Skip to content

chore(deps): update helm charts#462

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/helm-charts
Open

chore(deps): update helm charts#462
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/helm-charts

Conversation

@renovate

@renovate renovate Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
argo-cd helm_release minor 9.4.179.7.1
cert-manager (source) helm_release patch v1.20.1v1.20.3
cilium (source) helm_release patch 1.19.21.19.5
crossplane (source) minor 2.2.02.3.3
csi-driver-nfs helm_release patch 4.13.14.13.3
external-secrets helm_release minor 2.2.02.7.0
kyverno (source) patch 3.8.03.8.1

Release Notes

argoproj/argo-helm (argo-cd)

v9.7.1

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

  • fix(argo-cd): gate redis metrics NetworkPolicy rule behind exporter.enabled by @​yugstar in #​3930

New Contributors

Full Changelog: argoproj/argo-helm@argo-workflows-1.0.18...argo-cd-9.7.1

v9.7.0

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

  • feat(argo-cd): add startup probes and allow overriding httpGet path for health checks by @​alikhil in #​3934

New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.6.0...argo-cd-9.7.0

v9.6.0

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.22...argo-cd-9.6.0

v9.5.22

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-events-2.4.22...argo-cd-9.5.22

v9.5.21

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-workflows-1.0.15...argo-cd-9.5.21

v9.5.20

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-rollouts-2.41.0...argo-cd-9.5.20

v9.5.19

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.18...argo-cd-9.5.19

v9.5.18

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.5.17...argo-cd-9.5.18

v9.5.17

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

New Contributors

Full Changelog: argoproj/argo-helm@argo-rollouts-2.40.10...argo-cd-9.5.17

v9.5.16

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argocd-image-updater-1.2.2...argo-cd-9.5.16

v9.5.15

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argocd-image-updater-1.2.1...argo-cd-9.5.15

v9.5.14

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.13...argo-cd-9.5.14

v9.5.13

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.12...argo-cd-9.5.13

v9.5.12

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.11...argo-cd-9.5.12

v9.5.11

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.10...argo-cd-9.5.11

v9.5.10

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

  • chore(deps): bump step-security/harden-runner from 2.16.0 to 2.19.0 in the dependencies group across 1 directory by @​dependabot[bot] in #​3850
  • chore(argo-cd): Update ghcr.io/oliver006/redis_exporter Docker tag to v1.83.0 by @​argoproj-renovate[bot] in #​3866

Full Changelog: argoproj/argo-helm@argo-cd-9.5.9...argo-cd-9.5.10

v9.5.9

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.8...argo-cd-9.5.9

v9.5.8

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.7...argo-cd-9.5.8

v9.5.7

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

  • feat(argo-cd): Make PrometheusRule API version field overridable like it is in ServiceMonitor manifests. by @​rurod in #​3857

New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.5.6...argo-cd-9.5.7

v9.5.6

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.5.5...argo-cd-9.5.6

v9.5.5

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

New Contributors

Full Changelog: argoproj/argo-helm@argo-workflows-1.0.13...argo-cd-9.5.5

v9.5.4

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.5.3...argo-cd-9.5.4

v9.5.3

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.2...argo-cd-9.5.3

v9.5.2

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-cd-9.5.1...argo-cd-9.5.2

v9.5.1

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

  • feat(argo-cd): add repoServer.copyutil.extraArgs with default '--update=none' to support overriding by @​anandrkskd in #​3835

New Contributors

Full Changelog: argoproj/argo-helm@argo-workflows-1.0.10...argo-cd-9.5.1

v9.5.0

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed
New Contributors

Full Changelog: argoproj/argo-helm@argo-cd-9.4.18...argo-cd-9.5.0

v9.4.18

Compare Source

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

What's Changed

Full Changelog: argoproj/argo-helm@argo-workflows-1.0.7...argo-cd-9.4.18

cert-manager/cert-manager (cert-manager)

v1.20.3

Compare Source

v1.20.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config
and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies
to address reported vulnerabilities.

Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
cilium/cilium (cilium)

v1.19.5: 1.19.5

Compare Source

Summary of Changes

Minor Changes:

Bugfixes:

CI Changes:

Misc Changes:

Other Changes:

Docker Manifests

cilium

quay.io/cilium/cilium:v1.19.5@​sha256:20fbbc14ac20b55a292c0dcda5571bf31cde30a7dbc68c29db3e709390ab0732

clustermesh-apiserver

quay.io/cilium/clustermesh-apiserver:v1.19.5@​sha256:5ed9334b2254315740f9e2a8b6645bf69920f79ef14f436931579d2038784f9b

docker-plugin

quay.io/cilium/docker-plugin:v1.19.5@​sha256:4006d5558390120774a5a903a706dfd64089082bd653b7cb45e9e5a93ff4efea

hubble-relay

quay.io/cilium/hubble-relay:v1.19.5@​sha256:24409bfa1bca075c92acb26ba4b49cd573d99d68d5370f7cc825078185222a0c

operator-alibabacloud

quay.io/cilium/operator-alibabacloud:v1.19.5@​sha256:c9706343dde700804c2f50c09a2f8291797c707d1747fd50f70c939c23747c16

operator-aws

quay.io/cilium/operator-aws:v1.19.5@​sha256:b8473618e8d2bf8a610da445c8c37e1d1e8221aecd05989456d87a7588d66707

operator-azure

quay.io/cilium/operator-azure:v1.19.5@​sha256:8600299cb121f9df00fd32b93fa74de89ed49dd3a67e3d7301c07325c04c77f8

operator-generic

quay.io/cilium/operator-generic:v1.19.5@​sha256:be848a365776e07d0c5a895eda7aec928ddc52a5a1fa2f432fd7a286609e1db4

operator

quay.io/cilium/operator:v1.19.5@​sha256:07a25f6a248d77f0c8417d21b5ea5424a81fe551421e4baf04dc79b1360e832e

v1.19.4: 1.19.4

Compare Source

Summary of Changes

Minor Changes:

  • cilium-agent: when --k8s-service-proxy-name is set, EndpointSlices are now filtered by the service.kubernetes.io/service-proxy-name label at the watch level, matching how Services are already filtered, operators with hand-managed EndpointSlices must stamp the matching label on those slices. (Backport PR #​45755, Upstream PR #​45504, @​HadrienPatte)
  • iptables-based masquerading: Ensure iptables rules respect longest prefix match by sorting routes by mask length when enable-masquerade-to-route-source is enabled (Backport PR #​45630, Upstream PR #​45192, @​liyihuang)
  • operator/spire: make SPIRE client configurable for ztunnel (Backport PR #​45356, Upstream PR #​44136, @​nddq)
  • pkg/endpoint: skip logger rebuild on policy revision updates (Backport PR #​45630, Upstream PR #​45533, @​sjohnsonpal)

Bugfixes:

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file helm labels Apr 8, 2026
@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (03-services)

→ Resource Changes: 0 to create, 5 to update, 0 to re-create, 0 to delete, 0 ephemeral.

♻️ Update

helm_release.argocd
! id                         = "argocd" -> (known after apply)
! metadata                   = {
!     app_version    = "v3.3.6" -> (known after apply)
!     chart          = "argo-cd" -> (known after apply)
!     first_deployed = 1770562152 -> (known after apply)
!     last_deployed  = 1780837675 -> (known after apply)
!     name           = "argocd" -> (known after apply)
!     namespace      = "argocd" -> (known after apply)
!     notes          = <<-EOT
          In order to access the server UI you have the following options:
          
          1. kubectl port-forward service/argocd-server -n argocd 8080:443
          
              and then open the browser on http://localhost:8080 and accept the certificate
          
          2. enable ingress in the values file `server.ingress.enabled` and either
                - Add the annotation for ssl passthrough: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-1-ssl-passthrough
                - Set the `configs.params."server.insecure"` in the values file and terminate SSL at your ingress: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-2-multiple-ingress-objects-and-hosts
          
          
          After reaching the UI the first time you can login with username: admin and the random password generated during the installation. You can find the password by running:
          
          kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d
          
          (You should delete the initial secret afterwards as suggested by the Getting Started Guide: https://argo-cd.readthedocs.io/en/stable/getting_started/#4-login-using-the-cli)
      EOT -> (known after apply)
!     revision       = 10 -> (known after apply)
!     values         = jsonencode(
          {
            - applicationSet = {
                - enabled   = true
                - resources = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "64Mi"
                      }
                  }
              }
            - configs        = {
                - cm     = {
                    - "oidc.config" = <<-EOT
                          "clientID": "argocd"
                          "clientSecret": "$oidc.authentik.clientSecret"
                          "issuer": "https://auth.lippok.dev/application/o/argocd/"
                          "name": "Authentik"
                          "requestedScopes":
                          - "openid"
                          - "profile"
                          - "email"
                          - "groups"
                      EOT
                    - url           = "https://argocd.lippok.dev"
                  }
                - params = {
                    - "server.insecure" = "true"
                  }
                - rbac   = {
                    - "policy.csv"     = "g, authentik Admins, role:admin"
                    - "policy.default" = "role:readonly"
                    - scopes           = "[groups]"
                  }
              }
            - controller     = {
                - resources = {
                    - limits   = {
                        - memory = "1Gi"
                      }
                    - requests = {
                        - cpu    = "100m"
                        - memory = "256Mi"
                      }
                  }
              }
            - dex            = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
            - global         = {
                - logging = {
                    - level = "warn"
                  }
              }
            - notifications  = {
                - enabled       = true
                - notifiers     = {
                    - "service.webhook.discord" = <<-EOT
                          url: $discord-webhook
                      EOT
                    - "service.webhook.github"  = <<-EOT
                          url: https://api.github.com
                          headers:
                            - name: Authorization
                              value: "token $github-token"
                            - name: Content-Type
                              value: application/json
                      EOT
                  }
                - resources     = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
                - secret        = {
                    - create = false
                  }
                - subscriptions = [
                    - {
                        - recipients = [
                            - "github",
                          ]
                        - triggers   = [
                            - "on-sync-running",
                            - "on-sync-succeeded",
                            - "on-sync-failed",
                            - "on-health-degraded",
                          ]
                      },
                    - {
                        - recipients = [
                            - "discord",
                          ]
                        - triggers   = [
                            - "on-app-failed",
                          ]
                      },
                  ]
                - templates     = {
                    - "template.discord-alert"        = <<-EOT
                          webhook:
                            discord:
                              method: POST
                              path: /
                              body: |
                                {
                                  "content": "**ArgoCD** `{{.app.metadata.name}}` — {{if eq .app.status.operationState.phase "Error"}}Sync error: {{.app.status.operationState.message}}{{else if eq .app.status.operationState.phase "Failed"}}Sync failed: {{.app.status.operationState.message}}{{else}}Health degraded ({{.app.status.health.status}}){{end}}\n<https://argocd.lippok.dev/applications/{{.app.metadata.name}}>"
                                }
                      EOT
                    - "template.github-commit-status" = <<-EOT
                          webhook:
                            github:
                              method: POST
                              path: /repos/{{call .repo.FullNameByRepoURL .app.spec.source.repoURL}}/statuses/{{.app.status.operationState.operation.sync.revision}}
                              body: |
                                {
                                  "state": "{{if eq .app.status.operationState.phase "Running"}}pending{{else if and (eq .app.status.operationState.phase "Succeeded") (eq .app.status.health.status "Healthy")}}success{{else}}failure{{end}}",
                                  "description": "{{if eq .app.status.operationState.phase "Running"}}Syncing…{{else if and (eq .app.status.operationState.phase "Succeeded") (eq .app.status.health.status "Healthy")}}Healthy{{else if eq .app.status.health.status "Degraded"}}Health degraded{{else}}Sync failed{{end}}",
                                  "target_url": "https://argocd.lippok.dev/applications/{{.app.metadata.name}}",
                                  "context": "argocd/{{.app.metadata.name}}"
                                }
                      EOT
                  }
                - triggers      = {
                    - "trigger.on-app-failed"      = <<-EOT
                          - when: app.status.operationState.phase in ['Error', 'Failed'] || app.status.health.status == 'Degraded'
                            send: [discord-alert]
                      EOT
                    - "trigger.on-health-degraded" = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.health.status == 'Degraded'
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-failed"     = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState.phase in ['Error', 'Failed']
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-running"    = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState != nil && app.status.operationState.phase in ['Running']
                            send: [github-commit-status]
                      EOT
                    - "trigger.on-sync-succeeded"  = <<-EOT
                          - when: app.spec.source.repoURL contains 'github.com' && app.status.operationState.phase in ['Succeeded'] && app.status.health.status == 'Healthy'
                            send: [github-commit-status]
                      EOT
                  }
              }
            - redis          = {
                - enabled      = true
                - resources    = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
                - volumeMounts = [
                    - {
                        - mountPath = "/data"
                        - name      = "redis-data"
                      },
                  ]
                - volumes      = [
                    - {
                        - emptyDir = {
                            - medium    = "Memory"
                            - sizeLimit = "1Gi"
                          }
                        - name     = "redis-data"
                      },
                  ]
              }
            - redis-ha       = {
                - enabled = false
              }
            - repoServer     = {
                - env            = [
                    - {
                        - name  = "TMPDIR"
                        - value = "/git-cache"
                      },
                  ]
                - livenessProbe  = {
                    - timeoutSeconds = 10
                  }
                - readinessProbe = {
                    - timeoutSeconds = 10
                  }
                - resources      = {
                    - limits   = {
                        - memory = "1Gi"
                      }
                    - requests = {
                        - cpu    = "50m"
                        - memory = "128Mi"
                      }
                  }
                - volumeMounts   = [
                    - {
                        - mountPath = "/git-cache"
                        - name      = "git-cache"
                      },
                  ]
                - volumes        = [
                    - {
                        - emptyDir = {
                            - medium    = "Memory"
                            - sizeLimit = "512Mi"
                          }
                        - name     = "git-cache"
                      },
                  ]
              }
            - server         = {
                - extraArgs = [
                    - "--insecure",
                  ]
                - resources = {
                    - limits   = {
                        - memory = "256Mi"
                      }
                    - requests = {
                        - cpu    = "50m"
                        - memory = "64Mi"
                      }
                  }
              }
          }
      ) -> (known after apply)
!     version        = "9.4.17" -> (known after apply)
  } -> (known after apply)
  name                       = "argocd"
! version                    = "9.4.17" -> "9.7.1"
  # (28 unchanged attributes hidden)
helm_release.cert_manager
! id                         = "cert-manager" -> (known after apply)
! metadata                   = {
!     app_version    = "v1.20.1" -> (known after apply)
!     chart          = "cert-manager" -> (known after apply)
!     first_deployed = 1770562151 -> (known after apply)
!     last_deployed  = 1779394467 -> (known after apply)
!     name           = "cert-manager" -> (known after apply)
!     namespace      = "cert-manager" -> (known after apply)
!     notes          = <<-EOT
          cert-manager v1.20.1 has been deployed successfully!
          
