4d406c0223
scan.yaml / test (push) Successful in 11s
chore(deps): update dependency kubernetes-helm to v4 (#48)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [kubernetes-helm](https://github.com/helm/helm) | major | `3.20.2` → `4.2.4` |

---

### Release Notes

<details>
<summary>helm/helm (kubernetes-helm)</summary>

### [`v4.2.4`](https://github.com/helm/helm/releases/tag/v4.2.4): Helm v4.2.4

Helm v4.2.4 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom-lfx.platform.linuxfoundation.org/meeting/91295593969?password=17825db5-c698-44cc-9f00-ef1f61f5d3fb)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- fix: Improve error reporting for helm template --debug with --show-only- [#&#8203;31185](https://github.com/helm/helm/issues/31185) by [@&#8203;kyokuping](https://github.com/kyokuping)
- fix: fetch logs from all containers in test pods- [#&#8203;32099](https://github.com/helm/helm/issues/32099) by [@&#8203;SebTardif](https://github.com/SebTardif)
- fix(provenance): check error return in Digest and encodeRelease- [#&#8203;32136](https://github.com/helm/helm/issues/32136) by [@&#8203;SebTardif](https://github.com/SebTardif)
- fix panic on repeated IsReachable calls- [#&#8203;32184](https://github.com/helm/helm/issues/32184) by [@&#8203;atkrad](https://github.com/atkrad)
- fix: set \[pull,push] scope when helm push to a registry(use token auth) - v4- [#&#8203;31211](https://github.com/helm/helm/issues/31211) by [@&#8203;kimsungmin1](https://github.com/kimsungmin1)
- Fix missing conflict retry with server-side apply- [#&#8203;32088](https://github.com/helm/helm/issues/32088) by [@&#8203;Kajot-dev](https://github.com/Kajot-dev)
- Properly format the extra field in gzipped packages- [#&#8203;31884](https://github.com/helm/helm/issues/31884) by [@&#8203;ouillie](https://github.com/ouillie)
- Fix vanishing empty lines- [#&#8203;32327](https://github.com/helm/helm/issues/32327) by [@&#8203;matheuscscp](https://github.com/matheuscscp)
- fix: pass registry client to downloader.Manager in upgrade- [#&#8203;32400](https://github.com/helm/helm/issues/32400) by [@&#8203;SetagGnaw](https://github.com/SetagGnaw)
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1- for GO-2026-6061 [#&#8203;32450](https://github.com/helm/helm/issues/32450)
- fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158- [#&#8203;32521](https://github.com/helm/helm/issues/32521) by [@&#8203;TerryHowe](https://github.com/TerryHowe)

#### Installation and Upgrading

Download Helm v4.2.4. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.4-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-darwin-amd64.tar.gz.sha256sum) / 6c163d687ca03c3b5c01928e53bbbcf9518278f47ce7a2f249a5a08e8bdaa2bc)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.4-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-darwin-arm64.tar.gz.sha256sum) / d747eb4e28bd2727173d15b759fa0a17822291ec09db7ced3d55af290a3661a2)
- [Linux amd64](https://get.helm.sh/helm-v4.2.4-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-amd64.tar.gz.sha256sum) / c306b46f719b0a4da32d0f78ee21bf90ce8d602f15b22ab753f0674d1670a7f3)
- [Linux arm](https://get.helm.sh/helm-v4.2.4-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-arm.tar.gz.sha256sum) / 894e901f7daaf9b458baad7b5c685bfeef49070d7d53f99687bd5846a6c13639)
- [Linux arm64](https://get.helm.sh/helm-v4.2.4-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-arm64.tar.gz.sha256sum) / 564de2191b881e9f71b5606b25345821ea1682f06ab90499d3ab22b530176da1)
- [Linux i386](https://get.helm.sh/helm-v4.2.4-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-386.tar.gz.sha256sum) / 45297aeac0c65173a89e8de832997f952ba5115c2db09b2e3f2c23a601e70583)
- [Linux loong64](https://get.helm.sh/helm-v4.2.4-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-loong64.tar.gz.sha256sum) / faafbfecc1a06196e650c3ce0c74d5ac32cb1c0c0a855fa76e59dd100cb8d4c4)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.4-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-ppc64le.tar.gz.sha256sum) / 5c00073e9d493de201384bb7eb19d60615bd7c39db52148473e8ce6da84bc70a)
- [Linux s390x](https://get.helm.sh/helm-v4.2.4-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-s390x.tar.gz.sha256sum) / 5396a35fca5fa46e5614140363f389ce66f96886c1b25f256d9e3028299422fa)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.4-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-riscv64.tar.gz.sha256sum) / d8532a3524ca842887b15ab794377dc9c8ced8f26264c84171b4b0aafff05411)
- [Windows amd64](https://get.helm.sh/helm-v4.2.4-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.4-windows-amd64.zip.sha256sum) / e94d83a4706fd82078c98dade2079fa9d9680c1c2bfb93bfc304ee6bc2412a32)
- [Windows arm64](https://get.helm.sh/helm-v4.2.4-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.4-windows-arm64.zip.sha256sum) / dbe8b49ea9877abe3d77354a792efb01920da9f65a492fcb8b4fce4e08bbae8f)

