xml b/code/framework/module/pom.xml
index a9166a1df7..e0e8a7a674 100644
--- a/code/framework/module/pom.xml
+++ b/code/framework/module/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/object/pom.xml b/code/framework/object/pom.xml
index 892bb97627..83e4e7e957 100644
--- a/code/framework/object/pom.xml
+++ b/code/framework/object/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/pool/pom.xml b/code/framework/pool/pom.xml
index ac21ac3ff5..ebec57385d 100644
--- a/code/framework/pool/pom.xml
+++ b/code/framework/pool/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/resource-monitor/pom.xml b/code/framework/resource-monitor/pom.xml
index c2f62efefd..9b01d2815a 100644
--- a/code/framework/resource-monitor/pom.xml
+++ b/code/framework/resource-monitor/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/schema/pom.xml b/code/framework/schema/pom.xml
index b6e7fcb9a1..bc21c1fd07 100644
--- a/code/framework/schema/pom.xml
+++ b/code/framework/schema/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/server/pom.xml b/code/framework/server/pom.xml
index 7dfabca997..37795ab37b 100644
--- a/code/framework/server/pom.xml
+++ b/code/framework/server/pom.xml
@@ -4,7 +4,7 @@
cattle-meta-parent
io.cattle
- 0.183.316
+ 0.183.317
../../meta-parent/pom.xml
diff --git a/code/framework/spring/pom.xml b/code/framework/spring/pom.xml
index 7960e4a3db..539913c7c2 100644
--- a/code/framework/spring/pom.xml
+++ b/code/framework/spring/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/system-task/pom.xml b/code/framework/system-task/pom.xml
index 9fe77d4e4c..c81f545c87 100644
--- a/code/framework/system-task/pom.xml
+++ b/code/framework/system-task/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/token/pom.xml b/code/framework/token/pom.xml
index ca54566793..9fd5b49c42 100644
--- a/code/framework/token/pom.xml
+++ b/code/framework/token/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/framework/utils/pom.xml b/code/framework/utils/pom.xml
index 9ee4138793..af709fa3fb 100644
--- a/code/framework/utils/pom.xml
+++ b/code/framework/utils/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/agent-instance/pom.xml b/code/iaas/agent-instance/pom.xml
index 21ab80f3d8..c71235f9e2 100644
--- a/code/iaas/agent-instance/pom.xml
+++ b/code/iaas/agent-instance/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/agent-server/pom.xml b/code/iaas/agent-server/pom.xml
index d41bb898e6..c25597ef61 100644
--- a/code/iaas/agent-server/pom.xml
+++ b/code/iaas/agent-server/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/agent/pom.xml b/code/iaas/agent/pom.xml
index f49355d33b..08c224dcc9 100644
--- a/code/iaas/agent/pom.xml
+++ b/code/iaas/agent/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/allocator/pom.xml b/code/iaas/allocator/pom.xml
index 8956e301db..2e8ef82967 100644
--- a/code/iaas/allocator/pom.xml
+++ b/code/iaas/allocator/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/api-logic/pom.xml b/code/iaas/api-logic/pom.xml
index 9773a388db..c31516fdc3 100644
--- a/code/iaas/api-logic/pom.xml
+++ b/code/iaas/api-logic/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/archaius-management/pom.xml b/code/iaas/archaius-management/pom.xml
index 0e855b426e..d299d39a9c 100644
--- a/code/iaas/archaius-management/pom.xml
+++ b/code/iaas/archaius-management/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/auth-logic/pom.xml b/code/iaas/auth-logic/pom.xml
index 9cf60feca7..0c3df6de41 100644
--- a/code/iaas/auth-logic/pom.xml
+++ b/code/iaas/auth-logic/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/AbstractTokenUtil.java b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/AbstractTokenUtil.java
index 6a2d9b3ea9..280efd6ec4 100644
--- a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/AbstractTokenUtil.java
+++ b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/AbstractTokenUtil.java
@@ -61,6 +61,8 @@ public abstract class AbstractTokenUtil implements TokenUtil {
private static final Logger log = LoggerFactory.getLogger(AbstractTokenUtil.class);
private static final ConfigProperty CREATE_PROJECT = ArchaiusUtil.getBooleanProperty("project.create.default");
+ private static final ConfigProperty DEFAULT_PROJECT_PROVISIONING =
+ ArchaiusUtil.getStringProperty("project.default.provisioning");
@Inject
protected AuthDao authDao;
@@ -375,10 +377,24 @@ public Account getOrCreateAccount(Identity user, Set identities, Accou
}
addStableAccountIdentities(account, identities);
Object hasLoggedIn = DataAccessor.fields(account).withKey(SecurityConstants.HAS_LOGGED_IN).get();
- if (((hasLoggedIn == null || !((Boolean) hasLoggedIn)) &&
- !authDao.hasAccessToAnyProject(identities, false, null)) &&
- (CREATE_PROJECT.get())) {
- projectResourceManager.createProjectForUser(user);
+ boolean firstLogin = !Boolean.TRUE.equals(hasLoggedIn);
+ if (CREATE_PROJECT.get()) {
+ String provisioning = DEFAULT_PROJECT_PROVISIONING.get();
+ if ("shared".equalsIgnoreCase(provisioning)) {
+ // Reconcile on every login so accounts created by an older
+ // release also adopt the shared Default environment. The
+ // operation is idempotent and never removes a user's
+ // existing environments or overrides an explicit role.
+ projectResourceManager.ensureDefaultProjectMembership(account, identities);
+ } else if ("personal".equalsIgnoreCase(provisioning)) {
+ if (firstLogin && !authDao.hasAccessToAnyProject(identities, false, null)) {
+ projectResourceManager.createProjectForUser(user);
+ }
+ } else if (!"none".equalsIgnoreCase(provisioning)) {
+ throw new ClientVisibleException(ResponseCodes.INTERNAL_SERVER_ERROR,
+ "InvalidDefaultProjectProvisioning",
+ "project.default.provisioning must be shared, personal, or none.", null);
+ }
}
} else {
if (account == null) {
diff --git a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/AuthDao.java b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/AuthDao.java
index 8763fddae9..8d6be82f19 100644
--- a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/AuthDao.java
+++ b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/AuthDao.java
@@ -86,6 +86,8 @@ List extends ProjectMember> setProjectMembers(final Account project, final Set
ProjectMember createProjectMember(Account project, Member member);
+ ProjectMember ensureProjectMember(Account project, Member member);
+
void ensureAllProjectsHaveNonRancherIdMembers(Identity identity);
List searchUsers(String name);
diff --git a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/impl/AuthDaoImpl.java b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/impl/AuthDaoImpl.java
index af54d37204..c56e20cf7d 100644
--- a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/impl/AuthDaoImpl.java
+++ b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/dao/impl/AuthDaoImpl.java
@@ -959,6 +959,26 @@ public ProjectMember createProjectMember(Account project, Member member) {
return resourceDao.create(ProjectMember.class, objectManager.convertToPropertiesFor(ProjectMember.class, properties));
}
+ @Override
+ public ProjectMember ensureProjectMember(final Account project, final Member member) {
+ return lockManager.lock(new ProjectLock(project), new LockCallback() {
+ @Override
+ public ProjectMember doWithLock() {
+ ProjectMember existing = create()
+ .selectFrom(PROJECT_MEMBER)
+ .where(PROJECT_MEMBER.PROJECT_ID.eq(project.getId()))
+ .and(PROJECT_MEMBER.EXTERNAL_ID.eq(member.getExternalId()))
+ .and(PROJECT_MEMBER.EXTERNAL_ID_TYPE.eq(member.getExternalIdType()))
+ .and(PROJECT_MEMBER.STATE.eq(CommonStatesConstants.ACTIVE))
+ .and(PROJECT_MEMBER.REMOVED.isNull())
+ .orderBy(PROJECT_MEMBER.ID.asc())
+ .limit(1)
+ .fetchOne();
+ return existing == null ? createProjectMember(project, member) : existing;
+ }
+ });
+ }
+
@Override
public void ensureAllProjectsHaveNonRancherIdMembers(Identity identity) {
//This operation is expensive if there are alot of projects and members however this is
diff --git a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManager.java b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManager.java
index 3411a5b05a..e8e66fbe95 100644
--- a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManager.java
+++ b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManager.java
@@ -37,6 +37,7 @@
import java.util.HashMap;
import java.util.List;
import java.util.Map;
+import java.util.Set;
import java.util.TreeMap;
import jakarta.inject.Inject;
@@ -172,6 +173,22 @@ public Account createProjectForUser(Identity identity) {
return project;
}
+ public Account ensureDefaultProjectMembership(Account account, Set identities) {
+ Account project = authDao.getAccountByUuid(ProjectConstants.DEFAULT_PROJECT_UUID);
+ if (project == null || !ProjectConstants.TYPE.equalsIgnoreCase(project.getKind())) {
+ throw new ClientVisibleException(ResponseCodes.INTERNAL_SERVER_ERROR,
+ "DefaultProjectUnavailable",
+ "The shared default environment is unavailable.", null);
+ }
+ if (identities != null && !authDao.getProjectMembersByIdentity(project.getId(), identities).isEmpty()) {
+ return project;
+ }
+ Identity stableAccountIdentity = new Identity(ProjectConstants.RANCHER_ID,
+ String.valueOf(account.getId()), account.getName(), null, null, null, true);
+ authDao.ensureProjectMember(project, new Member(stableAccountIdentity, ProjectConstants.MEMBER));
+ return project;
+ }
+
@Override
protected Object deleteInternal(String type, String id, final Object obj, ApiRequest apiRequest) {
if (!(obj instanceof Account) || !(((Account) obj).getKind().equalsIgnoreCase(ProjectConstants.TYPE))) {
diff --git a/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManagerDefaultProjectTest.java b/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManagerDefaultProjectTest.java
new file mode 100644
index 0000000000..cac93b4bea
--- /dev/null
+++ b/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/projects/ProjectResourceManagerDefaultProjectTest.java
@@ -0,0 +1,152 @@
+package io.cattle.platform.iaas.api.auth.projects;
+
+import static org.junit.Assert.assertEquals;
+import static org.junit.Assert.assertSame;
+import static org.junit.Assert.fail;
+
+import io.cattle.platform.api.auth.Identity;
+import io.cattle.platform.core.constants.ProjectConstants;
+import io.cattle.platform.core.model.Account;
+import io.cattle.platform.core.model.ProjectMember;
+import io.cattle.platform.core.model.tables.records.AccountRecord;
+import io.cattle.platform.core.model.tables.records.ProjectMemberRecord;
+import io.cattle.platform.iaas.api.auth.dao.AuthDao;
+import io.github.ibuildthecloud.gdapi.exception.ClientVisibleException;
+
+import java.lang.reflect.Proxy;
+import java.util.Collections;
+import java.util.HashSet;
+import java.util.List;
+import java.util.Set;
+import java.util.concurrent.atomic.AtomicInteger;
+import java.util.concurrent.atomic.AtomicReference;
+
+import org.junit.Test;
+
+public class ProjectResourceManagerDefaultProjectTest {
+
+ @Test
+ public void addsStableAccountIdentityAsMemberOfSharedDefault() {
+ AccountRecord account = account(42L, "OIDC user", "user");
+ AccountRecord project = account(7L, "Renamed shared environment", ProjectConstants.TYPE);
+ AtomicInteger ensures = new AtomicInteger();
+ AtomicReference ensured = new AtomicReference<>();
+ ProjectResourceManager manager = manager(project, Collections.emptyList(), ensures, ensured);
+
+ Account result = manager.ensureDefaultProjectMembership(account, identities(
+ new Identity("oidc_user", "subject-42", "OIDC user", null, null, "user42", true)));
+
+ assertSame(project, result);
+ assertEquals(1, ensures.get());
+ assertEquals(ProjectConstants.RANCHER_ID, ensured.get().getExternalIdType());
+ assertEquals("42", ensured.get().getExternalId());
+ assertEquals(ProjectConstants.MEMBER, ensured.get().getRole());
+ }
+
+ @Test
+ public void preservesExistingGroupRoleWithoutAddingBaselineMember() {
+ AccountRecord account = account(42L, "OIDC user", "user");
+ AccountRecord project = account(7L, "Default", ProjectConstants.TYPE);
+ ProjectMemberRecord restrictedGroup = new ProjectMemberRecord();
+ restrictedGroup.setProjectId(7L);
+ restrictedGroup.setExternalIdType("oidc_group");
+ restrictedGroup.setExternalId("qa-team");
+ restrictedGroup.setRole("restricted");
+ AtomicInteger ensures = new AtomicInteger();
+ ProjectResourceManager manager = manager(project,
+ Collections.singletonList(restrictedGroup), ensures, new AtomicReference());
+
+ manager.ensureDefaultProjectMembership(account, identities(
+ new Identity("oidc_group", "qa-team", "QA team", null, null, null, false)));
+
+ assertEquals(0, ensures.get());
+ }
+
+ @Test
+ public void preservesExistingDirectNoAccessRoleWithoutEscalation() {
+ AccountRecord account = account(42L, "OIDC user", "user");
+ AccountRecord project = account(7L, "Default", ProjectConstants.TYPE);
+ ProjectMemberRecord noAccess = new ProjectMemberRecord();
+ noAccess.setProjectId(7L);
+ noAccess.setExternalIdType(ProjectConstants.RANCHER_ID);
+ noAccess.setExternalId("42");
+ noAccess.setRole("noaccess");
+ AtomicInteger ensures = new AtomicInteger();
+ ProjectResourceManager manager = manager(project,
+ Collections.singletonList(noAccess), ensures, new AtomicReference());
+