          In order to begin issuing certificates, you will need to set up a ClusterIssuer
          or Issuer resource (for example, by creating a 'letsencrypt-staging' issuer).
          
          More information on the different types of issuers and how to configure them
          can be found in our documentation:
          
          https://cert-manager.io/docs/configuration/
          
          For information on how to configure cert-manager to automatically provision
          Certificates for Ingress resources, take a look at the `ingress-shim`
          documentation:
          
          https://cert-manager.io/docs/usage/ingress/
          
          For information on how to configure cert-manager to automatically provision
          Certificates for Gateway API resources, take a look at the `gateway resource`
          documentation:
          
          https://cert-manager.io/docs/usage/gateway/
      EOT -> (known after apply)
!     revision       = 3 -> (known after apply)
!     values         = jsonencode(
          {
            - cainjector = {
                - resources = {
                    - limits   = {
                        - memory = "256Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "128Mi"
                      }
                  }
              }
            - config     = {
                - apiVersion       = "controller.config.cert-manager.io/v1alpha1"
                - enableGatewayAPI = true
                - kind             = "ControllerConfiguration"
              }
            - crds       = {
                - enabled = true
              }
            - resources  = {
                - limits   = {
                    - memory = "128Mi"
                  }
                - requests = {
                    - cpu    = "10m"
                    - memory = "64Mi"
                  }
              }
            - webhook    = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
          }
      ) -> (known after apply)
!     version        = "v1.20.1" -> (known after apply)
  } -> (known after apply)
  name                       = "cert-manager"
! version                    = "v1.20.1" -> "v1.20.3"
  # (28 unchanged attributes hidden)
helm_release.cilium
! id                         = "cilium" -> (known after apply)
! metadata                   = {
!     app_version    = "1.19.2" -> (known after apply)
!     chart          = "cilium" -> (known after apply)
!     first_deployed = 1770561953 -> (known after apply)
!     last_deployed  = 1779139398 -> (known after apply)
!     name           = "cilium" -> (known after apply)
!     namespace      = "kube-system" -> (known after apply)
!     notes          = <<-EOT
          You have successfully installed Cilium with Hubble Relay and Hubble UI.
          
