diff --git a/helm/external-secrets/kustomization.yaml b/helm/external-secrets/kustomization.yaml index 8b27dc2..9fc65bd 100644 --- a/helm/external-secrets/kustomization.yaml +++ b/helm/external-secrets/kustomization.yaml @@ -7,5 +7,5 @@ helmCharts: enabled: false # default, bitwarden-sdk-server doesn't work with vaultwarden (https://github.com/external-secrets/bitwarden-sdk-server/issues/18) namespace: external-secrets releaseName: external-secrets - version: 0.16.0 + version: 0.16.1 repo: https://charts.external-secrets.io diff --git a/helm/openbao/kustomization.yaml b/helm/openbao/kustomization.yaml index 9015a87..a123dae 100644 --- a/helm/openbao/kustomization.yaml +++ b/helm/openbao/kustomization.yaml @@ -34,5 +34,5 @@ helmCharts: repository: jankysolutions/infra/openbao tag: latest releaseName: openbao - version: 0.12.0 + version: 0.7.0 repo: https://openbao.github.io/openbao-helm diff --git a/k8s/forgejo/statefulset.yaml b/k8s/forgejo/statefulset.yaml index 5c8160f..312ec11 100644 --- a/k8s/forgejo/statefulset.yaml +++ b/k8s/forgejo/statefulset.yaml @@ -14,7 +14,7 @@ spec: app: forgejo spec: containers: - - image: codeberg.org/forgejo/forgejo:10.0.3 + - image: codeberg.org/forgejo/forgejo:11.0.0 imagePullPolicy: Always name: forgejo resources: {} diff --git a/k8s/matrix/bridge-facebook.yaml b/k8s/matrix/bridge-facebook.yaml index bb7a076..56ff896 100644 --- a/k8s/matrix/bridge-facebook.yaml +++ b/k8s/matrix/bridge-facebook.yaml @@ -60,7 +60,7 @@ spec: - secretRef: name: bridge-facebook containers: - - image: dock.mau.dev/mautrix/meta:v0.4.5 + - image: dock.mau.dev/mautrix/meta:v0.4.6 name: bridge-facebook resources: {} command: ["/usr/bin/mautrix-meta", "-c", "/data/config.yaml", "--no-update"] diff --git a/k8s/matrix/bridge-signal.yaml b/k8s/matrix/bridge-signal.yaml index be76ace..63adfca 100644 --- a/k8s/matrix/bridge-signal.yaml +++ b/k8s/matrix/bridge-signal.yaml @@ -57,7 +57,7 @@ spec: - secretRef: name: bridge-signal containers: - - image: dock.mau.dev/mautrix/signal:v0.8.1 + - image: dock.mau.dev/mautrix/signal:v0.8.2 name: bridge-signal resources: {} ports: diff --git a/k8s/monitoring/matrix-alertmanager-receiver.yaml b/k8s/monitoring/matrix-alertmanager-receiver.yaml index e7bd8e2..27176d6 100644 --- a/k8s/monitoring/matrix-alertmanager-receiver.yaml +++ b/k8s/monitoring/matrix-alertmanager-receiver.yaml @@ -31,7 +31,7 @@ spec: name: matrix-alertmanager-receiver containers: - name: matrix-alertmanager-receiver - image: docker.io/metio/matrix-alertmanager-receiver:2025.3.26 + image: docker.io/metio/matrix-alertmanager-receiver:2025.4.16 args: ["--config-path", "/config/config.yaml"] resources: limits: diff --git a/k8s/operators/external-secrets/bundle.yaml b/k8s/operators/external-secrets/bundle.yaml index 538e3e3..c372295 100644 --- a/k8s/operators/external-secrets/bundle.yaml +++ b/k8s/operators/external-secrets/bundle.yaml @@ -25642,8 +25642,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets namespace: external-secrets --- @@ -25654,8 +25654,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-cert-controller - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-cert-controller namespace: external-secrets --- @@ -25666,8 +25666,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-webhook namespace: external-secrets --- @@ -25678,8 +25678,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-leaderelection namespace: external-secrets rules: @@ -25716,8 +25716,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-cert-controller - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-cert-controller rules: - apiGroups: @@ -25790,8 +25790,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-controller rules: - apiGroups: @@ -25931,8 +25931,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" name: external-secrets-edit @@ -25980,8 +25980,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 servicebinding.io/controller: "true" name: external-secrets-servicebindings rules: @@ -26002,8 +26002,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" rbac.authorization.k8s.io/aggregate-to-view: "true" @@ -26048,8 +26048,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-leaderelection namespace: external-secrets roleRef: @@ -26068,8 +26068,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-cert-controller - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-cert-controller roleRef: apiGroup: rbac.authorization.k8s.io @@ -26087,8 +26087,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-controller roleRef: apiGroup: rbac.authorization.k8s.io @@ -26106,9 +26106,9 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 + app.kubernetes.io/version: v0.16.1 external-secrets.io/component: webhook - helm.sh/chart: external-secrets-0.16.0 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-webhook namespace: external-secrets --- @@ -26119,9 +26119,9 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 + app.kubernetes.io/version: v0.16.1 external-secrets.io/component: webhook - helm.sh/chart: external-secrets-0.16.0 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-webhook namespace: external-secrets spec: @@ -26142,8 +26142,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets namespace: external-secrets spec: @@ -26159,8 +26159,8 @@ spec: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 spec: automountServiceAccountToken: true containers: @@ -26169,7 +26169,7 @@ spec: - --metrics-addr=:8080 - --loglevel=info - --zap-time-encoding=epoch - image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.0 + image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.1 imagePullPolicy: IfNotPresent name: external-secrets ports: @@ -26197,8 +26197,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-cert-controller - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-cert-controller namespace: external-secrets spec: @@ -26214,8 +26214,8 @@ spec: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-cert-controller - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 spec: automountServiceAccountToken: true containers: @@ -26231,7 +26231,7 @@ spec: - --loglevel=info - --zap-time-encoding=epoch - --enable-partial-cache=true - image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.0 + image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.1 imagePullPolicy: IfNotPresent name: cert-controller ports: @@ -26264,8 +26264,8 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 name: external-secrets-webhook namespace: external-secrets spec: @@ -26281,8 +26281,8 @@ spec: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 - helm.sh/chart: external-secrets-0.16.0 + app.kubernetes.io/version: v0.16.1 + helm.sh/chart: external-secrets-0.16.1 spec: automountServiceAccountToken: true containers: @@ -26296,7 +26296,7 @@ spec: - --healthz-addr=:8081 - --loglevel=info - --zap-time-encoding=epoch - image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.0 + image: oci.external-secrets.io/external-secrets/external-secrets:v0.16.1 imagePullPolicy: IfNotPresent name: webhook ports: @@ -26340,9 +26340,9 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 + app.kubernetes.io/version: v0.16.1 external-secrets.io/component: webhook - helm.sh/chart: external-secrets-0.16.0 + helm.sh/chart: external-secrets-0.16.1 name: externalsecret-validate webhooks: - admissionReviewVersions: @@ -26377,9 +26377,9 @@ metadata: app.kubernetes.io/instance: external-secrets app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: external-secrets-webhook - app.kubernetes.io/version: v0.16.0 + app.kubernetes.io/version: v0.16.1 external-secrets.io/component: webhook - helm.sh/chart: external-secrets-0.16.0 + helm.sh/chart: external-secrets-0.16.1 name: secretstore-validate webhooks: - admissionReviewVersions: diff --git a/k8s/operators/openbao/bundle.yaml b/k8s/operators/openbao/bundle.yaml index ea323e3..3254781 100644 --- a/k8s/operators/openbao/bundle.yaml +++ b/k8s/operators/openbao/bundle.yaml @@ -6,7 +6,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao namespace: openbao --- @@ -52,7 +52,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-discovery-role namespace: openbao rules: @@ -108,7 +108,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-discovery-rolebinding namespace: openbao roleRef: @@ -144,7 +144,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-server-binding roleRef: apiGroup: rbac.authorization.k8s.io @@ -159,6 +159,7 @@ apiVersion: v1 data: extraconfig-from-values.hcl: |2- + disable_mlock = true ui = true listener "tcp" { @@ -182,7 +183,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-config namespace: openbao --- @@ -205,7 +206,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao-csi-provider - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-csi-provider-agent-config namespace: openbao --- @@ -216,7 +217,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao namespace: openbao spec: @@ -240,7 +241,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 openbao-active: "true" name: openbao-active namespace: openbao @@ -266,7 +267,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 openbao-internal: "true" name: openbao-internal namespace: openbao @@ -292,7 +293,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-standby namespace: openbao spec: @@ -317,7 +318,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao-ui - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao-ui namespace: openbao spec: @@ -357,7 +358,7 @@ spec: app.kubernetes.io/instance: openbao app.kubernetes.io/name: openbao component: server - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 spec: affinity: podAntiAffinity: @@ -485,7 +486,7 @@ metadata: app.kubernetes.io/instance: openbao app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: openbao - helm.sh/chart: openbao-0.12.0 + helm.sh/chart: openbao-0.7.0 name: openbao namespace: openbao spec: diff --git a/k8s/wordpress/hannah.yaml b/k8s/wordpress/hannah.yaml index 6fb4e36..60ab9c3 100644 --- a/k8s/wordpress/hannah.yaml +++ b/k8s/wordpress/hannah.yaml @@ -15,7 +15,7 @@ spec: spec: containers: - name: wordpress - image: library/wordpress:6.7.2 + image: library/wordpress:6.8.0 env: - name: WORDPRESS_DB_HOST value: hannah-db