Skip to content

feat(helm): update chart ingress-nginx to 4.15.0#29

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ingress-nginx-4.x
Open

feat(helm): update chart ingress-nginx to 4.15.0#29
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ingress-nginx-4.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jul 13, 2024

This PR contains the following updates:

Package Update Change
ingress-nginx minor 4.10.14.15.0

Release Notes

kubernetes/ingress-nginx (ingress-nginx)

v4.15.0

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.15.0
  • Update Ingress-Nginx version controller-v1.15.0

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.14.0...helm-chart-4.15.0

v4.14.4

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.14.4
  • Update Ingress-Nginx version controller-v1.14.4

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.14.3...helm-chart-4.14.4

v4.14.3

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.14.3
  • Update Ingress-Nginx version controller-v1.14.3

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.14.2...helm-chart-4.14.3

v4.14.2

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.14.2
  • Update Ingress-Nginx version controller-v1.14.2

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.14.1...helm-chart-4.14.2

v4.14.1

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.14.1
  • Update Ingress-Nginx version controller-v1.14.1

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.14.0...helm-chart-4.14.1

v4.14.0

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.14.0
  • Update Ingress-Nginx version controller-v1.14.0

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.3...helm-chart-4.14.0

v4.13.8

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.8
  • Update Ingress-Nginx version controller-v1.13.8

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.7...helm-chart-4.13.8

v4.13.7

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.7
  • Update Ingress-Nginx version controller-v1.13.7

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.6...helm-chart-4.13.7

v4.13.6

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.6
  • Update Ingress-Nginx version controller-v1.13.6

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.5...helm-chart-4.13.6

v4.13.5

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.5
  • Update Ingress-Nginx version controller-v1.13.5

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.4...helm-chart-4.13.5

v4.13.4

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.4
  • Update Ingress-Nginx version controller-v1.13.4

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.3...helm-chart-4.13.4

v4.13.3

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.3
  • Update Ingress-Nginx version controller-v1.13.3

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.2...helm-chart-4.13.3

v4.13.2

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.2
  • Update Ingress-Nginx version controller-v1.13.2

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.1...helm-chart-4.13.2

v4.13.1

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.1
  • Make: Add helm-test target. (#​13659)
  • Update Ingress-Nginx version controller-v1.13.1

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.13.0...helm-chart-4.13.1

v4.13.0

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.13.0
  • Update Ingress-Nginx version controller-v1.13.0

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.12.0...helm-chart-4.13.0

v4.12.8

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.12.8
  • Update Ingress-Nginx version controller-v1.12.8

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.12.7...helm-chart-4.12.8

v4.12.7

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.12.7
  • Update Ingress-Nginx version controller-v1.12.7

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.12.7...helm-chart-4.12.7

v4.12.6

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.12.6
  • Update Ingress-Nginx version controller-v1.12.6

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.12.5...helm-chart-4.12.6

v4.12.5

Changelog

This file documents all notable changes to ingress-nginx Helm Chart. The release numbering uses semantic versioning.

4.12.5
  • Make: Add helm-test target. (#​13660)
  • Update Ingress-Nginx version controller-v1.12.5

Full Changelog: kubernetes/ingress-nginx@helm-chart-4.12.4...helm-chart-4.12.5


Configuration

📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link

github-actions bot commented Jul 13, 2024

--- kubernetes/apps/network/ingress-nginx/external Kustomization: flux-system/ingress-nginx-external HelmRelease: network/ingress-nginx-external

+++ kubernetes/apps/network/ingress-nginx/external Kustomization: flux-system/ingress-nginx-external HelmRelease: network/ingress-nginx-external

@@ -13,13 +13,13 @@

     spec:
       chart: ingress-nginx
       sourceRef:
         kind: HelmRepository
         name: ingress-nginx
         namespace: flux-system
-      version: 4.10.1
+      version: 4.15.0
   dependsOn:
   - name: cloudflared
     namespace: network
   install:
     remediation:
       retries: 3
--- kubernetes/apps/network/ingress-nginx/internal Kustomization: flux-system/ingress-nginx-internal HelmRelease: network/ingress-nginx-internal

+++ kubernetes/apps/network/ingress-nginx/internal Kustomization: flux-system/ingress-nginx-internal HelmRelease: network/ingress-nginx-internal

@@ -13,13 +13,13 @@

     spec:
       chart: ingress-nginx
       sourceRef:
         kind: HelmRepository
         name: ingress-nginx
         namespace: flux-system
-      version: 4.10.1
+      version: 4.15.0
   install:
     remediation:
       retries: 3
   interval: 30m
   upgrade:
     cleanupOnFail: true

@github-actions
Copy link

github-actions bot commented Jul 13, 2024

--- HelmRelease: network/ingress-nginx-external ConfigMap: network/ingress-nginx-external-controller

+++ HelmRelease: network/ingress-nginx-external ConfigMap: network/ingress-nginx-external-controller

@@ -8,13 +8,12 @@

     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: controller
   name: ingress-nginx-external-controller
   namespace: network
 data:
-  allow-snippet-annotations: 'false'
   client-body-buffer-size: 100M
   client-body-timeout: '120'
   client-header-timeout: '120'
   enable-brotli: 'true'
   enable-real-ip: 'true'
   hsts-max-age: '3.14496e+07'
--- HelmRelease: network/ingress-nginx-external Deployment: network/ingress-nginx-external-controller

+++ HelmRelease: network/ingress-nginx-external Deployment: network/ingress-nginx-external-controller

@@ -28,13 +28,13 @@

         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: controller
     spec:
       dnsPolicy: ClusterFirst
       containers:
       - name: controller
-        image: registry.k8s.io/ingress-nginx/controller:v1.10.1@sha256:e24f39d3eed6bcc239a56f20098878845f62baa34b9f2be2fd2c38ce9fb0f29e
+        image: registry.k8s.io/ingress-nginx/controller:v1.15.0@sha256:4eea9a4cc2cb6ddcb7da14d377aaf452e68bd3dbe87fe280755d225c4d5e7e4e
         imagePullPolicy: IfNotPresent
         lifecycle:
           preStop:
             exec:
               command:
               - /wait-shutdown
@@ -45,16 +45,18 @@

         - --controller-class=k8s.io/external
         - --ingress-class=nginx
         - --configmap=$(POD_NAMESPACE)/ingress-nginx-external-controller
         - --validating-webhook=:8443
         - --validating-webhook-certificate=/usr/local/certificates/cert
         - --validating-webhook-key=/usr/local/certificates/key
+        - --enable-metrics=true
         - --default-ssl-certificate=network/-.PLACEHOLDER_SECRET_DOMAIN..-production-tls
         securityContext:
           runAsNonRoot: true
           runAsUser: 101
+          runAsGroup: 82
           allowPrivilegeEscalation: false
           seccompProfile:
             type: RuntimeDefault
           capabilities:
             drop:
             - ALL
@@ -124,12 +126,13 @@

             app.kubernetes.io/instance: ingress-nginx-external
             app.kubernetes.io/name: ingress-nginx
         maxSkew: 1
         topologyKey: kubernetes.io/hostname
         whenUnsatisfiable: DoNotSchedule
       serviceAccountName: ingress-nginx-external
+      automountServiceAccountToken: true
       terminationGracePeriodSeconds: 300
       volumes:
       - name: webhook-cert
         secret:
           secretName: ingress-nginx-external-admission
 
--- HelmRelease: network/ingress-nginx-external ValidatingWebhookConfiguration: network/ingress-nginx-external-admission

+++ HelmRelease: network/ingress-nginx-external ValidatingWebhookConfiguration: network/ingress-nginx-external-admission

@@ -27,12 +27,13 @@

   admissionReviewVersions:
   - v1
   clientConfig:
     service:
       name: ingress-nginx-external-controller-admission
       namespace: network
+      port: 443
       path: /networking/v1/ingresses
   objectSelector:
     matchExpressions:
     - key: ingress-class
       operator: In
       values:
--- HelmRelease: network/ingress-nginx-external ServiceMonitor: network/ingress-nginx-external-controller

+++ HelmRelease: network/ingress-nginx-external ServiceMonitor: network/ingress-nginx-external-controller

@@ -8,17 +8,17 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-external
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: controller
 spec:
-  endpoints:
-  - port: metrics
-    interval: 30s
   namespaceSelector:
     any: true
   selector:
     matchLabels:
       app.kubernetes.io/name: ingress-nginx
       app.kubernetes.io/instance: ingress-nginx-external
       app.kubernetes.io/component: controller
+  endpoints:
+  - port: metrics
+    interval: 30s
 
--- HelmRelease: network/ingress-nginx-external ServiceAccount: network/ingress-nginx-external-admission

+++ HelmRelease: network/ingress-nginx-external ServiceAccount: network/ingress-nginx-external-admission

@@ -10,7 +10,8 @@

   labels:
     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-external
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
+automountServiceAccountToken: true
 