          Your release version is 1.19.2.
          
          For any further help, visit https://docs.cilium.io/en/v1.19/gettinghelp
      EOT -> (known after apply)
!     revision       = 42 -> (known after apply)
!     values         = jsonencode(
          {
            - cgroup               = {
                - autoMount = {
                    - enabled = false
                  }
                - hostRoot  = "/sys/fs/cgroup"
              }
            - gatewayAPI           = {
                - enabled = true
              }
            - hubble               = {
                - enabled = true
                - metrics = {
                    - enableOpenMetrics = true
                    - enabled           = [
                        - "dns:query;ignoreAAAA",
                        - "drop",
                        - "tcp",
                        - "icmp",
                      ]
                    - serviceMonitor    = {
                        - enabled  = true
                        - interval = "30s"
                        - labels   = {
                            - release = "kube-prometheus-stack"
                          }
                      }
                  }
                - relay   = {
                    - enabled    = true
                    - prometheus = {
                        - enabled        = true
                        - serviceMonitor = {
                            - enabled  = true
                            - interval = "30s"
                            - labels   = {
                                - release = "kube-prometheus-stack"
                              }
                          }
                      }
                  }
                - tls     = {
                    - auto = {
                        - certManagerIssuerRef = {
                            - group = "cert-manager.io"
                            - kind  = "ClusterIssuer"
                            - name  = "internal-ca-issuer"
                          }
                        - certValidityDuration = 90
                        - enabled              = true
                        - method               = "certmanager"
                      }
                  }
                - ui      = {
                    - enabled = true
                  }
              }
            - ipam                 = {
                - mode = "kubernetes"
              }
            - k8sServiceHost       = "127.0.0.1"
            - k8sServicePort       = 7445
            - kubeProxyReplacement = "true"
            - l2announcements      = {
                - enabled = true
              }
            - operator             = {
                - prometheus = {
                    - enabled        = true
                    - serviceMonitor = {
                        - enabled  = true
                        - interval = "30s"
                        - labels   = {
                            - release = "kube-prometheus-stack"
                          }
                      }
                  }
              }
            - prometheus           = {
                - enabled        = true
                - serviceMonitor = {
                    - enabled  = true
                    - interval = "30s"
                    - labels   = {
                        - release = "kube-prometheus-stack"
                      }
                  }
              }
            - securityContext      = {
                - capabilities = {
                    - ciliumAgent      = [
                        - "CHOWN",
                        - "KILL",
                        - "NET_ADMIN",
                        - "NET_RAW",
                        - "IPC_LOCK",
                        - "SYS_ADMIN",
                        - "SYS_RESOURCE",
                        - "DAC_OVERRIDE",
                        - "FOWNER",
                        - "SETGID",
                        - "SETUID",
                      ]
                    - cleanCiliumState = [
                        - "NET_ADMIN",
                        - "SYS_ADMIN",
                        - "SYS_RESOURCE",
                      ]
                  }
              }
            - tls                  = {
                - ca       = {
                    - cert = "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJmRENDQVNLZ0F3SUJBZ0lRYU1iTEJjdU9XcW9uTFVNODJob3hPREFLQmdncWhrak9QUVFEQWpBZU1Sd3cKR2dZRFZRUURFeE5vYjIxbGJHRmlMV2x1ZEdWeWJtRnNMV05oTUI0WERUSTJNRFF4T1RJeE5UQXpPVm9YRFRNMgpNRFF4TmpJeE5UQXpPVm93SGpFY01Cb0dBMVVFQXhNVGFHOXRaV3hoWWkxcGJuUmxjbTVoYkMxallUQlpNQk1HCkJ5cUdTTTQ5QWdFR0NDcUdTTTQ5QXdFSEEwSUFCQXB1d2xaT2pZWlplVEFHOFEwelVBSGhxYmlGTWlmZlZDRk0KTjNpeExKUk9MNUYwSWxPejRuZlZqOExML1JJQU1mcFBDYVZJelVWOTIzai9qNWRacXdhalFqQkFNQTRHQTFVZApEd0VCL3dRRUF3SUJoakFQQmdOVkhSTUJBZjhFQlRBREFRSC9NQjBHQTFVZERnUVdCQlFFZW5KM2dKb0Nray81CnVpbHhtcjFsRTZ4ZHpqQUtCZ2dxaGtqT1BRUURBZ05JQURCRkFpQTRjcmNiSjhLL2pRWTgyTFJMY0t6OC9RdVUKRXMrSHBPQW9YTXlFMSt0ZFN3SWhBT1RWQnliYTJEaUlrcndhRmYwWVlJU1Z5bXNlenpGS3c1a1ZKUE93d3R6YQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="
                    - key  = "LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUFqSi9UdU1wQ0JBVFh5dHpHZEpOVEo4OUtFS1BLZWxqTFl6Y3NLbTdMaFdvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFQ203Q1ZrNk5obGw1TUFieERUTlFBZUdwdUlVeUo5OVVJVXczZUxFc2xFNHZrWFFpVTdQaQpkOVdQd3N2OUVnQXgrazhKcFVqTlJYM2JlUCtQbDFtckJnPT0KLS0tLS1FTkQgRUMgUFJJVkFURSBLRVktLS0tLQo="
                  }
                - caBundle = {
                    - content   = <<-EOT
                          -----BEGIN CERTIFICATE-----
                          MIIBfDCCASKgAwIBAgIQaMbLBcuOWqonLUM82hoxODAKBggqhkjOPQQDAjAeMRww
                          GgYDVQQDExNob21lbGFiLWludGVybmFsLWNhMB4XDTI2MDQxOTIxNTAzOVoXDTM2
                          MDQxNjIxNTAzOVowHjEcMBoGA1UEAxMTaG9tZWxhYi1pbnRlcm5hbC1jYTBZMBMG
                          ByqGSM49AgEGCCqGSM49AwEHA0IABApuwlZOjYZZeTAG8Q0zUAHhqbiFMiffVCFM
                          N3ixLJROL5F0IlOz4nfVj8LL/RIAMfpPCaVIzUV923j/j5dZqwajQjBAMA4GA1Ud
                          DwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBQEenJ3gJoCkk/5
                          uilxmr1lE6xdzjAKBggqhkjOPQQDAgNIADBFAiA4crcbJ8K/jQY82LRLcKz8/QuU
                          Es+HpOAoXMyE1+tdSwIhAOTVByba2DiIkrwaFf0YYISVymsezzFKw5kVJPOwwtza
                          -----END CERTIFICATE-----
                      EOT
                    - enabled   = true
                    - key       = "ca.crt"
                    - name      = "cilium-root-ca.crt"
                    - useSecret = false
                  }
              }
          }
      ) -> (known after apply)
!     version        = "1.19.2" -> (known after apply)
  } -> (known after apply)
  name                       = "cilium"
! version                    = "1.19.2" -> "1.19.5"
  # (28 unchanged attributes hidden)
helm_release.csi_driver_nfs
! id                         = "csi-driver-nfs" -> (known after apply)
! metadata                   = {
!     app_version    = "4.13.1" -> (known after apply)
!     chart          = "csi-driver-nfs" -> (known after apply)
!     first_deployed = 1770561951 -> (known after apply)
!     last_deployed  = 1775344870 -> (known after apply)
!     name           = "csi-driver-nfs" -> (known after apply)
!     namespace      = "kube-system" -> (known after apply)
!     notes          = <<-EOT
          The CSI NFS Driver is getting deployed to your cluster.
          
