-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update ghcr.io/maxmind/geoipupdate docker tag to v7.1.0 #1304
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Kustomization Diff
Click to expand--- kubernetes/gabernetes/apps/kube-vip/app Kustomization: kube-system/kube-vip HelmRelease: kube-system/kube-vip
+++ kubernetes/gabernetes/apps/kube-vip/app Kustomization: kube-system/kube-vip HelmRelease: kube-system/kube-vip
@@ -44,13 +44,13 @@
vip_leasename: plndr-cp-lock
vip_renewdeadline: '3'
vip_retryperiod: '1'
image:
pullPolicy: IfNotPresent
repository: ghcr.io/kube-vip/kube-vip
- tag: v0.8.6@sha256:1efe86893baf2d3c97c452fa53641ba647553ed0e639db69e56473d5a238462e
+ tag: v0.8.7@sha256:32829cc6f8630eba4e1b5e4df5bcbc34c767e70703d26e64a0f7317951c7b517
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
--- kubernetes/templates/apps/reloader Kustomization: reloader/app HelmRelease: reloader/reloader
+++ kubernetes/templates/apps/reloader Kustomization: reloader/app HelmRelease: reloader/reloader
@@ -13,13 +13,13 @@
chart: reloader
interval: 1h
sourceRef:
kind: HelmRepository
name: stakater
namespace: reloader
- version: 1.1.0
+ version: 1.2.0
driftDetection:
mode: enabled
interval: 1h
values:
fullnameOverride: reloader
reloader:
--- kubernetes/gabernetes/apps/authentik/app Kustomization: authentik/app HelmRelease: authentik/authentik
+++ kubernetes/gabernetes/apps/authentik/app Kustomization: authentik/app HelmRelease: authentik/authentik
@@ -46,12 +46,15 @@
containerSecurityContext:
readOnlyRootFilesystem: true
enabled: true
env:
- name: GEOIPUPDATE_HOST
value: ${geoip_host}
+ image:
+ repository: ghcr.io/maxmind/geoipupdate
+ tag: v7.1.0@sha256:e596817580fb150490f9897390a5a8b52bcfb8b9bb69354ae9bdfd47a949d84e
licenseKey: stub
volumeMounts:
- mountPath: /tmp
name: tmp
global:
deploymentAnnotations:
--- kubernetes/gabernetes/apps/esphome/app Kustomization: esphome/app HelmRelease: esphome/esphome
+++ kubernetes/gabernetes/apps/esphome/app Kustomization: esphome/app HelmRelease: esphome/esphome
@@ -32,13 +32,13 @@
- --user-data-dir=/cache
- --extensions-dir=/cache
- /config
image:
pullPolicy: IfNotPresent
repository: ghcr.io/coder/code-server
- tag: 4.95.2@sha256:51b9ff106f67bfe56aa88c7e63e7413276d0b509fb85290c3d361a38e97bfa8c
+ tag: 4.95.3@sha256:6d74583d68179cbb6ddadc2518b450d2ac3eaec2d342474fe1941e03371cd2cf
resources:
limits:
cpu: 500m
memory: 500Mi
securityContext:
allowPrivilegeEscalation: false
@@ -60,13 +60,13 @@
PIP_CACHE_DIR: /cache/pip
PLATFORMIO_CORE_DIR: /cache/pio
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/esphome/esphome
- tag: 2024.10.3@sha256:90f5ea3767d2ff69c696e8bdbc3539a00bbcc9aae2636a0eb3f748ac7e353610
+ tag: 2024.11.0@sha256:4d822f615c463c599db5240600faf481986a53d4333e94822efa194f26c725f9
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
--- kubernetes/gabernetes/apps/cilium/app Kustomization: kube-system/cilium-app HelmRelease: kube-system/cilium
+++ kubernetes/gabernetes/apps/cilium/app Kustomization: kube-system/cilium-app HelmRelease: kube-system/cilium
@@ -12,13 +12,13 @@
spec:
chart: cilium
sourceRef:
kind: HelmRepository
name: cilium
namespace: kube-system
- version: 1.16.3
+ version: 1.16.4
driftDetection:
mode: enabled
install:
crds: Create
interval: 1h
upgrade:
--- kubernetes/gabernetes/apps/immich/app Kustomization: immich/app HelmRelease: immich/immich
+++ kubernetes/gabernetes/apps/immich/app Kustomization: immich/app HelmRelease: immich/immich
@@ -24,13 +24,13 @@
machine-learning:
containers:
app:
image:
pullPolicy: IfNotPresent
repository: ghcr.io/immich-app/immich-machine-learning
- tag: v1.120.2@sha256:3cca923bc8eaa3616c48fc6088005e08d574cf1acf6c1253c92393ae11e4788d
+ tag: v1.121.0@sha256:1b8494bb9fe2194f2dc72c4d6b0104e16718f50e8772d54ade57909770816ad1
securityContext:
readOnlyRootFilesystem: true
pod:
labels:
policy.gabe565.com/egress-world: 'true'
policy.gabe565.com/ingress-namespace: 'true'
@@ -54,13 +54,13 @@
key: valkey-password
name: valkey
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/immich-app/immich-server
- tag: v1.120.2@sha256:99f97cb61cd1b49c23fbee46a0ed067f171970518d8834c7e8b2dd3ac0d39c63
+ tag: v1.121.0@sha256:851c02f28891f1854c5b5762ee8d2e254e2de528cfe3627b2fbcb37a7f108ff3
resources:
limits:
gpu.intel.com/i915: 1
requests:
gpu.intel.com/i915: 1
securityContext:
@@ -90,13 +90,13 @@
key: valkey-password
name: valkey
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/immich-app/immich-server
- tag: v1.120.2@sha256:99f97cb61cd1b49c23fbee46a0ed067f171970518d8834c7e8b2dd3ac0d39c63
+ tag: v1.121.0@sha256:851c02f28891f1854c5b5762ee8d2e254e2de528cfe3627b2fbcb37a7f108ff3
securityContext:
readOnlyRootFilesystem: true
pod:
labels:
policy.gabe565.com/egress-namespace: 'true'
policy.gabe565.com/egress-world: 'true'
--- kubernetes/gabernetes/apps/home-assistant/app Kustomization: home-assistant/app HelmRelease: home-assistant/home-assistant
+++ kubernetes/gabernetes/apps/home-assistant/app Kustomization: home-assistant/app HelmRelease: home-assistant/home-assistant
@@ -31,13 +31,13 @@
- --auth=none
- --user-data-dir=/config/.vscode
- /config
image:
pullPolicy: IfNotPresent
repository: ghcr.io/coder/code-server
- tag: 4.95.2@sha256:51b9ff106f67bfe56aa88c7e63e7413276d0b509fb85290c3d361a38e97bfa8c
+ tag: 4.95.3@sha256:6d74583d68179cbb6ddadc2518b450d2ac3eaec2d342474fe1941e03371cd2cf
resources:
limits:
cpu: 500m
memory: 500Mi
securityContext:
readOnlyRootFilesystem: true
--- kubernetes/gabernetes/apps/open-webui/app Kustomization: open-webui/app HelmRelease: open-webui/open-webui
+++ kubernetes/gabernetes/apps/open-webui/app Kustomization: open-webui/app HelmRelease: open-webui/open-webui
@@ -36,13 +36,13 @@
TZ: America/Chicago
WEBUI_AUTH_TRUSTED_EMAIL_HEADER: X-authentik-email
WEBUI_SECRET_KEY: ${secret_key}
image:
pullPolicy: IfNotPresent
repository: ghcr.io/open-webui/open-webui
- tag: 0.3.35@sha256:89fffc09527cebeb4d4cf268a6435a4f3ee8c07f72618b607a0fa3eef0ffc1c8
+ tag: 0.4.1@sha256:c4428fbe7e15863b3e83cb6293a0d31dbf66e6ed23a62c144143b87c1f3fa9a8
probes:
liveness:
enabled: true
path: /health
type: HTTP
readiness:
--- kubernetes/gabernetes/apps/plausible/clickhouse Kustomization: plausible/clickhouse HelmRelease: plausible/clickhouse
+++ kubernetes/gabernetes/apps/plausible/clickhouse Kustomization: plausible/clickhouse HelmRelease: plausible/clickhouse
@@ -57,13 +57,13 @@
clickhouse:
containers:
app:
image:
pullPolicy: IfNotPresent
repository: clickhouse/clickhouse-server
- tag: 24.10.1.2812-alpine@sha256:30818f119b3a3da4e9f6cdeeb053dfc666537f5b432bd484ba2a520de01be530
+ tag: 24.10.2.80-alpine@sha256:7144d515a4f12aea17869277297b1953e0a68b6f72e20ae897b5d7155c16359d
probes:
liveness:
enabled: true
path: /?query=SELECT+1
type: HTTP
readiness:
--- kubernetes/gabernetes/apps/plausible/app Kustomization: plausible/app HelmRelease: plausible/plausible
+++ kubernetes/gabernetes/apps/plausible/app Kustomization: plausible/app HelmRelease: plausible/plausible
@@ -72,13 +72,13 @@
GEOIPUPDATE_HOST: ${geoip_host}
GEOIPUPDATE_LICENSE_KEY: stub
GEOIPUPDATE_PRESERVE_FILE_TIMES: '1'
image:
pullPolicy: IfNotPresent
repository: ghcr.io/maxmind/geoipupdate
- tag: v7.0.1@sha256:80c57598a9ff552953e499cefc589cfe7b563d64262742ea42f2014251b557b0
+ tag: v7.1.0@sha256:e596817580fb150490f9897390a5a8b52bcfb8b9bb69354ae9bdfd47a949d84e
probes:
startup:
custom: true
enabled: true
spec:
exec:
--- kubernetes/gabernetes/apps/prowlarr/app Kustomization: prowlarr/app HelmRelease: prowlarr/prowlarr
+++ kubernetes/gabernetes/apps/prowlarr/app Kustomization: prowlarr/app HelmRelease: prowlarr/prowlarr
@@ -27,13 +27,13 @@
app:
env:
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/onedr0p/prowlarr
- tag: 1.25.4.4818@sha256:4df8b9d21469e5051d53d753fb1a277875ac5cdd1dc69068541adb165aae17a1
+ tag: 1.26.1.4844@sha256:6800e1aa76d25f67d79b567c753cb23e80f535486c065c4c3bb0eb1558e96c97
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
--- kubernetes/gabernetes/apps/qbittorrent/app Kustomization: qbittorrent/app HelmRelease: qbittorrent/qbittorrent
+++ kubernetes/gabernetes/apps/qbittorrent/app Kustomization: qbittorrent/app HelmRelease: qbittorrent/qbittorrent
@@ -30,13 +30,13 @@
env:
QBITTORRENT__BT_PORT: ${bittorrent_port}
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/onedr0p/qbittorrent
- tag: 5.0.1@sha256:7fc5af4f7f9c8e4998aaa18b5e2e634757c55f70c23b9bd46b40e09a4c7acda5
+ tag: 5.0.2@sha256:b905a9e4eef9ffabd10ad8618ffdc2661d20c1a910441e5f921c851c10974444
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
@@ -103,13 +103,13 @@
vuetorrent:
containers:
app:
image:
pullPolicy: IfNotPresent
repository: ghcr.io/gabe565/vuetorrent
- tag: 2.17.0@sha256:0459b2b7be320d306d6cbc9ede8779a0af86d88ff91b0d6b64244e6df8d40997
+ tag: 2.18.0@sha256:27c084ada5947eaf6d7e8dfbcaaf81294eefa4a8abd5f308a86363d6c95221c4
securityContext:
readOnlyRootFilesystem: true
pod:
labels:
policy.gabe565.com/ingress-ingress: 'true'
strategy: RollingUpdate
--- kubernetes/gabernetes/apps/radarr/app Kustomization: radarr/app HelmRelease: radarr/radarr
+++ kubernetes/gabernetes/apps/radarr/app Kustomization: radarr/app HelmRelease: radarr/radarr
@@ -27,13 +27,13 @@
app:
env:
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/onedr0p/radarr
- tag: 5.14.0.9383@sha256:e4ead782fd1d4842765e0ef96bb863fc2fef72ee3e87e2b2a51dc33fb3ebc32c
+ tag: 5.15.1.9463@sha256:d097137c8190f13ff8e2e92f7fb748083d377c7f8f9a90e1460fd3b6460c0488
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
--- kubernetes/gabernetes/apps/stirling-pdf/app Kustomization: stirling-pdf/app HelmRelease: stirling-pdf/stirling-pdf
+++ kubernetes/gabernetes/apps/stirling-pdf/app Kustomization: stirling-pdf/app HelmRelease: stirling-pdf/stirling-pdf
@@ -29,13 +29,13 @@
DOCKER_ENABLE_SECURITY: 'false'
INSTALL_BOOK_AND_ADVANCED_HTML_OPS: 'false'
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/stirling-tools/s-pdf
- tag: 0.33.0@sha256:7cd48320b45462e19bbe3478302ed339dfdc330344af554d9cb375fad029c16e
+ tag: 0.33.1@sha256:d30bf0b2826f0e71cf6fe1b806d918db6d90121ac70b3384569e3b49edf51b3f
probes:
liveness:
enabled: true
path: /api/v1/info/status
type: HTTP
readiness:
--- kubernetes/gabernetes/apps/zwave-js-ui/app Kustomization: zwave-js-ui/app HelmRelease: zwave-js-ui/zwave-js-ui
+++ kubernetes/gabernetes/apps/zwave-js-ui/app Kustomization: zwave-js-ui/app HelmRelease: zwave-js-ui/zwave-js-ui
@@ -29,13 +29,13 @@
FORCE_DISABLE_SSL: 'true'
TRUST_PROXY: 10.42.0.0/16
TZ: America/Chicago
image:
pullPolicy: IfNotPresent
repository: ghcr.io/zwave-js/zwave-js-ui
- tag: 9.27.2@sha256:ac7e66f98c39fe56b6ddb5d2e9cfced8246f74658278b82f6f60bee15206ae73
+ tag: 9.27.3@sha256:85cf89fd94d6bea7a73a614964ed3cd656e56747cec53d5b5c1d75dab42ab91c
probes:
liveness:
enabled: true
readiness:
enabled: true
startup: |
HelmRelease Diff
Click to expand--- HelmRelease: authentik/authentik Deployment: authentik/authentik-server
+++ HelmRelease: authentik/authentik Deployment: authentik/authentik-server
@@ -123,13 +123,13 @@
successThreshold: 1
timeoutSeconds: 1
resources: {}
securityContext:
readOnlyRootFilesystem: true
- name: geoip
- image: ghcr.io/maxmind/geoipupdate:v6.0.0
+ image: ghcr.io/maxmind/geoipupdate:v7.1.0@sha256:e596817580fb150490f9897390a5a8b52bcfb8b9bb69354ae9bdfd47a949d84e
imagePullPolicy: IfNotPresent
env:
- name: GEOIPUPDATE_HOST
value: ${geoip_host}
- name: GEOIPUPDATE_FREQUENCY
value: '8'
--- HelmRelease: authentik/authentik Deployment: authentik/authentik-worker
+++ HelmRelease: authentik/authentik Deployment: authentik/authentik-worker
@@ -108,13 +108,13 @@
successThreshold: 1
timeoutSeconds: 1
resources: {}
securityContext:
readOnlyRootFilesystem: true
- name: geoip
- image: ghcr.io/maxmind/geoipupdate:v6.0.0
+ image: ghcr.io/maxmind/geoipupdate:v7.1.0@sha256:e596817580fb150490f9897390a5a8b52bcfb8b9bb69354ae9bdfd47a949d84e
imagePullPolicy: IfNotPresent
env:
- name: GEOIPUPDATE_HOST
value: ${geoip_host}
- name: GEOIPUPDATE_FREQUENCY
value: '8'
--- HelmRelease: immich/immich Deployment: immich/immich-machine-learning
+++ HelmRelease: immich/immich Deployment: immich/immich-machine-learning
@@ -32,13 +32,13 @@
automountServiceAccountToken: true
hostIPC: false
hostNetwork: false
hostPID: false
dnsPolicy: ClusterFirst
containers:
- - image: ghcr.io/immich-app/immich-machine-learning:v1.120.2@sha256:3cca923bc8eaa3616c48fc6088005e08d574cf1acf6c1253c92393ae11e4788d
+ - image: ghcr.io/immich-app/immich-machine-learning:v1.121.0@sha256:1b8494bb9fe2194f2dc72c4d6b0104e16718f50e8772d54ade57909770816ad1
imagePullPolicy: IfNotPresent
name: app
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /cache
--- HelmRelease: immich/immich Deployment: immich/immich-microservices
+++ HelmRelease: immich/immich Deployment: immich/immich-microservices
@@ -61,13 +61,13 @@
valueFrom:
secretKeyRef:
key: valkey-password
name: valkey
- name: TZ
value: America/Chicago
- image: ghcr.io/immich-app/immich-server:v1.120.2@sha256:99f97cb61cd1b49c23fbee46a0ed067f171970518d8834c7e8b2dd3ac0d39c63
+ image: ghcr.io/immich-app/immich-server:v1.121.0@sha256:851c02f28891f1854c5b5762ee8d2e254e2de528cfe3627b2fbcb37a7f108ff3
imagePullPolicy: IfNotPresent
name: app
resources:
limits:
gpu.intel.com/i915: 1
requests:
--- HelmRelease: immich/immich Deployment: immich/immich-server
+++ HelmRelease: immich/immich Deployment: immich/immich-server
@@ -60,13 +60,13 @@
valueFrom:
secretKeyRef:
key: valkey-password
name: valkey
- name: TZ
value: America/Chicago
- image: ghcr.io/immich-app/immich-server:v1.120.2@sha256:99f97cb61cd1b49c23fbee46a0ed067f171970518d8834c7e8b2dd3ac0d39c63
+ image: ghcr.io/immich-app/immich-server:v1.121.0@sha256:851c02f28891f1854c5b5762ee8d2e254e2de528cfe3627b2fbcb37a7f108ff3
imagePullPolicy: IfNotPresent
name: app
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /tmp
--- HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf
+++ HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf
@@ -44,13 +44,13 @@
- name: DOCKER_ENABLE_SECURITY
value: 'false'
- name: INSTALL_BOOK_AND_ADVANCED_HTML_OPS
value: 'false'
- name: TZ
value: America/Chicago
- image: ghcr.io/stirling-tools/s-pdf:0.33.0@sha256:7cd48320b45462e19bbe3478302ed339dfdc330344af554d9cb375fad029c16e
+ image: ghcr.io/stirling-tools/s-pdf:0.33.1@sha256:d30bf0b2826f0e71cf6fe1b806d918db6d90121ac70b3384569e3b49edf51b3f
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
httpGet:
path: /api/v1/info/status
port: 8080
--- HelmRelease: kube-system/kube-vip DaemonSet: kube-system/kube-vip
+++ HelmRelease: kube-system/kube-vip DaemonSet: kube-system/kube-vip
@@ -79,13 +79,13 @@
- name: vip_leasename
value: plndr-cp-lock
- name: vip_renewdeadline
value: '3'
- name: vip_retryperiod
value: '1'
- image: ghcr.io/kube-vip/kube-vip:v0.8.6@sha256:1efe86893baf2d3c97c452fa53641ba647553ed0e639db69e56473d5a238462e
+ image: ghcr.io/kube-vip/kube-vip:v0.8.7@sha256:32829cc6f8630eba4e1b5e4df5bcbc34c767e70703d26e64a0f7317951c7b517
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: reloader/reloader ClusterRole: reloader/reloader-role
+++ HelmRelease: reloader/reloader ClusterRole: reloader/reloader-role
@@ -30,22 +30,12 @@
verbs:
- list
- get
- update
- patch
- apiGroups:
- - extensions
- resources:
- - deployments
- - daemonsets
- verbs:
- - list
- - get
- - update
- - patch
-- apiGroups:
- batch
resources:
- cronjobs
verbs:
- list
- get
--- HelmRelease: reloader/reloader Deployment: reloader/reloader
+++ HelmRelease: reloader/reloader Deployment: reloader/reloader
@@ -10,13 +10,13 @@
release: reloader
heritage: Helm
app.kubernetes.io/managed-by: Helm
group: com.stakater.platform
policy.gabe565.com/egress-kubeapi: 'true'
provider: stakater
- version: v1.1.0
+ version: v1.2.0
name: reloader
namespace: reloader
spec:
replicas: 1
revisionHistoryLimit: 2
selector:
@@ -30,27 +30,29 @@
release: reloader
heritage: Helm
app.kubernetes.io/managed-by: Helm
group: com.stakater.platform
policy.gabe565.com/egress-kubeapi: 'true'
provider: stakater
- version: v1.1.0
+ version: v1.2.0
spec:
containers:
- - image: ghcr.io/stakater/reloader:v1.1.0
+ - image: ghcr.io/stakater/reloader:v1.2.0
imagePullPolicy: IfNotPresent
name: reloader
env:
- name: GOMAXPROCS
valueFrom:
resourceFieldRef:
resource: limits.cpu
+ divisor: '1'
- name: GOMEMLIMIT
valueFrom:
resourceFieldRef:
resource: limits.memory
+ divisor: '1'
ports:
- name: http
containerPort: 9090
livenessProbe:
httpGet:
path: /live
@@ -72,12 +74,13 @@
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /tmp/
name: tmp-volume
args:
+ - --log-level=info
- --reload-strategy=annotations
securityContext:
runAsNonRoot: true
runAsUser: 65534
seccompProfile:
type: RuntimeDefault
--- HelmRelease: zwave-js-ui/zwave-js-ui Deployment: zwave-js-ui/zwave-js-ui
+++ HelmRelease: zwave-js-ui/zwave-js-ui Deployment: zwave-js-ui/zwave-js-ui
@@ -40,13 +40,13 @@
- name: FORCE_DISABLE_SSL
value: 'true'
- name: TRUST_PROXY
value: 10.42.0.0/16
- name: TZ
value: America/Chicago
- image: ghcr.io/zwave-js/zwave-js-ui:9.27.2@sha256:ac7e66f98c39fe56b6ddb5d2e9cfced8246f74658278b82f6f60bee15206ae73
+ image: ghcr.io/zwave-js/zwave-js-ui:9.27.3@sha256:85cf89fd94d6bea7a73a614964ed3cd656e56747cec53d5b5c1d75dab42ab91c
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: radarr/radarr Deployment: radarr/radarr
+++ HelmRelease: radarr/radarr Deployment: radarr/radarr
@@ -43,13 +43,13 @@
hostPID: false
dnsPolicy: ClusterFirst
containers:
- env:
- name: TZ
value: America/Chicago
- image: ghcr.io/onedr0p/radarr:5.14.0.9383@sha256:e4ead782fd1d4842765e0ef96bb863fc2fef72ee3e87e2b2a51dc33fb3ebc32c
+ image: ghcr.io/onedr0p/radarr:5.15.1.9463@sha256:d097137c8190f13ff8e2e92f7fb748083d377c7f8f9a90e1460fd3b6460c0488
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: prowlarr/prowlarr Deployment: prowlarr/prowlarr
+++ HelmRelease: prowlarr/prowlarr Deployment: prowlarr/prowlarr
@@ -39,13 +39,13 @@
hostPID: false
dnsPolicy: ClusterFirst
containers:
- env:
- name: TZ
value: America/Chicago
- image: ghcr.io/onedr0p/prowlarr:1.25.4.4818@sha256:4df8b9d21469e5051d53d753fb1a277875ac5cdd1dc69068541adb165aae17a1
+ image: ghcr.io/onedr0p/prowlarr:1.26.1.4844@sha256:6800e1aa76d25f67d79b567c753cb23e80f535486c065c4c3bb0eb1558e96c97
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: esphome/esphome Deployment: esphome/esphome-code
+++ HelmRelease: esphome/esphome Deployment: esphome/esphome-code
@@ -56,13 +56,13 @@
- --disable-telemetry
- --disable-update-check
- --auth=none
- --user-data-dir=/cache
- --extensions-dir=/cache
- /config
- image: ghcr.io/coder/code-server:4.95.2@sha256:51b9ff106f67bfe56aa88c7e63e7413276d0b509fb85290c3d361a38e97bfa8c
+ image: ghcr.io/coder/code-server:4.95.3@sha256:6d74583d68179cbb6ddadc2518b450d2ac3eaec2d342474fe1941e03371cd2cf
imagePullPolicy: IfNotPresent
name: app
resources:
limits:
cpu: 500m
memory: 500Mi
--- HelmRelease: esphome/esphome Deployment: esphome/esphome
+++ HelmRelease: esphome/esphome Deployment: esphome/esphome
@@ -67,13 +67,13 @@
- name: PIP_CACHE_DIR
value: /cache/pip
- name: PLATFORMIO_CORE_DIR
value: /cache/pio
- name: TZ
value: America/Chicago
- image: ghcr.io/esphome/esphome:2024.10.3@sha256:90f5ea3767d2ff69c696e8bdbc3539a00bbcc9aae2636a0eb3f748ac7e353610
+ image: ghcr.io/esphome/esphome:2024.11.0@sha256:4d822f615c463c599db5240600faf481986a53d4333e94822efa194f26c725f9
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: home-assistant/home-assistant Deployment: home-assistant/home-assistant-code
+++ HelmRelease: home-assistant/home-assistant Deployment: home-assistant/home-assistant-code
@@ -46,13 +46,13 @@
- args:
- --disable-telemetry
- --disable-update-check
- --auth=none
- --user-data-dir=/config/.vscode
- /config
- image: ghcr.io/coder/code-server:4.95.2@sha256:51b9ff106f67bfe56aa88c7e63e7413276d0b509fb85290c3d361a38e97bfa8c
+ image: ghcr.io/coder/code-server:4.95.3@sha256:6d74583d68179cbb6ddadc2518b450d2ac3eaec2d342474fe1941e03371cd2cf
imagePullPolicy: IfNotPresent
name: app
resources:
limits:
cpu: 500m
memory: 500Mi
--- HelmRelease: plausible/plausible Deployment: plausible/plausible
+++ HelmRelease: plausible/plausible Deployment: plausible/plausible
@@ -56,13 +56,13 @@
- name: GEOIPUPDATE_HOST
value: ${geoip_host}
- name: GEOIPUPDATE_LICENSE_KEY
value: stub
- name: GEOIPUPDATE_PRESERVE_FILE_TIMES
value: '1'
- image: ghcr.io/maxmind/geoipupdate:v7.0.1@sha256:80c57598a9ff552953e499cefc589cfe7b563d64262742ea42f2014251b557b0
+ image: ghcr.io/maxmind/geoipupdate:v7.1.0@sha256:e596817580fb150490f9897390a5a8b52bcfb8b9bb69354ae9bdfd47a949d84e
imagePullPolicy: IfNotPresent
name: geoip
restartPolicy: Always
securityContext:
readOnlyRootFilesystem: true
startupProbe:
--- HelmRelease: plausible/clickhouse StatefulSet: plausible/clickhouse
+++ HelmRelease: plausible/clickhouse StatefulSet: plausible/clickhouse
@@ -41,13 +41,13 @@
runAsUser: 101
hostIPC: false
hostNetwork: false
hostPID: false
dnsPolicy: ClusterFirst
containers:
- - image: clickhouse/clickhouse-server:24.10.1.2812-alpine@sha256:30818f119b3a3da4e9f6cdeeb053dfc666537f5b432bd484ba2a520de01be530
+ - image: clickhouse/clickhouse-server:24.10.2.80-alpine@sha256:7144d515a4f12aea17869277297b1953e0a68b6f72e20ae897b5d7155c16359d
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
httpGet:
path: /?query=SELECT+1
port: 8123
--- HelmRelease: open-webui/open-webui Deployment: open-webui/open-webui
+++ HelmRelease: open-webui/open-webui Deployment: open-webui/open-webui
@@ -56,13 +56,13 @@
- name: TZ
value: America/Chicago
- name: WEBUI_AUTH_TRUSTED_EMAIL_HEADER
value: X-authentik-email
- name: WEBUI_SECRET_KEY
value: ${secret_key}
- image: ghcr.io/open-webui/open-webui:0.3.35@sha256:89fffc09527cebeb4d4cf268a6435a4f3ee8c07f72618b607a0fa3eef0ffc1c8
+ image: ghcr.io/open-webui/open-webui:0.4.1@sha256:c4428fbe7e15863b3e83cb6293a0d31dbf66e6ed23a62c144143b87c1f3fa9a8
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
httpGet:
path: /health
port: 8080
--- HelmRelease: qbittorrent/qbittorrent Deployment: qbittorrent/qbittorrent
+++ HelmRelease: qbittorrent/qbittorrent Deployment: qbittorrent/qbittorrent
@@ -98,13 +98,13 @@
containers:
- env:
- name: QBITTORRENT__BT_PORT
value: ${bittorrent_port}
- name: TZ
value: America/Chicago
- image: ghcr.io/onedr0p/qbittorrent:5.0.1@sha256:7fc5af4f7f9c8e4998aaa18b5e2e634757c55f70c23b9bd46b40e09a4c7acda5
+ image: ghcr.io/onedr0p/qbittorrent:5.0.2@sha256:b905a9e4eef9ffabd10ad8618ffdc2661d20c1a910441e5f921c851c10974444
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
--- HelmRelease: qbittorrent/qbittorrent Deployment: qbittorrent/qbittorrent-vuetorrent
+++ HelmRelease: qbittorrent/qbittorrent Deployment: qbittorrent/qbittorrent-vuetorrent
@@ -31,13 +31,13 @@
automountServiceAccountToken: true
hostIPC: false
hostNetwork: false
hostPID: false
dnsPolicy: ClusterFirst
containers:
- - image: ghcr.io/gabe565/vuetorrent:2.17.0@sha256:0459b2b7be320d306d6cbc9ede8779a0af86d88ff91b0d6b64244e6df8d40997
+ - image: ghcr.io/gabe565/vuetorrent:2.18.0@sha256:27c084ada5947eaf6d7e8dfbcaaf81294eefa4a8abd5f308a86363d6c95221c4
imagePullPolicy: IfNotPresent
name: app
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /tmp
--- HelmRelease: kube-system/cilium ServiceAccount: kube-system/hubble-relay
+++ HelmRelease: kube-system/cilium ServiceAccount: kube-system/hubble-relay
@@ -1,7 +1,8 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: hubble-relay
namespace: kube-system
+automountServiceAccountToken: false
--- HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-config
+++ HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-config
@@ -125,12 +125,13 @@
mesh-auth-queue-size: '1024'
mesh-auth-rotated-identities-queue-size: '1024'
mesh-auth-gc-interval: 5m0s
proxy-xff-num-trusted-hops-ingress: '0'
proxy-xff-num-trusted-hops-egress: '0'
proxy-connect-timeout: '2'
+ proxy-initial-fetch-timeout: '30'
proxy-max-requests-per-connection: '0'
proxy-max-connection-duration-seconds: '0'
proxy-idle-timeout-seconds: '60'
external-envoy-proxy: 'true'
envoy-base-id: '0'
envoy-keep-cap-netbindservice: 'false'
--- HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-envoy-config
+++ HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-envoy-config
@@ -262,12 +262,13 @@
}
}
]
},
"dynamicResources": {
"ldsConfig": {
+ "initialFetchTimeout": "30s",
"apiConfigSource": {
"apiType": "GRPC",
"transportApiVersion": "V3",
"grpcServices": [
{
"envoyGrpc": {
@@ -277,12 +278,13 @@
],
"setNodeOnFirstMessageOnly": true
},
"resourceApiVersion": "V3"
},
"cdsConfig": {
+ "initialFetchTimeout": "30s",
"apiConfigSource": {
"apiType": "GRPC",
"transportApiVersion": "V3",
"grpcServices": [
{
"envoyGrpc": {
@@ -300,20 +302,19 @@
"name": "envoy.bootstrap.internal_listener",
"typed_config": {
"@type": "type.googleapis.com/envoy.extensions.bootstrap.internal_listener.v3.InternalListener"
}
}
],
- "layeredRuntime": {
- "layers": [
- {
- "name": "static_layer_0",
- "staticLayer": {
- "overload": {
- "global_downstream_max_connections": 50000
- }
+ "overload_manager": {
+ "resource_monitors": [
+ {
+ "name": "envoy.resource_monitors.global_downstream_max_connections",
+ "typed_config": {
+ "@type": "type.googleapis.com/envoy.extensions.resource_monitors.downstream_connections.v3.DownstreamConnectionsConfig",
+ "max_active_downstream_connections": "50000"
}
}
]
},
"admin": {
"address": {
--- HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium
+++ HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium
@@ -26,13 +26,13 @@
spec:
securityContext:
appArmorProfile:
type: Unconfined
containers:
- name: cilium-agent
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
command:
- cilium-agent
args:
- --config-dir=/tmp/cilium/config-map
startupProbe:
@@ -179,13 +179,13 @@
mountPath: /var/lib/cilium/tls/hubble
readOnly: true
- name: tmp
mountPath: /tmp
initContainers:
- name: config
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
command:
- cilium-dbg
- build-config
env:
- name: K8S_NODE_NAME
@@ -200,13 +200,13 @@
fieldPath: metadata.namespace
volumeMounts:
- name: tmp
mountPath: /tmp
terminationMessagePolicy: FallbackToLogsOnError
- name: mount-cgroup
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
env:
- name: CGROUP_ROOT
value: /run/cilium/cgroupv2
- name: BIN_PATH
value: /opt/cni/bin
@@ -232,13 +232,13 @@
- SYS_ADMIN
- SYS_CHROOT
- SYS_PTRACE
drop:
- ALL
- name: apply-sysctl-overwrites
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
env:
- name: BIN_PATH
value: /opt/cni/bin
command:
- sh
@@ -262,13 +262,13 @@
- SYS_ADMIN
- SYS_CHROOT
- SYS_PTRACE
drop:
- ALL
- name: mount-bpf-fs
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
args:
- mount | grep "/sys/fs/bpf type bpf" || mount -t bpf bpf /sys/fs/bpf
command:
- /bin/bash
- -c
@@ -278,13 +278,13 @@
privileged: true
volumeMounts:
- name: bpf-maps
mountPath: /sys/fs/bpf
mountPropagation: Bidirectional
- name: clean-cilium-state
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
command:
- /init-container.sh
env:
- name: CILIUM_ALL_STATE
valueFrom:
@@ -323,13 +323,13 @@
- name: cilium-cgroup
mountPath: /run/cilium/cgroupv2
mountPropagation: HostToContainer
- name: cilium-run
mountPath: /var/run/cilium
- name: install-cni-binaries
- image: quay.io/cilium/cilium:v1.16.3@sha256:62d2a09bbef840a46099ac4c69421c90f84f28d018d479749049011329aa7f28
+ image: quay.io/cilium/cilium:v1.16.4@sha256:d55ec38938854133e06739b1af237932b9c4dd4e75e9b7b2ca3acc72540a44bf
imagePullPolicy: IfNotPresent
command:
- /install-plugin.sh
resources:
requests:
cpu: 100m
--- HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium-envoy
+++ HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium-envoy
@@ -28,13 +28,13 @@
spec:
securityContext:
appArmorProfile:
type: Unconfined
containers:
- name: cilium-envoy
- image: quay.io/cilium/cilium-envoy:v1.29.9-1728346947-0d05e48bfbb8c4737ec40d5781d970a550ed2bbd@sha256:42614a44e508f70d03a04470df5f61e3cffd22462471a0be0544cf116f2c50ba
+ image: quay.io/cilium/cilium-envoy:v1.30.7-1731393961-97edc2815e2c6a174d3d12e71731d54f5d32ea16@sha256:0287b36f70cfbdf54f894160082f4f94d1ee1fb10389f3a95baa6c8e448586ed
imagePullPolicy: IfNotPresent
command:
- /usr/bin/cilium-envoy-starter
args:
- --
- -c /var/run/cilium/envoy/bootstrap-config.json
--- HelmRelease: kube-system/cilium Deployment: kube-system/cilium-operator
+++ HelmRelease: kube-system/cilium Deployment: kube-system/cilium-operator
@@ -30,13 +30,13 @@
name: cilium-operator
app.kubernetes.io/part-of: cilium
app.kubernetes.io/name: cilium-operator
spec:
containers:
- name: cilium-operator
- image: quay.io/cilium/operator-generic:v1.16.3@sha256:6e2925ef47a1c76e183c48f95d4ce0d34a1e5e848252f910476c3e11ce1ec94b
+ image: quay.io/cilium/operator-generic:v1.16.4@sha256:c55a7cbe19fe0b6b28903a085334edb586a3201add9db56d2122c8485f7a51c5
imagePullPolicy: IfNotPresent
command:
- cilium-operator-generic
args:
- --config-dir=/tmp/cilium/config-map
- --debug=$(CILIUM_DEBUG)
--- HelmRelease: kube-system/cilium Deployment: kube-system/hubble-relay
+++ HelmRelease: kube-system/cilium Deployment: kube-system/hubble-relay
@@ -36,13 +36,13 @@
capabilities:
drop:
- ALL
runAsGroup: 65532
runAsNonRoot: true
runAsUser: 65532
- image: quay.io/cilium/hubble-relay:v1.16.3@sha256:feb60efd767e0e7863a94689f4a8db56a0acc7c1d2b307dee66422e3dc25a089
+ image: quay.io/cilium/hubble-relay:v1.16.4@sha256:fb2c7d127a1c809f6ba23c05973f3dd00f6b6a48e4aee2da95db925a4f0351d2
imagePullPolicy: IfNotPresent
command:
- hubble-relay
args:
- serve
ports: |
Kustomization Diff
Click to expand--- kubernetes/templates/apps/reloader Kustomization: reloader/app HelmRelease: reloader/reloader
+++ kubernetes/templates/apps/reloader Kustomization: reloader/app HelmRelease: reloader/reloader
@@ -13,13 +13,13 @@
chart: reloader
interval: 1h
sourceRef:
kind: HelmRepository
name: stakater
namespace: reloader
- version: 1.1.0
+ version: 1.2.0
driftDetection:
mode: enabled
interval: 1h
values:
fullnameOverride: reloader
reloader: |
HelmRelease Diff
Click to expand--- HelmRelease: reloader/reloader ClusterRole: reloader/reloader-role
+++ HelmRelease: reloader/reloader ClusterRole: reloader/reloader-role
@@ -30,22 +30,12 @@
verbs:
- list
- get
- update
- patch
- apiGroups:
- - extensions
- resources:
- - deployments
- - daemonsets
- verbs:
- - list
- - get
- - update
- - patch
-- apiGroups:
- batch
resources:
- cronjobs
verbs:
- list
- get
--- HelmRelease: reloader/reloader Deployment: reloader/reloader
+++ HelmRelease: reloader/reloader Deployment: reloader/reloader
@@ -10,13 +10,13 @@
release: reloader
heritage: Helm
app.kubernetes.io/managed-by: Helm
group: com.stakater.platform
policy.gabe565.com/egress-kubeapi: 'true'
provider: stakater
- version: v1.1.0
+ version: v1.2.0
name: reloader
namespace: reloader
spec:
replicas: 1
revisionHistoryLimit: 2
selector:
@@ -30,27 +30,29 @@
release: reloader
heritage: Helm
app.kubernetes.io/managed-by: Helm
group: com.stakater.platform
policy.gabe565.com/egress-kubeapi: 'true'
provider: stakater
- version: v1.1.0
+ version: v1.2.0
spec:
containers:
- - image: ghcr.io/stakater/reloader:v1.1.0
+ - image: ghcr.io/stakater/reloader:v1.2.0
imagePullPolicy: IfNotPresent
name: reloader
env:
- name: GOMAXPROCS
valueFrom:
resourceFieldRef:
resource: limits.cpu
+ divisor: '1'
- name: GOMEMLIMIT
valueFrom:
resourceFieldRef:
resource: limits.memory
+ divisor: '1'
ports:
- name: http
containerPort: 9090
livenessProbe:
httpGet:
path: /live
@@ -72,12 +74,13 @@
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /tmp/
name: tmp-volume
args:
+ - --log-level=info
- --reload-strategy=annotations
securityContext:
runAsNonRoot: true
runAsUser: 65534
seccompProfile:
type: RuntimeDefault |
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v7.0.1
->v7.1.0
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.