Repository navigation
feat(oci/helm/app-template): update to v5.3.0 - #5682
Open
tinfoild[bot] wants to merge 1 commit into
Open
tinfoild[bot] wants to merge 1 commit into
tinfoild[bot] wants to merge 1 commit into
Conversation
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
May 14, 2026 18:42
a222a58 to
f3aff11
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
2 times, most recently
from
May 19, 2026 15:12
9908c05 to
db881db
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
2 times, most recently
from
June 7, 2026 13:38
a926808 to
3394fb3
Compare
Contributor
Author
kube/helmrelease/out00--- HelmRelease: media/copyparty Deployment: media/copyparty
+++ HelmRelease: media/copyparty Deployment: media/copyparty
@@ -14,25 +14,25 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: copyparty
app.kubernetes.io/name: copyparty
- app.kubernetes.io/instance: copyparty
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: copyparty
app.kubernetes.io/name: copyparty
ingress.home.arpa/envoy-internal: allow
ingress.home.arpa/jjgadgets: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: copyparty
automountServiceAccountToken: false
securityContext:
fsGroup: 6969
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 6969
runAsNonRoot: true
--- HelmRelease: media/copyparty ServiceAccount: media/copyparty
+++ HelmRelease: media/copyparty ServiceAccount: media/copyparty
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: copyparty
+ labels:
+ app.kubernetes.io/instance: copyparty
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: copyparty
+ namespace: media
+
--- HelmRelease: continuwuity/continuwuity Deployment: continuwuity/continuwuity
+++ HelmRelease: continuwuity/continuwuity Deployment: continuwuity/continuwuity
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: continuwuity
app.kubernetes.io/name: continuwuity
- app.kubernetes.io/instance: continuwuity
template:
metadata:
annotations:
ipam.cilium.io/ip-pool: vpn-vlan
ipam.cilium.io/require-pool-match: 'true'
labels:
@@ -32,13 +32,13 @@
egress.home.arpa/internet: allow
egress.home.arpa/ntfy: allow
ingress.home.arpa/envoy-external: allow
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: continuwuity
automountServiceAccountToken: false
runtimeClassName: kata
securityContext:
fsGroup: 65534
fsGroupChangePolicy: Always
runAsGroup: 65534
--- HelmRelease: continuwuity/continuwuity ServiceAccount: continuwuity/continuwuity
+++ HelmRelease: continuwuity/continuwuity ServiceAccount: continuwuity/continuwuity
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: continuwuity
+ labels:
+ app.kubernetes.io/instance: continuwuity
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: continuwuity
+ namespace: continuwuity
+
--- HelmRelease: cinny/cinny Deployment: cinny/cinny
+++ HelmRelease: cinny/cinny Deployment: cinny/cinny
@@ -14,24 +14,24 @@
replicas: 2
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: cinny
app.kubernetes.io/name: cinny
- app.kubernetes.io/instance: cinny
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: cinny
app.kubernetes.io/name: cinny
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: cinny
automountServiceAccountToken: false
runtimeClassName: kata
securityContext:
fsGroup: 65534
fsGroupChangePolicy: Always
runAsGroup: 65534
--- HelmRelease: cinny/cinny ServiceAccount: cinny/cinny
+++ HelmRelease: cinny/cinny ServiceAccount: cinny/cinny
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: cinny
+ labels:
+ app.kubernetes.io/instance: cinny
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: cinny
+ namespace: cinny
+
--- HelmRelease: code-server/code-server Deployment: code-server/code-server
+++ HelmRelease: code-server/code-server Deployment: code-server/code-server
@@ -17,14 +17,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: code-server
app.kubernetes.io/name: code-server
- app.kubernetes.io/instance: code-server
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: code-server
app.kubernetes.io/name: code-server
--- HelmRelease: gotosocial/gotosocial Deployment: gotosocial/gotosocial
+++ HelmRelease: gotosocial/gotosocial Deployment: gotosocial/gotosocial
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: gotosocial
app.kubernetes.io/name: gotosocial
- app.kubernetes.io/instance: gotosocial
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: gotosocial
app.kubernetes.io/name: gotosocial
@@ -29,13 +29,13 @@
egress.home.arpa/internet: allow
ingress.home.arpa/envoy-external: allow
ingress.home.arpa/envoy-internal: allow
prom.home.arpa/kps: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: gotosocial
automountServiceAccountToken: false
runtimeClassName: kata
securityContext:
fsGroup: 65534
fsGroupChangePolicy: Always
runAsGroup: 65534
--- HelmRelease: gotosocial/gotosocial ServiceMonitor: gotosocial/gotosocial
+++ HelmRelease: gotosocial/gotosocial ServiceMonitor: gotosocial/gotosocial
@@ -6,13 +6,13 @@
labels:
app.kubernetes.io/instance: gotosocial
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: gotosocial
namespace: gotosocial
spec:
- jobLabel: gotosocial
+ jobLabel: app.kubernetes.io/name
namespaceSelector:
matchNames:
- gotosocial
selector:
matchLabels:
app.kubernetes.io/service: gotosocial
--- HelmRelease: gotosocial/gotosocial ServiceAccount: gotosocial/gotosocial
+++ HelmRelease: gotosocial/gotosocial ServiceAccount: gotosocial/gotosocial
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: gotosocial
+ labels:
+ app.kubernetes.io/instance: gotosocial
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: gotosocial
+ namespace: gotosocial
+
--- HelmRelease: atuin/atuin Deployment: atuin/atuin
+++ HelmRelease: atuin/atuin Deployment: atuin/atuin
@@ -14,24 +14,24 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: atuin
app.kubernetes.io/name: atuin
- app.kubernetes.io/instance: atuin
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: atuin
app.kubernetes.io/name: atuin
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: atuin
automountServiceAccountToken: false
securityContext:
fsGroup: 1000
fsGroupChangePolicy: Always
runAsGroup: 1000
runAsNonRoot: true
--- HelmRelease: atuin/atuin ServiceAccount: atuin/atuin
+++ HelmRelease: atuin/atuin ServiceAccount: atuin/atuin
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: atuin
+ labels:
+ app.kubernetes.io/instance: atuin
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: atuin
+ namespace: atuin
+
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm Deployment: insurgency-sandstorm/insurgency-sandstorm-app
+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm Deployment: insurgency-sandstorm/insurgency-sandstorm-app
@@ -14,25 +14,25 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: insurgency-sandstorm
app.kubernetes.io/name: insurgency-sandstorm
- app.kubernetes.io/instance: insurgency-sandstorm
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: insurgency-sandstorm
app.kubernetes.io/name: insurgency-sandstorm
dns.home.arpa/l7: 'true'
ingress.home.arpa/world: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: insurgency-sandstorm
automountServiceAccountToken: false
runtimeClassName: kata
securityContext:
fsGroup: 1001
fsGroupChangePolicy: Always
runAsGroup: 1001
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm CronJob: insurgency-sandstorm/insurgency-sandstorm-download
+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm CronJob: insurgency-sandstorm/insurgency-sandstorm-download
@@ -27,13 +27,13 @@
app.kubernetes.io/controller: download
app.kubernetes.io/instance: insurgency-sandstorm
app.kubernetes.io/name: insurgency-sandstorm
egress.home.arpa/internet: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: insurgency-sandstorm
automountServiceAccountToken: false
securityContext:
fsGroup: 1001
fsGroupChangePolicy: Always
runAsGroup: 1001
runAsNonRoot: true
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm ServiceAccount: insurgency-sandstorm/insurgency-sandstorm
+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm ServiceAccount: insurgency-sandstorm/insurgency-sandstorm
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: insurgency-sandstorm
+ labels:
+ app.kubernetes.io/instance: insurgency-sandstorm
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: insurgency-sandstorm
+ namespace: insurgency-sandstorm
+
--- HelmRelease: cyberchef/cyberchef Deployment: cyberchef/cyberchef
+++ HelmRelease: cyberchef/cyberchef Deployment: cyberchef/cyberchef
@@ -14,24 +14,24 @@
replicas: 2
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: cyberchef
app.kubernetes.io/name: cyberchef
- app.kubernetes.io/instance: cyberchef
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: cyberchef
app.kubernetes.io/name: cyberchef
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: cyberchef
automountServiceAccountToken: false
securityContext:
fsGroup: 1000
fsGroupChangePolicy: Always
runAsGroup: 1000
runAsNonRoot: true
--- HelmRelease: cyberchef/cyberchef ServiceAccount: cyberchef/cyberchef
+++ HelmRelease: cyberchef/cyberchef ServiceAccount: cyberchef/cyberchef
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: cyberchef
+ labels:
+ app.kubernetes.io/instance: cyberchef
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: cyberchef
+ namespace: cyberchef
+
--- HelmRelease: mollysocket/mollysocket Deployment: mollysocket/mollysocket
+++ HelmRelease: mollysocket/mollysocket Deployment: mollysocket/mollysocket
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: mollysocket
app.kubernetes.io/name: mollysocket
- app.kubernetes.io/instance: mollysocket
template:
metadata:
annotations:
ipam.cilium.io/ip-pool: vpn-vlan
ipam.cilium.io/require-pool-match: 'true'
labels:
@@ -30,13 +30,13 @@
app.kubernetes.io/name: mollysocket
egress.home.arpa/internet: allow
egress.home.arpa/ntfy: allow
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: mollysocket
automountServiceAccountToken: false
securityContext:
fsGroup: 1000
fsGroupChangePolicy: Always
runAsGroup: 1000
runAsNonRoot: true
--- HelmRelease: mollysocket/mollysocket ServiceAccount: mollysocket/mollysocket
+++ HelmRelease: mollysocket/mollysocket ServiceAccount: mollysocket/mollysocket
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: mollysocket
+ labels:
+ app.kubernetes.io/instance: mollysocket
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: mollysocket
+ namespace: mollysocket
+
--- HelmRelease: minecraft/minecraft Deployment: minecraft/minecraft
+++ HelmRelease: minecraft/minecraft Deployment: minecraft/minecraft
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: minecraft
app.kubernetes.io/name: minecraft
- app.kubernetes.io/instance: minecraft
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: minecraft
app.kubernetes.io/name: minecraft
--- HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf
+++ HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: stirling-pdf
app.kubernetes.io/name: stirling-pdf
- app.kubernetes.io/instance: stirling-pdf
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: stirling-pdf
app.kubernetes.io/name: stirling-pdf
--- HelmRelease: ntfy/ntfy Deployment: ntfy/ntfy
+++ HelmRelease: ntfy/ntfy Deployment: ntfy/ntfy
@@ -14,24 +14,24 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: ntfy
app.kubernetes.io/name: ntfy
- app.kubernetes.io/instance: ntfy
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: ntfy
app.kubernetes.io/name: ntfy
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: ntfy
automountServiceAccountToken: false
runtimeClassName: gvisor
securityContext:
fsGroup: 65534
fsGroupChangePolicy: Always
runAsGroup: 65534
--- HelmRelease: ntfy/ntfy ServiceAccount: ntfy/ntfy
+++ HelmRelease: ntfy/ntfy ServiceAccount: ntfy/ntfy
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: ntfy
+ labels:
+ app.kubernetes.io/instance: ntfy
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: ntfy
+ namespace: ntfy
+
--- HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-app
+++ HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-app
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: sit-ics-go
app.kubernetes.io/name: sit-ics-go
- app.kubernetes.io/instance: sit-ics-go
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: sit-ics-go
app.kubernetes.io/name: sit-ics-go
--- HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-chromium
+++ HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-chromium
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: chromium
+ app.kubernetes.io/instance: sit-ics-go
app.kubernetes.io/name: sit-ics-go
- app.kubernetes.io/instance: sit-ics-go
template:
metadata:
labels:
app.kubernetes.io/controller: chromium
app.kubernetes.io/instance: sit-ics-go
app.kubernetes.io/name: sit-ics-go
--- HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-app
+++ HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-app
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: mindwtr
app.kubernetes.io/name: mindwtr
- app.kubernetes.io/instance: mindwtr
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: mindwtr
app.kubernetes.io/name: mindwtr
--- HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-cloud
+++ HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-cloud
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: cloud
+ app.kubernetes.io/instance: mindwtr
app.kubernetes.io/name: mindwtr
- app.kubernetes.io/instance: mindwtr
template:
metadata:
labels:
app.kubernetes.io/controller: cloud
app.kubernetes.io/instance: mindwtr
app.kubernetes.io/name: mindwtr
--- HelmRelease: openclaw/openclaw Deployment: openclaw/openclaw
+++ HelmRelease: openclaw/openclaw Deployment: openclaw/openclaw
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: openclaw
app.kubernetes.io/name: openclaw
- app.kubernetes.io/instance: openclaw
template:
metadata:
annotations:
ipam.cilium.io/ip-pool: vpn-vlan
ipam.cilium.io/require-pool-match: 'true'
labels:
--- HelmRelease: lunar-ics/lunar-ics Deployment: lunar-ics/lunar-ics
+++ HelmRelease: lunar-ics/lunar-ics Deployment: lunar-ics/lunar-ics
@@ -14,14 +14,14 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: lunar-ics
app.kubernetes.io/name: lunar-ics
- app.kubernetes.io/instance: lunar-ics
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: lunar-ics
app.kubernetes.io/name: lunar-ics
--- HelmRelease: out-of-your-element/out-of-your-element Deployment: out-of-your-element/out-of-your-element
+++ HelmRelease: out-of-your-element/out-of-your-element Deployment: out-of-your-element/out-of-your-element
@@ -14,26 +14,26 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: out-of-your-element
app.kubernetes.io/name: out-of-your-element
- app.kubernetes.io/instance: out-of-your-element
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: out-of-your-element
app.kubernetes.io/name: out-of-your-element
egress.home.arpa/internet: allow
ingress.home.arpa/envoy-external: allow
ingress.home.arpa/envoy-internal: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: out-of-your-element
automountServiceAccountToken: false
runtimeClassName: gvisor
securityContext:
fsGroup: 1000
fsGroupChangePolicy: Always
runAsGroup: 1000
--- HelmRelease: out-of-your-element/out-of-your-element ServiceAccount: out-of-your-element/out-of-your-element
+++ HelmRelease: out-of-your-element/out-of-your-element ServiceAccount: out-of-your-element/out-of-your-element
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: out-of-your-element
+ labels:
+ app.kubernetes.io/instance: out-of-your-element
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: out-of-your-element
+ namespace: out-of-your-element
+
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-app
+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-app
@@ -14,25 +14,25 @@
replicas: 0
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: app
+ app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
- app.kubernetes.io/instance: llama-cpp
template:
metadata:
labels:
app.kubernetes.io/controller: app
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
ingress.home.arpa/envoy-internal: allow
prom.home.arpa/kps: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding
+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding
@@ -14,25 +14,25 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: embedding
+ app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
- app.kubernetes.io/instance: llama-cpp
template:
metadata:
labels:
app.kubernetes.io/controller: embedding
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
ingress.home.arpa/envoy-internal: allow
prom.home.arpa/kps: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank
+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank
@@ -14,25 +14,25 @@
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/controller: rerank
+ app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
- app.kubernetes.io/instance: llama-cpp
template:
metadata:
labels:
app.kubernetes.io/controller: rerank
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
ingress.home.arpa/envoy-internal: allow
prom.home.arpa/kps: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull
+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull
@@ -18,13 +18,13 @@
app.kubernetes.io/controller: pull
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
egress.home.arpa/internet: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-embedding
+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-embedding
@@ -18,13 +18,13 @@
app.kubernetes.io/controller: pull-embedding
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
egress.home.arpa/internet: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-rerank
+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-rerank
@@ -18,13 +18,13 @@
app.kubernetes.io/controller: pull-rerank
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/name: llama-cpp
egress.home.arpa/internet: allow
spec:
enableServiceLinks: false
- serviceAccountName: default
+ serviceAccountName: llama-cpp
automountServiceAccountToken: false
securityContext:
fsGroup: 98341
fsGroupChangePolicy: Always
runAsGroup: 98341
runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-app
+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-app
@@ -6,13 +6,13 @@
labels:
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: llama-cpp
namespace: llama-cpp
spec:
- jobLabel: llama-cpp-app
+ jobLabel: app.kubernetes.io/name
namespaceSelector:
matchNames:
- llama-cpp
selector:
matchLabels:
app.kubernetes.io/service: llama-cpp
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-embedding
+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-embedding
@@ -6,13 +6,13 @@
labels:
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: llama-cpp
namespace: llama-cpp
spec:
- jobLabel: llama-cpp-embedding
+ jobLabel: app.kubernetes.io/name
namespaceSelector:
matchNames:
- llama-cpp
selector:
matchLabels:
app.kubernetes.io/service: llama-cpp-embedding
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-rerank
+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-rerank
@@ -6,13 +6,13 @@
labels:
app.kubernetes.io/instance: llama-cpp
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: llama-cpp
namespace: llama-cpp
spec:
- jobLabel: llama-cpp-rerank
+ jobLabel: app.kubernetes.io/name
namespaceSelector:
matchNames:
- llama-cpp
selector:
matchLabels:
app.kubernetes.io/service: llama-cpp-rerank
--- HelmRelease: llama-cpp/llama-cpp ServiceAccount: llama-cpp/llama-cpp
+++ HelmRelease: llama-cpp/llama-cpp ServiceAccount: llama-cpp/llama-cpp
@@ -0,0 +1,11 @@
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: llama-cpp
+ labels:
+ app.kubernetes.io/instance: llama-cpp
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: llama-cpp
+ namespace: llama-cpp
+ |
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
June 8, 2026 21:00
3394fb3 to
455a279
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
June 19, 2026 12:35
455a279 to
bc0b8d5
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
June 28, 2026 12:36
bc0b8d5 to
d405fcb
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
July 20, 2026 10:15
d405fcb to
99babfa
Compare
Contributor
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage: ghcr.io/bjw-s-labs/helm/app-template
Vulnerabilities in version 4.6.2No known vulnerabilities found. Vulnerabilities in version 5.0.1No known vulnerabilities found. Source scan summary
Changelog Security Highlights (4.6.2 → 5.0.1)
Recommendations
|
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
August 24, 2026 03:10
99babfa to
7c58d80
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
September 5, 2026 07:40
7c58d80 to
7381455
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
September 17, 2026 18:32
7381455 to
acd25c4
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
September 17, 2026 21:39
acd25c4 to
c65199c
Compare
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
branch
from
October 10, 2026 18:49
c65199c to
4498d76
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.0.1→5.3.04.6.2→5.3.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.