Skip to content

chore(deps): update helm charts - #659

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/helm-charts
Open

chore(deps): update helm charts#659
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/helm-charts

Conversation

@renovate

@renovate renovate Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
argo-cd helm_release minor 10.3.210.4.2
cilium (source) helm_release patch 1.20.01.20.1
crossplane (source) minor 2.3.42.4.0
external-secrets helm_release minor 2.9.02.10.0
kyverno (source) minor 3.8.23.9.0

Release Notes

argoproj/argo-helm (argo-cd)

v10.4.2

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-10.4.1...argo-cd-10.4.2

v10.4.1

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-workflows-2.0.3...argo-cd-10.4.1

v10.4.0

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-workflows-2.0.1...argo-cd-10.4.0

v10.3.3

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-workflows-2.0.0...argo-cd-10.3.3

cilium/cilium (cilium)

v1.20.1: 1.20.1

Compare Source

Summary of Changes

Major Changes:

  • docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR #​47615, Upstream PR #​47351, @​MrFreezeex)

Minor Changes:

Bugfixes:

CI Changes:

Misc Changes:

Other Changes:

Docker Manifests

cilium

quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b
quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b

clustermesh-apiserver

quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5
quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5

hubble-relay

quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4
quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4

operator-alibabacloud

quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c
quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c

operator-aws

quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7
quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7

operator-azure

quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031
quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031

operator-generic

quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf
quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf

operator

quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d
quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d

crossplane/crossplane (crossplane)

v2.4.0

Compare Source

The v2.4.0 release is a regular quarterly Crossplane release that is focused on maturing a number of key areas of functionality across the project, as Crossplane continues to become more capable, more reliable, and more performant for your production workloads. This release includes the ability to watch required resources and reconcile XRs immediately when they change, scale to zero for safe-start capable providers, release artifacts that are vulnerability scannable, and a wide range of fixes and reliability improvements. It also includes security fixes in Crossplane's Go toolchain and dependencies.

🚨 v1.20 end-of-life (EOL) November 2026

This v2.4 release marks the final release cycle where v1.20 will be maintained.

When v2.5 is released in Nov 2026, v1.20 will reach its EOL and no longer receive any support or maintenance by the Crossplane project. Until that time, we will continue to provide critical fixes and security related dependency updates to v1.20.

[!IMPORTANT]
This EOL notice applies only to the v1.20 release. v1 legacy workloads like Claims and cluster scoped resources remain supported in Crossplane v2 through extensive backwards compatibility support.

Is your control plane ready for v2?

Upgrading to Crossplane v2 does not require any migration as part of the upgrade process, with the exception of the minimal breaking changes explicitly called out in the v2 documentation. If your control plane is not affected by those changes, you can simply upgrade to v2 right away.

To better assist Crossplane users in determining if their control planes are affected by any of the breaking changes in v2, we have released a v2 readiness checker tool in the v1.20 Crossplane CLI that can be invoked via crossplane beta upgrade check. You can read all about this tool in the following resources:

Crossplane Downstream Distributions

Downstream distributions are eligible to continue their extended support and maintenance for their releases that are based on upstream Crossplane's v1.20. Check with your vendor for more details if you are using a downstream distribution of Crossplane.

🚨 v2.4 Notable and Breaking Changes

  • ⚠️ The Crossplane CLI is no longer published to releases.crossplane.io. New CLI releases go only to cli.crossplane.io, under the binary name crossplane rather than crank. This completes the CLI's move to https://github.com/crossplane/cli, which was announced in the v2.3.0 release notes and dual published to both locations for v2.3.0 to ease the transition.
    • f you are using custom installation scripts or CI steps that download the CLI directly from releases.crossplane.io, update them to use cli.crossplane.io, and update any firewall or proxy rule that allows releases.crossplane.io to now allow cli.crossplane.io instead.
      • Users of the install.sh script as their installation procedure are unaffected.
    • The CLI now follows its own release schedule, so a CLI release will not accompany every core Crossplane release and the two version numbers have diverged.
    • Documentation and installation instructions for the Crossplane CLI can be found on https://docs.crossplane.io/cli/latest/.
  • Package revision names are now derived from both the package digest and the package's metadata.generation, so any change to a package's spec produces a new PackageRevision. #​7473
    • This fixes the long standing issue where changing a package's runtimeConfigRef reused the existing revision, along with its stale runtime settings. #​5068
    • When upgrading to v2.4, every installed package gets a new revision, with a new name, on its first reconcile.
    • ⚠️ The Pods for Providers and Functions will be restarted for this new revision.
  • Package runtime objects (Deployment, ServiceAccount, Service, and TLS Secrets) are now applied with server-side apply under the pkg.crossplane.io/runtime field manager, replacing the previous merge patch applicator. #​7563
    • A field you remove from a DeploymentRuntimeConfig is now removed from the live runtime object, rather than lingering until that object is replaced. #​4817
    • Additions that Crossplane doesn't declare are left alone rather than replaced along with the array that held them, e.g. an injected sidecar container or an extra volume added out of band now survives a reconcile.
  • The RUNTIME printer column on ProviderRevision and FunctionRevision was renamed to RUNTIME-HEALTHY, and a new RUNTIME-ACTIVE column was added. #​7586
    • Update any tooling that reads kubectl get providerrevision or kubectl get functionrevision output by column position.
  • The type label on the engine_watches_started_total and engine_watches_stopped_total metrics changed from ComposedResource to Dependency, now that a single watch mechanism covers both composed and required resources. #​7572
    • Update any dashboards or alerts that filter on that label value.

🎉 Highlights

  • Watching required resources: Composition functions can require resources they don't compose, but Crossplane didn't watch them, so a change to a required resource didn't reconcile the XRs that required it until their next poll. Crossplane now tracks the resources each XR depends on and drives watches from that. A change to a required resource now reconciles the XRs that required it the same way a change to a composed resource does. This works when realtime compositions are enabled, which is the default. See design/one-pager-watching-required-resources.md and #​7572.
  • Safe-start provider runtimes scale to zero until activated: A provider with the safe-start capability runs no managed resource controllers while all of its ManagedResourceDefinitions are inactive, so there is no reason to run its pods. Crossplane now creates such a provider's runtime Deployment with zero replicas and scales it up once its first MRD becomes active, such as through a matching ManagedResourceActivationPolicy. Installing a broad set of providers no longer costs you a running pod for each one that has nothing to reconcile yet. #​7586
    • A new RuntimeActive condition on ProviderRevision and FunctionRevision makes this visible. It is False with reason AwaitingActivation while the runtime is intentionally scaled to zero and True once it has been scaled up. RuntimeHealthy stays healthy in both cases, and the package's Healthy condition surfaces the awaiting state with the same reason.
    • Scaling to zero takes precedence over an explicit spec.replicas in a DeploymentRuntimeConfig, which is now read as how many replicas to run while running, rather than a demand to always be running. #​7639
  • Vulnerability-scannable container images: Crossplane container images are now built with nixpkgs' buildGoModule, which includes the full Go dependency list into the binary. Scanners such as grype and trivy previously were only able to discover the Crossplane main module and the Go standard library, so CVEs in our third-party dependencies were not visible to them. Now Crossplane and its complete set of dependencies are visible to security scanner tools. #​7549
  • More reliable package runtime management: Server-side apply for package runtime objects means a field you remove from a DeploymentRuntimeConfig is now actually removed from the live Deployment instead of lingering (#​7563, fixing #​4817). Deactivating a revision also no longer deletes a runtime Deployment that another revision controls, which could happen when a DeploymentRuntimeConfig pins a stable deploymentTemplate.metadata.name (#​7561).
  • Hardening across composition and package paths: Several changes tighten paths where a caller could reach further than intended. The composed resource garbage collector now only deletes resources whose controller reference points back to the XR, so spec.resourceRefs can no longer be used to make the composite controller delete arbitrary resources (#​7627). The claim to XR syncers now strip XR machinery fields such as resourceRefs and the crossplane stanza, which a claim could otherwise smuggle through an XRD schema that sets x-kubernetes-preserve-unknown-fields: true (#​7626).
  • Version-aware docs search: Searching from an older version of the docs, such as /v1.20/, used to return results from all versions, potentially returning features and APIs that don't exist in the version you're actually reading. Search is now scoped to the version you're on, results carry a clearly visible version badge, and pages from older versions show a banner explaining that, with a link to latest. Thanks to @​haarchri for this one in crossplane/docs#1051, so give it a try at https://docs.crossplane.io.
  • Security fixes in dependencies: The Go version Crossplane builds/runs with was bumped to pick up standard library CVE fixes, alongside a steady stream of security updates to Crossplane's Go dependencies across this release cycle.
  • Other notable improvements:
    • Several fixes to the render engine that backs crossplane render: an XRD schema can now be supplied to crossplane internal render (#​7452), requirements are returned even when a function returns a fatal result (#​7455), a namespace is set on injected resource references only for cluster-scoped XRs, matching the real reconciler (#​7523), and an input XR fetched from a real cluster keeps its own UID so its observed resources are read correctly, with clear errors when observed resources don't line up with the XR (#​7544).
    • The sha256 files published with release binaries are now calculated after Nix strips the binary, so amd64 checksums match what you download. They didn't for v2.2.0 through v2.3.1, and CI now verifies checksums before uploading artifacts. #​7660
    • A composed Usage no longer gets a redundant owner update on every reconcile, which could repeatedly trigger composition reconciliation and eventually open the XR circuit breaker. #​7591
    • The deletion protection field index now uses a separator that can't appear in a group, kind, name, or namespace, so two distinct resources can no longer collide and block a deletion that should be allowed. #​7508
    • Sorting of spec.resourceRefs now includes the namespace, so references stay stable when composed resources share a name across namespaces. #​7341

🏅 Release MVP

For the v2.4 release cycle, we'd like to recognize @​rafal-jan as the release MVP!

They had an enormous impact in crossplane-runtime, first by diagnosing the root cause in crossplane/crossplane-runtime#1056 of significant memory usage by providers that are safe-start capable when they essentially watch and cache every CRD in the control plane. Then @​rafal-jan went a step further and submitted an elegant solution in crossplane/crossplane-runtime#1058 to strip the cached CRDs down to just the fields needed to watch and respond appropriately to events, drastically reducing the memory consumption by these providers. Thank you @​rafal-jan!

📖 Full Changelog

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file helm labels Aug 15, 2026
@github-actions

github-actions Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (03-services)

→ Resource Changes: 0 to create, 3 to update, 0 to re-create, 0 to delete, 0 ephemeral, 0 to import.

♻️ Update

helm_release.argocd
! id                         = "argocd" -> (known after apply)
! metadata                   = {
!     app_version    = "v3.5.0" -> (known after apply)
!     chart          = "argo-cd" -> (known after apply)
!     first_deployed = 1770562152 -> (known after apply)
!     last_deployed  = 1786479350 -> (known after apply)
!     name           = "argocd" -> (known after apply)
!     namespace      = "argocd" -> (known after apply)
!     notes          = <<-EOT
          In order to access the server UI you have the following options:
          
          1. kubectl port-forward service/argocd-server -n argocd 8080:443
          
              and then open the browser on http://localhost:8080 and accept the certificate
          
          2. enable ingress in the values file `server.ingress.enabled` and either
                - Add the annotation for ssl passthrough: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-1-ssl-passthrough
                - Set the `configs.params."server.insecure"` in the values file and terminate SSL at your ingress: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-2-multiple-ingress-objects-and-hosts
          
          
          After reaching the UI the first time you can login with username: admin and the random password generated during the installation. You can find the password by running:
          
          kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d
          
          (You should delete the initial secret afterwards as suggested by the Getting Started Guide: https://argo-cd.readthedocs.io/en/stable/getting_started/#4-login-using-the-cli)
      EOT -> (known after apply)
!     revision       = 14 -> (known after apply)
!     values         = jsonencode(
          {
            - applicationSet  = {
                - enabled   = true
                - resources = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "64Mi"
                      }
                  }
              }
            - configs         = {
                - cm     = {
                    - "oidc.config" = <<-EOT
                          "clientID": "argocd"
                          "clientSecret": "$oidc.authentik.clientSecret"
                          "issuer": "https://auth.lippok.dev/application/o/argocd/"
                          "name": "Authentik"
                          "requestedScopes":
                          - "openid"
                          - "profile"
                          - "email"
                          - "groups"
                      EOT
                    - url           = "https://argocd.lippok.dev"
                  }
                - params = {
                    - "server.insecure" = "true"
                  }
                - rbac   = {
                    - "policy.csv"     = "g, authentik Admins, role:admin"
                    - "policy.default" = "role:readonly"
                    - scopes           = "[groups]"
                  }
              }
            - controller      = {
                - resources = {
                    - limits   = {
                        - memory = "2Gi"
                      }
                    - requests = {
                        - cpu    = "100m"
                        - memory = "512Mi"
                      }
                  }
              }
            - dex             = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
            - global          = {
                - logging = {
                    - level = "warn"
                  }
              }
            - notifications   = {
                - enabled       = true
                - notifiers     = {
                    - "service.webhook.discord" = <<-EOT
                          url: $discord-webhook
                      EOT
                    - "service.webhook.github"  = <<-EOT
                          url: https://api.github.com
                          headers:
                            - name: Authorization
                              value: "token $github-token"
                            - name: Content-Type
                              value: application/json
                      EOT
                  }
                - resources     = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
                - secret        = {
                    - create = false
                  }
                - subscriptions = [
                    - {
                        - recipients = [
                            - "github",
                          ]
                        - triggers   = [
                            - "on-sync-running",
                            - "on-sync-succeeded",
                            - "on-sync-failed",
                            - "on-health-degraded",
                          ]
                      },
                    - {
                        - recipients = [
                            - "discord",
                          ]
                        - triggers   = [
                            - "on-app-failed",
                          ]
                      },
                  ]
                - templates     = {
                    - "template.discord-alert"        = <<-EOT
                          webhook:
                            discord:
                              method: POST
                              path: /
                              body: |
                                {
                                  "content": "**ArgoCD** `{{.app.metadata.name}}` — {{if eq .app.status.operationState.phase "Error"}}Sync error: {{.app.status.operationState.message}}{{else if eq .app.status.operationState.phase "Failed"}}Sync failed: {{.app.status.operationState.message}}{{else}}Health degraded ({{.app.status.health.status}}){{end}}\n<https://argocd.lippok.dev/applications/{{.app.metadata.name}}>"
                                }
                      EOT
                    - "template.github-commit-status" = <<-EOT
                          webhook:
                            github:
                              method: POST
                              path: /repos/{{call .repo.FullNameByRepoURL .app.spec.source.repoURL}}/statuses/{{.app.status.operationState.operation.sync.revision}}
                              body: |
                                {
                                  "state": "{{if eq .app.status.operationState.phase "Running"}}pending{{else if and (eq .app.status.operationState.phase "Succeeded") (eq .app.status.health.status "Healthy")}}success{{else}}failure{{end}}",
                                  "description": "{{if eq .app.status.operationState.phase "Running"}}Syncing…{{else if and (eq .app.status.operationState.phase "Succeeded") (eq .app.status.health.status "Healthy")}}Healthy{{else if eq .app.status.health.status "Degraded"}}Health degraded{{else}}Sync failed{{end}}",
                                  "target_url": "https://argocd.lippok.dev/applications/{{.app.metadata.name}}",
                                  "context": "argocd/{{.app.metadata.name}}"
                                }
                      EOT
                  }
                - triggers      = {
                    - "trigger.on-app-failed"      = <<-EOT
                          - when: app.status.operationState.phase in ['Error', 'Failed'] || app.status.health.status == 'Degraded'
                            send: [discord-alert]
                      EOT
                    - "trigger.on-health-degraded" = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.health.status == 'Degraded'
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-failed"     = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState.phase in ['Error', 'Failed']
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-running"    = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState != nil && app.status.operationState.phase in ['Running']
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-succeeded"  = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState.phase in ['Succeeded'] && app.status.health.status == 'Healthy'
                            send: [github-commit-status]
                      EOT
                  }
              }
            - redis           = {
                - enabled      = true
                - resources    = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
                - volumeMounts = [
                    - {
                        - mountPath = "/data"
                        - name      = "redis-data"
                      },
                  ]
                - volumes      = [
                    - {
                        - emptyDir = {
                            - medium    = "Memory"
                            - sizeLimit = "1Gi"
                          }
                        - name     = "redis-data"
                      },
                  ]
              }
            - redis-ha        = {
                - enabled = false
              }
            - redisSecretInit = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
            - repoServer      = {
                - env            = [
                    - {
                        - name  = "TMPDIR"
                        - value = "/git-cache"
                      },
                  ]
                - livenessProbe  = {
                    - timeoutSeconds = 10
                  }
                - readinessProbe = {
                    - timeoutSeconds = 10
                  }
                - resources      = {
                    - limits   = {
                        - memory = "1Gi"
                      }
                    - requests = {
                        - cpu    = "50m"
                        - memory = "128Mi"
                      }
                  }
                - volumeMounts   = [
                    - {
                        - mountPath = "/git-cache"
                        - name      = "git-cache"
                      },
                  ]
                - volumes        = [
                    - {
                        - emptyDir = {
                            - medium    = "Memory"
                            - sizeLimit = "512Mi"
                          }
                        - name     = "git-cache"
                      },
                  ]
              }
            - server          = {
                - extraArgs = [
                    - "--insecure",
                  ]
                - resources = {
                    - limits   = {
                        - memory = "256Mi"
                      }
                    - requests = {
                        - cpu    = "50m"
                        - memory = "64Mi"
                      }
                  }
              }
          }
      ) -> (known after apply)
!     version        = "10.3.2" -> (known after apply)
  } -> (known after apply)
  name                       = "argocd"
! version                    = "10.3.2" -> "10.4.2"
  # (28 unchanged attributes hidden)
helm_release.cilium
! id                         = "cilium" -> (known after apply)
! metadata                   = {
!     app_version    = "1.20.0" -> (known after apply)
!     chart          = "cilium" -> (known after apply)
!     first_deployed = 1770561953 -> (known after apply)
!     last_deployed  = 1786479033 -> (known after apply)
!     name           = "cilium" -> (known after apply)
!     namespace      = "kube-system" -> (known after apply)
!     notes          = <<-EOT
          You have successfully installed Cilium with Hubble Relay and Hubble UI.
          
          WARNINGS:
          - WARNING: TLS is not enabled for the Hubble Relay server (hubble.relay.tls.server.enabled=false).
            This means Hubble Relay communications may not be encrypted. For more information about the security
            implications and suggested controls, please see: https://docs.cilium.io/en/stable/security/threat-model/#hubble-data-attacker
          
          Your release version is 1.20.0.
          
          For any further help, visit https://docs.cilium.io/en/v1.20/gettinghelp
      EOT -> (known after apply)
!     revision       = 43 -> (known after apply)
!     values         = jsonencode(
          {
            - cgroup               = {
                - autoMount = {
                    - enabled = false
                  }
                - hostRoot  = "/sys/fs/cgroup"
              }
            - gatewayAPI           = {
                - enabled = true
              }
            - hubble               = {
                - enabled = true
                - metrics = {
                    - enableOpenMetrics = true
                    - enabled           = [
                        - "dns:query;ignoreAAAA",
                        - "drop",
                        - "tcp",
                        - "icmp",
                      ]
                    - serviceMonitor    = {
                        - enabled  = true
                        - interval = "30s"
                        - labels   = {
                            - release = "kube-prometheus-stack"
                          }
                      }
                  }
                - relay   = {
                    - enabled    = true
                    - prometheus = {
                        - enabled        = true
                        - serviceMonitor = {
                            - enabled  = true
                            - interval = "30s"
                            - labels   = {
                                - release = "kube-prometheus-stack"
                              }
                          }
                      }
                  }
                - tls     = {
                    - auto = {
                        - certManagerIssuerRef = {
                            - group = "cert-manager.io"
                            - kind  = "ClusterIssuer"
                            - name  = "internal-ca-issuer"
                          }
                        - certValidityDuration = 90
                        - enabled              = true
                        - method               = "certmanager"
                      }
                  }
                - ui      = {
                    - enabled = true
                  }
              }
            - ipam                 = {
                - mode = "kubernetes"
              }
            - k8sServiceHost       = "127.0.0.1"
            - k8sServicePort       = 7445
            - kubeProxyReplacement = "true"
            - l2announcements      = {
                - enabled = true
              }
            - operator             = {
                - prometheus = {
                    - enabled        = true
                    - serviceMonitor = {
                        - enabled  = true
                        - interval = "30s"
                        - labels   = {
                            - release = "kube-prometheus-stack"
                          }
                      }
                  }
              }
            - prometheus           = {
                - enabled        = true
                - serviceMonitor = {
                    - enabled  = true
                    - interval = "30s"
                    - labels   = {
                        - release = "kube-prometheus-stack"
                      }
                  }
              }
            - securityContext      = {
                - capabilities = {
                    - ciliumAgent      = [
                        - "CHOWN",
                        - "KILL",
                        - "NET_ADMIN",
                        - "NET_RAW",
                        - "IPC_LOCK",
                        - "SYS_ADMIN",
                        - "SYS_RESOURCE",
                        - "DAC_OVERRIDE",
                        - "FOWNER",
                        - "SETGID",
                        - "SETUID",
                      ]
                    - cleanCiliumState = [
                        - "NET_ADMIN",
                        - "SYS_ADMIN",
                        - "SYS_RESOURCE",
                      ]
                  }
              }
            - tls                  = {
                - ca       = {
                    - cert = "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJmRENDQVNLZ0F3SUJBZ0lRYU1iTEJjdU9XcW9uTFVNODJob3hPREFLQmdncWhrak9QUVFEQWpBZU1Sd3cKR2dZRFZRUURFeE5vYjIxbGJHRmlMV2x1ZEdWeWJtRnNMV05oTUI0WERUSTJNRFF4T1RJeE5UQXpPVm9YRFRNMgpNRFF4TmpJeE5UQXpPVm93SGpFY01Cb0dBMVVFQXhNVGFHOXRaV3hoWWkxcGJuUmxjbTVoYkMxallUQlpNQk1HCkJ5cUdTTTQ5QWdFR0NDcUdTTTQ5QXdFSEEwSUFCQXB1d2xaT2pZWlplVEFHOFEwelVBSGhxYmlGTWlmZlZDRk0KTjNpeExKUk9MNUYwSWxPejRuZlZqOExML1JJQU1mcFBDYVZJelVWOTIzai9qNWRacXdhalFqQkFNQTRHQTFVZApEd0VCL3dRRUF3SUJoakFQQmdOVkhSTUJBZjhFQlRBREFRSC9NQjBHQTFVZERnUVdCQlFFZW5KM2dKb0Nray81CnVpbHhtcjFsRTZ4ZHpqQUtCZ2dxaGtqT1BRUURBZ05JQURCRkFpQTRjcmNiSjhLL2pRWTgyTFJMY0t6OC9RdVUKRXMrSHBPQW9YTXlFMSt0ZFN3SWhBT1RWQnliYTJEaUlrcndhRmYwWVlJU1Z5bXNlenpGS3c1a1ZKUE93d3R6YQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="
                    - key  = "LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUFqSi9UdU1wQ0JBVFh5dHpHZEpOVEo4OUtFS1BLZWxqTFl6Y3NLbTdMaFdvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFQ203Q1ZrNk5obGw1TUFieERUTlFBZUdwdUlVeUo5OVVJVXczZUxFc2xFNHZrWFFpVTdQaQpkOVdQd3N2OUVnQXgrazhKcFVqTlJYM2JlUCtQbDFtckJnPT0KLS0tLS1FTkQgRUMgUFJJVkFURSBLRVktLS0tLQo="
                  }
                - caBundle = {
                    - content   = <<-EOT
                          -----BEGIN CERTIFICATE-----
                          MIIBfDCCASKgAwIBAgIQaMbLBcuOWqonLUM82hoxODAKBggqhkjOPQQDAjAeMRww
                          GgYDVQQDExNob21lbGFiLWludGVybmFsLWNhMB4XDTI2MDQxOTIxNTAzOVoXDTM2
                          MDQxNjIxNTAzOVowHjEcMBoGA1UEAxMTaG9tZWxhYi1pbnRlcm5hbC1jYTBZMBMG
                          ByqGSM49AgEGCCqGSM49AwEHA0IABApuwlZOjYZZeTAG8Q0zUAHhqbiFMiffVCFM
                          N3ixLJROL5F0IlOz4nfVj8LL/RIAMfpPCaVIzUV923j/j5dZqwajQjBAMA4GA1Ud
                          DwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBQEenJ3gJoCkk/5
                          uilxmr1lE6xdzjAKBggqhkjOPQQDAgNIADBFAiA4crcbJ8K/jQY82LRLcKz8/QuU
                          Es+HpOAoXMyE1+tdSwIhAOTVByba2DiIkrwaFf0YYISVymsezzFKw5kVJPOwwtza
                          -----END CERTIFICATE-----
                      EOT
                    - enabled   = true
                    - key       = "ca.crt"
                    - name      = "cilium-root-ca.crt"
                    - useSecret = false
                  }
              }
          }
      ) -> (known after apply)
!     version        = "1.20.0" -> (known after apply)
  } -> (known after apply)
  name                       = "cilium"
! version                    = "1.20.0" -> "1.20.1"
  # (28 unchanged attributes hidden)
helm_release.external_secrets
! id                         = "external-secrets" -> (known after apply)
! metadata                   = {
!     app_version    = "v2.9.0" -> (known after apply)
!     chart          = "external-secrets" -> (known after apply)
!     first_deployed = 1772488004 -> (known after apply)
!     last_deployed  = 1786479347 -> (known after apply)
!     name           = "external-secrets" -> (known after apply)
!     namespace      = "external-secrets" -> (known after apply)
!     notes          = <<-EOT
          external-secrets has been deployed successfully in namespace external-secrets!
          
          In order to begin using ExternalSecrets, you will need to set up a SecretStore
          or ClusterSecretStore resource (for example, by creating a 'vault' SecretStore).
          
          More information on the different types of SecretStores and how to configure them
          can be found in our Github: https://github.com/external-secrets/external-secrets
      EOT -> (known after apply)
!     revision       = 5 -> (known after apply)
!     values         = jsonencode(
          {
            - certController = {
                - resources = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "64Mi"
                      }
                  }
              }
            - installCRDs    = true
            - resources      = {
                - limits   = {
                    - memory = "128Mi"
                  }
                - requests = {
                    - cpu    = "10m"
                    - memory = "64Mi"
                  }
              }
            - webhook        = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
          }
      ) -> (known after apply)
!     version        = "2.9.0" -> (known after apply)
  } -> (known after apply)
  name                       = "external-secrets"
! version                    = "2.9.0" -> "2.10.0"
  # (28 unchanged attributes hidden)

Triggered by @renovate[bot], Commit: d7fb97e347b14689e21094000c708ea4c397e5b2

@renovate
renovate Bot force-pushed the renovate/helm-charts branch from 502355f to 432e5d0 Compare August 17, 2026 22:47
@renovate renovate Bot changed the title chore(deps): update helm release argo-cd to v10.3.3 chore(deps): update helm release argo-cd to v10.4.0 Aug 17, 2026
@renovate renovate Bot changed the title chore(deps): update helm release argo-cd to v10.4.0 chore(deps): update helm charts Aug 18, 2026
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from 432e5d0 to ca49dd4 Compare August 18, 2026 16:04
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from ca49dd4 to c3ae6f9 Compare August 20, 2026 09:46
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from c3ae6f9 to 7e359af Compare August 20, 2026 14:08
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from 7e359af to 8dffc34 Compare August 21, 2026 13:44
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from 8dffc34 to a7addff Compare August 28, 2026 11:48
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from a7addff to 6a414ef Compare August 28, 2026 16:58
@renovate
renovate Bot force-pushed the renovate/helm-charts branch from 6a414ef to d7fb97e Compare August 29, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file helm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants