Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 27 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,35 @@ in each release's notes.
Changes to be including in future/planned release notes will be added here.

## [Unreleased]

## [0.6.9](https://github.com/Worklytics/psoxy/releases/tag/v0.6.9)
- `gcp`: **beta** first-class optional external Application Load Balancer (ALB) via `external_api_alb` on `gcp-host` (replaces the prior root `external-api-alb.tf` composition). Cloud Armor IP rules apply only when `allowed_data_access_ip_blocks` is non-null. BYO ALB remains available via `api_connector_external_lb_host`. If you applied the old root composition, destroy those root ALB resources (or `terraform state mv` into the new module addresses) before upgrading. Enabling the ALB may add `hashicorp/tls` to your root provider lockfile (self-signed PoC path).
- `msft-onedrive`: adding support for a new **beta** connector for fetching Microsoft OneDrive data from users and groups via Microsoft Graph API. See [docs/sources/microsoft-365/msft-onedrive/README.md](docs/sources/microsoft-365/msft-onedrive/README.md) for details.
Comment on lines +10 to +12
- `gcp`: add troubleshooting guidance for common deploy failures (permission prerequisites, org-policy networking constraints).

## [0.6.8](https://github.com/Worklytics/psoxy/releases/tag/v0.6.8)
- `gcp`: optional external Application Load Balancer in front of API connector deployments via root `external-api-alb.tf` composition (superseded in 0.6.9 by first-class `external_api_alb` on `gcp-host`).
- `zoom`: default rules updated.
- Anthropic connectors (`claude`, `claude-enterprise-analytics`): rules updated.
- Google Workspace connector docs: document GCP APIs and DWD scope strings.
- example-repo publish scripts: keep LF line endings for WSL shebang compatibility.

## [0.6.7](https://github.com/Worklytics/psoxy/releases/tag/v0.6.7)
- bulk: support JSONL input format.
- `claude-code` / `sales-for-copilot`: **beta** bulk connector support for AI tool usage data.
- `gcp`: skip Google Workspace provisioning when not configured.
- `aws`/`gcp`: fix Terraform plan failure when `enable_remote_resources = true` but no artifacts bucket exists (e.g. with a prebuilt `deployment_bundle`). When remote resources are enabled, an artifacts bucket is now provisioned if one is not already created or provided via `artifacts_bucket_name` / `custom_artifacts_bucket_name`.
- `msft-onedrive`: adding support for a new connector for fetching Microsoft OneDrive data from users and groups via Microsoft Graph API. See [docs](docs/sources/microsoft-365/msft-onedrive/README.md) for details.
- fix unsanitized request metadata leaking into sync API response headers and sanitized side outputs.
- fix duplicate query parameters from API Gateway 1.0 payloads.
- fix possible null body in side outputs.
- `gcp`: bulk connector memory controls.
- secret reads: handle transient failures when fetching secrets.
- `upgrade-terraform-modules.sh`: improved feedback during module ref upgrades.

## [0.6.6](https://github.com/Worklytics/psoxy/releases/tag/v0.6.6)
- `gcp`: reduce apparent Terraform drift on repeat applies.
- `gcp`: VPC troubleshooting documentation and related Terraform style fixes.
- `chatgpt-enterprise`: fix logs sanitization regression from rules update.

## [0.6.5](https://github.com/Worklytics/psoxy/releases/tag/v0.6.5)
- added `claude-enterprise-analytics` connector in **beta**; imports per-user daily activity, token usage, and cost data from the [Claude Enterprise Analytics API](https://support.claude.com/en/articles/13703965-claude-enterprise-analytics-api-reference-guide); see [docs/sources/anthropic/claude-enterprise-analytics/README.md](docs/sources/anthropic/claude-enterprise-analytics/README.md)
Expand Down
34 changes: 17 additions & 17 deletions docs/aws/sbom.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"serialNumber" : "urn:uuid:5b2e5a90-72e5-3e17-9198-ef97bbc050aa",
"version" : 1,
"metadata" : {
"timestamp" : "2026-07-24T19:08:18Z",
"timestamp" : "2026-07-31T15:47:12Z",
"lifecycles" : [
{
"phase" : "build"
Expand Down Expand Up @@ -91,35 +91,35 @@
"hashes" : [
{
"alg" : "MD5",
"content" : "018676511efaf39fb255c9abd76a18e6"
"content" : "30e82d8721a7a8a07478fc2722f5aded"
},
{
"alg" : "SHA-1",
"content" : "0be25742f175aa15ff68ac6ad9960c03049560d8"
"content" : "6c5772a59790ff5c584c4e9e2cde5274efe4ffcf"
},
{
"alg" : "SHA-256",
"content" : "6d235b1ed2a194b3e9d66f599a8937e20c4794a3f981a882294c8fca069a0cf5"
"content" : "da86b74c418fb9fa63075309e11e7e0ba9ae32a1ddd85ec742cc79ecf73f8eb6"
},
{
"alg" : "SHA-512",
"content" : "f095a753c2e63ed820058fca6241d29ff675599ef8e700caf277a1b2b2b32fdc009208569d6d4381c0102cac81a3936fc1df9beb383904d7be7eeac94300800a"
"content" : "00a69e29a6aa201ca661ebf41a04ef4d5832fae932899f1a89d42317b0e47410e927a1f15df79ecbacc7570b540e06151cf92734f4fbcf7bf95a4054fc99364b"
},
{
"alg" : "SHA-384",
"content" : "bc1e5d81dfa6075d4a973a403a4e5023763ec2de900166861b1c73f896a2826efd030ab787cd673c7cd4bb3c2e5736b4"
"content" : "22803c7d29d33c37f8f202fc4bf9d5cec722dd6181f9404d8a41456cea38e843453d3d0678703c76bdaa3ed5da9bd044"
},
{
"alg" : "SHA3-384",
"content" : "99d582413e7c975a40ccca79e68f0c13087c0b73ed389d8ffcc7414e87daa90530fe1479ee8e72651b8770b11e962917"
"content" : "e1baf4021849a6e59e357d2ba08f1aa91b3e0b386d43195da2e7b5d7f95e71f7e980d216b28f3063afb4afbf13aabe73"
},
{
"alg" : "SHA3-256",
"content" : "bc4a39197aaf7d20a295c935f0c452703e07d834d23fa9f2b25c2c48892a1911"
"content" : "dcc41cdda26f109676c35ade0cfe37f6a23a7f91e00414e71be41809fd981317"
},
{
"alg" : "SHA3-512",
"content" : "8a81a98145064d905de6616c6e91b2b4cf2b05d6ccd01d9ef7db2785fae33e5e286c6046e5b8da95686b9000690c11ab1aaae454ee90825483be6046ec53d8b4"
"content" : "1a316ec3b754b4c9f2f59eae296a06f810347f6b0b2932c7ed0bbab2d6d3a07c112bae3babcdec5413d3283fc05e68a1268075cc7c85ee629e4bb9979c3890d9"
}
],
"licenses" : [
Expand All @@ -142,35 +142,35 @@
"hashes" : [
{
"alg" : "MD5",
"content" : "dc6f97abc47234aea3b75b22e72be16a"
"content" : "1a98de4c72ecb19903901fc44308c113"
},
{
"alg" : "SHA-1",
"content" : "f6a6809f8518400f550a8680ca8af9f76c7c654b"
"content" : "0ac5dffba35a3e55691d1e9c1167df963433dc67"
},
{
"alg" : "SHA-256",
"content" : "32d7951244c230dc2076cb8f4b590c351a10b895dcb472691727c35156899e72"
"content" : "d885763bb7a64c23c06a3fd4ed0b445bb8ac669b98432c2bd56410fac785bca6"
},
{
"alg" : "SHA-512",
"content" : "5d2c16e196bbea00d9b4a392537eae13297695870ec1389e14d6c2ac3abd20bdeebee5d326638f91dc6af4f29385862e7d1118ab39619d44b72c6ae504cf2bc1"
"content" : "f16624355075e1f86b8eb6635a0b88bddb8ca63931da87e741185657ada324c91b2abc2adfbf291c7d8aa5c43e335c00724b6e23c189198c16d84901128fd76a"
},
{
"alg" : "SHA-384",
"content" : "992cd6543833d3186f002da7a8d368895ffa448b35137178cf7a2e903b2ba58cc655e56e9838ad797be164d95f0ab013"
"content" : "1bdf9aaae61eecfebed53160ccc3f459c58b9ed891ed226d04835c81b1128a3ab89b7b8060b702fa0674ab1d169b3c91"
},
{
"alg" : "SHA3-384",
"content" : "fbd8622095b42c80a85ce7fd56121cd741b718efa5b0630b103a73ce8e8e3dec49b83a8c3b9e738d49fb8b1517f0023a"
"content" : "47cc6d78107c1a2ae73121bc866f85a5e74ee23ffe91619dbf1103d42d24bb5969c8ed48e3bc17c6fcc5c0fd652538f7"
},
{
"alg" : "SHA3-256",
"content" : "df23ae4ae1aef938b24db86f4357395e6267a203fd871f4b52b0c50f73fd9b35"
"content" : "8b1f557d3f2c1f54df826302c76779b3a3329ffec6d1e4dbe0fae03152146eba"
},
{
"alg" : "SHA3-512",
"content" : "81012c4bf7bc8ac0d908449ab8bc2fbb673b28caf391056397aa257e6ae11179d680abd8096cba35f49d9e5d9b938d799513df6e430b500833159914aef9754d"
"content" : "17f7983ff8228a7261af11f1099f715c9d48325400fd2453b6df8d3e13468404524d897f35e7e10505c78462a144d2362e0a370dabca05e9ad1aaa56cc4e59d3"
}
],
"licenses" : [
Expand Down
34 changes: 17 additions & 17 deletions docs/gcp/sbom.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"serialNumber" : "urn:uuid:0b2acc99-2158-37ba-8994-42dbb0663ddc",
"version" : 1,
"metadata" : {
"timestamp" : "2026-07-24T19:08:53Z",
"timestamp" : "2026-07-31T15:47:59Z",
"lifecycles" : [
{
"phase" : "build"
Expand Down Expand Up @@ -91,35 +91,35 @@
"hashes" : [
{
"alg" : "MD5",
"content" : "67d58f35b8e153c62121a4186c85b674"
"content" : "f36913e7653ef02786778dc87e3d6700"
},
{
"alg" : "SHA-1",
"content" : "54045d7d4112cc107bc7889a7e268abdc421fc58"
"content" : "168f02a2aea1be4f7646cdfea70ec34eba08b382"
},
{
"alg" : "SHA-256",
"content" : "3318ee4dcc5f14931e9f0a5d5a5b7e0d2772b973626401c9e84adce19318fe41"
"content" : "3f076843d8ac448ec940f80d0a831316931ce68db2f722acade933c7813248d4"
},
{
"alg" : "SHA-512",
"content" : "ad9a9e1b761d11fdbfc93c9dfaa7ab9aec982563077717b891af19ffb03eb7d9313acfea3850547dd7ba0006a1a0e3ca33860a170997751ea790850fccca2a09"
"content" : "f24ddb46607bca46ce17feb36b96dfcf0c7bbf9b72c2a3f8a22429e54cbaa135759d77f1d07804f89fe590c8b29efae3852d86a98ab873f3972145615df8e6d6"
},
{
"alg" : "SHA-384",
"content" : "9ba1a361e5c86b3592e348eca38acdde9e831c1b94a481110b877ad7e599587dc71f6e12ce045d029037dd9545dac36a"
"content" : "9a7d02630d1acf5203c6a7488186553df39577ec0888d8e30fe548735ac6a01388bd9af6003f2241c8b6aa203a3721b0"
},
{
"alg" : "SHA3-384",
"content" : "dc93de53bcca298495d020c6a47f71d16266a9ec01c9734cc7caef434cb8756f601f6bd6e9df836c0d6952e152f6f012"
"content" : "4969224d64e0923d8d75e86861d08a7e0be33c4deeac5ae9a6a3214e9e0a0e7ee2da7b2a22c44e572cad865a17c5baa4"
},
{
"alg" : "SHA3-256",
"content" : "4cd864f369cb384bb9b058aa9d7069c1f4e27d5d589b03d2df7794cd3e5165d4"
"content" : "5d1acce266ae1280c0ed0706bb658b09399e21149243772a689bbffde7b07fef"
},
{
"alg" : "SHA3-512",
"content" : "458fe4986e0c2b8b881a4618d6b38e0330e4a8dfdd7be1b2203c429bf4175e5448bef612e1ff03c29eec6c00bd4a86beeb2b01c22c56c4713b09ca9c9e2ac14f"
"content" : "e4dc8d021d39b3c8337b950414c66a0821b0288cac5ec51b7c5b1b21a9464d0f5e649482df166cced5568f0b29fcc5345b2bc8da3b1f4ca6742a3889e6236011"
}
],
"licenses" : [
Expand All @@ -142,35 +142,35 @@
"hashes" : [
{
"alg" : "MD5",
"content" : "227e16e213b0a25381f545798add8c4e"
"content" : "0556b1b41a51606d0b920de0dfb86afc"
},
{
"alg" : "SHA-1",
"content" : "518a57c552a482c95a7f3e088f2e6a06ce99d814"
"content" : "bd8823627717bd9a02c533460ea51985f42cfb2e"
},
{
"alg" : "SHA-256",
"content" : "3748ba2f7dd750ed90e1595b4ffaa28716cdd726a3354212a6b2f58b63acb542"
"content" : "7e73b6932087a01a5d757d855b86022d8af936b9039466fd08c5352e985e9f0a"
},
{
"alg" : "SHA-512",
"content" : "47c5a30065292e1bfc4249766950e363d2a9ce047f60465029b27de23e5116fa6c9342b8e61f8110593e4576187edbf2e5914829c1111ca272844717e02e38e5"
"content" : "88af5d2706e83df669545726426625b35e1d8c3c0646b5cdb1fbac965fef86b287af26ccd90256543e000247acf39b2d1d5ed5a3acd9cb03cba21ae098ffcaa6"
},
{
"alg" : "SHA-384",
"content" : "9b78de3e345274d8e0ad0963111206cbfcf0decf23b8a8102b1a4fd13e05d66e66fe49def2d8998ea645be1755bc9aa8"
"content" : "10f67471a93695a29fb6d38ba3010d9899b9de15b80497fbd7442b81fed4ce7c52008d4dc6381118173ba54b9ddd490b"
},
{
"alg" : "SHA3-384",
"content" : "7a3c75f22265a8a7217b4253e3a3ca153a9b5d3bb78bbbd7ea591746a9e125021d5e8a67efb1207eda31ab2bde7df6d7"
"content" : "3cf14d8a3d3427d1b02695b041f6ec5c35c75288d067df090beb7e7d11e7ed7d67fcc2f2d3f26aa98a5b3a493d3e96fc"
},
{
"alg" : "SHA3-256",
"content" : "3841e142e9dc75ffb7f76fc674a3487afb678eb7672667e3304d820e41b8e1e2"
"content" : "e989cf6f2a4ba802b5c25d7846ef9bf78613949776696f6af8463f6adb7e13e6"
},
{
"alg" : "SHA3-512",
"content" : "2d2ceda70a3518e4777047d5e8efaf3a90511bb06e31085c3e84bf8e3c85fd3f3be1849fce16a11daa761455f2fef916f6234201169a50bd9330d9578d0f1ab7"
"content" : "2f36c055636651be9b16ba346f58190042b6087ee9945f8efb4cf904ba4f53548a2a54b6c0d52c613c4282a99e3bf07e7b42b495bb1a8b0cf450925dc2e716c7"
}
],
"licenses" : [
Expand Down
2 changes: 1 addition & 1 deletion infra/examples-dev/aws/google-workspace.tf
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ provider "google" {

module "worklytics_connectors_google_workspace" {
source = "../../modules/worklytics-connectors-google-workspace"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-google-workspace?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-google-workspace?ref=v0.6.9"

google_workspace_connector_settings = var.google_workspace_connector_settings

Expand Down
6 changes: 3 additions & 3 deletions infra/examples-dev/aws/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ terraform {
# general cases
module "worklytics_connectors" {
source = "../../modules/worklytics-connectors"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors?ref=v0.6.9"

enabled_connectors = var.enabled_connectors
connector_settings = var.connector_settings
Expand Down Expand Up @@ -121,7 +121,7 @@ locals {

module "psoxy" {
source = "../../modules/aws-host"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-host?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-host?ref=v0.6.9"

environment_name = var.environment_name
aws_account_id = var.aws_account_id
Expand Down Expand Up @@ -200,7 +200,7 @@ module "connection_in_worklytics" {
for_each = local.all_instances

source = "../../modules/worklytics-proxy-connection-aws"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-proxy-connection-aws?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-proxy-connection-aws?ref=v0.6.9"

proxy_instance_id = each.key
worklytics_host = var.worklytics_host
Expand Down
8 changes: 4 additions & 4 deletions infra/examples-dev/aws/msft-365.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

module "worklytics_connectors_msft_365" {
source = "../../modules/worklytics-connectors-msft-365"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-msft-365?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-msft-365?ref=v0.6.9"

msft_365_connector_settings = var.msft_365_connector_settings

Expand Down Expand Up @@ -52,7 +52,7 @@ module "cognito_identity_pool" {
count = local.msft_365_enabled ? 1 : 0 # only provision identity pool if MSFT-365 connectors are enabled

source = "../../modules/aws-cognito-pool"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-cognito-pool?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-cognito-pool?ref=v0.6.9"

developer_provider_name = local.developer_provider_name
name = "${local.env_qualifier}-azure-ad-federation"
Expand All @@ -75,7 +75,7 @@ module "cognito_identity" {
count = local.msft_365_enabled ? 1 : 0 # only provision identity pool if MSFT-365 connectors are enabled

source = "../../modules/aws-cognito-identity-cli"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-cognito-identity-cli?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/aws-cognito-identity-cli?ref=v0.6.9"


aws_region = data.aws_region.current.region
Expand Down Expand Up @@ -113,7 +113,7 @@ module "msft_connection_auth_federation" {
for_each = local.provision_entraid_apps ? local.enabled_to_entraid_object : local.shared_to_entraid_object

source = "../../modules/azuread-federated-credentials"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/azuread-federated-credentials?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/azuread-federated-credentials?ref=v0.6.9"

application_id = each.value.connector_id
display_name = "${local.env_qualifier}AccessFromAWS"
Expand Down
2 changes: 1 addition & 1 deletion infra/examples-dev/gcp/google-workspace.tf
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ provider "google" {

module "worklytics_connectors_google_workspace" {
source = "../../modules/worklytics-connectors-google-workspace"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-google-workspace?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-google-workspace?ref=v0.6.9"

google_workspace_connector_settings = var.google_workspace_connector_settings

Expand Down
6 changes: 3 additions & 3 deletions infra/examples-dev/gcp/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ locals {
# call this 'generic_source_connectors'?
module "worklytics_connectors" {
source = "../../modules/worklytics-connectors"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors?ref=v0.6.9"

base_dir = var.psoxy_base_dir
enabled_connectors = var.enabled_connectors
Expand Down Expand Up @@ -108,7 +108,7 @@ locals {

module "psoxy" {
source = "../../modules/gcp-host"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/gcp-host?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/gcp-host?ref=v0.6.9"

gcp_project_id = var.gcp_project_id
environment_name = var.environment_name
Expand Down Expand Up @@ -176,7 +176,7 @@ module "connection_in_worklytics" {
for_each = local.all_instances

source = "../../modules/worklytics-proxy-connection-generic"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-proxy-connection-generic?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-proxy-connection-generic?ref=v0.6.9"

host_platform_id = local.host_platform_id
proxy_instance_id = each.key
Expand Down
4 changes: 2 additions & 2 deletions infra/examples-dev/gcp/msft-365.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

module "worklytics_connectors_msft_365" {
source = "../../modules/worklytics-connectors-msft-365"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-msft-365?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/worklytics-connectors-msft-365?ref=v0.6.9"

msft_365_connector_settings = var.msft_365_connector_settings

Expand Down Expand Up @@ -37,7 +37,7 @@ module "msft-connection-auth-federation" {
for_each = module.worklytics_connectors_msft_365.enabled_api_connectors

source = "../../modules/azuread-federated-credentials"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/azuread-federated-credentials?ref=rc-v0.6.9"
# source = "git::https://github.com/worklytics/psoxy//infra/modules/azuread-federated-credentials?ref=v0.6.9"

application_id = each.value.connector.id
display_name = "GcpFederation"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ public class ProxyConstants {
/**
* Version of the Java source code. Used to identify the version of the proxy.
*/
public static final String JAVA_SOURCE_CODE_VERSION = "rc-v0.6.9";
public static final String JAVA_SOURCE_CODE_VERSION = "v0.6.9";

/**
* a random UUID used to salt the hash of the salt. Purpose of this is to invalidate any non-purpose built rainbow table solution.
Expand Down
Loading
Loading