-
Notifications
You must be signed in to change notification settings - Fork 0
fix(helm): update chart external-secrets to 0.19.2 #620
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Claude finished @renovate[bot]'s task —— View job Code Review CompleteReview Checklist:
Review SummaryThis PR updates the external-secrets Helm chart from version 0.19.1 to 0.19.2. After thorough analysis, this is a safe and recommended update. Code Quality & Best Practices ✅The change follows excellent practices:
Security Analysis ✅Positive security aspects:
Performance Considerations ✅Performance improvements:
Potential Issues & Recommendations 🔍Minor considerations:
Repository-specific observations:
Test Coverage Assessment 📋The current HelmRelease configuration includes good operational practices:
Recommendation: Consider adding a basic smoke test in the repository's CI/CD pipeline to validate ExternalSecret CRD functionality after chart upgrades. Conclusion ✅This PR is approved for merge. The external-secrets 0.19.2 update includes important security fixes and performance improvements with no breaking changes. The change follows repository conventions and maintains the existing secure configuration. Key benefits of this update:
|
--- kubernetes/apps/external-secrets/external-secrets/app Kustomization: flux-system/external-secrets HelmRelease: external-secrets/external-secrets
+++ kubernetes/apps/external-secrets/external-secrets/app Kustomization: flux-system/external-secrets HelmRelease: external-secrets/external-secrets
@@ -13,13 +13,13 @@
spec:
chart: external-secrets
sourceRef:
kind: HelmRepository
name: external-secrets
namespace: flux-system
- version: 0.19.1
+ version: 0.19.2
dependsOn:
- name: onepassword-connect
namespace: external-secrets
install:
remediation:
retries: 3 |
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-cert-controller
+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-cert-controller
@@ -34,13 +34,13 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.1
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.2
imagePullPolicy: IfNotPresent
args:
- certcontroller
- --crd-requeue-interval=5m
- --service-name=external-secrets-webhook
- --service-namespace=external-secrets
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets
+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets
@@ -34,13 +34,13 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.1
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.2
imagePullPolicy: IfNotPresent
args:
- --concurrent=1
- --metrics-addr=:8080
- --loglevel=info
- --zap-time-encoding=epoch
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-webhook
+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-webhook
@@ -34,13 +34,13 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.1
+ image: oci.external-secrets.io/external-secrets/external-secrets:v0.19.2
imagePullPolicy: IfNotPresent
args:
- webhook
- --port=10250
- --dns-name=external-secrets-webhook.external-secrets.svc
- --cert-dir=/tmp/certs |
This PR contains the following updates:
0.19.1->0.19.2Release Notes
external-secrets/external-secrets (external-secrets)
v0.19.2Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.19.2Image:
ghcr.io/external-secrets/external-secrets:v0.19.2-ubiImage:
ghcr.io/external-secrets/external-secrets:v0.19.2-ubi-boringsslWhat's Changed
2.2.1by @jakobmoellerdev in https://github.com/external-secrets/external-secrets/pull/5126b7b9a69to2e114d2by @dependabot[bot] inhttps://github.com/external-secrets/external-secrets/pull/51188a463a8eto4f0a4e4by @dependabot[bot] inhttps://github.com/external-secrets/external-secrets/pull/51166New Contributors
Full Changelog: external-secrets/external-secrets@v0.19.1...v0.19.2
Configuration
📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.