+ manager.ensureDefaultProjectMembership(account, identities(
+ new Identity(ProjectConstants.RANCHER_ID, "42", "OIDC user", null, null, null, true)));
+
+ assertEquals(0, ensures.get());
+ }
+
+ @Test
+ public void failsClosedWhenSharedDefaultIsUnavailable() {
+ AccountRecord account = account(42L, "OIDC user", "user");
+ ProjectResourceManager manager = manager(null, Collections.emptyList(),
+ new AtomicInteger(), new AtomicReference());
+
+ try {
+ manager.ensureDefaultProjectMembership(account, Collections.emptySet());
+ fail("Expected the missing shared Default to fail closed");
+ } catch (ClientVisibleException e) {
+ assertEquals(500, e.getStatus());
+ assertEquals("DefaultProjectUnavailable", e.getCode());
+ }
+ }
+
+ private ProjectResourceManager manager(Account project, List extends ProjectMember> existing,
+ AtomicInteger ensures, AtomicReference ensured) {
+ AuthDao authDao = AuthDao.class.cast(Proxy.newProxyInstance(
+ AuthDao.class.getClassLoader(), new Class>[] {AuthDao.class},
+ (proxy, method, args) -> {
+ switch (method.getName()) {
+ case "getAccountByUuid":
+ assertEquals(ProjectConstants.DEFAULT_PROJECT_UUID, args[0]);
+ return project;
+ case "getProjectMembersByIdentity":
+ return existing;
+ case "ensureProjectMember":
+ ensures.incrementAndGet();
+ ensured.set((Member) args[1]);
+ return new ProjectMemberRecord();
+ default:
+ return defaultValue(method.getReturnType());
+ }
+ }));
+ ProjectResourceManager manager = new ProjectResourceManager();
+ manager.authDao = authDao;
+ return manager;
+ }
+
+ private Set identities(Identity identity) {
+ Set result = new HashSet<>();
+ result.add(identity);
+ return result;
+ }
+
+ private AccountRecord account(long id, String name, String kind) {
+ AccountRecord result = new AccountRecord();
+ result.setId(id);
+ result.setName(name);
+ result.setKind(kind);
+ return result;
+ }
+
+ private static Object defaultValue(Class> type) {
+ if (!type.isPrimitive()) {
+ return null;
+ }
+ if (type == boolean.class) {
+ return false;
+ }
+ if (type == long.class) {
+ return 0L;
+ }
+ if (type == int.class) {
+ return 0;
+ }
+ return null;
+ }
+}
diff --git a/code/iaas/bootstrap/pom.xml b/code/iaas/bootstrap/pom.xml
index 83a4ae1959..b7aad3c4c4 100644
--- a/code/iaas/bootstrap/pom.xml
+++ b/code/iaas/bootstrap/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/config-item/api/pom.xml b/code/iaas/config-item/api/pom.xml
index 03e05d458c..acf1a2ff34 100644
--- a/code/iaas/config-item/api/pom.xml
+++ b/code/iaas/config-item/api/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/iaas/config-item/common/pom.xml b/code/iaas/config-item/common/pom.xml
index a5a89a963d..c368388136 100644
--- a/code/iaas/config-item/common/pom.xml
+++ b/code/iaas/config-item/common/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/iaas/config-item/server/pom.xml b/code/iaas/config-item/server/pom.xml
index 67e019c39b..f1f54b5429 100644
--- a/code/iaas/config-item/server/pom.xml
+++ b/code/iaas/config-item/server/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/iaas/engine-jooq/pom.xml b/code/iaas/engine-jooq/pom.xml
index 27e2ec315a..86afbcbfc0 100644
--- a/code/iaas/engine-jooq/pom.xml
+++ b/code/iaas/engine-jooq/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/events/pom.xml b/code/iaas/events/pom.xml
index 1adee7214f..b5cf1723b8 100644
--- a/code/iaas/events/pom.xml
+++ b/code/iaas/events/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/external-handler/pom.xml b/code/iaas/external-handler/pom.xml
index 93369ea8a1..c1f07a4910 100644
--- a/code/iaas/external-handler/pom.xml
+++ b/code/iaas/external-handler/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/ha/pom.xml b/code/iaas/ha/pom.xml
index 09a98678b7..deda3f7ed1 100644
--- a/code/iaas/ha/pom.xml
+++ b/code/iaas/ha/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/healthcheck/pom.xml b/code/iaas/healthcheck/pom.xml
index 546f964f90..5f905d82af 100644
--- a/code/iaas/healthcheck/pom.xml
+++ b/code/iaas/healthcheck/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/labels/pom.xml b/code/iaas/labels/pom.xml
index 9a8ffd06dd..e242621486 100644
--- a/code/iaas/labels/pom.xml
+++ b/code/iaas/labels/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/logic-common/pom.xml b/code/iaas/logic-common/pom.xml
index 062447353a..077e233cb1 100644
--- a/code/iaas/logic-common/pom.xml
+++ b/code/iaas/logic-common/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/logic/pom.xml b/code/iaas/logic/pom.xml
index a34d3d5266..b385fa59fd 100644
--- a/code/iaas/logic/pom.xml
+++ b/code/iaas/logic/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/metadata/pom.xml b/code/iaas/metadata/pom.xml
index 3851267afe..0e2b5ee1a3 100644
--- a/code/iaas/metadata/pom.xml
+++ b/code/iaas/metadata/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/model/pom.xml b/code/iaas/model/pom.xml
index 471e5b198c..b765108b7a 100644
--- a/code/iaas/model/pom.xml
+++ b/code/iaas/model/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/model/src/main/java/io/cattle/platform/core/constants/ProjectConstants.java b/code/iaas/model/src/main/java/io/cattle/platform/core/constants/ProjectConstants.java
index 1f99b8da8d..305d633788 100644
--- a/code/iaas/model/src/main/java/io/cattle/platform/core/constants/ProjectConstants.java
+++ b/code/iaas/model/src/main/java/io/cattle/platform/core/constants/ProjectConstants.java
@@ -9,11 +9,13 @@ public class ProjectConstants {
public static final String TYPE = "project";
public static final String PROJECT_DEFAULT_NAME = "-Default";
+ public static final String DEFAULT_PROJECT_UUID = "adminProject";
public static final String RANCHER_ID = "rancher_id";
public static final String NAME = "rancher";
public static final String OWNER = "owner";
+ public static final String MEMBER = "member";
public static final String SET_MEMBERS = "setMembers";
diff --git a/code/iaas/resource-pool/pom.xml b/code/iaas/resource-pool/pom.xml
index a5ffab7d60..7449534796 100644
--- a/code/iaas/resource-pool/pom.xml
+++ b/code/iaas/resource-pool/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/service-discovery/api/pom.xml b/code/iaas/service-discovery/api/pom.xml
index 7daefa51cd..880c6a9646 100644
--- a/code/iaas/service-discovery/api/pom.xml
+++ b/code/iaas/service-discovery/api/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/iaas/service-discovery/server/pom.xml b/code/iaas/service-discovery/server/pom.xml
index 3b14ac6656..d68e710acc 100644
--- a/code/iaas/service-discovery/server/pom.xml
+++ b/code/iaas/service-discovery/server/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/iaas/ssh-common/pom.xml b/code/iaas/ssh-common/pom.xml
index a165bb07a0..57e9a12259 100644
--- a/code/iaas/ssh-common/pom.xml
+++ b/code/iaas/ssh-common/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/storage-service/pom.xml b/code/iaas/storage-service/pom.xml
index 989fb89bad..97bf2f7d8b 100644
--- a/code/iaas/storage-service/pom.xml
+++ b/code/iaas/storage-service/pom.xml
@@ -4,7 +4,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/iaas/task-jooq/pom.xml b/code/iaas/task-jooq/pom.xml
index a31a614528..bf381d97aa 100644
--- a/code/iaas/task-jooq/pom.xml
+++ b/code/iaas/task-jooq/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/activity-log/pom.xml b/code/implementation/activity-log/pom.xml
index 49001919e8..e61ecb4a22 100644
--- a/code/implementation/activity-log/pom.xml
+++ b/code/implementation/activity-log/pom.xml
@@ -5,7 +5,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/agent-instance-impl/pom.xml b/code/implementation/agent-instance-impl/pom.xml
index 64aa470268..7bf00213a6 100644
--- a/code/implementation/agent-instance-impl/pom.xml
+++ b/code/implementation/agent-instance-impl/pom.xml
@@ -3,7 +3,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
cattle-agent-instance-impl
diff --git a/code/implementation/docker/api/pom.xml b/code/implementation/docker/api/pom.xml
index ff8688cf20..864fa1732b 100644
--- a/code/implementation/docker/api/pom.xml
+++ b/code/implementation/docker/api/pom.xml
@@ -5,7 +5,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/docker/common/pom.xml b/code/implementation/docker/common/pom.xml
index ae81594d61..74664a2d0f 100644
--- a/code/implementation/docker/common/pom.xml
+++ b/code/implementation/docker/common/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/docker/compute/pom.xml b/code/implementation/docker/compute/pom.xml
index 281f70179d..c09dd8c2d9 100644
--- a/code/implementation/docker/compute/pom.xml
+++ b/code/implementation/docker/compute/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/docker/machine/pom.xml b/code/implementation/docker/machine/pom.xml
index e489cd9c76..1d8311097e 100644
--- a/code/implementation/docker/machine/pom.xml
+++ b/code/implementation/docker/machine/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/docker/storage/pom.xml b/code/implementation/docker/storage/pom.xml
index c50625bbc1..30f8c09f87 100644
--- a/code/implementation/docker/storage/pom.xml
+++ b/code/implementation/docker/storage/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
@@ -21,12 +21,12 @@
io.cattle
cattle-docker-common
- 0.183.316
+ 0.183.317
io.cattle
cattle-iaas-allocator
- 0.183.316
+ 0.183.317
diff --git a/code/implementation/extension-api/pom.xml b/code/implementation/extension-api/pom.xml
index fa0f746d20..60b0d05307 100644
--- a/code/implementation/extension-api/pom.xml
+++ b/code/implementation/extension-api/pom.xml
@@ -3,7 +3,7 @@
cattle-parent
io.cattle
- 0.183.316
+ 0.183.317
../../parent/pom.xml
cattle-extension-api
diff --git a/code/implementation/hazelcast/common/pom.xml b/code/implementation/hazelcast/common/pom.xml
index bdad6fa878..6fc5654d83 100644
--- a/code/implementation/hazelcast/common/pom.xml
+++ b/code/implementation/hazelcast/common/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/hazelcast/eventing/pom.xml b/code/implementation/hazelcast/eventing/pom.xml
index 3db98a6f1e..5242736e71 100644
--- a/code/implementation/hazelcast/eventing/pom.xml
+++ b/code/implementation/hazelcast/eventing/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/hazelcast/lock/pom.xml b/code/implementation/hazelcast/lock/pom.xml
index 4ecf6787f3..e604dbe8a9 100644
--- a/code/implementation/hazelcast/lock/pom.xml
+++ b/code/implementation/hazelcast/lock/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../../parent/pom.xml
diff --git a/code/implementation/host-api/pom.xml b/code/implementation/host-api/pom.xml
index 15cf009eb1..904bbfebbb 100644
--- a/code/implementation/host-api/pom.xml
+++ b/code/implementation/host-api/pom.xml
@@ -5,7 +5,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/host-stats/pom.xml b/code/implementation/host-stats/pom.xml
index 67709d947a..a1f359d1a5 100644
--- a/code/implementation/host-stats/pom.xml
+++ b/code/implementation/host-stats/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/register/pom.xml b/code/implementation/register/pom.xml
index bc69049ab5..227f324d80 100644
--- a/code/implementation/register/pom.xml
+++ b/code/implementation/register/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/sample-setup/pom.xml b/code/implementation/sample-setup/pom.xml
index 200784747b..386684c5cc 100644
--- a/code/implementation/sample-setup/pom.xml
+++ b/code/implementation/sample-setup/pom.xml
@@ -4,7 +4,7 @@
io.cattle
cattle-parent
- 0.183.316
+ 0.183.317
../../parent/pom.xml
diff --git a/code/implementation/sample-setup/src/main/java/io/cattle/platform/sample/data/SampleDataStartupV3.java b/code/implementation/sample-setup/src/main/java/io/cattle/platform/sample/data/SampleDataStartupV3.java
index 970f7fe3cb..26f18ea255 100644
--- a/code/implementation/sample-setup/src/main/java/io/cattle/platform/sample/data/SampleDataStartupV3.java
+++ b/code/implementation/sample-setup/src/main/java/io/cattle/platform/sample/data/SampleDataStartupV3.java
@@ -19,7 +19,7 @@ protected String getName() {
@Override
protected void populatedData(Account system, List