Skip to content

feat(container): update ghcr.io/external-secrets/charts/external-secrets ( 0.18.2 → 0.19.0 ) #4837

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mchesterbot[bot]
Copy link
Contributor

@mchesterbot mchesterbot bot commented Aug 2, 2025

This PR contains the following updates:

Package Update Change
ghcr.io/external-secrets/charts/external-secrets minor 0.18.2 -> 0.19.0

Release Notes

external-secrets/external-secrets (ghcr.io/external-secrets/charts/external-secrets)

v0.19.0

Compare Source

BREAKING CHANGE

🔴 🔴 BREAKING CHANGE 🔴 🔴

Please note that this a breaking change because our CRDs are now too big. Meaning a simple kubectl apply or Argo's default client side apply WILL NOT WORK! You have to add --server-side to kubectl apply and in argo add:

spec:
  project: default
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
    - CreateNamespace=true
    - ServerSideApply=true

How to do it in kubectl:

kubectl apply --server-side ...

for it to correctly install the CRDs. Thank you.

Image: ghcr.io/external-secrets/external-secrets:v0.19.0
Image: ghcr.io/external-secrets/external-secrets:v0.19.0-ubi
Image: ghcr.io/external-secrets/external-secrets:v0.19.0-ubi-boringssl

What's Changed

New Contributors

Full Changelog: external-secrets/external-secrets@v0.18.2...v0.19.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@mchesterbot mchesterbot bot requested a review from mchestr as a code owner August 2, 2025 19:07
@mchesterbot mchesterbot bot added renovate/container type/minor area/kubernetes Changes made in the kubernetes directory labels Aug 2, 2025
@mchesterbot
Copy link
Contributor Author

mchesterbot bot commented Aug 2, 2025

--- kubernetes/apps/external-secrets/external-secrets/app Kustomization: external-secrets/external-secrets OCIRepository: external-secrets/external-secrets

+++ kubernetes/apps/external-secrets/external-secrets/app Kustomization: external-secrets/external-secrets OCIRepository: external-secrets/external-secrets

@@ -11,13 +11,13 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 0.18.2
+    tag: 0.19.0
   url: oci://ghcr.io/external-secrets/charts/external-secrets
   verify:
     matchOIDCIdentity:
     - issuer: ^https://token.actions.githubusercontent.com$
       subject: ^https://github.com/external-secrets/external-secrets.*$
     provider: cosign

@mchesterbot
Copy link
Contributor Author

mchesterbot bot commented Aug 2, 2025

--- HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-controller

+++ HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-controller

@@ -67,12 +67,13 @@

   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
   - githubaccesstokens
   - quayaccesstokens
   - passwords
+  - sshkeys
   - stssessiontokens
   - uuids
   - vaultdynamicsecrets
   - webhooks
   - grafanas
   - mfas
--- HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-view

+++ HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-view

@@ -31,16 +31,18 @@

   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
   - githubaccesstokens
   - quayaccesstokens
   - passwords
+  - sshkeys
   - vaultdynamicsecrets
   - webhooks
   - grafanas
   - generatorstates
   - mfas
+  - uuids
   verbs:
   - get
   - watch
   - list
 
--- HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-edit

+++ HelmRelease: external-secrets/external-secrets ClusterRole: external-secrets/external-secrets-edit

@@ -32,17 +32,19 @@

   - ecrauthorizationtokens
   - fakes
   - gcraccesstokens
   - githubaccesstokens
   - quayaccesstokens
   - passwords
+  - sshkeys
   - vaultdynamicsecrets
   - webhooks
   - grafanas
   - generatorstates
   - mfas
+  - uuids
   verbs:
   - create
   - delete
   - deletecollection
   - patch
   - update
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-cert-controller

+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-cert-controller

@@ -34,13 +34,13 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.18.2
+        image: ghcr.io/external-secrets/external-secrets:v0.19.0
         imagePullPolicy: IfNotPresent
         args:
         - certcontroller
         - --crd-requeue-interval=5m
         - --service-name=external-secrets-webhook
         - --service-namespace=external-secrets
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets

+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets

@@ -34,13 +34,13 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.18.2
+        image: ghcr.io/external-secrets/external-secrets:v0.19.0
         imagePullPolicy: IfNotPresent
         args:
         - --enable-leader-election=true
         - --concurrent=1
         - --metrics-addr=:8080
         - --loglevel=info
--- HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-webhook

+++ HelmRelease: external-secrets/external-secrets Deployment: external-secrets/external-secrets-webhook

@@ -34,13 +34,13 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: ghcr.io/external-secrets/external-secrets:v0.18.2
+        image: ghcr.io/external-secrets/external-secrets:v0.19.0
         imagePullPolicy: IfNotPresent
         args:
         - webhook
         - --port=10250
         - --dns-name=external-secrets-webhook.external-secrets.svc
         - --cert-dir=/tmp/certs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/kubernetes Changes made in the kubernetes directory renovate/container type/minor
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants