-
Notifications
You must be signed in to change notification settings - Fork 16.8k
Conversation
Hi @jfrabaute. Thanks for your PR. I'm waiting for a helm member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]>
/ok-to-test |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jfrabaute, paulczar The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: camelusluo <[email protected]>
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]>
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]>
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]>
* [stable/prometheus-operator] Scraping kubelet for /metrics/resource/v1alpha1 (#22586) [stable/prometheus-operator] Fixing the template Signed-off-by: Mohsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nginx-ingress] Add support for an internal load balancer along with an external one (#22758) * [stable/nginx-ingress] Add support for an internal load balancer along with an external one Signed-off-by: Luis Garnica Guilarte <[email protected]> * [stable/nginx-ingress] Add support for an internal load balancer along with an external one Signed-off-by: Luis Garnica Guilarte <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/minio] Support imagePullSecrets (#22812) Signed-off-by: Deepa Vijaykumar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kube-state-metrics] Version bump to 1.9.7 (#22649) https://github.com/kubernetes/kube-state-metrics/releases/v1.9.7 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Fix kubeconfig s3 bucket configuration in spinnaker chart (#22767) * Removed default for kubeconfig secret from values.yaml and updated helm templates to check for kubeconfig secret name before creating volumes and mountpaths Signed-off-by: Karthick Prabu <[email protected]> * Added version bump Signed-off-by: Karthick Prabu <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Remove the incubating label and update related infos for Apache Druid (#22788) * Remove the incubating label and update related infos for Apache Druid Signed-off-by: asdf2014 <[email protected]> * Bump to 0.2.2 Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] fix invalid image pull policy for admission webhook patch image (#22773) Signed-off-by: Quentin Bisson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fixed label selector in install note (#22825) Signed-off-by: Micah Hausler <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nextcloud] Add HPA (#22836) * [stable/nextcloud] Add HPA Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Bump chart version Signed-off-by: Tom Koch <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Move "imagePullSecrets" to the right indentation level (#22802) "imagePullSecrets" should be at the same indentation level as "containers", not under it. Signed-off-by: Mathieu Plourde <[email protected]> Co-authored-by: Unknown <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch] Deprecate Elasticsearch chart in favor of official Elastic chart. (#21955) Signed-off-by: Cédric de Saint Martin <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sematext-agent] add /dev mount (#22846) * replicasets roles Signed-off-by: rabbitstack <[email protected]> * bump version Signed-off-by: rabbitstack <[email protected]> * pods/log cluster role, log level to info Signed-off-by: rabbitstack <[email protected]> * pods/log should appear in resources section Signed-off-by: rabbitstack <[email protected]> * add /dev mount to daemonset Signed-off-by: rabbitstack <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Add psp option (#22743) Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * nginx-ingress can now set resources for admission webhook jobs (#22771) * nginx-ingress can now set resources for admission webhook jobs Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress update chart version Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress add with block to hide empty resources Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress update readme with admissionWebhooks resources configuration property Signed-off-by: Aram Ahmed <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update postgres values (#20622) Update requirements.yaml bump hackmd version Signed-off-by: Robert Brennan <[email protected]> ping circleci update requirements Signed-off-by: Robert Brennan <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix issue caused by #22288 (#22839) * [stable/prometheus-operator] namespace override Signed-off-by: yoninl2 <[email protected]> * bump chart version Signed-off-by: Jeremy <[email protected]> * revert changes in hack folder Signed-off-by: Jeremy <[email protected]> * [stable/prometheus-operator]fix template inside range Signed-off-by: jeremy <[email protected]> * [stable/prometheus-operator]bump up version Signed-off-by: jeremy <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] allow configurable nginx conf. Add example (#22639) * allow configurable nginx conf. Add example Signed-off-by: George Kaz <[email protected]> * fix lint complaints Signed-off-by: George Kaz <[email protected]> * add new line as per request Signed-off-by: George Kaz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/dex] Dex v2.24.0 (#22736) This change updates the dex version to v2.24.0 and the chart version as appropriate. There were no features or bugs that I reviewed in Dex that required any additional changes. Signed-off-by: Ken Perkins <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * add an optional sqelf container for ingesting GELF (#22831) bump Seq chart to 2.1. Signed-off-by: Ashley Mannix <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Added 'extraEntries.service' parameter (#22852) Signed-off-by: Maksim Shatravko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sentry] Add Ingress extraPaths to prepend to every host configuration (#22822) Signed-off-by: Evgeniy Moskalenko <[email protected]> Co-authored-by: Evgeniy Moskalenko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/rabbitmq-ha] Upgrade RabbitMQ to 3.8.5 version (#22811) Signed-off-by: tyranron <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Bump Apache Druid to 0.18.1 (#22832) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/rabbitmq-ha] Added support for extraLables in the ingress.yaml template (#22858) * Added support for extraLables in the ingress.yaml template Added support for extraLables in the ingress.yaml template. Include vesion bump Added support for extraLables in the ingress.yaml template Added support for extraLables in the ingress.yaml template. Include vesion bump Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> * Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> * Revert bumped version Signed-off-by: Marco Mojica <[email protected]> * Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> Revert bumped version Signed-off-by: Marco Mojica <[email protected]> Co-authored-by: Marco Mojica <[email protected]> Co-authored-by: Marco Mojica <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/openebs] add deprecation notice to openebs chart (#22860) * add deprecation notice to openebs chart Signed-off-by: kmova <[email protected]> * add deprecation flag to openebs chart Signed-off-by: kmova <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/efs-provisioner] Add extra env variables and envFrom support (#22845) Signed-off-by: Jean-Baptiste Delpech <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] updated all prometheus docker images to latest versions (#22849) * updated all prometheus dockeri mages to latest versions Signed-off-by: André Bauer <[email protected]> * removed blank line Signed-off-by: André Bauer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/oauth2-proxy] Add ingress extraPaths support (#22248) * [stable/oauth2-proxy] Add ingress extraPaths support Signed-off-by: Michael Barrientos <[email protected]> * [oauth2-proxy] Add ci test for ingress extraPaths Signed-off-by: Michael Barrientos <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Relax PSP (#22867) Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Add ServiceAccount option (#22694) (#22697) Signed-off-by: Krzysztof Miemiec <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Deprecating minecraft chart (#22885) Signed-off-by: Geoff Bourne <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fix grafana ingress (#22883) * Fix example for ingresss.hosts Signed-off-by: David Gleich <[email protected]> * Allow empty ingress which is required for the use of GKE Ingress Signed-off-by: David Gleich <[email protected]> * Release a new chart version Signed-off-by: David Gleich <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/ipfs] generated yaml syntax fixes for ipfs ingress (#21882) * fix gateway ingress template: ipfs/templates/ingress-gateway.yaml:24:30: executing "ipfs/templates/ingress-gateway.yaml" at <include "ipfs.fullname" .>: error calling include: template: ipfs/templates/_helpers.tpl:14:27: executing "ipfs.fullname" at <.Chart.Name>: can''t evaluate field Chart in type string' Signed-off-by: Matthew Donoughe <[email protected]> * fix indentation of tls settings Signed-off-by: Matthew Donoughe <[email protected]> * fix underquoting of host name Signed-off-by: Matthew Donoughe <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Adding hostNetwork for operator (#22726) * Adding hostNetwork for prometheus-operator Signed-off-by: LuciferInLove <[email protected]> * Update Chart.yaml Signed-off-by: LuciferInLove <[email protected]> * Update Chart.yaml Signed-off-by: LuciferInLove <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] The kubernetes account may not have access to all the namespaces. (#22862) * The kubernetes account may not have access to all the namespaces. This will allow a user to set the namespaces the account can access. There is a hal command to set this for kubernetes accounts. Adding that capabiity to the helm chart to do the same for the default kubernetes account. Note, Spinnaker does not allow both namespaces and omittedNamespaces to be set. Clouddriver fails if both are set. That is also handled here. Signed-off-by: Nirmalyasen <[email protected]> * The kubernetes account may not have access to all the namespaces. This will allow a user to set the namespaces the account can access. There is a hal command to set this for kubernetes accounts. Adding that capabiity to the helm chart to do the same for the default kubernetes account. Note, Spinnaker does not allow both namespaces and omittedNamespaces to be set. Clouddriver fails if both are set. That is also handled here. Signed-off-by: Nirmalyasen <[email protected]> Co-authored-by: Nirmalyasen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kube-state-metrics] Document `kubeTargetVersionOverride` (#22792) Signed-off-by: Denys Havrysh <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] add pvc, sa, common labels, upgrade app and chart version (#22882) * add pvc, sa, common labels, upgrade app and chart version Signed-off-by: Jonathan Cole <[email protected]> * cleanup trailing spaces Signed-off-by: Jonathan Cole <[email protected]> * missed readme update Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/gocd] Bump up GoCD Version to 20.5.0 (#22908) * Bump up GoCD Version to 20.5.0 Signed-off-by: GoCD Build User <[email protected]> * Updated Changelog. Signed-off-by: GoCD Build User <[email protected]> Co-authored-by: GoCD Build User <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Bump the default version of the docker images (#22910) Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Align CLC configuration with other agent - fix endpoint checks (#22874) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Add the possibility to specify a priorityClassName for the deployment's pods (#22914) Signed-off-by: machine424 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/prometheus-cloudwatch-exporter Add shasum of secrets yaml render to annotations (#22906) * Add shasum of secrets yaml render to annotations Also added missing changelog entry for previous release. Signed-off-by: Todd Lyons <[email protected]> * Correct prom-cloudwatch-exporter issue number Signed-off-by: Todd Lyons <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Use dedicated endpoints for liveness and readiness probes (#21942) Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Allow overriding cluster-agent command (#22913) Signed-off-by: Stanislav Petrashov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Specify these configurations about druid_indexer_logs_xxx (#22912) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/sso-buzzfeed] Add default interval the group cache should refresh at (#22871) * Add default interval the group cache should refresh at Signed-off-by: Alen Komljen <[email protected]> * Move env variable into adminEmail if else block Signed-off-by: Alen Komljen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/fluentd-cloudwatch] update apiVersion to be compatible with k8s >= 1.16 (#21660) * update apiVersion in fluentd-cloudwatch helm to be compatible with k8s >= 1.16 Signed-off-by: Simone Marcato <[email protected]> * fixed copy/paste error Signed-off-by: Simone Marcato <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] fixes broken deployment strategy and annotations (#22921) * fixes broken deployment strategy and annotations Signed-off-by: Jonathan Cole <[email protected]> * chart version bump Signed-off-by: Jonathan Cole <[email protected]> * update README Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Mount kernel headers in system-probe container (#22686) The goal is to implement runtime-compiled eBPF probes in system-probe and collect the data to convert them in DataDog metrics in the agent. Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/graylog] Adding the ability to specify externalTrafficPolicy for LoadBalancer services (#22933) * Adding the ability to specify externalTrafficPolicy, and thus preserve client IP addresses Signed-off-by: Jeff Kolb <[email protected]> * Updated readme Signed-off-by: Jeff Kolb <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Volume mounts and ServiceAccount annotations for Cluster Checks runners (#22659) * [stable/datadog] Add params for mounting volumes to cluster checks runners Signed-off-by: Marica Odagaki <[email protected]> * [stable/datadog] Add param for annotating ServiceAccount for cluster checks runners Signed-off-by: Marica Odagaki <[email protected]> * [stable/datadog] Bump to 2.3.9 Signed-off-by: Marica Odagaki <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Typo and grammar fixes in documentation (#22944) * grammar edits! Signed-off-by: Lénaïc Huard <[email protected]> * Typo in log config Signed-off-by: Lénaïc Huard <[email protected]> Co-authored-by: cswatt <[email protected]> Co-authored-by: John Girvan <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Handle arguments in the cluster-agent command (#22922) Without quotes around the command and its arguments Kubernetes joins all string in a single binary name, so it's not possible to run `datadog-cluster-agent start` in the container Signed-off-by: Stanislav Petrashov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] add enabled flag to all druid roles (#22870) * add enabled flag to all druid roles Signed-off-by: slyao <[email protected]> * add some comments for enabled properties in values.yaml Signed-off-by: slyao <[email protected]> * delete zookeeper.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * delete postgresql.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * delete postgresql.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * update version to 0.2.5 Signed-off-by: slyao <[email protected]> Co-authored-by: slyao <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch-exporter] Add serviceMonitor targetLabels (#22951) Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update service port name to follow istio convention (#22977) Signed-off-by: Thi Nguyen <[email protected]> Co-authored-by: Thi Nguyen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix helm3 ClusterIP updates (#22958) Signed-off-by: Łukasz Sowa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Allow serviceAccount annotations for Halyard (#21060) * [stable/spinnaker] Option to add annotation to the created Halyard serviceaccount. This is required when using 'IAM roles for serviceaccounts' when authenticating in AWS Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Updating README with information about Halyard serviceaccount annotations Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Updating Chart version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Increment Chart version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Setting version level with current Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Incrementing version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Use correct name (serviceAccountAnnotations) in the values.yaml file Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Increment Chart version Signed-off-by: Adam Robinson <[email protected]> Co-authored-by: Adam Robinson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * adding backwards compatible component label key override (#22983) Signed-off-by: Rodrigo Lomonaco <[email protected]> Co-authored-by: rodrigo.lomonaco <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cluster-overprovisioner] add pod security context (#22985) Signed-off-by: Peter Wilson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Add option for priorityClassName (#22990) Signed-off-by: Ciprian Hacman <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-mysql-exporter]: Add service labels and annotations (#22986) Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nextcloud] Add prometheus metrics exporter (#22876) * [stable/nextcloud] Add prometheus metrics exporter Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Add new line at end of values.yaml Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Use specific metrics img-tag, add service for metrics Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Add docu for metrics, add annotations to metrics service Signed-off-by: Tom Koch <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update Seq chart to 2020 container version (#22991) Signed-off-by: Ashley Mannix <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/airflow] Fix typo in airflow/templates/configmap-env.yaml (#22830) Signed-off-by: Ales Nosek <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluentd] Minor typo in README.md (#22898) * Minor typo in the stable/fluentd/README.md Signed-off-by: David Calvert <[email protected]> * Updated Chart version from 2.4.2 to 2.4.3 (minor) Signed-off-by: David Calvert <[email protected]> * Updated stable/fluentd Chart version from 2.4.2 to 2.4.3 (minor) Signed-off-by: David Calvert <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * incubator/kube-downscaler: Manage Resources (#22929) This commit makes a few minor modifications to the way the Helm chart allows users to manage downscaler resources. The core functionality has not changed since `extraArgs` already existed. These changes improve upon how a user interacts with specific commandline arguments to better manage the resources. First `clusterrole.yaml` was updated to take a list of resources from the values file. This will allow the resource configuration in the for the role to match the commandline argument for `include-resources`. Second `include-resources` was added as a commandline argument so that users can have full control over which resources the downscaler does and does not have access to. This could be achieved previously by the use of `extraArgs` but it is now a cleaner interaction for the user since they don't need to worry about list formatting. _Both the `clusterrole.yaml` and `deployment.yaml` get the resources to manage from `downscaleResources` in `values.yaml`._ Third `exclude-namespaces` and `exclude-deployments` were added as commandline arguments to help improve users ability to exclude specific namespaces and deployments from the downscaler. This was able to be done previously with the use of `extraArgs` but much like the other changes this makes the user interaction more clean and manageable. Both of these arguments derive their values from `excludedNamespaces` and `excludedDeployments` in `values.yaml` respectively. Signed-off-by: Christopher Pisano <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Bump version to 0.9.2 (#23012) * Bump cerebro version to 0.9.2 Signed-off-by: Nathan Webster <[email protected]> * bump chart version Signed-off-by: David Karlsen <[email protected]> Co-authored-by: David Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Using favicon instead of druid_nav (#22984) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix: new line is removed from useSocketVolume section (#23020) Template produces invalid yaml when useSocketVolume is enabled. Signed-off-by: Roarke Gaskill <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * enable secret for ldap even when admin password is passed via file. bump version (#23006) Signed-off-by: Tiago Posse <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Ensure all rules can be toggled (#22879) * [stable/prometheus-operator] Ensure all rules can be toggled Signed-off-by: Sean Clemmer <[email protected]> * [stable/prometheus-operator] Bump chart verison to 8.15.7 Signed-off-by: Sean Clemmer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * incubator/kube-downscaler - fix a regression about namespaces (#23030) * Fix a kube-downscaler regression about namespaces The present fixes a regression where invalid option value 'namespaces' is passed to the tool and overly generous permissions are granted over namespaces. Signed-off-by: Danil Mironov <[email protected]> * Delete excessive quotes in arguments Signed-off-by: Danil Mironov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-cloudwatch-exporter] additional docu on service account usage (#23028) * additional info on service account config so one can read mounted secret this worked OK: ``` securityContext: runAsUser: 65534 # run as nobody user instead of root fsGroup: 65534 # to read mounted secret with the same id ``` Signed-off-by: Peter Triesz <[email protected]> * updating chart version after readme modification Signed-off-by: Peter Triesz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/karma] Upgrade karma to v0.68 (#22950) Signed-off-by: Łukasz Mierzwa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fix sed replacing special sources (#22960) Signed-off-by: Andrey Voronkov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/coredns] Version bump to 1.7.0 (#23013) * [stable/coredns] Version bump to 1.7.0 https://coredns.io/2020/06/15/coredns-1.7.0-release/ Signed-off-by: Manuel Rüger <[email protected]> * [stable/coredns] Drop annotations from service As it was changed in cea2d6f158a640e6d49e291008ed61c0ec827b17 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Mount system-probe.yaml in the process-agent container when enabled (#23035) * Mount system-probe.yaml in the process-agent container when enabled https://github.com/helm/charts/pull/22686/files changed the location of the system-probe socket away from the default. Since the process-agent was relying on the socket being at the default location by dint of not having the system-probe.yaml file, this commit broke the process-agent -> system-probe communication. Signed-off-by: Lee Avital <[email protected]> * rev version Signed-off-by: Lee Avital <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] Fix rbac for get ingress info (#23015) * Fix rbac for get ingress info Signed-off-by: Eugene Medvedev <[email protected]> * Update chart version Signed-off-by: Eugene Medvedev <[email protected]> * support newer and older clusters Signed-off-by: Eugene Medvedev <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] fix blueocean dependency issue (#23045) Signed-off-by: Mike Scholze <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [Stable/Efs-Provisioner] add namespace to deployment/sa (#23056) * feat: [Stable/Efs-Provisioner] add namespace to deployment/sa Add the namespace information to deployment and serviaccount. this Prevent helm3 to push the object to the current ns and not the one Refered by the option "--namespace" Signed-off-by: David Sabatie <[email protected]> * bump chart version Signed-off-by: David Sabatie <[email protected]> * fix bad char in serviceaccount file Signed-off-by: David Sabatie <[email protected]> * fix bad char in deployment Signed-off-by: David Sabatie <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] modify the default value by nano-quickstart to decrease memory cost (#23044) * change the default setting to nano quickstart Signed-off-by: AWaterColorPen <[email protected]> * change the comment to adapt nano quickstart Signed-off-by: AWaterColorPen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Update grafana Chart (#22891) * Update grafana Chart Signed-off-by: David Gleich <[email protected]> * Update Chart version Signed-off-by: David Gleich <[email protected]> * Update requirements.lock Signed-off-by: David Gleich <[email protected]> * Using helm2 for updateing the requirements Signed-off-by: David Gleich <[email protected]> * Needs a versionbump Signed-off-by: David Gleich <[email protected]> * Bump Chart version Signed-off-by: David Gleich <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * deprecate the kured-chart (#23055) Signed-off-by: Christian Kotzbauer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/grafana Grafana statefulset pod labels (#22590) * StatefulSet do not include podLabels. Signed-off-by: Ryan Bonham <[email protected]> * Bump Chart Version Signed-off-by: Ryan Bonham <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix empty annotations (#22580) Currently setting the serviceAccountAnnotations without the other rbac stuff fails with `error validating data: [apiVersion not set, kind not set]`, this is because the only line being rendered is the `annotations: {{ toYaml...` line. This change would prevent failure, but will swallow a potential misconfiguration (would a user want to have serviceAccountAnnotations with the service account not being created? - maybe but I'm not too sure about this). As an alternative, an explicit fail message could be set if serviceAccountAnnotations are set without the service account being created. Signed-off-by: Jonathan Cowling <[email protected]> Version bump Signed-off-by: Jonathan Cowling <[email protected]> Signed-off-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/traefik] Update traefik version from 1.7.23 to 1.7.24 (#22646) * Update traefik version from 1.7.23 to 1.7.24 Signed-off-by: Sebastian Brandt <[email protected]> * chart and app version raised for traefik Signed-off-by: Sebastian Brandt <[email protected]> * README.md updated for traefik Signed-off-by: Sebastian Brandt <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Fix a bunch of nil defaults (#22999) Signed-off-by: George Christou <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Replace configmap-reload image (#22988) Upstream switched to this image in https://github.com/coreos/prometheus-operator/commit/3c1456eac35d2ace824d478d6bd9dad6939f6db3#diff-e237ffe304b9b2407ed7d9424a2770a9 This also enables support for multi-arch for the configmap-reload image Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Merge several pending PRs (#23066) * Remove duplicate imagePullSecrets Signed-off-by: Brian Choy <[email protected]> * [stable/datadog] Fix a bunch of nil defaults Signed-off-by: George Christou <[email protected]> * [stable/datadog] Adding explanation for metricsProvider.enabled Signed-off-by: Lénaïc Huard <[email protected]> * [stable/datadog] Fix DataDog location to useConfigMap in docs Signed-off-by: Lénaïc Huard <[email protected]> Co-authored-by: Brian Choy <[email protected]> Co-authored-by: George Christou <[email protected]> Co-authored-by: Sagar2366 <[email protected]> Co-authored-by: Gregory Jones <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix typo in document of stable jenkins (#22847) Signed-off-by: tottoto <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] kubelet servicemonitor skip tls verify (#22927) * chomp newline Signed-off-by: Jordan Sokolic <[email protected]> * skip TLS verify for kubelet metrics endpoint Signed-off-by: Jordan Sokolic <[email protected]> * bump version Signed-off-by: Jordan Sokolic <[email protected]> * bump dependency versions Signed-off-by: Jordan Sokolic <[email protected]> * Revert "bump dependency versions" This reverts commit 9f5ca83b359b16d871d27424f7ef7632a8a52a85. Signed-off-by: Jordan Sokolic <[email protected]> * add http counterpart for kubelet servicemonitor Signed-off-by: Jordan Sokolic <[email protected]> * bump Signed-off-by: Jordan Sokolic <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Added cacert option (#22893) Signed-off-by: Anders Nyvang <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/docker-registry] LoadBalancer settings (#21506) * LoadBalancer settings Signed-off-by: wilinger <[email protected]> * bump version Signed-off-by: David J. M. Karlsen <[email protected]> Co-authored-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mcrouter] create a template for api version (#22638) Signed-off-by: lwsanty <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] envSecret, awsConfigSecret, kubeConfigSecret, extraConfigSecret, nginx req size (#23004) * chart v2, envSecret, kubeConfigSecret, extraConfigSecret, req size Signed-off-by: Jonathan Cole <[email protected]> * drop back to Chart API V1 Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] trigger re-deployment if envRenderSecret has been changed. (#23052) Signed-off-by: Jan-Otto Kröpke <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Update hyperkube image (#23073) Update to a support version of kubernetes: 1.16.12 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] increase retries for sidecar reload (#22787) * [stable/jenkins] increase retries for sidecar reload Signed-off-by: Torsten Walter <[email protected]> * add missing changelog Signed-off-by: Torsten Walter <[email protected]> * Fix README entry Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sealed-secrets] update version to 0.12.4 (#23076) Signed-off-by: Christian Groschupp <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Add PSP and SCC (#22529) * [stable/datadog] Add PSP and SCC Signed-off-by: cedric lamoriniere <[email protected]> * update after review Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] add orchestrator-explorer option (#23018) * add setting to enable the orchestrator explorer Signed-off-by: Haissam Kaj <[email protected]> * switch default to false Signed-off-by: Haissam Kaj <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Add networkPolicy podLabels (#22706) * [stable/jenkins] Add networkPolicy podLabels Signed-off-by: Olivier Vernin <[email protected]> * Update changelog Signed-off-by: Olivier Vernin <[email protected]> * Update version to 2.3.0 Signed-off-by: Olivier Vernin <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Add the ability to deploy the auth and proxy components separately, and do not mandate supplying a Google service account. (#23060) Signed-off-by: Damian Peckett <[email protected]> Co-authored-by: Damian Peckett <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Align ENV var handling (avoid ranging through them to allow any K8S valid syntax) (#23080) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] fix PodSecurityContext seLinux (#23088) Fixes #23084 Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Make unguiculus/mongodb-install multiarch and include arm platforms (#22322) (#22323) - also bumped mongodb-install image version number - bumped chart version number Signed-off-by: Kris Gandhi <[email protected]> Co-authored-by: Kris Gandhi <[email protected]> Co-authored-by: Reinhard Nägele <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/selenium] Add ability to pass additional pod labels for all pods (#22931) * Add ability to pass additional pod labels for all pods My use case for these is to add a pod label to be used with and AWS EKS Fargate profile. By default no additional labels are added. Signed-off-by: Daniel Schaaff <[email protected]> * Bump the chart version Signed-off-by: Daniel Schaaff <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-pushgateway] Fix networkPolicy podSelector and ingress rule (#23053) * Fix `podSelector` by adding `release` label * Fix ingress rule by ensuring port is restricted Before it was: * Source: any, Port: `targetPort` * Source: `customSelectors`, Port: any Now it is: * Source: `customSelectors`, Port: `targetPort` and `allowAll` does not add an any/any rule anymore. Signed-off-by: Maxime Brunet <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mysql] Add support for extra environment variables (#22945) (#22947) Signed-off-by: Casey Buto <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/aws-alb-ingress-controller] Fix a typo in the aws-alb-ingress-controller chart README (#22164) * [incubator/aws-alb-ingress-controller] Fix a typo in the aws-alb-ingress-controller chart README Signed-off-by: enokawa <[email protected]> * [incubator/aws-alb-ingress-controller] Bump the chart version Signed-off-by: enokawa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Correct indentation of 'volumes' property (#22494) Signed-off-by: Marcus van Dam <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/cluster-autoscaler (#23092) * Set default value for .rbac.create to true (so the serviceaccount and associated pods can be created in the deployment). Signed-off-by: Robert J <[email protected]> * Updated README.md Signed-off-by: Robert J <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mysql] MySQL chart version bump to 1.6.6 (#23075) * Update busybox and bats testFramework to newer image tag Signed-off-by: Tyler Nguyen <[email protected]> * Enable securityContext support and switch to user the other testFramework repository Signed-off-by: Tyler Nguyen <[email protected]> * Fix wrong bats dir Signed-off-by: Tyler Nguyen <[email protected]> Co-authored-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Warning fixed, made client service optional (#22209, #22759). (#22971) Made the headless client service optional, fixed warning when used as a subchart. Signed-off-by: Berk Soysal <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-mongodb-exporter] Add serviceMonitor targetLabels and service labels (#22952) * [stable/prometheus-mongodb-exporter] Add serviceMonitor targetLabels Signed-off-by: Calvin Bui <[email protected]> * [stable/prometheus-mongodb-exporter] Add labels to service Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/airflow] Adding basic auth values for flower (#23036) Signed-off-by: Alex Begg <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Sync dashboards and rules for #22081 (#23024) Signed-off-by: Dan Sexton <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] add support for running without cluster-admin privileges (#23049) * add support for running on kubernetes setups (such as openshift) where you only have access to your own namespaces Signed-off-by: Klavs Klavsen <[email protected]> * bump chart versions Signed-off-by: Klavs Klavsen <[email protected]> * reverted kube-state-metrics so this branch is only about prometheus chart Signed-off-by: Klavs Klavsen <[email protected]> * signing Signed-off-by: Klavs Klavsen <[email protected]> * lint fix Signed-off-by: Klavs Klavsen <[email protected]> * lint fix Signed-off-by: Klavs Klavsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update the grafana to 7.0.5 (#23111) Signed-off-by: gowrisankar <[email protected]> Co-authored-by: gowrisankar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] remove namespace field from non-namespaced resources (#22949) * [stable/prometheus-operator] remove namespace field from non-namespaced resources Signed-off-by: Riccardo M. Cefala <[email protected]> * [stable/prometheus-operator] bump chart version Signed-off-by: Riccardo M. Cefala <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Treat alertmanager additionalPeers as YAML (#23112) Avoids string templating errors, for example when passing an array of string literals containing colons. Signed-off-by: Craig Furman <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cockroachdb] deprecating this cockroachdb chart repository (#23000) * [stable/cockroachdb] deprecating this cockroachdb chart repository Given the deprecation of `stable`, future CockroachDB Helm charts are now located at: code repository: https://github.com/cockroachdb/helm-charts charts repository: https://charts.cockroachdb.com Update this repository to point users to the new locations. Signed-off-by: James H. Linder <[email protected]> * Complete the deprecation steps as described in PROCESSES.md Signed-off-by: James H. Linder <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update to linux agent ciprod06302020 and add the tolerations for windows (#23099) Signed-off-by: Ganga Mahesh Siddem <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/sparkoperator] Add scheduling.volcano.sh to apiGroup in spark-operator-rbac.yaml (#23125) * added scheduling.volcano.sh to rbac Signed-off-by: Goutham Reddy Kotapalle <[email protected]> * version bump to 0.7.2 Signed-off-by: Goutham Reddy Kotapalle <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] Improve Prometheus Server Probes. Fix MD Syntax Issues in README. (#23116) * fix md style issues sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * add periodseconds to liveness and readiness probes. on par probes for deployment and statefulset. sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * include liveness and readiness probes documentation sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * bump chart to v11.7.0 sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nginx-ingress] add controller.podAnnotationConfigChecksum (#22998) Signed-off-by: raittes <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/aws-alb-ingress-controller] Bump chart version bump to 1.0.2 (#23089) * Support chart image version v1.1.8 Signed-off-by: Tyler Nguyen <[email protected]> * Update README Signed-off-by: Tyler Nguyen <[email protected]> * Fix wrong region mentioned in README Signed-off-by: Tyler Nguyen <[email protected]> * Merge branch 'master' into aws-alb-ingress-controller-1.0.2 Signed-off-by: Tyler Nguyen <[email protected]> * Bump Chart version Signed-off-by: Tyler Nguyen <[email protected]> * Fix conflicts in README Signed-off-by: Tyler Nguyen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * add support for init containers and custom volumes (for plugins) (#22653) Signed-off-by: George Kaz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] modify the default value(the previously pr is closed, I can't reopen it. #23072) (#23115) * change druid_coordinator_balancer_strategy Signed-off-by: camelusluo <[email protected]> * Update Chart.yaml Signed-off-by: camelusluo <[email protected]> * Update values.yaml Signed-off-by: camelusluo <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/dex] Add imagePullSecrets (#22956) * [stable/dex] Add imagePullSecrets Signed-off-by: Konstantinos Sideris <[email protected]> * Add docs and default value Signed-off-by: Konstantinos Sideris <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] possibility to add annotations to default dashboards (#22900) * adapt sync script to add annotations to dashboards Signed-off-by: Marius Svechla <[email protected]> * run sync_grafana_dashboards, add new value to values.yaml Signed-off-by: Marius Svechla <[email protected]> * update readme for new grafana.sidecar.dashboards.annotations variable Signed-off-by: Marius Svechla <[email protected]> * rebase Signed-off-by: Marius Svechla <[email protected]> * fix trailing spaces Signed-off-by: Marius Svechla <[email protected]> * fix namespace template Signed-off-by: Marius Svechla <[email protected]> * re-run sync_grafana_dashboards Signed-off-by: Marius Svechla <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Added option to disable kube-apiserver-availability rules (#23136) Signed-off-by: Dan Sexton <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] add systemProbe.collectDNSStats (#23086) * [stable/datadog] add collectDNSStats option, remove selinux defaults Adds collectDNSStats which enabled the system_probe.collect_dns_stats flag. The flag is only rendered into system-probe.yaml if set to true. This will allow the agent default to changed to true down the line without requiring a chart bump. Signed-off-by: Lee Avital <[email protected]> * Update stable/datadog/templates/system-probe-configmap.yaml Co-authored-by: Cedric Lamoriniere <[email protected]> Signed-off-by: Lee Avital <[email protected]> Co-authored-by: Cedric Lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/atlantis] Add envFrom secrets option (#23122) * Add envFrom to atlantis Signed-off-by: Armaan Tobaccowalla <[email protected]> * Fix version Signed-off-by: Armaan Tobaccowalla <[email protected]> * Add warning Signed-off-by: Armaan Tobaccowalla <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluent-bit] Added `input.tail.exclude_path` parameter (#22392) Signed-off-by: Ivan Kurnosov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix daemonset generation if `datadog.securityContext==nil` (#23146) If the `datadog.securityContext` value is set to `nil` instead of `{}` when a user want to remove the default `securityContext`, helm is not able to generate the Daemonset manifest. To support this configuration we have change how we test the value. With the new `{{ if ...}}` check we don't check the second comparison if the first already return false. Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Small chart tweaks for cluster agent (#23079) * [stable/datadog] Default external metrics provider port to 8443 In order to avoid issues with non-root users inside a container trying to listen on port 443, from now on we're going to set the default port for the external metrics provider in the DCA container to 8443. Signed-off-by: Julio Greff <[email protected]> * [stable/datadog] Document `clusterAgent.env` Signed-off-by: Julio Greff <[email protected]> * [stable/datadog] Bump version to 2.3.29 Signed-off-by: Julio Greff <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/ignite] Ignite features (#22023) * feat() Added envVars envFrom extraInitContainers extraContainers extraVolumes extraVolumeMounts features Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() linting Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() imagePullPolicy is not working Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() statefulset env section is wrong Signed-off-by: Mehmet Onur Yalazi <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Prevent error on upgrade (#22394) Work around: https://github.com/helm/helm/issues/8101 Signed-off-by: Jan Kantert <[email protected]> Co-authored-by: Jan Kantert <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/hlf-peer] Configure chaincode builder and chaincode runtime image (#23153) Signed-off-by: AlexandrePicosson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Mount always ref/secrets. (#23137) The `ref/secrets` is mounted only when `master.enableXmlConfig == true`. This is bug. The `ref/secrets` must be always mounted. Just because `master.secretsFilesSecret` and `master.enableXmlConfig` are unrelated, as well as: ./templates/config.yaml has unconditional: apply_config.sh: |- echo "applying Jenkins configuration" mkdir -p {{ .Values.master.jenkinsRef }}/secrets/; This mkdir will fail in UID != 0. We need to mount always secrets. Signed-off-by: Andrei Stepanov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Fix overwritePluginsFromImage and syntax error (#23175) Setting overwritePluginsFromImage: Fixes #23003 Fixes #22633 Correcting indentation Fixes #23114 Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Fix master.slaveJenkinsUrl (#23176) Fixes #22708 Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] liveness/startupProbe tuning (#23046) * MongoDB liveness/startupProbe tuning Signed-off-by: Bernard Grymonpon <[email protected]> * Changes after review - 1.18 as target k8s api version - aligned the values and readme - changed probe for the metrics server Signed-off-by: Bernard Grymonpon <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Update the app version to 7.0.5 (#23130) * Update the app version to 7.0.5 Signed-off-by: gowrisankar <[email protected]> * Update the app version to 7.0.5 Signed-off-by: gowrisankar <[email protected]> Co-authored-by: gowrisankar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/atlantis] Use newer ingress API (#23162) Kubernetes 1.16 deprecates various APIs and therefore manifests require updates. This change is backwards compatible and can still be used with older Kubernetes versions. Signed-off-by: Enrico Stahn <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Change to use specified port instead of default (#23154) * Change to use specified port instead of default Signed-off-by: Timo Sand <[email protected]> * Bump patch version Signed-off-by: Timo Sand <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/oauth2-proxy] Use newer ingress API to be compatible with Kubernetes 1.16 (#23161) * [stable/oauth2-proxy] Use newer ingress API Kubernetes 1.16 deprecates various APIs and therefore manifests require updates. This change is backwards compatible and can still be used with older Kubernetes versions. Signed-off-by: Enrico Stahn <[email protected]> * [stable/oauth2-proxy] Bump chart version to 3.2.1 Signed-off-by: Enrico Stahn <[email protected]> * [stable/oauth2-proxy] use .Capabilities.APIVersions.Has Signed-off-by: Enrico Stahn <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/buzzfeed-sso] Allow Independent auth Ingress (#23165) * [buzzfeed/sso] Allow independent auth ingresses Signed-off-by: Damian Peckett <[email protected]> * [buzzfeed/sso] remove trailing spaces Signed-off-by: Damian Peckett <[email protected]> Co-authored-by: Damian Peckett <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] update agent image (#23191) Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] fix daemonset templates for go 1.14 (#23166) * fix datadog daemonset.yaml to be compatible with go 1.14 Signed-off-by: Shun Yamamoto <[email protected]> * bump version up Signed-off-by: Shun Yamamoto <[email protected]> * Update stable/datadog/CHANGELOG.md Co-authored-by: Harrison Heck <[email protected]> Signed-off-by: Shun Yamamoto <[email protected]> * bump version up Signed-off-by: Shun Yamamoto <[email protected]> Co-authored-by: Shun Yamamoto <[email protected]> Co-authored-by: Harrison Heck <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-node-exporter] Version bump to 1.0.1 (#23151) https://github.com/prometheus/node_exporter/releases/tag/v1.0.1 Try fixing CI as suggested by @vsliouniaev Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Version bump, deprecation of additionalScrapeConfigsExternal (#23147) * Version bump, deprecation of additionalScrapeConfigsExternal Signed-off-by: Alexander Cristian <[email protected]> * Removed prometheus.prometheusSpec.additionalScrapeConfigsExternal from README Signed-off-by: Alexander Cristian <[email protected]> * Modified values for naming convention Signed-off-by: Alexander Cristian <[email protected]> * Added newline for test to pass Signed-off-by: Alexander Cristian <[email protected]> * Correct node exporter for tests to pass Signed-off-by: Alexander Cristian <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/opa] Add extra{containers,ports,volumes} to OPA deployment (#23190) * Add extra-{containers,ports,volumes} to OPA stable chart Signed-off-by: Ángel Barrera Sánchez <[email protected]> * Bump OPA chart version Signed-off-by: Ángel Barrera Sánchez <[email protected]> * Update stable/opa chart documentation Signed-off-by: Ángel Barrera Sánchez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Version bump alertmanager and prometheus (#23150) * [stable/prometheus-operator] Version bump prometheus to 2.18.2 https://github.com/prometheus/prometheus/releases/tag/v2.18.2 Signed-off-by: Manuel Rüger <[email protected]> * [stable/prometheus-operator] Version bump alertmanager to 0.21.0 https://github.com/prometheus/alertmanager/releases/v0.21.0 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Always add os in nodeSelector based on `targetSystem` (#23199) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kibana] possility customize url for dashboard import script (#23192) * [stable/kibana] possility customize url for dashboard import script Signed-off-by: mikhail_znak <[email protected]> * [stable/kibana] possility customize url for dashboard import script Signed-off-by: mikhail_znak <[email protected]> Co-authored-by: mikhail_znak <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluentd] Add podLabels (#23169) * [stable/fluentd] Add support for podLabels Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Bump chart version Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Update README Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Rename labels property Signed-off-by: Pavel Dmytrenko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/instana-agent] Chart version 1.0.29 (#23211) Signed-off-by: Instana CD <[email protected]> Co-authored-by: Instana CD <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Add option to specify storageclass for halyard persistence data volume (#22828) * Added feature to specify storage class for halyard persistence volume Signed-off-by: Karthick Prabu <[email protected]> * Fix requirements.lock Signed-off-by: Karthick Prabu <[email protected]> * Fixed linting issues Signed-off-by: Karthick Prabu <[email protected]> * Bumped version Signed-off-by: Karthick Prabu <[email protected]> * Update Chart.yaml Signed-off-by: Paul Czarkowski <[email protected]> Co-authored-by: Paul Czarkowski <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/percona-xtradb-cluster] Fixes #23207 (#23208) * [stable/percona-xtradb-cluster] Fixes #23207 Signed-off-by: Rafael Rivero <[email protected]> * [stable/percona-xtradb-cluster] fix linting issues Signed-off-by: Rafael Rivero <[email protected]> Co-authored-by: Rafael Rivero <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update incubator/cockroach to a placeholder deprecated chart. See README and NOTES for explanation (#23129) Signed-off-by: Scott Rigby <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/azuremonitor-containers] updates for hotfix release ciprod07152020 (#23212) * updates for hotfix release ciprod07152020 Signed-off-by: Ganga Mahesh Siddem <[email protected]> * bump chart version Signed-off-by: Ganga Mahesh Siddem <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Allow specifying checksum for docker images (#23195) Signed-off-by: Gabriel Martinez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/hlf-peer] Add docker config.json secret for private registry (#23206) Signed-off-by: Kelvin Moutet <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Enable ability to set annotations on service account (#23219) Signed-off-by: Amir Alavi <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/metabase] Allow MB_SITE_URL to be set from values.yaml (#23221) * [stable/metabase] Allow MB_SITE_URL to be set from values.yaml Signed-off-by: Oliver Evans <[email protected]> * Document siteUrl parameter Signed-off-by: Oliver Evans <[email protected]> * bump chart version Signed-off-by: Oliver Evans <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch-exporter]: customize log flags (#23216) * [stable/elasticsearch-exporter]: customize log flags Signed-off-by: Carlos Alexandro Becker <[email protected]> * fix: small fixes Signed-off-by: Carlos Alexandro Becker <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Add docker checksum option (#23194) * [stable/prometheus-operator] Allow specifying checksum for docker images Signed-off-by: Gabriel Martinez <[email protected]> * [stable/prometheus-operator] Don't specify default digest for docker images Signed-off-by: Gabriel Martinez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/…
* [stable/prometheus-operator] Scraping kubelet for /metrics/resource/v1alpha1 (#22586) [stable/prometheus-operator] Fixing the template Signed-off-by: Mohsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nginx-ingress] Add support for an internal load balancer along with an external one (#22758) * [stable/nginx-ingress] Add support for an internal load balancer along with an external one Signed-off-by: Luis Garnica Guilarte <[email protected]> * [stable/nginx-ingress] Add support for an internal load balancer along with an external one Signed-off-by: Luis Garnica Guilarte <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/minio] Support imagePullSecrets (#22812) Signed-off-by: Deepa Vijaykumar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kube-state-metrics] Version bump to 1.9.7 (#22649) https://github.com/kubernetes/kube-state-metrics/releases/v1.9.7 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Fix kubeconfig s3 bucket configuration in spinnaker chart (#22767) * Removed default for kubeconfig secret from values.yaml and updated helm templates to check for kubeconfig secret name before creating volumes and mountpaths Signed-off-by: Karthick Prabu <[email protected]> * Added version bump Signed-off-by: Karthick Prabu <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Remove the incubating label and update related infos for Apache Druid (#22788) * Remove the incubating label and update related infos for Apache Druid Signed-off-by: asdf2014 <[email protected]> * Bump to 0.2.2 Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] fix invalid image pull policy for admission webhook patch image (#22773) Signed-off-by: Quentin Bisson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fixed label selector in install note (#22825) Signed-off-by: Micah Hausler <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nextcloud] Add HPA (#22836) * [stable/nextcloud] Add HPA Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Bump chart version Signed-off-by: Tom Koch <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Move "imagePullSecrets" to the right indentation level (#22802) "imagePullSecrets" should be at the same indentation level as "containers", not under it. Signed-off-by: Mathieu Plourde <[email protected]> Co-authored-by: Unknown <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch] Deprecate Elasticsearch chart in favor of official Elastic chart. (#21955) Signed-off-by: Cédric de Saint Martin <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sematext-agent] add /dev mount (#22846) * replicasets roles Signed-off-by: rabbitstack <[email protected]> * bump version Signed-off-by: rabbitstack <[email protected]> * pods/log cluster role, log level to info Signed-off-by: rabbitstack <[email protected]> * pods/log should appear in resources section Signed-off-by: rabbitstack <[email protected]> * add /dev mount to daemonset Signed-off-by: rabbitstack <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Add psp option (#22743) Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * nginx-ingress can now set resources for admission webhook jobs (#22771) * nginx-ingress can now set resources for admission webhook jobs Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress update chart version Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress add with block to hide empty resources Signed-off-by: Aram Ahmed <[email protected]> * nginx-ingress update readme with admissionWebhooks resources configuration property Signed-off-by: Aram Ahmed <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update postgres values (#20622) Update requirements.yaml bump hackmd version Signed-off-by: Robert Brennan <[email protected]> ping circleci update requirements Signed-off-by: Robert Brennan <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix issue caused by #22288 (#22839) * [stable/prometheus-operator] namespace override Signed-off-by: yoninl2 <[email protected]> * bump chart version Signed-off-by: Jeremy <[email protected]> * revert changes in hack folder Signed-off-by: Jeremy <[email protected]> * [stable/prometheus-operator]fix template inside range Signed-off-by: jeremy <[email protected]> * [stable/prometheus-operator]bump up version Signed-off-by: jeremy <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] allow configurable nginx conf. Add example (#22639) * allow configurable nginx conf. Add example Signed-off-by: George Kaz <[email protected]> * fix lint complaints Signed-off-by: George Kaz <[email protected]> * add new line as per request Signed-off-by: George Kaz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/dex] Dex v2.24.0 (#22736) This change updates the dex version to v2.24.0 and the chart version as appropriate. There were no features or bugs that I reviewed in Dex that required any additional changes. Signed-off-by: Ken Perkins <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * add an optional sqelf container for ingesting GELF (#22831) bump Seq chart to 2.1. Signed-off-by: Ashley Mannix <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Added 'extraEntries.service' parameter (#22852) Signed-off-by: Maksim Shatravko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sentry] Add Ingress extraPaths to prepend to every host configuration (#22822) Signed-off-by: Evgeniy Moskalenko <[email protected]> Co-authored-by: Evgeniy Moskalenko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/rabbitmq-ha] Upgrade RabbitMQ to 3.8.5 version (#22811) Signed-off-by: tyranron <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Bump Apache Druid to 0.18.1 (#22832) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/rabbitmq-ha] Added support for extraLables in the ingress.yaml template (#22858) * Added support for extraLables in the ingress.yaml template Added support for extraLables in the ingress.yaml template. Include vesion bump Added support for extraLables in the ingress.yaml template Added support for extraLables in the ingress.yaml template. Include vesion bump Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> * Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> * Revert bumped version Signed-off-by: Marco Mojica <[email protected]> * Added support for extraLabels and bumped the version Signed-off-by: Marco Mojica <[email protected]> Revert bumped version Signed-off-by: Marco Mojica <[email protected]> Co-authored-by: Marco Mojica <[email protected]> Co-authored-by: Marco Mojica <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/openebs] add deprecation notice to openebs chart (#22860) * add deprecation notice to openebs chart Signed-off-by: kmova <[email protected]> * add deprecation flag to openebs chart Signed-off-by: kmova <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/efs-provisioner] Add extra env variables and envFrom support (#22845) Signed-off-by: Jean-Baptiste Delpech <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] updated all prometheus docker images to latest versions (#22849) * updated all prometheus dockeri mages to latest versions Signed-off-by: André Bauer <[email protected]> * removed blank line Signed-off-by: André Bauer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/oauth2-proxy] Add ingress extraPaths support (#22248) * [stable/oauth2-proxy] Add ingress extraPaths support Signed-off-by: Michael Barrientos <[email protected]> * [oauth2-proxy] Add ci test for ingress extraPaths Signed-off-by: Michael Barrientos <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Relax PSP (#22867) Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Add ServiceAccount option (#22694) (#22697) Signed-off-by: Krzysztof Miemiec <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Deprecating minecraft chart (#22885) Signed-off-by: Geoff Bourne <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fix grafana ingress (#22883) * Fix example for ingresss.hosts Signed-off-by: David Gleich <[email protected]> * Allow empty ingress which is required for the use of GKE Ingress Signed-off-by: David Gleich <[email protected]> * Release a new chart version Signed-off-by: David Gleich <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/ipfs] generated yaml syntax fixes for ipfs ingress (#21882) * fix gateway ingress template: ipfs/templates/ingress-gateway.yaml:24:30: executing "ipfs/templates/ingress-gateway.yaml" at <include "ipfs.fullname" .>: error calling include: template: ipfs/templates/_helpers.tpl:14:27: executing "ipfs.fullname" at <.Chart.Name>: can''t evaluate field Chart in type string' Signed-off-by: Matthew Donoughe <[email protected]> * fix indentation of tls settings Signed-off-by: Matthew Donoughe <[email protected]> * fix underquoting of host name Signed-off-by: Matthew Donoughe <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Adding hostNetwork for operator (#22726) * Adding hostNetwork for prometheus-operator Signed-off-by: LuciferInLove <[email protected]> * Update Chart.yaml Signed-off-by: LuciferInLove <[email protected]> * Update Chart.yaml Signed-off-by: LuciferInLove <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] The kubernetes account may not have access to all the namespaces. (#22862) * The kubernetes account may not have access to all the namespaces. This will allow a user to set the namespaces the account can access. There is a hal command to set this for kubernetes accounts. Adding that capabiity to the helm chart to do the same for the default kubernetes account. Note, Spinnaker does not allow both namespaces and omittedNamespaces to be set. Clouddriver fails if both are set. That is also handled here. Signed-off-by: Nirmalyasen <[email protected]> * The kubernetes account may not have access to all the namespaces. This will allow a user to set the namespaces the account can access. There is a hal command to set this for kubernetes accounts. Adding that capabiity to the helm chart to do the same for the default kubernetes account. Note, Spinnaker does not allow both namespaces and omittedNamespaces to be set. Clouddriver fails if both are set. That is also handled here. Signed-off-by: Nirmalyasen <[email protected]> Co-authored-by: Nirmalyasen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kube-state-metrics] Document `kubeTargetVersionOverride` (#22792) Signed-off-by: Denys Havrysh <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] add pvc, sa, common labels, upgrade app and chart version (#22882) * add pvc, sa, common labels, upgrade app and chart version Signed-off-by: Jonathan Cole <[email protected]> * cleanup trailing spaces Signed-off-by: Jonathan Cole <[email protected]> * missed readme update Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/gocd] Bump up GoCD Version to 20.5.0 (#22908) * Bump up GoCD Version to 20.5.0 Signed-off-by: GoCD Build User <[email protected]> * Updated Changelog. Signed-off-by: GoCD Build User <[email protected]> Co-authored-by: GoCD Build User <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Bump the default version of the docker images (#22910) Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Align CLC configuration with other agent - fix endpoint checks (#22874) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Add the possibility to specify a priorityClassName for the deployment's pods (#22914) Signed-off-by: machine424 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/prometheus-cloudwatch-exporter Add shasum of secrets yaml render to annotations (#22906) * Add shasum of secrets yaml render to annotations Also added missing changelog entry for previous release. Signed-off-by: Todd Lyons <[email protected]> * Correct prom-cloudwatch-exporter issue number Signed-off-by: Todd Lyons <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Use dedicated endpoints for liveness and readiness probes (#21942) Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Allow overriding cluster-agent command (#22913) Signed-off-by: Stanislav Petrashov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Specify these configurations about druid_indexer_logs_xxx (#22912) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/sso-buzzfeed] Add default interval the group cache should refresh at (#22871) * Add default interval the group cache should refresh at Signed-off-by: Alen Komljen <[email protected]> * Move env variable into adminEmail if else block Signed-off-by: Alen Komljen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/fluentd-cloudwatch] update apiVersion to be compatible with k8s >= 1.16 (#21660) * update apiVersion in fluentd-cloudwatch helm to be compatible with k8s >= 1.16 Signed-off-by: Simone Marcato <[email protected]> * fixed copy/paste error Signed-off-by: Simone Marcato <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] fixes broken deployment strategy and annotations (#22921) * fixes broken deployment strategy and annotations Signed-off-by: Jonathan Cole <[email protected]> * chart version bump Signed-off-by: Jonathan Cole <[email protected]> * update README Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Mount kernel headers in system-probe container (#22686) The goal is to implement runtime-compiled eBPF probes in system-probe and collect the data to convert them in DataDog metrics in the agent. Signed-off-by: Lénaïc Huard <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/graylog] Adding the ability to specify externalTrafficPolicy for LoadBalancer services (#22933) * Adding the ability to specify externalTrafficPolicy, and thus preserve client IP addresses Signed-off-by: Jeff Kolb <[email protected]> * Updated readme Signed-off-by: Jeff Kolb <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Volume mounts and ServiceAccount annotations for Cluster Checks runners (#22659) * [stable/datadog] Add params for mounting volumes to cluster checks runners Signed-off-by: Marica Odagaki <[email protected]> * [stable/datadog] Add param for annotating ServiceAccount for cluster checks runners Signed-off-by: Marica Odagaki <[email protected]> * [stable/datadog] Bump to 2.3.9 Signed-off-by: Marica Odagaki <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Typo and grammar fixes in documentation (#22944) * grammar edits! Signed-off-by: Lénaïc Huard <[email protected]> * Typo in log config Signed-off-by: Lénaïc Huard <[email protected]> Co-authored-by: cswatt <[email protected]> Co-authored-by: John Girvan <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Handle arguments in the cluster-agent command (#22922) Without quotes around the command and its arguments Kubernetes joins all string in a single binary name, so it's not possible to run `datadog-cluster-agent start` in the container Signed-off-by: Stanislav Petrashov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] add enabled flag to all druid roles (#22870) * add enabled flag to all druid roles Signed-off-by: slyao <[email protected]> * add some comments for enabled properties in values.yaml Signed-off-by: slyao <[email protected]> * delete zookeeper.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * delete postgresql.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * delete postgresql.persistence.enabled setting, it is true by default Signed-off-by: slyao <[email protected]> * update version to 0.2.5 Signed-off-by: slyao <[email protected]> Co-authored-by: slyao <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch-exporter] Add serviceMonitor targetLabels (#22951) Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update service port name to follow istio convention (#22977) Signed-off-by: Thi Nguyen <[email protected]> Co-authored-by: Thi Nguyen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix helm3 ClusterIP updates (#22958) Signed-off-by: Łukasz Sowa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Allow serviceAccount annotations for Halyard (#21060) * [stable/spinnaker] Option to add annotation to the created Halyard serviceaccount. This is required when using 'IAM roles for serviceaccounts' when authenticating in AWS Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Updating README with information about Halyard serviceaccount annotations Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Updating Chart version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Increment Chart version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Setting version level with current Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Incrementing version Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Use correct name (serviceAccountAnnotations) in the values.yaml file Signed-off-by: Adam Robinson <[email protected]> * [stable/spinnaker] Increment Chart version Signed-off-by: Adam Robinson <[email protected]> Co-authored-by: Adam Robinson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * adding backwards compatible component label key override (#22983) Signed-off-by: Rodrigo Lomonaco <[email protected]> Co-authored-by: rodrigo.lomonaco <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cluster-overprovisioner] add pod security context (#22985) Signed-off-by: Peter Wilson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Add option for priorityClassName (#22990) Signed-off-by: Ciprian Hacman <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-mysql-exporter]: Add service labels and annotations (#22986) Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nextcloud] Add prometheus metrics exporter (#22876) * [stable/nextcloud] Add prometheus metrics exporter Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Add new line at end of values.yaml Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Use specific metrics img-tag, add service for metrics Signed-off-by: Tom Koch <[email protected]> * [stable/nextcloud] Add docu for metrics, add annotations to metrics service Signed-off-by: Tom Koch <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update Seq chart to 2020 container version (#22991) Signed-off-by: Ashley Mannix <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/airflow] Fix typo in airflow/templates/configmap-env.yaml (#22830) Signed-off-by: Ales Nosek <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluentd] Minor typo in README.md (#22898) * Minor typo in the stable/fluentd/README.md Signed-off-by: David Calvert <[email protected]> * Updated Chart version from 2.4.2 to 2.4.3 (minor) Signed-off-by: David Calvert <[email protected]> * Updated stable/fluentd Chart version from 2.4.2 to 2.4.3 (minor) Signed-off-by: David Calvert <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * incubator/kube-downscaler: Manage Resources (#22929) This commit makes a few minor modifications to the way the Helm chart allows users to manage downscaler resources. The core functionality has not changed since `extraArgs` already existed. These changes improve upon how a user interacts with specific commandline arguments to better manage the resources. First `clusterrole.yaml` was updated to take a list of resources from the values file. This will allow the resource configuration in the for the role to match the commandline argument for `include-resources`. Second `include-resources` was added as a commandline argument so that users can have full control over which resources the downscaler does and does not have access to. This could be achieved previously by the use of `extraArgs` but it is now a cleaner interaction for the user since they don't need to worry about list formatting. _Both the `clusterrole.yaml` and `deployment.yaml` get the resources to manage from `downscaleResources` in `values.yaml`._ Third `exclude-namespaces` and `exclude-deployments` were added as commandline arguments to help improve users ability to exclude specific namespaces and deployments from the downscaler. This was able to be done previously with the use of `extraArgs` but much like the other changes this makes the user interaction more clean and manageable. Both of these arguments derive their values from `excludedNamespaces` and `excludedDeployments` in `values.yaml` respectively. Signed-off-by: Christopher Pisano <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Bump version to 0.9.2 (#23012) * Bump cerebro version to 0.9.2 Signed-off-by: Nathan Webster <[email protected]> * bump chart version Signed-off-by: David Karlsen <[email protected]> Co-authored-by: David Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] Using favicon instead of druid_nav (#22984) Signed-off-by: asdf2014 <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix: new line is removed from useSocketVolume section (#23020) Template produces invalid yaml when useSocketVolume is enabled. Signed-off-by: Roarke Gaskill <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * enable secret for ldap even when admin password is passed via file. bump version (#23006) Signed-off-by: Tiago Posse <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Ensure all rules can be toggled (#22879) * [stable/prometheus-operator] Ensure all rules can be toggled Signed-off-by: Sean Clemmer <[email protected]> * [stable/prometheus-operator] Bump chart verison to 8.15.7 Signed-off-by: Sean Clemmer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * incubator/kube-downscaler - fix a regression about namespaces (#23030) * Fix a kube-downscaler regression about namespaces The present fixes a regression where invalid option value 'namespaces' is passed to the tool and overly generous permissions are granted over namespaces. Signed-off-by: Danil Mironov <[email protected]> * Delete excessive quotes in arguments Signed-off-by: Danil Mironov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-cloudwatch-exporter] additional docu on service account usage (#23028) * additional info on service account config so one can read mounted secret this worked OK: ``` securityContext: runAsUser: 65534 # run as nobody user instead of root fsGroup: 65534 # to read mounted secret with the same id ``` Signed-off-by: Peter Triesz <[email protected]> * updating chart version after readme modification Signed-off-by: Peter Triesz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/karma] Upgrade karma to v0.68 (#22950) Signed-off-by: Łukasz Mierzwa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Fix sed replacing special sources (#22960) Signed-off-by: Andrey Voronkov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/coredns] Version bump to 1.7.0 (#23013) * [stable/coredns] Version bump to 1.7.0 https://coredns.io/2020/06/15/coredns-1.7.0-release/ Signed-off-by: Manuel Rüger <[email protected]> * [stable/coredns] Drop annotations from service As it was changed in cea2d6f158a640e6d49e291008ed61c0ec827b17 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Mount system-probe.yaml in the process-agent container when enabled (#23035) * Mount system-probe.yaml in the process-agent container when enabled https://github.com/helm/charts/pull/22686/files changed the location of the system-probe socket away from the default. Since the process-agent was relying on the socket being at the default location by dint of not having the system-probe.yaml file, this commit broke the process-agent -> system-probe communication. Signed-off-by: Lee Avital <[email protected]> * rev version Signed-off-by: Lee Avital <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] Fix rbac for get ingress info (#23015) * Fix rbac for get ingress info Signed-off-by: Eugene Medvedev <[email protected]> * Update chart version Signed-off-by: Eugene Medvedev <[email protected]> * support newer and older clusters Signed-off-by: Eugene Medvedev <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] fix blueocean dependency issue (#23045) Signed-off-by: Mike Scholze <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [Stable/Efs-Provisioner] add namespace to deployment/sa (#23056) * feat: [Stable/Efs-Provisioner] add namespace to deployment/sa Add the namespace information to deployment and serviaccount. this Prevent helm3 to push the object to the current ns and not the one Refered by the option "--namespace" Signed-off-by: David Sabatie <[email protected]> * bump chart version Signed-off-by: David Sabatie <[email protected]> * fix bad char in serviceaccount file Signed-off-by: David Sabatie <[email protected]> * fix bad char in deployment Signed-off-by: David Sabatie <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] modify the default value by nano-quickstart to decrease memory cost (#23044) * change the default setting to nano quickstart Signed-off-by: AWaterColorPen <[email protected]> * change the comment to adapt nano quickstart Signed-off-by: AWaterColorPen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Update grafana Chart (#22891) * Update grafana Chart Signed-off-by: David Gleich <[email protected]> * Update Chart version Signed-off-by: David Gleich <[email protected]> * Update requirements.lock Signed-off-by: David Gleich <[email protected]> * Using helm2 for updateing the requirements Signed-off-by: David Gleich <[email protected]> * Needs a versionbump Signed-off-by: David Gleich <[email protected]> * Bump Chart version Signed-off-by: David Gleich <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * deprecate the kured-chart (#23055) Signed-off-by: Christian Kotzbauer <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/grafana Grafana statefulset pod labels (#22590) * StatefulSet do not include podLabels. Signed-off-by: Ryan Bonham <[email protected]> * Bump Chart Version Signed-off-by: Ryan Bonham <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix empty annotations (#22580) Currently setting the serviceAccountAnnotations without the other rbac stuff fails with `error validating data: [apiVersion not set, kind not set]`, this is because the only line being rendered is the `annotations: {{ toYaml...` line. This change would prevent failure, but will swallow a potential misconfiguration (would a user want to have serviceAccountAnnotations with the service account not being created? - maybe but I'm not too sure about this). As an alternative, an explicit fail message could be set if serviceAccountAnnotations are set without the service account being created. Signed-off-by: Jonathan Cowling <[email protected]> Version bump Signed-off-by: Jonathan Cowling <[email protected]> Signed-off-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/traefik] Update traefik version from 1.7.23 to 1.7.24 (#22646) * Update traefik version from 1.7.23 to 1.7.24 Signed-off-by: Sebastian Brandt <[email protected]> * chart and app version raised for traefik Signed-off-by: Sebastian Brandt <[email protected]> * README.md updated for traefik Signed-off-by: Sebastian Brandt <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Fix a bunch of nil defaults (#22999) Signed-off-by: George Christou <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Replace configmap-reload image (#22988) Upstream switched to this image in https://github.com/coreos/prometheus-operator/commit/3c1456eac35d2ace824d478d6bd9dad6939f6db3#diff-e237ffe304b9b2407ed7d9424a2770a9 This also enables support for multi-arch for the configmap-reload image Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Merge several pending PRs (#23066) * Remove duplicate imagePullSecrets Signed-off-by: Brian Choy <[email protected]> * [stable/datadog] Fix a bunch of nil defaults Signed-off-by: George Christou <[email protected]> * [stable/datadog] Adding explanation for metricsProvider.enabled Signed-off-by: Lénaïc Huard <[email protected]> * [stable/datadog] Fix DataDog location to useConfigMap in docs Signed-off-by: Lénaïc Huard <[email protected]> Co-authored-by: Brian Choy <[email protected]> Co-authored-by: George Christou <[email protected]> Co-authored-by: Sagar2366 <[email protected]> Co-authored-by: Gregory Jones <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Fix typo in document of stable jenkins (#22847) Signed-off-by: tottoto <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] kubelet servicemonitor skip tls verify (#22927) * chomp newline Signed-off-by: Jordan Sokolic <[email protected]> * skip TLS verify for kubelet metrics endpoint Signed-off-by: Jordan Sokolic <[email protected]> * bump version Signed-off-by: Jordan Sokolic <[email protected]> * bump dependency versions Signed-off-by: Jordan Sokolic <[email protected]> * Revert "bump dependency versions" This reverts commit 9f5ca83b359b16d871d27424f7ef7632a8a52a85. Signed-off-by: Jordan Sokolic <[email protected]> * add http counterpart for kubelet servicemonitor Signed-off-by: Jordan Sokolic <[email protected]> * bump Signed-off-by: Jordan Sokolic <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cerebro] Added cacert option (#22893) Signed-off-by: Anders Nyvang <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/docker-registry] LoadBalancer settings (#21506) * LoadBalancer settings Signed-off-by: wilinger <[email protected]> * bump version Signed-off-by: David J. M. Karlsen <[email protected]> Co-authored-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mcrouter] create a template for api version (#22638) Signed-off-by: lwsanty <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/rundeck] envSecret, awsConfigSecret, kubeConfigSecret, extraConfigSecret, nginx req size (#23004) * chart v2, envSecret, kubeConfigSecret, extraConfigSecret, req size Signed-off-by: Jonathan Cole <[email protected]> * drop back to Chart API V1 Signed-off-by: Jonathan Cole <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] trigger re-deployment if envRenderSecret has been changed. (#23052) Signed-off-by: Jan-Otto Kröpke <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Update hyperkube image (#23073) Update to a support version of kubernetes: 1.16.12 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] increase retries for sidecar reload (#22787) * [stable/jenkins] increase retries for sidecar reload Signed-off-by: Torsten Walter <[email protected]> * add missing changelog Signed-off-by: Torsten Walter <[email protected]> * Fix README entry Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/sealed-secrets] update version to 0.12.4 (#23076) Signed-off-by: Christian Groschupp <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Add PSP and SCC (#22529) * [stable/datadog] Add PSP and SCC Signed-off-by: cedric lamoriniere <[email protected]> * update after review Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] add orchestrator-explorer option (#23018) * add setting to enable the orchestrator explorer Signed-off-by: Haissam Kaj <[email protected]> * switch default to false Signed-off-by: Haissam Kaj <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Add networkPolicy podLabels (#22706) * [stable/jenkins] Add networkPolicy podLabels Signed-off-by: Olivier Vernin <[email protected]> * Update changelog Signed-off-by: Olivier Vernin <[email protected]> * Update version to 2.3.0 Signed-off-by: Olivier Vernin <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Add the ability to deploy the auth and proxy components separately, and do not mandate supplying a Google service account. (#23060) Signed-off-by: Damian Peckett <[email protected]> Co-authored-by: Damian Peckett <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Align ENV var handling (avoid ranging through them to allow any K8S valid syntax) (#23080) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] fix PodSecurityContext seLinux (#23088) Fixes #23084 Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Make unguiculus/mongodb-install multiarch and include arm platforms (#22322) (#22323) - also bumped mongodb-install image version number - bumped chart version number Signed-off-by: Kris Gandhi <[email protected]> Co-authored-by: Kris Gandhi <[email protected]> Co-authored-by: Reinhard Nägele <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/selenium] Add ability to pass additional pod labels for all pods (#22931) * Add ability to pass additional pod labels for all pods My use case for these is to add a pod label to be used with and AWS EKS Fargate profile. By default no additional labels are added. Signed-off-by: Daniel Schaaff <[email protected]> * Bump the chart version Signed-off-by: Daniel Schaaff <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-pushgateway] Fix networkPolicy podSelector and ingress rule (#23053) * Fix `podSelector` by adding `release` label * Fix ingress rule by ensuring port is restricted Before it was: * Source: any, Port: `targetPort` * Source: `customSelectors`, Port: any Now it is: * Source: `customSelectors`, Port: `targetPort` and `allowAll` does not add an any/any rule anymore. Signed-off-by: Maxime Brunet <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mysql] Add support for extra environment variables (#22945) (#22947) Signed-off-by: Casey Buto <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/aws-alb-ingress-controller] Fix a typo in the aws-alb-ingress-controller chart README (#22164) * [incubator/aws-alb-ingress-controller] Fix a typo in the aws-alb-ingress-controller chart README Signed-off-by: enokawa <[email protected]> * [incubator/aws-alb-ingress-controller] Bump the chart version Signed-off-by: enokawa <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Correct indentation of 'volumes' property (#22494) Signed-off-by: Marcus van Dam <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * stable/cluster-autoscaler (#23092) * Set default value for .rbac.create to true (so the serviceaccount and associated pods can be created in the deployment). Signed-off-by: Robert J <[email protected]> * Updated README.md Signed-off-by: Robert J <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mysql] MySQL chart version bump to 1.6.6 (#23075) * Update busybox and bats testFramework to newer image tag Signed-off-by: Tyler Nguyen <[email protected]> * Enable securityContext support and switch to user the other testFramework repository Signed-off-by: Tyler Nguyen <[email protected]> * Fix wrong bats dir Signed-off-by: Tyler Nguyen <[email protected]> Co-authored-by: David J. M. Karlsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] Warning fixed, made client service optional (#22209, #22759). (#22971) Made the headless client service optional, fixed warning when used as a subchart. Signed-off-by: Berk Soysal <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-mongodb-exporter] Add serviceMonitor targetLabels and service labels (#22952) * [stable/prometheus-mongodb-exporter] Add serviceMonitor targetLabels Signed-off-by: Calvin Bui <[email protected]> * [stable/prometheus-mongodb-exporter] Add labels to service Signed-off-by: Calvin Bui <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/airflow] Adding basic auth values for flower (#23036) Signed-off-by: Alex Begg <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Sync dashboards and rules for #22081 (#23024) Signed-off-by: Dan Sexton <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] add support for running without cluster-admin privileges (#23049) * add support for running on kubernetes setups (such as openshift) where you only have access to your own namespaces Signed-off-by: Klavs Klavsen <[email protected]> * bump chart versions Signed-off-by: Klavs Klavsen <[email protected]> * reverted kube-state-metrics so this branch is only about prometheus chart Signed-off-by: Klavs Klavsen <[email protected]> * signing Signed-off-by: Klavs Klavsen <[email protected]> * lint fix Signed-off-by: Klavs Klavsen <[email protected]> * lint fix Signed-off-by: Klavs Klavsen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update the grafana to 7.0.5 (#23111) Signed-off-by: gowrisankar <[email protected]> Co-authored-by: gowrisankar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] remove namespace field from non-namespaced resources (#22949) * [stable/prometheus-operator] remove namespace field from non-namespaced resources Signed-off-by: Riccardo M. Cefala <[email protected]> * [stable/prometheus-operator] bump chart version Signed-off-by: Riccardo M. Cefala <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Treat alertmanager additionalPeers as YAML (#23112) Avoids string templating errors, for example when passing an array of string literals containing colons. Signed-off-by: Craig Furman <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/cockroachdb] deprecating this cockroachdb chart repository (#23000) * [stable/cockroachdb] deprecating this cockroachdb chart repository Given the deprecation of `stable`, future CockroachDB Helm charts are now located at: code repository: https://github.com/cockroachdb/helm-charts charts repository: https://charts.cockroachdb.com Update this repository to point users to the new locations. Signed-off-by: James H. Linder <[email protected]> * Complete the deprecation steps as described in PROCESSES.md Signed-off-by: James H. Linder <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * update to linux agent ciprod06302020 and add the tolerations for windows (#23099) Signed-off-by: Ganga Mahesh Siddem <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/sparkoperator] Add scheduling.volcano.sh to apiGroup in spark-operator-rbac.yaml (#23125) * added scheduling.volcano.sh to rbac Signed-off-by: Goutham Reddy Kotapalle <[email protected]> * version bump to 0.7.2 Signed-off-by: Goutham Reddy Kotapalle <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus] Improve Prometheus Server Probes. Fix MD Syntax Issues in README. (#23116) * fix md style issues sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * add periodseconds to liveness and readiness probes. on par probes for deployment and statefulset. sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * include liveness and readiness probes documentation sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> * bump chart to v11.7.0 sign: Xtigyro <[email protected]> Signed-off-by: Miroslav Hadzhiev <[email protected]> Signed-off-by: Xtigyro <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/nginx-ingress] add controller.podAnnotationConfigChecksum (#22998) Signed-off-by: raittes <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/aws-alb-ingress-controller] Bump chart version bump to 1.0.2 (#23089) * Support chart image version v1.1.8 Signed-off-by: Tyler Nguyen <[email protected]> * Update README Signed-off-by: Tyler Nguyen <[email protected]> * Fix wrong region mentioned in README Signed-off-by: Tyler Nguyen <[email protected]> * Merge branch 'master' into aws-alb-ingress-controller-1.0.2 Signed-off-by: Tyler Nguyen <[email protected]> * Bump Chart version Signed-off-by: Tyler Nguyen <[email protected]> * Fix conflicts in README Signed-off-by: Tyler Nguyen <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * add support for init containers and custom volumes (for plugins) (#22653) Signed-off-by: George Kaz <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/druid] modify the default value(the previously pr is closed, I can't reopen it. #23072) (#23115) * change druid_coordinator_balancer_strategy Signed-off-by: camelusluo <[email protected]> * Update Chart.yaml Signed-off-by: camelusluo <[email protected]> * Update values.yaml Signed-off-by: camelusluo <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/dex] Add imagePullSecrets (#22956) * [stable/dex] Add imagePullSecrets Signed-off-by: Konstantinos Sideris <[email protected]> * Add docs and default value Signed-off-by: Konstantinos Sideris <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] possibility to add annotations to default dashboards (#22900) * adapt sync script to add annotations to dashboards Signed-off-by: Marius Svechla <[email protected]> * run sync_grafana_dashboards, add new value to values.yaml Signed-off-by: Marius Svechla <[email protected]> * update readme for new grafana.sidecar.dashboards.annotations variable Signed-off-by: Marius Svechla <[email protected]> * rebase Signed-off-by: Marius Svechla <[email protected]> * fix trailing spaces Signed-off-by: Marius Svechla <[email protected]> * fix namespace template Signed-off-by: Marius Svechla <[email protected]> * re-run sync_grafana_dashboards Signed-off-by: Marius Svechla <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Added option to disable kube-apiserver-availability rules (#23136) Signed-off-by: Dan Sexton <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] add systemProbe.collectDNSStats (#23086) * [stable/datadog] add collectDNSStats option, remove selinux defaults Adds collectDNSStats which enabled the system_probe.collect_dns_stats flag. The flag is only rendered into system-probe.yaml if set to true. This will allow the agent default to changed to true down the line without requiring a chart bump. Signed-off-by: Lee Avital <[email protected]> * Update stable/datadog/templates/system-probe-configmap.yaml Co-authored-by: Cedric Lamoriniere <[email protected]> Signed-off-by: Lee Avital <[email protected]> Co-authored-by: Cedric Lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/atlantis] Add envFrom secrets option (#23122) * Add envFrom to atlantis Signed-off-by: Armaan Tobaccowalla <[email protected]> * Fix version Signed-off-by: Armaan Tobaccowalla <[email protected]> * Add warning Signed-off-by: Armaan Tobaccowalla <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluent-bit] Added `input.tail.exclude_path` parameter (#22392) Signed-off-by: Ivan Kurnosov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * fix daemonset generation if `datadog.securityContext==nil` (#23146) If the `datadog.securityContext` value is set to `nil` instead of `{}` when a user want to remove the default `securityContext`, helm is not able to generate the Daemonset manifest. To support this configuration we have change how we test the value. With the new `{{ if ...}}` check we don't check the second comparison if the first already return false. Signed-off-by: cedric lamoriniere <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Small chart tweaks for cluster agent (#23079) * [stable/datadog] Default external metrics provider port to 8443 In order to avoid issues with non-root users inside a container trying to listen on port 443, from now on we're going to set the default port for the external metrics provider in the DCA container to 8443. Signed-off-by: Julio Greff <[email protected]> * [stable/datadog] Document `clusterAgent.env` Signed-off-by: Julio Greff <[email protected]> * [stable/datadog] Bump version to 2.3.29 Signed-off-by: Julio Greff <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/ignite] Ignite features (#22023) * feat() Added envVars envFrom extraInitContainers extraContainers extraVolumes extraVolumeMounts features Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() linting Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() imagePullPolicy is not working Signed-off-by: Mehmet Onur Yalazi <[email protected]> * fix() statefulset env section is wrong Signed-off-by: Mehmet Onur Yalazi <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Prevent error on upgrade (#22394) Work around: https://github.com/helm/helm/issues/8101 Signed-off-by: Jan Kantert <[email protected]> Co-authored-by: Jan Kantert <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/hlf-peer] Configure chaincode builder and chaincode runtime image (#23153) Signed-off-by: AlexandrePicosson <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Mount always ref/secrets. (#23137) The `ref/secrets` is mounted only when `master.enableXmlConfig == true`. This is bug. The `ref/secrets` must be always mounted. Just because `master.secretsFilesSecret` and `master.enableXmlConfig` are unrelated, as well as: ./templates/config.yaml has unconditional: apply_config.sh: |- echo "applying Jenkins configuration" mkdir -p {{ .Values.master.jenkinsRef }}/secrets/; This mkdir will fail in UID != 0. We need to mount always secrets. Signed-off-by: Andrei Stepanov <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Fix overwritePluginsFromImage and syntax error (#23175) Setting overwritePluginsFromImage: Fixes #23003 Fixes #22633 Correcting indentation Fixes #23114 Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] Fix master.slaveJenkinsUrl (#23176) Fixes #22708 Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/mongodb-replicaset] liveness/startupProbe tuning (#23046) * MongoDB liveness/startupProbe tuning Signed-off-by: Bernard Grymonpon <[email protected]> * Changes after review - 1.18 as target k8s api version - aligned the values and readme - changed probe for the metrics server Signed-off-by: Bernard Grymonpon <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Update the app version to 7.0.5 (#23130) * Update the app version to 7.0.5 Signed-off-by: gowrisankar <[email protected]> * Update the app version to 7.0.5 Signed-off-by: gowrisankar <[email protected]> Co-authored-by: gowrisankar <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/atlantis] Use newer ingress API (#23162) Kubernetes 1.16 deprecates various APIs and therefore manifests require updates. This change is backwards compatible and can still be used with older Kubernetes versions. Signed-off-by: Enrico Stahn <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Change to use specified port instead of default (#23154) * Change to use specified port instead of default Signed-off-by: Timo Sand <[email protected]> * Bump patch version Signed-off-by: Timo Sand <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/oauth2-proxy] Use newer ingress API to be compatible with Kubernetes 1.16 (#23161) * [stable/oauth2-proxy] Use newer ingress API Kubernetes 1.16 deprecates various APIs and therefore manifests require updates. This change is backwards compatible and can still be used with older Kubernetes versions. Signed-off-by: Enrico Stahn <[email protected]> * [stable/oauth2-proxy] Bump chart version to 3.2.1 Signed-off-by: Enrico Stahn <[email protected]> * [stable/oauth2-proxy] use .Capabilities.APIVersions.Has Signed-off-by: Enrico Stahn <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/buzzfeed-sso] Allow Independent auth Ingress (#23165) * [buzzfeed/sso] Allow independent auth ingresses Signed-off-by: Damian Peckett <[email protected]> * [buzzfeed/sso] remove trailing spaces Signed-off-by: Damian Peckett <[email protected]> Co-authored-by: Damian Peckett <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/jenkins] update agent image (#23191) Signed-off-by: Torsten Walter <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] fix daemonset templates for go 1.14 (#23166) * fix datadog daemonset.yaml to be compatible with go 1.14 Signed-off-by: Shun Yamamoto <[email protected]> * bump version up Signed-off-by: Shun Yamamoto <[email protected]> * Update stable/datadog/CHANGELOG.md Co-authored-by: Harrison Heck <[email protected]> Signed-off-by: Shun Yamamoto <[email protected]> * bump version up Signed-off-by: Shun Yamamoto <[email protected]> Co-authored-by: Shun Yamamoto <[email protected]> Co-authored-by: Harrison Heck <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-node-exporter] Version bump to 1.0.1 (#23151) https://github.com/prometheus/node_exporter/releases/tag/v1.0.1 Try fixing CI as suggested by @vsliouniaev Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Version bump, deprecation of additionalScrapeConfigsExternal (#23147) * Version bump, deprecation of additionalScrapeConfigsExternal Signed-off-by: Alexander Cristian <[email protected]> * Removed prometheus.prometheusSpec.additionalScrapeConfigsExternal from README Signed-off-by: Alexander Cristian <[email protected]> * Modified values for naming convention Signed-off-by: Alexander Cristian <[email protected]> * Added newline for test to pass Signed-off-by: Alexander Cristian <[email protected]> * Correct node exporter for tests to pass Signed-off-by: Alexander Cristian <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/opa] Add extra{containers,ports,volumes} to OPA deployment (#23190) * Add extra-{containers,ports,volumes} to OPA stable chart Signed-off-by: Ángel Barrera Sánchez <[email protected]> * Bump OPA chart version Signed-off-by: Ángel Barrera Sánchez <[email protected]> * Update stable/opa chart documentation Signed-off-by: Ángel Barrera Sánchez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Version bump alertmanager and prometheus (#23150) * [stable/prometheus-operator] Version bump prometheus to 2.18.2 https://github.com/prometheus/prometheus/releases/tag/v2.18.2 Signed-off-by: Manuel Rüger <[email protected]> * [stable/prometheus-operator] Version bump alertmanager to 0.21.0 https://github.com/prometheus/alertmanager/releases/v0.21.0 Signed-off-by: Manuel Rüger <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/datadog] Always add os in nodeSelector based on `targetSystem` (#23199) Signed-off-by: Vincent Boulineau <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/kibana] possility customize url for dashboard import script (#23192) * [stable/kibana] possility customize url for dashboard import script Signed-off-by: mikhail_znak <[email protected]> * [stable/kibana] possility customize url for dashboard import script Signed-off-by: mikhail_znak <[email protected]> Co-authored-by: mikhail_znak <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/fluentd] Add podLabels (#23169) * [stable/fluentd] Add support for podLabels Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Bump chart version Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Update README Signed-off-by: Pavel Dmytrenko <[email protected]> * [stable/fluentd] Rename labels property Signed-off-by: Pavel Dmytrenko <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/instana-agent] Chart version 1.0.29 (#23211) Signed-off-by: Instana CD <[email protected]> Co-authored-by: Instana CD <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/spinnaker] Add option to specify storageclass for halyard persistence data volume (#22828) * Added feature to specify storage class for halyard persistence volume Signed-off-by: Karthick Prabu <[email protected]> * Fix requirements.lock Signed-off-by: Karthick Prabu <[email protected]> * Fixed linting issues Signed-off-by: Karthick Prabu <[email protected]> * Bumped version Signed-off-by: Karthick Prabu <[email protected]> * Update Chart.yaml Signed-off-by: Paul Czarkowski <[email protected]> Co-authored-by: Paul Czarkowski <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/percona-xtradb-cluster] Fixes #23207 (#23208) * [stable/percona-xtradb-cluster] Fixes #23207 Signed-off-by: Rafael Rivero <[email protected]> * [stable/percona-xtradb-cluster] fix linting issues Signed-off-by: Rafael Rivero <[email protected]> Co-authored-by: Rafael Rivero <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Update incubator/cockroach to a placeholder deprecated chart. See README and NOTES for explanation (#23129) Signed-off-by: Scott Rigby <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [incubator/azuremonitor-containers] updates for hotfix release ciprod07152020 (#23212) * updates for hotfix release ciprod07152020 Signed-off-by: Ganga Mahesh Siddem <[email protected]> * bump chart version Signed-off-by: Ganga Mahesh Siddem <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/grafana] Allow specifying checksum for docker images (#23195) Signed-off-by: Gabriel Martinez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/hlf-peer] Add docker config.json secret for private registry (#23206) Signed-off-by: Kelvin Moutet <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * Enable ability to set annotations on service account (#23219) Signed-off-by: Amir Alavi <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/metabase] Allow MB_SITE_URL to be set from values.yaml (#23221) * [stable/metabase] Allow MB_SITE_URL to be set from values.yaml Signed-off-by: Oliver Evans <[email protected]> * Document siteUrl parameter Signed-off-by: Oliver Evans <[email protected]> * bump chart version Signed-off-by: Oliver Evans <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/elasticsearch-exporter]: customize log flags (#23216) * [stable/elasticsearch-exporter]: customize log flags Signed-off-by: Carlos Alexandro Becker <[email protected]> * fix: small fixes Signed-off-by: Carlos Alexandro Becker <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/prometheus-operator] Add docker checksum option (#23194) * [stable/prometheus-operator] Allow specifying checksum for docker images Signed-off-by: Gabriel Martinez <[email protected]> * [stable/prometheus-operator] Don't specify default digest for docker images Signed-off-by: Gabriel Martinez <[email protected]> Signed-off-by: Adrien Loiseau <[email protected]> * [stable/…
Some processes need to change files from different users (deck for instance). If the pod is run as non root, deck does not start: ********************** cp: cannot create regular file 'spinnaker.conf': Permission denied sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory sed: can't read spinnaker.conf: No such file or directory mv: cannot stat 'spinnaker.conf': No such file or directory ERROR: Site spinnaker does not exist! Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied cp: cannot create regular file 'ports.conf': Permission denied sed: can't read ports.conf: No such file or directory sed: can't read ports.conf: No such file or directory mv: cannot stat 'ports.conf': No such file or directory cp: cannot create regular file 'passphrase': Permission denied sed: can't read passphrase: No such file or directory chmod: cannot access 'passphrase': No such file or directory mv: cannot stat 'passphrase': No such file or directory cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted ********************** Relaxing the PSP to allow this. Signed-off-by: Fabrice Rabaute <[email protected]> Signed-off-by: Miguel Mingorance <[email protected]>
Some processes need to change files from different users (deck for
instance).
If the pod is run as non root, deck does not start:
cp: cannot create regular file 'spinnaker.conf': Permission denied
sed: can't read spinnaker.conf: No such file or directory
sed: can't read spinnaker.conf: No such file or directory
sed: can't read spinnaker.conf: No such file or directory
mv: cannot stat 'spinnaker.conf': No such file or directory
ERROR: Site spinnaker does not exist!
Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied
cp: cannot create regular file 'ports.conf': Permission denied
sed: can't read ports.conf: No such file or directory
sed: can't read ports.conf: No such file or directory
mv: cannot stat 'ports.conf': No such file or directory
cp: cannot create regular file 'passphrase': Permission denied
sed: can't read passphrase: No such file or directory
chmod: cannot access 'passphrase': No such file or directory
mv: cannot stat 'passphrase': No such file or directory
cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied
chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted
Relaxing the PSP to allow this.
Is this a new chart
What this PR does / why we need it:
Which issue this PR fixes
(optional, in
fixes #<issue number>(, fixes #<issue_number>, ...)
format, will close that issue when PR gets merged)Special notes for your reviewer:
Checklist
[Place an '[x]' (no spaces) in all applicable fields. Please remove unrelated fields.]
[stable/mychartname]
)