Skip to content

Commit 3c87f41

Browse files
committed
Update Helm release postgresql to v16
Signed-off-by: Renovate Bot <tech+renovate@vshn.ch>
1 parent a3b8bfa commit 3c87f41

File tree

17 files changed

+200
-52
lines changed

17 files changed

+200
-52
lines changed

class/defaults.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ parameters:
6262
version: v2.3.0
6363
postgresql:
6464
source: https://charts.bitnami.com/bitnami
65-
version: 12.12.10
65+
version: 16.0.5
6666
# FQDN should be overwritten on the cluster level
6767
fqdn: keycloak.example.com
6868
# Default path since Quarkus is "/" rather than "/auth"

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/networkpolicy.yaml

+9-9
Original file line numberDiff line numberDiff line change
@@ -6,21 +6,21 @@ metadata:
66
app.kubernetes.io/instance: keycloak
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: postgresql
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
11-
name: keycloak-postgresql-ingress
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
14+
egress:
15+
- {}
1416
ingress:
15-
- from:
16-
- podSelector:
17-
matchLabels:
18-
app.kubernetes.io/instance: keycloakx
19-
app.kubernetes.io/name: keycloakx
20-
ports:
17+
- ports:
2118
- port: 5432
2219
podSelector:
2320
matchLabels:
2421
app.kubernetes.io/component: primary
2522
app.kubernetes.io/instance: keycloak
2623
app.kubernetes.io/name: postgresql
24+
policyTypes:
25+
- Ingress
26+
- Egress
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
apiVersion: policy/v1
2+
kind: PodDisruptionBudget
3+
metadata:
4+
labels:
5+
app.kubernetes.io/component: primary
6+
app.kubernetes.io/instance: builtin
7+
app.kubernetes.io/managed-by: commodore
8+
app.kubernetes.io/name: keycloak
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
12+
namespace: syn-builtin
13+
spec:
14+
maxUnavailable: 1
15+
selector:
16+
matchLabels:
17+
app.kubernetes.io/component: primary
18+
app.kubernetes.io/instance: keycloak
19+
app.kubernetes.io/name: postgresql

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/statefulset.yaml

+42-10
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ metadata:
66
app.kubernetes.io/instance: builtin
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
1111
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
@@ -29,8 +29,8 @@ spec:
2929
app.kubernetes.io/instance: keycloak
3030
app.kubernetes.io/managed-by: Helm
3131
app.kubernetes.io/name: postgresql
32-
app.kubernetes.io/version: 15.4.0
33-
helm.sh/chart: postgresql-12.12.10
32+
app.kubernetes.io/version: 17.0.0
33+
helm.sh/chart: postgresql-16.0.5
3434
name: keycloak-postgresql
3535
spec:
3636
affinity:
@@ -46,6 +46,7 @@ spec:
4646
app.kubernetes.io/name: postgresql
4747
topologyKey: kubernetes.io/hostname
4848
weight: 1
49+
automountServiceAccountToken: false
4950
containers:
5051
- env:
5152
- name: BITNAMI_DEBUG
@@ -125,20 +126,36 @@ spec:
125126
successThreshold: 1
126127
timeoutSeconds: 5
127128
resources:
128-
limits: {}
129+
limits:
130+
cpu: 150m
131+
ephemeral-storage: 2Gi
132+
memory: 192Mi
129133
requests:
130-
cpu: 250m
131-
memory: 256Mi
134+
cpu: 100m
135+
ephemeral-storage: 50Mi
136+
memory: 128Mi
132137
securityContext:
133138
allowPrivilegeEscalation: false
134139
capabilities:
135140
drop:
136141
- ALL
142+
privileged: false
143+
readOnlyRootFilesystem: true
137144
runAsNonRoot: true
138145
runAsUser: 1001
146+
seLinuxOptions: {}
139147
seccompProfile:
140148
type: RuntimeDefault
141149
volumeMounts:
150+
- mountPath: /tmp
151+
name: empty-dir
152+
subPath: tmp-dir
153+
- mountPath: /opt/bitnami/postgresql/conf
154+
name: empty-dir
155+
subPath: app-conf-dir
156+
- mountPath: /opt/bitnami/postgresql/tmp
157+
name: empty-dir
158+
subPath: app-tmp-dir
142159
- mountPath: /opt/bitnami/postgresql/certs
143160
name: postgresql-certificates
144161
readOnly: true
@@ -166,15 +183,25 @@ spec:
166183
imagePullPolicy: IfNotPresent
167184
name: init-chmod-data
168185
resources:
169-
limits: {}
170-
requests: {}
186+
limits:
187+
cpu: 150m
188+
ephemeral-storage: 2Gi
189+
memory: 192Mi
190+
requests:
191+
cpu: 100m
192+
ephemeral-storage: 50Mi
193+
memory: 128Mi
171194
securityContext:
172195
runAsGroup: 0
173196
runAsNonRoot: false
174197
runAsUser: 0
198+
seLinuxOptions: {}
175199
seccompProfile:
176200
type: RuntimeDefault
177201
volumeMounts:
202+
- mountPath: /tmp
203+
name: empty-dir
204+
subPath: tmp-dir
178205
- mountPath: /bitnami/postgresql
179206
name: data
180207
- mountPath: /dev/shm
@@ -185,8 +212,13 @@ spec:
185212
name: postgresql-certificates
186213
securityContext:
187214
fsGroup: 1001
188-
serviceAccountName: default
215+
fsGroupChangePolicy: Always
216+
supplementalGroups: []
217+
sysctls: []
218+
serviceAccountName: keycloak-postgresql
189219
volumes:
220+
- emptyDir: {}
221+
name: empty-dir
190222
- name: raw-certificates
191223
secret:
192224
secretName: keycloak-postgresql-tls

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/svc-headless.yaml

+3-4
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,14 @@
11
apiVersion: v1
22
kind: Service
33
metadata:
4-
annotations:
5-
service.alpha.kubernetes.io/tolerate-unready-endpoints: 'true'
4+
annotations: null
65
labels:
76
app.kubernetes.io/component: primary
87
app.kubernetes.io/instance: keycloak
98
app.kubernetes.io/managed-by: Helm
109
app.kubernetes.io/name: postgresql
11-
app.kubernetes.io/version: 15.4.0
12-
helm.sh/chart: postgresql-12.12.10
10+
app.kubernetes.io/version: 17.0.0
11+
helm.sh/chart: postgresql-16.0.5
1312
name: keycloak-postgresql-hl
1413
namespace: syn-builtin
1514
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/svc.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ metadata:
66
app.kubernetes.io/instance: keycloak
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: postgresql
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
1111
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
automountServiceAccountToken: false
3+
kind: ServiceAccount
4+
metadata:
5+
labels:
6+
app.kubernetes.io/instance: keycloak
7+
app.kubernetes.io/managed-by: Helm
8+
app.kubernetes.io/name: postgresql
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
12+
namespace: syn-builtin

tests/golden/external/external/external/01_keycloak_helmchart/postgresql/templates/primary/pdb.yaml

Whitespace-only changes.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
automountServiceAccountToken: false
3+
kind: ServiceAccount
4+
metadata:
5+
labels:
6+
app.kubernetes.io/instance: keycloak
7+
app.kubernetes.io/managed-by: Helm
8+
app.kubernetes.io/name: postgresql
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
12+
namespace: syn-external

tests/golden/openshift-postgres/openshift-postgres/openshift-postgres/01_keycloak_helmchart/postgresql/templates/primary/networkpolicy.yaml

+9-9
Original file line numberDiff line numberDiff line change
@@ -6,21 +6,21 @@ metadata:
66
app.kubernetes.io/instance: keycloak
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: postgresql
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
11-
name: keycloak-postgresql-ingress
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
1212
namespace: syn-openshift-postgres
1313
spec:
14+
egress:
15+
- {}
1416
ingress:
15-
- from:
16-
- podSelector:
17-
matchLabels:
18-
app.kubernetes.io/instance: keycloakx
19-
app.kubernetes.io/name: keycloakx
20-
ports:
17+
- ports:
2118
- port: 5432
2219
podSelector:
2320
matchLabels:
2421
app.kubernetes.io/component: primary
2522
app.kubernetes.io/instance: keycloak
2623
app.kubernetes.io/name: postgresql
24+
policyTypes:
25+
- Ingress
26+
- Egress
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
apiVersion: policy/v1
2+
kind: PodDisruptionBudget
3+
metadata:
4+
labels:
5+
app.kubernetes.io/component: primary
6+
app.kubernetes.io/instance: openshift-postgres
7+
app.kubernetes.io/managed-by: commodore
8+
app.kubernetes.io/name: keycloak
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
11+
name: keycloak-postgresql
12+
namespace: syn-openshift-postgres
13+
spec:
14+
maxUnavailable: 1
15+
selector:
16+
matchLabels:
17+
app.kubernetes.io/component: primary
18+
app.kubernetes.io/instance: keycloak
19+
app.kubernetes.io/name: postgresql

tests/golden/openshift-postgres/openshift-postgres/openshift-postgres/01_keycloak_helmchart/postgresql/templates/primary/statefulset.yaml

+43-11
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ metadata:
66
app.kubernetes.io/instance: openshift-postgres
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
9+
app.kubernetes.io/version: 17.0.0
10+
helm.sh/chart: postgresql-16.0.5
1111
name: keycloak-postgresql
1212
namespace: syn-openshift-postgres
1313
spec:
@@ -29,8 +29,8 @@ spec:
2929
app.kubernetes.io/instance: keycloak
3030
app.kubernetes.io/managed-by: Helm
3131
app.kubernetes.io/name: postgresql
32-
app.kubernetes.io/version: 15.4.0
33-
helm.sh/chart: postgresql-12.12.10
32+
app.kubernetes.io/version: 17.0.0
33+
helm.sh/chart: postgresql-16.0.5
3434
name: keycloak-postgresql
3535
spec:
3636
affinity:
@@ -46,6 +46,7 @@ spec:
4646
app.kubernetes.io/name: postgresql
4747
topologyKey: kubernetes.io/hostname
4848
weight: 1
49+
automountServiceAccountToken: false
4950
containers:
5051
- env:
5152
- name: BITNAMI_DEBUG
@@ -125,19 +126,35 @@ spec:
125126
successThreshold: 1
126127
timeoutSeconds: 5
127128
resources:
128-
limits: {}
129+
limits:
130+
cpu: 150m
131+
ephemeral-storage: 2Gi
132+
memory: 192Mi
129133
requests:
130-
cpu: 250m
131-
memory: 256Mi
134+
cpu: 100m
135+
ephemeral-storage: 50Mi
136+
memory: 128Mi
132137
securityContext:
133138
allowPrivilegeEscalation: false
134139
capabilities:
135140
drop:
136141
- ALL
142+
privileged: false
143+
readOnlyRootFilesystem: true
137144
runAsNonRoot: true
145+
seLinuxOptions: {}
138146
seccompProfile:
139147
type: RuntimeDefault
140148
volumeMounts:
149+
- mountPath: /tmp
150+
name: empty-dir
151+
subPath: tmp-dir
152+
- mountPath: /opt/bitnami/postgresql/conf
153+
name: empty-dir
154+
subPath: app-conf-dir
155+
- mountPath: /opt/bitnami/postgresql/tmp
156+
name: empty-dir
157+
subPath: app-tmp-dir
141158
- mountPath: /opt/bitnami/postgresql/certs
142159
name: postgresql-certificates
143160
readOnly: true
@@ -156,28 +173,43 @@ spec:
156173
imagePullPolicy: IfNotPresent
157174
name: copy-certs
158175
resources:
159-
limits: {}
176+
limits:
177+
cpu: 150m
178+
ephemeral-storage: 2Gi
179+
memory: 192Mi
160180
requests:
161-
cpu: 250m
162-
memory: 256Mi
181+
cpu: 100m
182+
ephemeral-storage: 50Mi
183+
memory: 128Mi
163184
securityContext:
164185
allowPrivilegeEscalation: false
165186
capabilities:
166187
drop:
167188
- ALL
189+
privileged: false
190+
readOnlyRootFilesystem: true
168191
runAsNonRoot: true
192+
seLinuxOptions: {}
169193
seccompProfile:
170194
type: RuntimeDefault
171195
volumeMounts:
196+
- mountPath: /tmp
197+
name: empty-dir
198+
subPath: tmp-dir
172199
- mountPath: /tmp/certs
173200
name: raw-certificates
174201
- mountPath: /opt/bitnami/postgresql/certs
175202
name: postgresql-certificates
176203
securityContext:
204+
fsGroupChangePolicy: Always
177205
seccompProfile:
178206
type: RuntimeDefault
179-
serviceAccountName: default
207+
supplementalGroups: []
208+
sysctls: []
209+
serviceAccountName: keycloak-postgresql
180210
volumes:
211+
- emptyDir: {}
212+
name: empty-dir
181213
- name: raw-certificates
182214
secret:
183215
secretName: keycloak-postgresql-tls

0 commit comments

Comments
 (0)