Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(helm): update chart external-secrets ( 0.9.13 → 0.12.1 ) #5295

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 30, 2024

This PR contains the following updates:

Package Update Change
external-secrets minor 0.9.13 -> 0.12.1

Release Notes

external-secrets/external-secrets (external-secrets)

v0.12.1

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.12.1
Image: ghcr.io/external-secrets/external-secrets:v0.12.1-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.12.1-ubi-boringssl

What's Changed

Full Changelog: external-secrets/external-secrets@v0.12.0...v0.12.1

v0.11.0

Compare Source

Deprecation of OLM Releases

As of 0.11.0 is the last release available for OLM until further notice. Depending on the way this goes, we might still have OLM support (ideally with a properly built operator for that), but for sure in a different support scheme as to not overload maintainers anymore.
Also a valid note - you can still use 0.11.0 OLM release and the newest ESO images, you just need to set image.tag appropriately in your setup.

Kubernetes API load and significant decrease

A new way of reconciling external secrets has been added with pull request #​4086.

This significantly reduces the number of API calls that we make to the kubernetes API server.

  1. Memory usage might increase if you are not already using --enable-secrets-caching
    1. If you are using --enable-secrets-caching and want to decrease memory usage at the expense of slightly higher API usage, you can disable it and only enable --enable-managed-secrets-caching (which is the new default)
  2. In ALL cases (even when CreationPolicy is Merge), if a data key in the target Secret was created by the ExternalSecret, and it no longer exists in the template (or data/dataFrom), it will be removed from the target secret:
    1. This might cause some peoples secrets to be "cleaned of data keys" when updating to 0.11.
    2. Previously, the behaviour was undefined, and confusing because it was sort of broken when the template feature was added.
    3. The one exception is that ALL the data suddenly becomes empty and the DeletionPolicy is retain, in which case we will not even report and error, just change the SecretSynced message to explain that the secret was retained.
  3. When CreationPolicy is Owner, we now will NEVER retain any keys and fully calculate the "desired state" of the target secret each loop:
    1. This means that some peoples secrets might have keys removed when updating to 0.11.
Generators and ClusterGenerator

We added ClusterGenerators and Generator caching as well. This might create some problems in the way generators are defined now.

CRD Admission Restrictions

All of the CRDs now have proper kubebuilder markers for validation. This might surprise someone leaving out some data that was essentially actually required or expected in a certain format. This is now validated in #​4104.

Images

Image: ghcr.io/external-secrets/external-secrets:v0.11.0
Image: ghcr.io/external-secrets/external-secrets:v0.11.0-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.11.0-ubi-boringssl

What's Changed
New Contributors

Full Changelog: external-secrets/external-secrets@v0.10.7...v0.11.0

v0.10.7

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.7
Image: ghcr.io/external-secrets/external-secrets:v0.10.7-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.10.7-ubi-boringssl

What's Changed
New Contributors

Full Changelog: external-secrets/external-secrets@v0.10.6...v0.10.7

v0.10.6

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.6
Image: ghcr.io/external-secrets/external-secrets:v0.10.6-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.10.6-ubi-boringssl

What's Changed
New Contributors

Full Changelog: external-secrets/external-secrets@v0.10.5...v0.10.6

v0.10.5

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.5
Image: ghcr.io/external-secrets/external-secrets:v0.10.5-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.10.5-ubi-boringssl

What's Changed
New Contributors

Full Changelog: external-secrets/external-secrets@v0.10.4...v0.10.5

v0.10.4

Compare Source

WARNING: With this update, Pulumi has added projectID to it's required properties.

Image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.4
Image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.4-ubi
Image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.4-ubi-boringssl

Default image registry change

From this version onwards, the default image registry name will be oci.external-secrets.io. While GHCR.io will keep on working for the foreseeable future, this change is to allow an eventual migration away from GHCR.

deprecation of GHCR - if performed, will be announced previous to its implementation and switch.

What's Changed

New Contributors

Full Changelog: external-secrets/external-secrets@v0.10.3...v0.10.4

v0.10.3

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.3
Image: ghcr.io/external-secrets/external-secrets:v0.10.3-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.10.3-ubi-boringssl

What's Changed


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@carpenike-bot
Copy link
Contributor

carpenike-bot bot commented Mar 30, 2024

--- kubernetes/nas-1/apps/kube-system/external-secrets/app Kustomization: flux-system/cluster-apps-external-secrets HelmRelease: kube-system/external-secrets

+++ kubernetes/nas-1/apps/kube-system/external-secrets/app Kustomization: flux-system/cluster-apps-external-secrets HelmRelease: kube-system/external-secrets

@@ -12,13 +12,13 @@

     spec:
       chart: external-secrets
       sourceRef:
         kind: HelmRepository
         name: external-secrets
         namespace: flux-system
-      version: 0.9.13
+      version: 0.10.7
   install:
     createNamespace: true
     remediation:
       retries: 3
   interval: 15m
   maxHistory: 2

@carpenike-bot
Copy link
Contributor

carpenike-bot bot commented Mar 30, 2024

--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-cert-controller

+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-cert-controller

@@ -20,15 +20,23 @@

   - patch
 - apiGroups:
   - admissionregistration.k8s.io
   resources:
   - validatingwebhookconfigurations
   verbs:
-  - get
   - list
   - watch
+  - get
+- apiGroups:
+  - admissionregistration.k8s.io
+  resources:
+  - validatingwebhookconfigurations
+  resourceNames:
+  - secretstore-validate
+  - externalsecret-validate
+  verbs:
   - update
   - patch
 - apiGroups:
   - ''
   resources:
   - endpoints
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-controller

+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-controller

@@ -36,23 +36,26 @@

   - clusterexternalsecrets/status
   - clusterexternalsecrets/finalizers
   - pushsecrets
   - pushsecrets/status
   - pushsecrets/finalizers
   verbs:
+  - get
   - update
   - patch
 - apiGroups:
   - generators.external-secrets.io
   resources:
   - acraccesstokens
   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
+  - githubaccesstokens
   - passwords
   - vaultdynamicsecrets
+  - webhooks
   verbs:
   - get
   - list
   - watch
 - apiGroups:
   - ''
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-view

+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-view

@@ -26,13 +26,15 @@

   - generators.external-secrets.io
   resources:
   - acraccesstokens
   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
+  - githubaccesstokens
   - passwords
   - vaultdynamicsecrets
+  - webhooks
   verbs:
   - get
   - watch
   - list
 
--- HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-edit

+++ HelmRelease: kube-system/external-secrets ClusterRole: kube-system/external-secrets-edit

@@ -27,14 +27,16 @@

   - generators.external-secrets.io
   resources:
   - acraccesstokens
   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
+  - githubaccesstokens
   - passwords
   - vaultdynamicsecrets
+  - webhooks
   verbs:
   - create
   - delete
   - deletecollection
   - patch
   - update
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-cert-controller

+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-cert-controller

@@ -34,23 +34,26 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.9.13
+        image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
         imagePullPolicy: IfNotPresent
         args:
         - certcontroller
         - --crd-requeue-interval=5m
         - --service-name=external-secrets-webhook
         - --service-namespace=kube-system
         - --secret-name=external-secrets-webhook
         - --secret-namespace=kube-system
         - --metrics-addr=:8080
         - --healthz-addr=:8081
+        - --loglevel=info
+        - --zap-time-encoding=epoch
+        - --enable-partial-cache=true
         ports:
         - containerPort: 8080
           protocol: TCP
           name: metrics
         readinessProbe:
           httpGet:
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets

+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets

@@ -34,16 +34,19 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.9.13
+        image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
         imagePullPolicy: IfNotPresent
         args:
         - --concurrent=1
         - --metrics-addr=:8080
+        - --loglevel=info
+        - --zap-time-encoding=epoch
         ports:
         - containerPort: 8080
           protocol: TCP
           name: metrics
+      dnsPolicy: ClusterFirst
 
--- HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-webhook

+++ HelmRelease: kube-system/external-secrets Deployment: kube-system/external-secrets-webhook

@@ -34,22 +34,24 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.9.13
+        image: oci.external-secrets.io/external-secrets/external-secrets:v0.10.7
         imagePullPolicy: IfNotPresent
         args:
         - webhook
         - --port=10250
         - --dns-name=external-secrets-webhook.kube-system.svc
         - --cert-dir=/tmp/certs
         - --check-interval=5m
         - --metrics-addr=:8080
         - --healthz-addr=:8081
+        - --loglevel=info
+        - --zap-time-encoding=epoch
         ports:
         - containerPort: 8080
           protocol: TCP
           name: metrics
         - containerPort: 10250
           protocol: TCP
--- HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/secretstore-validate

+++ HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/secretstore-validate

@@ -1,12 +1,15 @@

 ---
 apiVersion: admissionregistration.k8s.io/v1
 kind: ValidatingWebhookConfiguration
 metadata:
   name: secretstore-validate
   labels:
+    app.kubernetes.io/name: external-secrets-webhook
+    app.kubernetes.io/instance: external-secrets
+    app.kubernetes.io/managed-by: Helm
     external-secrets.io/component: webhook
 webhooks:
 - name: validate.secretstore.external-secrets.io
   rules:
   - apiGroups:
     - external-secrets.io
--- HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/externalsecret-validate

+++ HelmRelease: kube-system/external-secrets ValidatingWebhookConfiguration: kube-system/externalsecret-validate

@@ -1,12 +1,15 @@

 ---
 apiVersion: admissionregistration.k8s.io/v1
 kind: ValidatingWebhookConfiguration
 metadata:
   name: externalsecret-validate
   labels:
+    app.kubernetes.io/name: external-secrets-webhook
+    app.kubernetes.io/instance: external-secrets
+    app.kubernetes.io/managed-by: Helm
     external-secrets.io/component: webhook
 webhooks:
 - name: validate.externalsecret.external-secrets.io
   rules:
   - apiGroups:
     - external-secrets.io

@carpenike-bot
Copy link
Contributor

carpenike-bot bot commented Mar 30, 2024

🦙 MegaLinter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Elapsed time
❌ COPYPASTE jscpd yes 2 1.14s
✅ REPOSITORY git_diff yes no 0.02s
✅ REPOSITORY secretlint yes no 3.23s
✅ YAML prettier 1 0 0.36s
✅ YAML yamllint 1 0 0.35s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from f2ec7c5 to 7925a29 Compare April 18, 2024 15:09
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.14 ) fix(helm): update chart external-secrets ( 0.9.13 → 0.9.16 ) Apr 18, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 7925a29 to 0559b33 Compare May 1, 2024 18:34
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.16 ) fix(helm): update chart external-secrets ( 0.9.13 → 0.9.17 ) May 1, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 0559b33 to e68f99a Compare May 14, 2024 08:36
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.17 ) fix(helm): update chart external-secrets ( 0.9.13 → 0.9.18 ) May 14, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from e68f99a to 40f402a Compare June 4, 2024 20:05
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.18 ) fix(helm): update chart external-secrets ( 0.9.13 → 0.9.19 ) Jun 4, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 40f402a to 82b4b73 Compare July 6, 2024 22:18
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.19 ) fix(helm): update chart external-secrets ( 0.9.13 → 0.9.20 ) Jul 6, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 82b4b73 to c9ff693 Compare August 3, 2024 11:16
@renovate renovate bot changed the title fix(helm): update chart external-secrets ( 0.9.13 → 0.9.20 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.0 ) Aug 3, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from c9ff693 to 00e6554 Compare August 28, 2024 11:52
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.0 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.1 ) Aug 28, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 00e6554 to b0aafda Compare August 28, 2024 20:15
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.1 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.2 ) Aug 28, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from b0aafda to e05ce88 Compare September 9, 2024 15:28
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.2 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.3 ) Sep 9, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from e05ce88 to debd967 Compare September 25, 2024 13:45
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.3 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.4 ) Sep 25, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from debd967 to 079d9d2 Compare October 25, 2024 07:34
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.4 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.5 ) Oct 25, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 079d9d2 to d1688c2 Compare November 20, 2024 20:52
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.5 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.6 ) Nov 20, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from d1688c2 to f9b32e0 Compare November 23, 2024 10:12
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.6 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.10.7 ) Nov 23, 2024
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from f9b32e0 to 4fc4d71 Compare December 2, 2024 12:38
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.10.7 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.11.0 ) Dec 2, 2024
| datasource | package          | from   | to     |
| ---------- | ---------------- | ------ | ------ |
| helm       | external-secrets | 0.9.13 | 0.12.1 |
@renovate renovate bot force-pushed the renovate/nas-1-external-secrets-0.x branch from 4fc4d71 to b4cd1fe Compare December 23, 2024 22:47
@renovate renovate bot changed the title feat(helm): update chart external-secrets ( 0.9.13 → 0.11.0 ) feat(helm): update chart external-secrets ( 0.9.13 → 0.12.1 ) Dec 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants