diff --git a/charts/gitops-runtime/Chart.yaml b/charts/gitops-runtime/Chart.yaml index 966a559c..a979f9e0 100644 --- a/charts/gitops-runtime/Chart.yaml +++ b/charts/gitops-runtime/Chart.yaml @@ -1,8 +1,8 @@ apiVersion: v2 -appVersion: 0.1.38 +appVersion: 0.1.39 description: A Helm chart for Codefresh gitops runtime name: gitops-runtime -version: 0.4.1 +version: 0.4.2 home: https://github.com/codefresh-io/gitops-runtime-helm icon: https://avatars1.githubusercontent.com/u/11412079?v=3 keywords: @@ -15,19 +15,23 @@ annotations: artifacthub.io/alternativeName: "codefresh-gitops-runtime" artifacthub.io/changes: | - kind: changed - description: Update app version to 0.1.38 + description: Update app version to 0.1.39 - kind: changed - description: Update argo-cd to 2.9-2023.12.28-a52e719a5 + description: Update argo-cd chart to 5.51.6-5-cap-2.9-2024.1.17-0d221227f - kind: changed - description: Update app-proxy to 1.2585.0 + description: Update sealed-secrets chart to 2.14.1 - kind: changed - description: Update argo-workflows to 0.22.10-2-CR-20826 + description: Update sealed-secrets image to v0.24.5 + - kind: changed + description: Update app-proxy to 1.2608.0 + - kind: fixed + description: Fix runtime components log - kind: fixed - description: fail template if secretKeyRef uses reserved secret name codefresh-token + description: fix critical security vulnerability dependencies: - name: argo-cd repository: https://codefresh-io.github.io/argo-helm - version: 5.51.6-3-cap-2.9-2023.12.28-a52e719a5 + version: 5.51.6-5-cap-2.9-2024.1.17-0d221227f - name: argo-events repository: https://codefresh-io.github.io/argo-helm version: 2.0.9-1-cap-CR-19893 @@ -41,7 +45,7 @@ dependencies: condition: argo-rollouts.enabled - name: sealed-secrets repository: https://bitnami-labs.github.io/sealed-secrets/ - version: 2.7.3 + version: 2.14.1 - name: codefresh-tunnel-client repository: oci://quay.io/codefresh/charts version: 0.1.15 diff --git a/charts/gitops-runtime/README.md b/charts/gitops-runtime/README.md index 120a011f..454857f7 100644 --- a/charts/gitops-runtime/README.md +++ b/charts/gitops-runtime/README.md @@ -1,5 +1,5 @@ ## Codefresh gitops runtime -![Version: 0.4.1](https://img.shields.io/badge/Version-0.4.1-informational?style=flat-square) ![AppVersion: 0.1.38](https://img.shields.io/badge/AppVersion-0.1.38-informational?style=flat-square) +![Version: 0.4.2](https://img.shields.io/badge/Version-0.4.2-informational?style=flat-square) ![AppVersion: 0.1.39](https://img.shields.io/badge/AppVersion-0.1.39-informational?style=flat-square) ## Prerequisites @@ -27,7 +27,7 @@ We have created a helper utility to resolve this issue: The utility is packaged in a container image. Below are instructions on executing the utility using Docker: ``` -docker run -v :/output quay.io/codefresh/gitops-runtime-private-registry-utils:0.4.1 +docker run -v :/output quay.io/codefresh/gitops-runtime-private-registry-utils:0.4.2 ``` `output_dir` - is a local directory where the utility will output files.
`local_registry` - is your local registry where you want to mirror the images to @@ -100,14 +100,14 @@ sealed-secrets: | app-proxy.image-enrichment.serviceAccount.name | string | `"codefresh-image-enrichment-sa"` | Name of the service account to create or the name of the existing one to use | | app-proxy.image.pullPolicy | string | `"IfNotPresent"` | | | app-proxy.image.repository | string | `"quay.io/codefresh/cap-app-proxy"` | | -| app-proxy.image.tag | string | `"1.2585.0"` | | +| app-proxy.image.tag | string | `"1.2608.0"` | | | app-proxy.imagePullSecrets | list | `[]` | | | app-proxy.initContainer.command[0] | string | `"./init.sh"` | | | app-proxy.initContainer.env | object | `{}` | | | app-proxy.initContainer.extraVolumeMounts | list | `[]` | Extra volume mounts for init container | | app-proxy.initContainer.image.pullPolicy | string | `"IfNotPresent"` | | | app-proxy.initContainer.image.repository | string | `"quay.io/codefresh/cap-app-proxy-init"` | | -| app-proxy.initContainer.image.tag | string | `"1.2585.0"` | | +| app-proxy.initContainer.image.tag | string | `"1.2608.0"` | | | app-proxy.initContainer.resources.limits.cpu | string | `"1"` | | | app-proxy.initContainer.resources.limits.memory | string | `"512Mi"` | | | app-proxy.initContainer.resources.requests.cpu | string | `"0.2"` | | @@ -325,7 +325,7 @@ sealed-secrets: | internal-router.serviceAccount.create | bool | `true` | | | internal-router.serviceAccount.name | string | `""` | | | internal-router.tolerations | list | `[]` | | -| sealed-secrets | object | `{"fullnameOverride":"sealed-secrets-controller","image":{"registry":"quay.io","repository":"codefresh/sealed-secrets-controller","tag":"v0.19.4"},"keyrenewperiod":"720h","resources":{"limits":{"cpu":"500m","memory":"1Gi"},"requests":{"cpu":"200m","memory":"512Mi"}}}` | --------------------------------------------------------------------------------------------------------------------- | +| sealed-secrets | object | `{"fullnameOverride":"sealed-secrets-controller","image":{"registry":"quay.io","repository":"codefresh/sealed-secrets-controller","tag":"v0.24.5"},"keyrenewperiod":"720h","resources":{"limits":{"cpu":"500m","memory":"1Gi"},"requests":{"cpu":"200m","memory":"512Mi"}}}` | --------------------------------------------------------------------------------------------------------------------- | | tunnel-client | object | `{"enabled":true,"libraryMode":true,"tunnelServer":{"host":"register-tunnels.cf-cd.com","subdomainHost":"tunnels.cf-cd.com"}}` | Tunnel based runtime. Not supported for on-prem platform. In on-prem use ingress based runtimes. | | tunnel-client.enabled | bool | `true` | Will only be used if global.runtime.ingress.enabled = false | | tunnel-client.libraryMode | bool | `true` | Do not change this value! Breaks chart logic | diff --git a/charts/gitops-runtime/values.yaml b/charts/gitops-runtime/values.yaml index a82e9fc1..c2fa3a36 100644 --- a/charts/gitops-runtime/values.yaml +++ b/charts/gitops-runtime/values.yaml @@ -123,7 +123,7 @@ sealed-secrets: image: registry: 'quay.io' repository: 'codefresh/sealed-secrets-controller' - tag: 'v0.19.4' + tag: 'v0.24.5' resources: limits: cpu: 500m @@ -418,7 +418,7 @@ app-proxy: tag: 1.1.10-main image: repository: quay.io/codefresh/cap-app-proxy - tag: 1.2585.0 + tag: 1.2608.0 pullPolicy: IfNotPresent # -- Extra volume mounts for main container extraVolumeMounts: [] @@ -426,7 +426,7 @@ app-proxy: initContainer: image: repository: quay.io/codefresh/cap-app-proxy-init - tag: 1.2585.0 + tag: 1.2608.0 pullPolicy: IfNotPresent command: - ./init.sh