          To check CSI NFS Driver pods status, please run:
          
            kubectl --namespace=kube-system get pods --selector="app.kubernetes.io/instance=csi-driver-nfs" --watch
      EOT -> (known after apply)
!     revision       = 2 -> (known after apply)
!     values         = jsonencode({}) -> (known after apply)
!     version        = "4.13.1" -> (known after apply)
  } -> (known after apply)
  name                       = "csi-driver-nfs"
! version                    = "4.13.1" -> "4.13.3"
  # (27 unchanged attributes hidden)
helm_release.external_secrets
! id                         = "external-secrets" -> (known after apply)
! metadata                   = {
!     app_version    = "v2.2.0" -> (known after apply)
!     chart          = "external-secrets" -> (known after apply)
!     first_deployed = 1772488004 -> (known after apply)
!     last_deployed  = 1779394467 -> (known after apply)
!     name           = "external-secrets" -> (known after apply)
!     namespace      = "external-secrets" -> (known after apply)
!     notes          = <<-EOT
          external-secrets has been deployed successfully in namespace external-secrets!
          
          In order to begin using ExternalSecrets, you will need to set up a SecretStore
          or ClusterSecretStore resource (for example, by creating a 'vault' SecretStore).
          
          More information on the different types of SecretStores and how to configure them
          can be found in our Github: https://github.com/external-secrets/external-secrets
      EOT -> (known after apply)
!     revision       = 4 -> (known after apply)
!     values         = jsonencode(
          {
            - certController = {
                - resources = {
                    - limits   = {
                        - memory = "128Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "64Mi"
                      }
                  }
              }
            - installCRDs    = true
            - resources      = {
                - limits   = {
                    - memory = "128Mi"
                  }
                - requests = {
                    - cpu    = "10m"
                    - memory = "64Mi"
                  }
              }
            - webhook        = {
                - resources = {
                    - limits   = {
                        - memory = "64Mi"
                      }
                    - requests = {
                        - cpu    = "10m"
                        - memory = "32Mi"
                      }
                  }
              }
          }
      ) -> (known after apply)
!     version        = "2.2.0" -> (known after apply)
  } -> (known after apply)
  name                       = "external-secrets"
! version                    = "2.2.0" -> "2.7.0"
  # (28 unchanged attributes hidden)

Triggered by @renovate[bot], Commit: 8d0334306fcfc7b45e2f432e1e46d6db5dedf75e

@renovate renovate Bot force-pushed the renovate/helm-charts branch from 180cf28 to d08ef33 Compare April 10, 2026 15:07
@renovate renovate Bot changed the title chore(deps): update helm release argo-cd to v9.5.0 chore(deps): update helm charts Apr 10, 2026
@renovate renovate Bot force-pushed the renovate/helm-charts branch from d08ef33 to 4ad6cc6 Compare April 13, 2026 10:03
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 4ad6cc6 to 70e9cc0 Compare April 16, 2026 09:19
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 70e9cc0 to c0119a9 Compare April 17, 2026 10:02
@renovate renovate Bot force-pushed the renovate/helm-charts branch from c0119a9 to 47f1fa5 Compare April 17, 2026 19:11
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 47f1fa5 to 5b5cb34 Compare April 20, 2026 18:53
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 5b5cb34 to 1738eea Compare April 21, 2026 23:59
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 1738eea to 5ffea9b Compare April 22, 2026 16:07
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 5ffea9b to e32a0f5 Compare April 24, 2026 19:22
@renovate renovate Bot force-pushed the renovate/helm-charts branch from e32a0f5 to 3484a6a Compare April 28, 2026 06:08
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 3484a6a to 1e5ebd6 Compare April 28, 2026 15:43
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 1e5ebd6 to 61556f9 Compare April 29, 2026 00:41
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 61556f9 to 8340b2d Compare April 29, 2026 13:38
@renovate renovate Bot force-pushed the renovate/helm-charts branch from b588987 to 8f1640d Compare May 15, 2026 14:06
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 8f1640d to e967935 Compare May 16, 2026 23:42
@renovate renovate Bot force-pushed the renovate/helm-charts branch from e967935 to 48a4026 Compare May 17, 2026 00:21
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 48a4026 to ac1200d Compare May 17, 2026 00:25
@renovate renovate Bot force-pushed the renovate/helm-charts branch from ac1200d to f274a6b Compare May 18, 2026 17:12
@renovate renovate Bot force-pushed the renovate/helm-charts branch from f274a6b to 731e546 Compare May 21, 2026 05:09
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 731e546 to e7bcded Compare May 21, 2026 19:16
@renovate renovate Bot force-pushed the renovate/helm-charts branch from e7bcded to b0b005b Compare May 22, 2026 22:02
@renovate renovate Bot force-pushed the renovate/helm-charts branch from b0b005b to 81a1a4a Compare May 28, 2026 16:40
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 81a1a4a to b38b1d3 Compare May 29, 2026 14:58
@renovate renovate Bot force-pushed the renovate/helm-charts branch from b38b1d3 to 1e514a0 Compare June 4, 2026 09:52
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 1e514a0 to 897e4ef Compare June 5, 2026 01:08
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 897e4ef to 4326307 Compare June 6, 2026 23:01
@renovate renovate Bot force-pushed the renovate/helm-charts branch from 4326307 to 2713a30 Compare June 7, 2026 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file helm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants