diff --git a/codefresh/Chart.lock b/codefresh/Chart.lock index 9cf2f8c87..21a9529b2 100644 --- a/codefresh/Chart.lock +++ b/codefresh/Chart.lock @@ -7,7 +7,7 @@ dependencies: version: 0.10.6 - name: consul repository: https://charts.bitnami.com/bitnami - version: 11.4.23 + version: 11.4.32 - name: mongodb repository: https://charts.bitnami.com/bitnami version: 15.6.26 @@ -37,85 +37,85 @@ dependencies: version: 1.4.0 - name: ingress-nginx repository: https://kubernetes.github.io/ingress-nginx - version: 4.12.1 + version: 4.12.5 - name: cluster-providers repository: oci://quay.io/codefresh/charts - version: 1.17.17 + version: 1.18.0 - name: kube-integration repository: oci://quay.io/codefresh/charts - version: 1.31.21 + version: 1.32.0 - name: charts-manager repository: oci://quay.io/codefresh/charts - version: 1.23.3 + version: 1.23.4 - name: cfsign repository: oci://quay.io/codefresh/charts version: 1.8.10 - name: tasker-kubernetes repository: oci://quay.io/codefresh/charts - version: 1.26.20 + version: 1.27.0 - name: context-manager repository: oci://quay.io/codefresh/charts - version: 2.34.4 + version: 2.34.5 - name: pipeline-manager repository: oci://quay.io/codefresh/charts - version: 3.139.4 + version: 3.139.5 - name: gitops-dashboard-manager repository: oci://quay.io/codefresh/charts - version: 1.14.24 + version: 1.15.0 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfapi repository: oci://quay.io/codefresh/charts - version: 21.279.7 + version: 21.279.8 - name: cfui repository: oci://quay.io/codefresh/charts version: 14.98.29 @@ -124,31 +124,31 @@ dependencies: version: 4.11.16 - name: runtime-environment-manager repository: oci://quay.io/codefresh/charts - version: 3.41.3 + version: 3.41.5 - name: cf-broadcaster repository: oci://quay.io/codefresh/charts - version: 1.13.2 + version: 1.14.0 - name: helm-repo-manager repository: oci://quay.io/codefresh/charts version: 0.20.2 - name: hermes repository: oci://quay.io/codefresh/charts - version: 0.21.19 + version: 0.21.20 - name: nomios repository: oci://quay.io/codefresh/charts version: 0.11.11 - name: cronus repository: oci://quay.io/codefresh/charts - version: 0.8.11 + version: 0.8.12 - name: cf-platform-analytics repository: oci://quay.io/codefresh/charts - version: 0.50.4 + version: 0.51.0 - name: cf-platform-analytics repository: oci://quay.io/codefresh/charts - version: 0.50.4 + version: 0.51.0 - name: argo-platform repository: oci://quay.io/codefresh/charts - version: 1.3525.2-onprem-45cda44 + version: 1.3525.3-onprem-24aeab4 - name: argo-hub-platform repository: oci://quay.io/codefresh/charts version: 0.1.27 @@ -157,15 +157,15 @@ dependencies: version: 0.1.0 - name: mailer repository: oci://quay.io/codefresh/charts - version: 1.20.8 + version: 1.21.0 - name: payments repository: oci://quay.io/codefresh/charts - version: 2.23.19 + version: 2.24.0 - name: segment-reporter repository: oci://quay.io/codefresh/charts - version: 1.17.8 + version: 1.18.0 - name: salesforce-reporter repository: oci://quay.io/codefresh/charts version: 1.30.11 -digest: sha256:e2e4e1952f711bce5964851802a9bdbc84c3337e673ef58e149ec9e2a46112e6 -generated: "2025-07-28T12:05:24.039668+03:00" +digest: sha256:6a1af6f7dc7b6b6ea843b922929016b581a031a63838eaf107a687cc78d89b71 +generated: "2025-08-22T10:31:59.553695+03:00" diff --git a/codefresh/Chart.yaml b/codefresh/Chart.yaml index e2c75a716..7c27ab931 100644 --- a/codefresh/Chart.yaml +++ b/codefresh/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 description: Helm Chart for Codefresh On-Prem name: codefresh -version: 2.8.11 +version: 2.8.12 keywords: - codefresh home: https://codefresh.io/ @@ -15,11 +15,13 @@ appVersion: 2.8.0 annotations: artifacthub.io/prerelease: "false" artifacthub.io/alternativeName: "codefresh-onprem" - # artifacthub.io/containsSecurityUpdates: "true" + artifacthub.io/containsSecurityUpdates: "true" # supported kinds are added, changed, deprecated, removed, fixed and security. artifacthub.io/changes: | - kind: fixed description: "Fix RabbitMQ version requirements." + - kind: security + description: "Contains security fixes" dependencies: - name: cf-common repository: oci://quay.io/codefresh/charts @@ -29,7 +31,7 @@ dependencies: version: 0.10.6 condition: internal-gateway.enabled - name: consul - version: 11.4.23 + version: 11.4.32 repository: https://charts.bitnami.com/bitnami condition: consul.enabled - name: mongodb @@ -69,7 +71,7 @@ dependencies: condition: runner.enabled version: 1.4.0 - name: ingress-nginx - version: 4.12.1 + version: 4.12.5 repository: https://kubernetes.github.io/ingress-nginx condition: ingress-nginx.enabled - name: cluster-providers @@ -237,7 +239,7 @@ dependencies: repository: oci://quay.io/codefresh/charts condition: argo-platform.enabled - name: argo-platform - version: "1.3525.2-onprem-45cda44" + version: "1.3525.3-onprem-24aeab4" repository: oci://quay.io/codefresh/charts condition: argo-platform.enabled - name: argo-hub-platform diff --git a/codefresh/README.md b/codefresh/README.md index b579df1c2..9e6e0ba5e 100644 --- a/codefresh/README.md +++ b/codefresh/README.md @@ -1,6 +1,6 @@ ## Codefresh On-Premises -![Version: 2.8.11](https://img.shields.io/badge/Version-2.8.11-informational?style=flat-square) ![AppVersion: 2.8.0](https://img.shields.io/badge/AppVersion-2.8.0-informational?style=flat-square) +![Version: 2.8.12](https://img.shields.io/badge/Version-2.8.12-informational?style=flat-square) ![AppVersion: 2.8.0](https://img.shields.io/badge/AppVersion-2.8.0-informational?style=flat-square) Helm chart for deploying [Codefresh On-Premises](https://codefresh.io/docs/docs/getting-started/intro-to-codefresh/) to Kubernetes. @@ -2450,7 +2450,7 @@ After platform upgrade, Consul fails with the error `refusing to rejoin cluster | argo-platform.runtime-monitor | object | See below | runtime-monitor Don't enable! Not used in onprem! | | argo-platform.ui | object | See below | ui | | argo-platform.useExternalSecret | bool | `false` | Use regular k8s secret object. Keep `false`! | -| builder | object | `{"affinity":{},"container":{"image":{"registry":"docker.io","repository":"library/docker","tag":"28.3-dind"}},"enabled":true,"imagePullSecrets":[],"initContainers":{"register":{"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/curl","tag":"8.11.1"}}},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | builder | +| builder | object | `{"affinity":{},"container":{"image":{"registry":"docker.io","repository":"library/docker","tag":"28.3-dind"}},"enabled":true,"imagePullSecrets":[],"initContainers":{"register":{"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/curl","tag":"8.14.1"}}},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | builder | | cf-broadcaster | object | See below | broadcaster | | cf-oidc-provider | object | See below | cf-oidc-provider | | cf-platform-analytics-etlstarter | object | See below | etl-starter | @@ -2613,7 +2613,7 @@ After platform upgrade, Consul fails with the error `refusing to rejoin cluster | hooks | object | See below | Pre/post-upgrade Job hooks. | | hooks.consul | object | `{"affinity":{},"enabled":true,"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/kubectl","tag":"1.33.3"},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | Recreates `consul-headless` service due to duplicated ports in Service during the upgrade. | | hooks.mongodb | object | `{"affinity":{},"enabled":true,"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/mongosh","tag":"2.5.0"},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | Updates images in `system/default` runtime. | -| hooks.rabbitmq | object | `{"affinity":{},"enabled":true,"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/rabbitmqadmin","tag":"2.1.0"},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | Enable stable feature flags in RabbitMQ. | +| hooks.rabbitmq | object | `{"affinity":{},"enabled":true,"image":{"registry":"us-docker.pkg.dev/codefresh-inc/public-gcr-io","repository":"codefresh/rabbitmqadmin","tag":"2.8.0"},"nodeSelector":{},"podSecurityContext":{},"resources":{},"tolerations":[]}` | Enable stable feature flags in RabbitMQ. | | imageCredentials | object | `{}` | Credentials for Image Pull Secret object | | ingress | object | `{"annotations":{"nginx.ingress.kubernetes.io/service-upstream":"true","nginx.ingress.kubernetes.io/ssl-redirect":"false","nginx.org/redirect-to-https":"false"},"enabled":true,"ingressClassName":"nginx-codefresh","labels":{},"nameOverride":"","services":{"internal-gateway":["/"]},"tls":{"cert":"","enabled":false,"existingSecret":"","key":"","secretName":"star.codefresh.io"}}` | Ingress | | ingress-nginx | object | See below | ingress-nginx Ref: https://github.com/kubernetes/ingress-nginx/blob/main/charts/ingress-nginx/values.yaml | diff --git a/codefresh/values.yaml b/codefresh/values.yaml index 9d7c1c68b..b129b8b41 100644 --- a/codefresh/values.yaml +++ b/codefresh/values.yaml @@ -67,7 +67,7 @@ seed: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/postgresql - tag: 17 + tag: 17.5.0-debian-12-r20 # -- (optional) "postgres" admin user in plain text (required ONLY for seed job!) # Must be a privileged user allowed to create databases and grant roles. # If omitted, username and password from `.Values.global.postgresUser/postgresPassword` will be used. @@ -471,7 +471,7 @@ hooks: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/rabbitmqadmin - tag: 2.1.0 + tag: 2.8.0 affinity: {} nodeSelector: {} podSecurityContext: {} @@ -486,7 +486,7 @@ postgresqlCleanJob: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/postgresql - tag: 17 + tag: 17.5.0-debian-12-r20 schedule: "0 0 * * *" successfulJobsHistoryLimit: 1 failedJobsHistoryLimit: 1 @@ -773,6 +773,10 @@ cf-platform-analytics-platform: redis: enabled: true nameOverride: redis-platform-analytics + image: + registry: quay.io + repository: codefresh/redis + tag: 7.4.3-debian-12-r0 resources: requests: cpu: 100m @@ -824,7 +828,7 @@ cfsign: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/curl - tag: 8.11.1 + tag: 8.14.1 affinity: {} nodeSelector: {} podSecurityContext: {} @@ -1159,7 +1163,7 @@ postgresql: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/postgresql - tag: 17.5.0-debian-12-r15 + tag: 17.5.0-debian-12-r20 auth: enablePostgresUser: true postgresPassword: "eC9arYka4ZbH" @@ -1215,6 +1219,10 @@ redis: requests: cpu: 200m memory: 256Mi + image: + registry: quay.io + repository: codefresh/redis + tag: 7.4.3-debian-12-r0 # -- redis-ha ## Ref: https://github.com/DandyDeveloper/charts/blob/master/charts/redis-ha/values.yaml @@ -1243,7 +1251,7 @@ redis-ha: rabbitmq: enabled: true image: - tag: "4.0" + tag: "4.1.3" replicaCount: 1 auth: username: user @@ -1263,7 +1271,7 @@ builder: image: registry: us-docker.pkg.dev/codefresh-inc/public-gcr-io repository: codefresh/curl - tag: 8.11.1 + tag: 8.14.1 container: image: registry: docker.io