--- HelmRelease: network/ingress-nginx-external Job: network/ingress-nginx-external-admission-create

+++ HelmRelease: network/ingress-nginx-external Job: network/ingress-nginx-external-admission-create

@@ -11,25 +11,26 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-external
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
 spec:
+  ttlSecondsAfterFinished: 0
   template:
     metadata:
       name: ingress-nginx-external-admission-create
       labels:
         app.kubernetes.io/name: ingress-nginx
         app.kubernetes.io/instance: ingress-nginx-external
         app.kubernetes.io/part-of: ingress-nginx
         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: admission-webhook
     spec:
       containers:
       - name: create
-        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.1@sha256:36d05b4077fb8e3d13663702fa337f124675ba8667cbd949c03a8e8ea6fa4366
+        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.8@sha256:d7e8257f8d8bce64b6df55f81fba92011a6a77269b3350f8b997b152af348dba
         imagePullPolicy: IfNotPresent
         args:
         - create
         - --host=ingress-nginx-external-controller-admission,ingress-nginx-external-controller-admission.$(POD_NAMESPACE).svc
         - --namespace=$(POD_NAMESPACE)
         - --secret-name=ingress-nginx-external-admission
@@ -41,15 +42,17 @@

         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
             - ALL
           readOnlyRootFilesystem: true
+          runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
       restartPolicy: OnFailure
       serviceAccountName: ingress-nginx-external-admission
+      automountServiceAccountToken: true
       nodeSelector:
         kubernetes.io/os: linux
 
--- HelmRelease: network/ingress-nginx-external Job: network/ingress-nginx-external-admission-patch

+++ HelmRelease: network/ingress-nginx-external Job: network/ingress-nginx-external-admission-patch

@@ -11,25 +11,26 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-external
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
 spec:
+  ttlSecondsAfterFinished: 0
   template:
     metadata:
       name: ingress-nginx-external-admission-patch
       labels:
         app.kubernetes.io/name: ingress-nginx
         app.kubernetes.io/instance: ingress-nginx-external
         app.kubernetes.io/part-of: ingress-nginx
         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: admission-webhook
     spec:
       containers:
       - name: patch
-        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.1@sha256:36d05b4077fb8e3d13663702fa337f124675ba8667cbd949c03a8e8ea6fa4366
+        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.8@sha256:d7e8257f8d8bce64b6df55f81fba92011a6a77269b3350f8b997b152af348dba
         imagePullPolicy: IfNotPresent
         args:
         - patch
         - --webhook-name=ingress-nginx-external-admission
         - --namespace=$(POD_NAMESPACE)
         - --patch-mutating=false
@@ -43,15 +44,17 @@

         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
             - ALL
           readOnlyRootFilesystem: true
+          runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
       restartPolicy: OnFailure
       serviceAccountName: ingress-nginx-external-admission
+      automountServiceAccountToken: true
       nodeSelector:
         kubernetes.io/os: linux
 
--- HelmRelease: network/ingress-nginx-internal ConfigMap: network/ingress-nginx-internal-controller

+++ HelmRelease: network/ingress-nginx-internal ConfigMap: network/ingress-nginx-internal-controller

@@ -8,13 +8,12 @@

     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: controller
   name: ingress-nginx-internal-controller
   namespace: network
 data:
-  allow-snippet-annotations: 'false'
   client-body-buffer-size: 100M
   client-body-timeout: '120'
   client-header-timeout: '120'
   enable-brotli: 'true'
   enable-real-ip: 'true'
   hsts-max-age: '3.14496e+07'
--- HelmRelease: network/ingress-nginx-internal Deployment: network/ingress-nginx-internal-controller

+++ HelmRelease: network/ingress-nginx-internal Deployment: network/ingress-nginx-internal-controller

@@ -28,13 +28,13 @@

         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: controller
     spec:
       dnsPolicy: ClusterFirst
       containers:
       - name: controller
-        image: registry.k8s.io/ingress-nginx/controller:v1.10.1@sha256:e24f39d3eed6bcc239a56f20098878845f62baa34b9f2be2fd2c38ce9fb0f29e
+        image: registry.k8s.io/ingress-nginx/controller:v1.15.0@sha256:4eea9a4cc2cb6ddcb7da14d377aaf452e68bd3dbe87fe280755d225c4d5e7e4e
         imagePullPolicy: IfNotPresent
         lifecycle:
           preStop:
             exec:
               command:
               - /wait-shutdown
@@ -45,16 +45,18 @@

         - --controller-class=k8s.io/internal
         - --ingress-class=nginx
         - --configmap=$(POD_NAMESPACE)/ingress-nginx-internal-controller
         - --validating-webhook=:8443
         - --validating-webhook-certificate=/usr/local/certificates/cert
         - --validating-webhook-key=/usr/local/certificates/key
+        - --enable-metrics=true
         - --default-ssl-certificate=network/-.PLACEHOLDER_SECRET_DOMAIN..-production-tls
         securityContext:
           runAsNonRoot: true
           runAsUser: 101
+          runAsGroup: 82
           allowPrivilegeEscalation: false
           seccompProfile:
             type: RuntimeDefault
           capabilities:
             drop:
             - ALL
@@ -124,12 +126,13 @@

             app.kubernetes.io/instance: ingress-nginx-internal
             app.kubernetes.io/name: ingress-nginx
         maxSkew: 1
         topologyKey: kubernetes.io/hostname
         whenUnsatisfiable: DoNotSchedule
       serviceAccountName: ingress-nginx-internal
+      automountServiceAccountToken: true
       terminationGracePeriodSeconds: 300
       volumes:
       - name: webhook-cert
         secret:
           secretName: ingress-nginx-internal-admission
 
--- HelmRelease: network/ingress-nginx-internal ValidatingWebhookConfiguration: network/ingress-nginx-internal-admission

+++ HelmRelease: network/ingress-nginx-internal ValidatingWebhookConfiguration: network/ingress-nginx-internal-admission

@@ -27,12 +27,13 @@

   admissionReviewVersions:
   - v1
   clientConfig:
     service:
       name: ingress-nginx-internal-controller-admission
       namespace: network
+      port: 443
       path: /networking/v1/ingresses
   objectSelector:
     matchExpressions:
     - key: ingress-class
       operator: In
       values:
--- HelmRelease: network/ingress-nginx-internal ServiceMonitor: network/ingress-nginx-internal-controller

+++ HelmRelease: network/ingress-nginx-internal ServiceMonitor: network/ingress-nginx-internal-controller

@@ -8,17 +8,17 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-internal
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: controller
 spec:
-  endpoints:
-  - port: metrics
-    interval: 30s
   namespaceSelector:
     any: true
   selector:
     matchLabels:
       app.kubernetes.io/name: ingress-nginx
       app.kubernetes.io/instance: ingress-nginx-internal
       app.kubernetes.io/component: controller
+  endpoints:
+  - port: metrics
+    interval: 30s
 
--- HelmRelease: network/ingress-nginx-internal ServiceAccount: network/ingress-nginx-internal-admission

+++ HelmRelease: network/ingress-nginx-internal ServiceAccount: network/ingress-nginx-internal-admission

@@ -10,7 +10,8 @@

   labels:
     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-internal
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
+automountServiceAccountToken: true
 
--- HelmRelease: network/ingress-nginx-internal Job: network/ingress-nginx-internal-admission-create

+++ HelmRelease: network/ingress-nginx-internal Job: network/ingress-nginx-internal-admission-create

@@ -11,25 +11,26 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-internal
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
 spec:
+  ttlSecondsAfterFinished: 0
   template:
     metadata:
       name: ingress-nginx-internal-admission-create
       labels:
         app.kubernetes.io/name: ingress-nginx
         app.kubernetes.io/instance: ingress-nginx-internal
         app.kubernetes.io/part-of: ingress-nginx
         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: admission-webhook
     spec:
       containers:
       - name: create
-        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.1@sha256:36d05b4077fb8e3d13663702fa337f124675ba8667cbd949c03a8e8ea6fa4366
+        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.8@sha256:d7e8257f8d8bce64b6df55f81fba92011a6a77269b3350f8b997b152af348dba
         imagePullPolicy: IfNotPresent
         args:
         - create
         - --host=ingress-nginx-internal-controller-admission,ingress-nginx-internal-controller-admission.$(POD_NAMESPACE).svc
         - --namespace=$(POD_NAMESPACE)
         - --secret-name=ingress-nginx-internal-admission
@@ -41,15 +42,17 @@

         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
             - ALL
           readOnlyRootFilesystem: true
+          runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
       restartPolicy: OnFailure
       serviceAccountName: ingress-nginx-internal-admission
+      automountServiceAccountToken: true
       nodeSelector:
         kubernetes.io/os: linux
 
--- HelmRelease: network/ingress-nginx-internal Job: network/ingress-nginx-internal-admission-patch

+++ HelmRelease: network/ingress-nginx-internal Job: network/ingress-nginx-internal-admission-patch

@@ -11,25 +11,26 @@

     app.kubernetes.io/name: ingress-nginx
     app.kubernetes.io/instance: ingress-nginx-internal
     app.kubernetes.io/part-of: ingress-nginx
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/component: admission-webhook
 spec:
+  ttlSecondsAfterFinished: 0
   template:
     metadata:
       name: ingress-nginx-internal-admission-patch
       labels:
         app.kubernetes.io/name: ingress-nginx
         app.kubernetes.io/instance: ingress-nginx-internal
         app.kubernetes.io/part-of: ingress-nginx
         app.kubernetes.io/managed-by: Helm
         app.kubernetes.io/component: admission-webhook
     spec:
       containers:
       - name: patch
-        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.1@sha256:36d05b4077fb8e3d13663702fa337f124675ba8667cbd949c03a8e8ea6fa4366
+        image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.8@sha256:d7e8257f8d8bce64b6df55f81fba92011a6a77269b3350f8b997b152af348dba
         imagePullPolicy: IfNotPresent
         args:
         - patch
         - --webhook-name=ingress-nginx-internal-admission
         - --namespace=$(POD_NAMESPACE)
         - --patch-mutating=false
@@ -43,15 +44,17 @@

         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
             - ALL
           readOnlyRootFilesystem: true
+          runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
       restartPolicy: OnFailure
       serviceAccountName: ingress-nginx-internal-admission
+      automountServiceAccountToken: true
       nodeSelector:
         kubernetes.io/os: linux
 

@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from e3351bf to df3c6ca Compare July 18, 2024 18:36
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.11.0 feat(helm): update chart ingress-nginx to 4.11.1 Jul 18, 2024
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from df3c6ca to 8d600d4 Compare August 16, 2024 07:43
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.11.1 feat(helm): update chart ingress-nginx to 4.11.2 Aug 16, 2024
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.11.2 feat(helm): update chart ingress-nginx to 4.11.3 Oct 9, 2024
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 8d600d4 to bb25610 Compare October 9, 2024 09:24
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from bb25610 to 0864ae3 Compare December 30, 2024 18:05
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.11.3 feat(helm): update chart ingress-nginx to 4.12.0 Dec 30, 2024
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.12.0 feat(helm): update chart ingress-nginx to 4.12.1 Mar 25, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 0864ae3 to a3fafd3 Compare March 25, 2025 03:55
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from a3fafd3 to 08529a8 Compare April 30, 2025 12:41
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.12.1 feat(helm): update chart ingress-nginx to 4.12.2 Apr 30, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 08529a8 to bbd89eb Compare June 5, 2025 23:49
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.12.2 feat(helm): update chart ingress-nginx to 4.12.3 Jun 5, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from bbd89eb to c7c26a7 Compare July 8, 2025 03:48
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.12.3 feat(helm): update chart ingress-nginx to 4.13.0 Jul 8, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from c7c26a7 to 2155f5b Compare August 12, 2025 13:34
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.13.0 feat(helm): update chart ingress-nginx to 4.13.1 Aug 12, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 2155f5b to af1ec50 Compare August 31, 2025 08:58
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.13.1 feat(helm): update chart ingress-nginx to 4.13.2 Aug 31, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from af1ec50 to ce357dc Compare September 30, 2025 20:00
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.13.2 feat(helm): update chart ingress-nginx to 4.13.3 Sep 30, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from ce357dc to 7e91040 Compare November 3, 2025 17:07
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.13.3 feat(helm): update chart ingress-nginx to 4.14.0 Nov 3, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 7e91040 to 0dbf13d Compare December 5, 2025 13:36
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.14.0 feat(helm): update chart ingress-nginx to 4.14.1 Dec 5, 2025
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 0dbf13d to 1c7063a Compare January 27, 2026 02:35
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.14.1 feat(helm): update chart ingress-nginx to 4.14.2 Jan 27, 2026
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 1c7063a to 33567d1 Compare February 3, 2026 02:15
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.14.2 feat(helm): update chart ingress-nginx to 4.14.3 Feb 3, 2026
@renovate renovate bot force-pushed the renovate/ingress-nginx-4.x branch from 33567d1 to db0b8bf Compare March 9, 2026 22:04
@renovate renovate bot changed the title feat(helm): update chart ingress-nginx to 4.14.3 feat(helm): update chart ingress-nginx to 4.15.0 Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants