-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(helm): update chart external-secrets ( 0.9.13 → 0.12.1 ) #5295
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/nas-1-external-secrets-0.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- kubernetes/nas-1/apps/kube-system/external-secrets/app Kustomization: flux-system/cluster-apps-external-secrets HelmRelease: kube-system/external-secrets
+++ kubernetes/nas-1/apps/kube-system/external-secrets/app Kustomization: flux-system/cluster-apps-external-secrets HelmRelease: kube-system/external-secrets
@@ -12,13 +12,13 @@
spec:
chart: external-secrets
sourceRef:
kind: HelmRepository
name: external-secrets
namespace: flux-system
- version: 0.9.13
+ version: 0.10.7
install:
createNamespace: true
remediation:
retries: 3
interval: 15m
maxHistory: 2 |
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-cert-controller
+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-cert-controller
@@ -20,15 +20,23 @@
- patch
- apiGroups:
- admissionregistration.k8s.io
resources:
- validatingwebhookconfigurations
verbs:
- - get
- list
- watch
+ - get
+- apiGroups:
+ - admissionregistration.k8s.io
+ resources:
+ - validatingwebhookconfigurations
+ resourceNames:
+ - secretstore-validate
+ - externalsecret-validate
+ verbs:
- update
- patch
- apiGroups:
- ''
resources:
- endpoints
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-controller
+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-controller
@@ -36,23 +36,26 @@
- clusterexternalsecrets/status
- clusterexternalsecrets/finalizers
- pushsecrets
- pushsecrets/status
- pushsecrets/finalizers
verbs:
+ - get
- update
- patch
- apiGroups:
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- get
- list
- watch
- apiGroups:
- ''
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-view
+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-view
@@ -26,13 +26,15 @@
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- get
- watch
- list
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-edit
+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-edit
@@ -27,14 +27,16 @@
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- create
- delete
- deletecollection
- patch
- update
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-cert-controller
+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-cert-controller
@@ -34,23 +34,26 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.13
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
imagePullPolicy: IfNotPresent
args:
- certcontroller
- --crd-requeue-interval=5m
- --service-name=external-secrets-webhook
- --service-namespace=kube-system
- --secret-name=external-secrets-webhook
- --secret-namespace=kube-system
- --metrics-addr=:8080
- --healthz-addr=:8081
+ - --loglevel=info
+ - --zap-time-encoding=epoch
+ - --enable-partial-cache=true
ports:
- containerPort: 8080
protocol: TCP
name: metrics
readinessProbe:
httpGet:
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets
+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets
@@ -34,16 +34,19 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.13
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
imagePullPolicy: IfNotPresent
args:
- --concurrent=1
- --metrics-addr=:8080
+ - --loglevel=info
+ - --zap-time-encoding=epoch
ports:
- containerPort: 8080
protocol: TCP
name: metrics
+ dnsPolicy: ClusterFirst
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-webhook
+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-webhook
@@ -34,22 +34,24 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.13
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
imagePullPolicy: IfNotPresent
args:
- webhook
- --port=10250
- --dns-name=external-secrets-webhook.kube-system.svc
- --cert-dir=/tmp/certs
- --check-interval=5m
- --metrics-addr=:8080
- --healthz-addr=:8081
+ - --loglevel=info
+ - --zap-time-encoding=epoch
ports:
- containerPort: 8080
protocol: TCP
name: metrics
- containerPort: 10250
protocol: TCP
--- HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/secretstore-validate
+++ HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/secretstore-validate
@@ -1,12 +1,15 @@
---
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingWebhookConfiguration
metadata:
name: secretstore-validate
labels:
+ app.kubernetes.io/name: external-secrets-webhook
+ app.kubernetes.io/instance: external-secrets
+ app.kubernetes.io/managed-by: Helm
external-secrets.io/component: webhook
webhooks:
- name: validate.secretstore.external-secrets.io
rules:
- apiGroups:
- external-secrets.io
--- HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/externalsecret-validate
+++ HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/externalsecret-validate
@@ -1,12 +1,15 @@
---
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingWebhookConfiguration
metadata:
name: externalsecret-validate
labels:
+ app.kubernetes.io/name: external-secrets-webhook
+ app.kubernetes.io/instance: external-secrets
+ app.kubernetes.io/managed-by: Helm
external-secrets.io/component: webhook
webhooks:
- name: validate.externalsecret.external-secrets.io
rules:
- apiGroups:
- external-secrets.io |
🦙 MegaLinter status: ❌ ERROR
See detailed report in MegaLinter reports |
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
April 18, 2024 15:09
f2ec7c5
to
7925a29
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.14 )
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.16 )
Apr 18, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
May 1, 2024 18:34
7925a29
to
0559b33
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.16 )
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.17 )
May 1, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
May 14, 2024 08:36
0559b33
to
e68f99a
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.17 )
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.18 )
May 14, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
June 4, 2024 20:05
e68f99a
to
40f402a
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.18 )
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.19 )
Jun 4, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
July 6, 2024 22:18
40f402a
to
82b4b73
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.19 )
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.20 )
Jul 6, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
August 3, 2024 11:16
82b4b73
to
c9ff693
Compare
renovate
bot
changed the title
fix(helm): update chart external-secrets ( 0.9.13 → 0.9.20 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.0 )
Aug 3, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
August 28, 2024 11:52
c9ff693
to
00e6554
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.0 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.1 )
Aug 28, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
August 28, 2024 20:15
00e6554
to
b0aafda
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.1 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.2 )
Aug 28, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
September 9, 2024 15:28
b0aafda
to
e05ce88
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.2 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.3 )
Sep 9, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
September 25, 2024 13:45
e05ce88
to
debd967
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.3 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.4 )
Sep 25, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
October 25, 2024 07:34
debd967
to
079d9d2
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.4 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.5 )
Oct 25, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
November 20, 2024 20:52
079d9d2
to
d1688c2
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.5 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.6 )
Nov 20, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
November 23, 2024 10:12
d1688c2
to
f9b32e0
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.6 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.7 )
Nov 23, 2024
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
December 2, 2024 12:38
f9b32e0
to
4fc4d71
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.10.7 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.11.0 )
Dec 2, 2024
| datasource | package | from | to | | ---------- | ---------------- | ------ | ------ | | helm | external-secrets | 0.9.13 | 0.12.1 |
renovate
bot
force-pushed
the
renovate/nas-1-external-secrets-0.x
branch
from
December 23, 2024 22:47
4fc4d71
to
b4cd1fe
Compare
renovate
bot
changed the title
feat(helm): update chart external-secrets ( 0.9.13 → 0.11.0 )
feat(helm): update chart external-secrets ( 0.9.13 → 0.12.1 )
Dec 23, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.13
->0.12.1
Release Notes
external-secrets/external-secrets (external-secrets)
v0.12.1
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.12.1
Image:
ghcr.io/external-secrets/external-secrets:v0.12.1-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.12.1-ubi-boringssl
What's Changed
7287624
to37cdac4
by @dependabot in https://github.com/external-secrets/external-secrets/pull/4245Full Changelog: external-secrets/external-secrets@v0.12.0...v0.12.1
v0.11.0
Compare Source
Deprecation of OLM Releases
As of
0.11.0
is the last release available for OLM until further notice. Depending on the way this goes, we might still have OLM support (ideally with a properly built operator for that), but for sure in a different support scheme as to not overload maintainers anymore.Also a valid note - you can still use 0.11.0 OLM release and the newest ESO images, you just need to set image.tag appropriately in your setup.
Kubernetes API load and significant decrease
A new way of reconciling external secrets has been added with pull request #4086.
This significantly reduces the number of API calls that we make to the kubernetes API server.
--enable-secrets-caching
--enable-secrets-caching
and want to decrease memory usage at the expense of slightly higher API usage, you can disable it and only enable--enable-managed-secrets-caching
(which is the new default)Generators and ClusterGenerator
We added ClusterGenerators and Generator caching as well. This might create some problems in the way generators are defined now.
CRD Admission Restrictions
All of the CRDs now have proper kubebuilder markers for validation. This might surprise someone leaving out some data that was essentially actually required or expected in a certain format. This is now validated in #4104.
Images
Image:
ghcr.io/external-secrets/external-secrets:v0.11.0
Image:
ghcr.io/external-secrets/external-secrets:v0.11.0-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.11.0-ubi-boringssl
What's Changed
New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.7...v0.11.0
v0.10.7
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.7
Image:
ghcr.io/external-secrets/external-secrets:v0.10.7-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.7-ubi-boringssl
What's Changed
New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.6...v0.10.7
v0.10.6
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.6
Image:
ghcr.io/external-secrets/external-secrets:v0.10.6-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.6-ubi-boringssl
What's Changed
69830f2
tocc226ca
by @dependabot in https://github.com/external-secrets/external-secrets/pull/4043cc226ca
tof4a57e8
by @dependabot in https://github.com/external-secrets/external-secrets/pull/41120974259
toc694a4d
by @dependabot in https://github.com/external-secrets/external-secrets/pull/4113beefdbd
to1e42bbe
by @dependabot in https://github.com/external-secrets/external-secrets/pull/4114beefdbd
to1e42bbe
in /hack/api-docs by @dependabot in https://github.com/external-secrets/external-secrets/pull/4118beefdbd
to1e42bbe
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/41190e3377d
to3f3b9da
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/4120New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.5...v0.10.6
v0.10.5
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.5
Image:
ghcr.io/external-secrets/external-secrets:v0.10.5-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.5-ubi-boringssl
What's Changed
1a5326b
todba79eb
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/3968ac67716
toac67716
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3969b033683
to69830f2
by @dependabot in https://github.com/external-secrets/external-secrets/pull/39709dd2625
to9dd2625
by @dependabot in https://github.com/external-secrets/external-secrets/pull/400718d2f94
to2341ddf
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/40249dd2625
to9dd2625
by @dependabot in https://github.com/external-secrets/external-secrets/pull/4025New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.4...v0.10.5
v0.10.4
Compare Source
WARNING: With this update, Pulumi has added
projectID
to it's required properties.Image:
oci.external-secrets.io/external-secrets/external-secrets:v0.10.4
Image:
oci.external-secrets.io/external-secrets/external-secrets:v0.10.4-ubi
Image:
oci.external-secrets.io/external-secrets/external-secrets:v0.10.4-ubi-boringssl
Default image registry change
From this version onwards, the default image registry name will be oci.external-secrets.io. While GHCR.io will keep on working for the foreseeable future, this change is to allow an eventual migration away from GHCR.
deprecation of GHCR - if performed, will be announced previous to its implementation and switch.
What's Changed
ac67716
toac67716
by @dependabot in https://github.com/external-secrets/external-secrets/pull/391495eb83a
tob033683
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3947New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.3...v0.10.4
v0.10.3
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3-ubi-boringssl
What's Changed
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.