This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- Minimal fix to build failure from [#&#8203;31211](https://github.com/helm/helm/issues/31211). [`3900f43`](https://github.com/helm/helm/commit/3900f434fd3ef2b84065dc04508df48f288dba00) (Scott Rigby)
- fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158 ([#&#8203;32521](https://github.com/helm/helm/issues/32521)) [`f7c6e8f`](https://github.com/helm/helm/commit/f7c6e8f0f1e0e649e8d03b1535db4f3b8d0c9af2) (Terry Howe)
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 [`035a2c3`](https://github.com/helm/helm/commit/035a2c38e9a75ca0988c8449c0b7257f30d04064) (dependabot\[bot])
- fix: pass registry client to downloader.Manager in upgrade [`f76a5f4`](https://github.com/helm/helm/commit/f76a5f46a952f731cc1543f348121297c8b3f6cc) (Gates Wang)
- Apply suggestions [`5a7c6c7`](https://github.com/helm/helm/commit/5a7c6c7c732b04ad6517b452d538da9e18993d67) (Will Noble)
- Properly format the extra field in gzipped packages [`2281848`](https://github.com/helm/helm/commit/22818486ce0fc18d92e01ba39faf65f70ffa8865) (Will Noble)
- Fix missing conflict retry with server-side apply ([#&#8203;32088](https://github.com/helm/helm/issues/32088)) [`2c979a1`](https://github.com/helm/helm/commit/2c979a17ac6b6d7bfe2d6650b69fa9effe963d4d) (Jakub Jaruszewski)
- Potential fix for pull request finding [`2bd2c66`](https://github.com/helm/helm/commit/2bd2c66544634e419ede3cfa18952cce5a5acd08) (kimsungmin1)
- fix(registry): resolve golangci-lint issues in token-auth tests [`183a540`](https://github.com/helm/helm/commit/183a5402291c553898b9c404bc17c95c81ea1c6c) (kimsm28)
- chore: go mod tidy after rebase on main [`08d8da1`](https://github.com/helm/helm/commit/08d8da1aa9080772e57ab5bf5b00b3c13364af00) (kimsm28)
- fix(registry): use plain-http registry in token-auth scope test [`9655b5a`](https://github.com/helm/helm/commit/9655b5aecc0d36142d0620ff5ed762065a997739) (kimsm28)
- Update pkg/registry/client.go [`430dfac`](https://github.com/helm/helm/commit/430dfac3eeab03886f511761e3969f738f760364) (Terry Howe)
- test: improve client\_scope\_test.go to avoid data races and brittle assertions [`9569605`](https://github.com/helm/helm/commit/9569605eccf8318fe25bf78c46c4eb462ce8fc3f) (kimsm28)
- fix typos in withScopeHint function comment [`63f2b68`](https://github.com/helm/helm/commit/63f2b6809919e5e8e3e04f52064a536a14f1ff9b) (kimsm28)
- fix registry test failures by adjusting DockerRegistryHost and auth server listener management [`f7488c0`](https://github.com/helm/helm/commit/f7488c0be8c65dd16386c215cac4332900667278) (kimsm28)
- fix variable naming requestUrl -> requestURL [`8fe78fb`](https://github.com/helm/helm/commit/8fe78fbe46eb2db5c75ab1cc89699c750017dca6) (kimsm28)
- fix typo, remove unnecessary code, fix to avoid to use the assertion in http hanlder [`d0670d2`](https://github.com/helm/helm/commit/d0670d2fb2c3426cde4b41927b5e9b8b4370df93) (kimsm28)
- change suite.Nil, suite.NotNill to more proper function(suite.NoError, suite.Error) [`804256e`](https://github.com/helm/helm/commit/804256ef659226f26b2222ccb8f9cf18ef1b1946) (kimsungmin1)
- change client\_scope\_test.go to use httptest [`d79bceb`](https://github.com/helm/helm/commit/d79bceb807692512461d8007040c41bcd1547041) (kimsungmin1)
- fix typo [`d34fcd9`](https://github.com/helm/helm/commit/d34fcd9264225a1e6296c4b0ee124dc69f3b3ecc) (kimsungmin1)
- remove freeport dependency [`9fbd190`](https://github.com/helm/helm/commit/9fbd190c30addb4786e4fe930a0fe98bf354116a) (kimsungmin1)
- add newline in license header [`9275661`](https://github.com/helm/helm/commit/9275661357afdfe12b8ce561e8103673f16cca8d) (kimsungmin1)
- fix scope when helm push to a registry that use token auth [`fef91f3`](https://github.com/helm/helm/commit/fef91f3e6942a20148542461eaebfb24f2c09584) (kimsungmin1)
- fix panic on repeated IsReachable calls [`e89ce68`](https://github.com/helm/helm/commit/e89ce68bc5fec430bc1e2f0aef1aca6a2e71f795) (Mohammad Abdolirad)
- fix(provenance): check error return in Digest [`ff1ac83`](https://github.com/helm/helm/commit/ff1ac83bfb1246cdf1b57a4db0042085cc8b265d) (Sebastien Tardif)
- fix: address review feedback [`4b4dedb`](https://github.com/helm/helm/commit/4b4dedb2bdcfac886c124a361a5126e3c5e3c5df) (Sebastien Tardif)
- fix: fetch logs from all containers in test pods [`7c80103`](https://github.com/helm/helm/commit/7c8010322b8639cdf7844ac1ae5f8d444db43935) (Sebastien Tardif)
- chore: rename savedErr to clear its specific purpose [`ecc9cd2`](https://github.com/helm/helm/commit/ecc9cd2f1b5b53dadcd12395c032bc5b3ca02937) (Jeaeun Kim)
- chore: fix lint [`f6211ba`](https://github.com/helm/helm/commit/f6211ba49bfbf5768ea44be3a1402869a4709b37) (Jeaeun Kim)
- chore: store err separately for clarity [`3507ea5`](https://github.com/helm/helm/commit/3507ea5bfdbad921684ac131896b6968c76e9ca6) (Jeaeun Kim)
- chore: Improve error reporting for `helm template --debug` with `--show-only` [`211ffae`](https://github.com/helm/helm/commit/211ffae93d2d741a2dbcd74b4aa2a1bc2fc27d5f) (Jeaeun Kim)
- Address review comments [`51a9837`](https://github.com/helm/helm/commit/51a9837ba177812c381515886c4f0cd0b7a633e6) (Matheus Pimenta)
- Fix vanishing empty lines [`83a8b70`](https://github.com/helm/helm/commit/83a8b70ffc1bcf97bb293cf6b35bd3b5093e8c30) (Matheus Pimenta)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.3...v4.2.4>

### [`v4.2.3`](https://github.com/helm/helm/releases/tag/v4.2.3): Helm v4.2.3

Helm v4.2.3 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Installation and Upgrading

Download Helm v4.2.3. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz.sha256sum) / ff3ac86755a45f3422473bc1200776aac0fe04c5766abe6ca66699f7b564b23b)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz.sha256sum) / 048ecf5ad3160f83d918f9fe945238d2132b079640f7b106175331c25f242c64)
- [Linux amd64](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz.sha256sum) / e9b88b4ee95b18c706839c28d3a0220e5bc470e9cd9262410c90793c45ff8b7c)
- [Linux arm](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz.sha256sum) / ba00678361ca7a03ec42ca1ea459543e1d8eab2a7d5429a5eda71dc9741c8a9b)
- [Linux arm64](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz.sha256sum) / 21abd9354d39b2cd79a8d76be6912cd137a983cbf997193503fb8a6a6e2f2785)
- [Linux i386](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz.sha256sum) / 31d57972d36e60388e173327fffcf9d58f272349dfa9ed3e1914f3cd88fe7283)
- [Linux loong64](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz.sha256sum) / 232f82d787d530a621b2006965ed2b99644b4391bbc6261e9787f95700fc44f7)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz.sha256sum) / 43fc5a4b20839c3669a0748498bd2613b095e288425bf5678c6ba664eb4a0e70)
- [Linux s390x](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz.sha256sum) / 17932091e19d352585b540a482fca9b953d32a8ad7afec72bf9cbbcd96b094cb)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz.sha256sum) / 09ff0772730678c652b9ac4a2b32cd20f4e62a2b040403bcacd4ad845d3d3e9c)
- [Windows amd64](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip.sha256sum) / 5ca7de684c92d48b93d5c34a029fdda57b38e1eac04bc8541bdf1eb249388679)
- [Windows arm64](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip.sha256sum) / 5f444ed097688ed3abaf1d8801e21110d9bddeb6ed13939afcac302888527ab5)

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.4 and 3.21.4 are the next patch releases scheduled for August 12, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 [`43e8b7f`](https://github.com/helm/helm/commit/43e8b7feece8beb0fcba47059ec9b522fd929a64) (Terry Howe)

### [`v4.2.2`](https://github.com/helm/helm/releases/tag/v4.2.2): Helm v4.2.2

Helm v4.2.2 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Revert: Fixed a race condition in WaitForDelete where the status observer canceled the watch too early, causing intermittent failures when running a full test suite [#&#8203;32214](https://github.com/helm/helm/issues/32214)

#### Installation and Upgrading

Download Helm v4.2.2. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.2-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-darwin-amd64.tar.gz.sha256sum) / 10c1e36ee8c5f2e2ee25a16599cb03ab74c0953cd889cacb980a49ba4b6574ba)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.2-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-darwin-arm64.tar.gz.sha256sum) / 5410a0dae3d5d91f45653b161260d9301aabc4ae80ae50a6605d66884b6df8ea)
- [Linux amd64](https://get.helm.sh/helm-v4.2.2-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-amd64.tar.gz.sha256sum) / 9adafecab4d406853bba163a70e9f104f47dbbf65ce24b7653bae7e36150bcb6)
- [Linux arm](https://get.helm.sh/helm-v4.2.2-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-arm.tar.gz.sha256sum) / 7e9490169874695e04ab1af47c5620621fc13c84219a258fcc1afdcd40ca7438)
- [Linux arm64](https://get.helm.sh/helm-v4.2.2-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-arm64.tar.gz.sha256sum) / 78803142087a0069fa4b50d3f32a84d3ef25c14d1ee8a40fbccf86a6216d2f36)
- [Linux i386](https://get.helm.sh/helm-v4.2.2-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-386.tar.gz.sha256sum) / 8e1fdcda4a476ffc5d1179c7f16d33a3d54267efa08fd720f7678277d68bc2d5)
- [Linux loong64](https://get.helm.sh/helm-v4.2.2-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-loong64.tar.gz.sha256sum) / b8bfe96b8b0b0e2af51af4a00ef521cc5a7e03793aea3568cf8500a63ae05041)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.2-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-ppc64le.tar.gz.sha256sum) / 814a80fd98eb9e4c5a9d610f3b9c15ffe120c2f5e39df16a2f491723ebc90126)
- [Linux s390x](https://get.helm.sh/helm-v4.2.2-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-s390x.tar.gz.sha256sum) / d84cdf1123f20cfbef19a2af1cd6afe8b00626bd9846bccb9dae978c810c8274)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.2-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-riscv64.tar.gz.sha256sum) / f07c105180dff2619ab45134b9b47b7845387e8f3299e12ebe0efb87c7548717)
- [Windows amd64](https://get.helm.sh/helm-v4.2.2-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.2-windows-amd64.zip.sha256sum) / 5fad8562e98c34fa5af3ef904086a5874a6701050f9bf36e30238c975df94dcd)
- [Windows arm64](https://get.helm.sh/helm-v4.2.2-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.2-windows-arm64.zip.sha256sum) / 2e993d6a1dd8197a33e65d8e90b26df9d248ff3501701dea401856aa265a2dab)

This release was signed by [@&#8203;gjenkins8](https://github.com/gjenkins8) with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at <https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739>. Please use the attached signatures for verifying this release using gpg.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.3 and 3.21.2 are the next patch releases scheduled for July 8, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- Revert "fix(kube): prevent spurious early exit in WaitForDelete during informer sync" [`b05881c`](https://github.com/helm/helm/commit/b05881cf967a5a09e19866799d0edfd40675803a) (George Jenkins)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.1...v4.2.2>

### [`v4.2.1`](https://github.com/helm/helm/releases/tag/v4.2.1): Helm v4.2.1

Helm v4.2.1 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Fixed data race detected by -race flag when concurrent goroutines (upgrade + rollback, install + uninstall) both call GetWaiterWithOptions on the same FailingKubeClient instance [#&#8203;31925](https://github.com/helm/helm/issues/31925)
- Fixed helm command success messages writing to stderr instead of stdout. Now correctly outputing to stdout [#&#8203;32056](https://github.com/helm/helm/issues/32056)
- Fixed Helm 4 emitting "unable to find exact version" when using version range constraints [#&#8203;31757](https://github.com/helm/helm/issues/31757)
- Fixed a race condition in WaitForDelete where the status observer canceled the watch too early, causing intermittent failures when running a full test suite [#&#8203;32081](https://github.com/helm/helm/issues/32081)
- Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 [#&#8203;32153](https://github.com/helm/helm/issues/32153)
- Fixed SDK errors by upgrading dependencies: cli-utils 1.2.1, controller-runtime 0.24.1 and k8s 1.36.1 [#&#8203;32128](https://github.com/helm/helm/issues/32128)
- Dependency updates

#### Installation and Upgrading

Download Helm v4.2.1. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.1-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-darwin-amd64.tar.gz.sha256sum) / 2a21c9f368d608bcf6eb794ebc06514eb6b529a846b60fe4a43dea7bcce65228)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.1-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-darwin-arm64.tar.gz.sha256sum) / 896472d2ec0740c60f64a9df0fc30d478beee38a1a2a6ed91aa6e6ee177c1575)
- [Linux amd64](https://get.helm.sh/helm-v4.2.1-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-amd64.tar.gz.sha256sum) / 479dca836e5b45e8bd222400c5591b0e3a647378f03ff96597180db97c17fdae)
- [Linux arm](https://get.helm.sh/helm-v4.2.1-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-arm.tar.gz.sha256sum) / 49e8f7856de6eab170dc09671cfb0578cc455d820df5b0f54e6453058dc0e3f3)
- [Linux arm64](https://get.helm.sh/helm-v4.2.1-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-arm64.tar.gz.sha256sum) / 596b9a73d366c1e72ce67d595c22805480e30914593aafbc9f547694e72814db)
- [Linux i386](https://get.helm.sh/helm-v4.2.1-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-386.tar.gz.sha256sum) / e038eab680f22b1cebe68fd0536cf2397b0c10798dcb23c28e500e0804ec1a55)
- [Linux loong64](https://get.helm.sh/helm-v4.2.1-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-loong64.tar.gz.sha256sum) / 8ae26f15638d951c4ed21d0d3018b8800a137646e5e5151a3856cf324c2852ae)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.1-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-ppc64le.tar.gz.sha256sum) / 6f34eca5e314e941577a07be6c8b356f66b9cdefbed1175da1e7916368febcfc)
- [Linux s390x](https://get.helm.sh/helm-v4.2.1-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-s390x.tar.gz.sha256sum) / e6355691887d4185b7e077f058483c04f353229feb7d4a72edc3ebe0b8738a6a)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.1-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-riscv64.tar.gz.sha256sum) / 16a4299f14ff1ffa79bb22115051911c662fa2ecdd90e85b65d7d143e8de9d02)
- [Windows amd64](https://get.helm.sh/helm-v4.2.1-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.1-windows-amd64.zip.sha256sum) / 6e7fa7839444b8ddc407c5bcdb1edd1024f57d09c2db971dec511ee2f2616eb0)
- [Windows arm64](https://get.helm.sh/helm-v4.2.1-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.1-windows-arm64.zip.sha256sum) / ae4c9acd0d9acd1f9e9da2f60105f793f65fd49ab7c03c6c7d13804c3b885657)

This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.2 and 3.21.2 are the next patch releases scheduled for July 8, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- fix: protect FailingKubeClient.RecordedWaitOptions from data race ([#&#8203;31925](https://github.com/helm/helm/issues/31925)) [`d591a19`](https://github.com/helm/helm/commit/d591a19b953bd9cfdf7d9ddd83c2f4ffdaeafb29) (Terry Howe)
- fix: route registry client output to stdout instead of stderr ([#&#8203;32056](https://github.com/helm/helm/issues/32056)) [`2a9fcae`](https://github.com/helm/helm/commit/2a9fcae29280472edec988c6bf0528e4ae79b33a) (Terry Howe)
- chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 [`ffa5bd6`](https://github.com/helm/helm/commit/ffa5bd693eee68ba9c1ba42d160c69114eda962c) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 [`9f9dbaf`](https://github.com/helm/helm/commit/9f9dbaf94008044a516cda4837565237306578a7) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 [`64a2891`](https://github.com/helm/helm/commit/64a2891699ae9c8f2d0e06d5db3dd117649886a2) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 [`e54a4a2`](https://github.com/helm/helm/commit/e54a4a2b7d4ed9ca3bb4be7562f76dd5f2fd8f71) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 [`acb762b`](https://github.com/helm/helm/commit/acb762b0ef8882b062ba8f6b87261411309875b8) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 [`768586d`](https://github.com/helm/helm/commit/768586df3f2a79fca5202b6713f8675bb097a904) (dependabot\[bot])
- fix(version): avoid false range detection on prerelease x/X [`eabfae5`](https://github.com/helm/helm/commit/eabfae560459d1ffe1f7a3268d5441238e9f84b2) (Benoit Tigeot)
- fix(version): version range || can has no space [`e3fd51f`](https://github.com/helm/helm/commit/e3fd51f331e14fb4056951540d2f2ffde81b405c) (Benoit Tigeot)
- feat: report in debug the version we select with version range arg [`1e47395`](https://github.com/helm/helm/commit/1e47395a9566bcaaaf7ed9e31a8367eb1f95e0a3) (Benoit Tigeot)
- fix: prevent warning when using version range constraints [`a33e239`](https://github.com/helm/helm/commit/a33e23939a85ac60eb9a6bee818f2c5459fda576) (Benoit Tigeot)
- fix(kube): always propagate context.Canceled in WaitForDelete [`fa06d44`](https://github.com/helm/helm/commit/fa06d4455724afe22bbe00af7925549a82d95e6c) (Terry Howe)
- fix(kube): prevent spurious early exit in WaitForDelete during informer sync [`360d483`](https://github.com/helm/helm/commit/360d4835df0fb8bd7cbde4cad0cbc79de01a6e93) (Terry Howe)
- chore(deps): bump github.com/tetratelabs/wazero from 1.11.0 to 1.12.0 [`7651edf`](https://github.com/helm/helm/commit/7651edf21e31b5c33df82e67f23855d1358d021d) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 [`b132e7e`](https://github.com/helm/helm/commit/b132e7e43f3620eb60ef3524527c1b2fceed90e9) (dependabot\[bot])
- fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026 [`eee491a`](https://github.com/helm/helm/commit/eee491a7461a524b87e5bb73ea5a0c4f82c72469) (Terry Howe)
- chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 [`3e3c575`](https://github.com/helm/helm/commit/3e3c5751b1723239cbce042533db0d84b65c6bc1) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 [`c4ce2bb`](https://github.com/helm/helm/commit/c4ce2bb364dbfb781059e628572d7177ba191cc4) (dependabot\[bot])
- chore(deps): bump actions/stale from 10.2.0 to 10.3.0 [`3892dc2`](https://github.com/helm/helm/commit/3892dc2a11b2e111acddcbc55d5a4733ba461f20) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.4 to 4.35.5 [`c4bbb62`](https://github.com/helm/helm/commit/c4bbb6263f59fe541acd75ce0b508034c65899e1) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 [`a0d7f16`](https://github.com/helm/helm/commit/a0d7f16b58aa4cb9dbaf8c37055faa28b1b350ae) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 [`8a3de05`](https://github.com/helm/helm/commit/8a3de054b5ab1b59f60c790fad39861e294671f1) (dependabot\[bot])
- fix(upstream): upgrade to cli-utils 1.2.1, controller-runtime 0.24.1 and k8s 1.36.1 [`57a4803`](https://github.com/helm/helm/commit/57a4803bd4953d8ef9d51d927f492ecaaf5df9db) (Matheus Pimenta)
- chore(deps): bump github.com/fluxcd/cli-utils from 1.2.0 to 1.2.1 [`b33ae02`](https://github.com/helm/helm/commit/b33ae02b9cd7fcba804391ab3d364739cb2a8780) (dependabot\[bot])

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.0...v4.2.1>

### [`v4.2.0`](https://github.com/helm/helm/releases/tag/v4.2.0): Helm v4.2.0

Helm v4.2.0 is a feature release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Switch to `goreleaser` for release builds
- Kubernetes client libraries to v1.36
- Add `mustToToml` template function
- deprecate unused `--hide-notes` and `--render-subchart-notes` flags
- `--dry-run=server` now respects `generateName:`

#### Installation and Upgrading

Download Helm v4.2.0. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.0-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-darwin-amd64.tar.gz.sha256sum) / 1376ea697140e4db316736e760d5a47d12afc1524dce704476ef06fd7fdeddc6)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.0-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-darwin-arm64.tar.gz.sha256sum) / f13f959015447b6bc309f9fd506509926543988a39035c088b52522ec95e2acb)
- [Linux amd64](https://get.helm.sh/helm-v4.2.0-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-amd64.tar.gz.sha256sum) / 97dbeb971be4ac4b27e3839976d9564c0fb35c6f3b1da89dd1e292d236af4096)
- [Linux arm](https://get.helm.sh/helm-v4.2.0-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-arm.tar.gz.sha256sum) / ae624870b2d50e655b6462daff117eb9d28c4bad45234ef24c1275113540fcb0)
- [Linux arm64](https://get.helm.sh/helm-v4.2.0-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-arm64.tar.gz.sha256sum) / 1f8de130dfbd04de64978e7b852a7a547be1404956a366608276d2520b678670)
- [Linux i386](https://get.helm.sh/helm-v4.2.0-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-386.tar.gz.sha256sum) / 9cf44acc59081aca98b4d9f09138348836b26761258e02ad2b99616f66eead5c)
- [Linux loong64](https://get.helm.sh/helm-v4.2.0-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-loong64.tar.gz.sha256sum) / 5b04f0167b8b415a057c1f4f809ede86d5ead840e0aa560db097da5be19f86d0)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.0-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-ppc64le.tar.gz.sha256sum) / 48f0637b93247717b725e8d4a8d2cf8df0e2fdea91bdd0e36e2426c2d5c76e4e)
- [Linux s390x](https://get.helm.sh/helm-v4.2.0-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-s390x.tar.gz.sha256sum) / 328e9ed27904f9910026240c4311bb1b0bf91c6fde1634f212097694507a702f)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.0-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-riscv64.tar.gz.sha256sum) / 5d292d57ab1f40e47e373a87187bafa66e8daac4ddc4a1333421c174e8184755)
- [Windows amd64](https://get.helm.sh/helm-v4.2.0-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.0-windows-amd64.zip.sha256sum) / 614f68ddc567ac9bfb0c205f869b1f83ba4e0a9aacd26cbae47743ae6082a579)
- [Windows arm64](https://get.helm.sh/helm-v4.2.0-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.0-windows-arm64.zip.sha256sum) / e740e4c19b6e2a0b428f7a52c38b7f0b092f0c43ac49870537d7e7fac9cedc07)

This release was signed by [@&#8203;gjenkins8](https://github.com/gjenkins8) with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at <https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739>. Please use the attached signatures for verifying this release using gpg.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.1 will contain only bug fixes
- 4.3.0 is the next feature release

#### Changelog

- Bump to version v4.2 [`0646808`](https://github.com/helm/helm/commit/06468084e85c244c712834933d25ea232a4c2093) (George Jenkins)
- build: Clean up Goreleaser change ([#&#8203;32098](https://github.com/helm/helm/issues/32098)) [`e23bf3a`](https://github.com/helm/helm/commit/e23bf3af53c52185123278e83b7023c102707778) (Scott Rigby)
- fix: add -extldflags -static to dist target to match build-cross [`f60ab7c`](https://github.com/helm/helm/commit/f60ab7c31c81a73b8e0aade5aff41bfc01c08820) (Terry Howe)
- build: use goreleaser build with manual archive creation [`64aa46f`](https://github.com/helm/helm/commit/64aa46f2f1cf239cf6535c5e847e14dcb933a847) (Terry Howe)
- chore: remove build-cross dependency from test-acceptance [`d199a1a`](https://github.com/helm/helm/commit/d199a1a42c04bccb287f2c7d9c3f73b669412e5a) (Terry Howe)
- ci: add fetch-depth 0 to canary checkout for goreleaser [`8289940`](https://github.com/helm/helm/commit/82899404a68f3826389bb38cf67bf75085db6b2c) (Terry Howe)
- fix: address goreleaser build issues flagged in review [`c075022`](https://github.com/helm/helm/commit/c075022ce16489f5f7afd45a37b679cf58fa36ea) (Terry Howe)
- fix: pass VERSION as GORELEASER\_CURRENT\_TAG to preserve v-prefix in archive names [`04885dd`](https://github.com/helm/helm/commit/04885dd905b6f8a823733dbc9b9f5cb2843a975f) (Terry Howe)
- fix: disable goreleaser checksums.txt and restrict zip to windows only [`93103ce`](https://github.com/helm/helm/commit/93103ce66cb6374d9d7b552802f53b21ea2c2dd1) (Terry Howe)
- fix: use index for optional env var in version\_template [`e49a1dc`](https://github.com/helm/helm/commit/e49a1dc16eee526928d8928b8d96c01ee513ebd9) (Terry Howe)
- fix: canary build file names [`eaa0910`](https://github.com/helm/helm/commit/eaa09100b9b18175d878b1e114cbe9df2a3f70c2) (Terry Howe)
- Fix archive name [`5a75279`](https://github.com/helm/helm/commit/5a75279c1a017a60b97bd44986288af7399c6ff8) (Terry Howe)
- fix goreleaser archive [`37284a9`](https://github.com/helm/helm/commit/37284a9211972f7f41a2acc3c3313517596dd4b0) (Terry Howe)
- add support for loong64 [`45336cc`](https://github.com/helm/helm/commit/45336ccd5b2621357e3f785c1fe93627c5990a6e) (Terry Howe)
- fix artifact directory [`a9659b0`](https://github.com/helm/helm/commit/a9659b07e3eec20ab5b964fddae05f51f478f704) (Terry Howe)
- update configuration to v2 [`e368f17`](https://github.com/helm/helm/commit/e368f170af8a200e672adac5f765b8101db0c8fa) (Terry Howe)
- remove GOTOOLCHAIN [`e7bea85`](https://github.com/helm/helm/commit/e7bea8513c30475664919f031774e18fecdf1f66) (Terry Howe)
- chore: replace mitchellh/gox with goreleaser [`075c096`](https://github.com/helm/helm/commit/075c096afec70155bc43ac3587a119df1ae5fcc6) (Terry Howe)
- chore(deps): bump github.com/distribution/distribution/v3 [`12f2c41`](https://github.com/helm/helm/commit/12f2c41c0d7a74739c58a5995cbbb3125d9247e5) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 [`58e8ffd`](https://github.com/helm/helm/commit/58e8ffdc3302260b1b55718c9b72c6f169a76ee0) (dependabot\[bot])
- chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 [`e61bbfb`](https://github.com/helm/helm/commit/e61bbfbfff41958b0ba1984e4d6799fe131f325e) (dependabot\[bot])
- Upgrade kstatus to 1.2 and controller-runtime to 0.24 [`081c6df`](https://github.com/helm/helm/commit/081c6dff537087f52ec6e470d8986439e24e8e33) (Matheus Pimenta)
- fix: adds topLevel permissions to improve openSSF scores [`277d970`](https://github.com/helm/helm/commit/277d9702555532d13426119d31c70fffb389d589) (Gagan H R)
- Upgrade Go to 1.26, Kubernetes to 1.36, kstatus to 1.1 [`a4a9cc7`](https://github.com/helm/helm/commit/a4a9cc7a314d98456a2f23798a78e9ad05d96d0c) (Matheus Pimenta)
- fix(templating): hooks conflicting with templates in post-renderers ([#&#8203;32049](https://github.com/helm/helm/issues/32049)) [`8f56f24`](https://github.com/helm/helm/commit/8f56f24d638612a46f3e23265d06338c1f93bccb) (Matheus Pimenta)
- docs: fix grammar and spacing in CONTRIBUTING.md [`db40adb`](https://github.com/helm/helm/commit/db40adb1d13573280b65bc2002df7d75c009235a) (Mohit)
- chore(deps): bump the k8s-io group with 7 updates [`775e794`](https://github.com/helm/helm/commit/775e794319639f5c1e6b40448ce15ad3cc10d4e1) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.1 to 4.35.2 [`934ace3`](https://github.com/helm/helm/commit/934ace35dfaef9eeb9997bf1ee385db0986daecc) (dependabot\[bot])
- fix(templating): SplitManifests must preserve line endings for downstream YAML parsers ([#&#8203;31952](https://github.com/helm/helm/issues/31952)) [`265c5eb`](https://github.com/helm/helm/commit/265c5eb530a36ec651e79ecf4d37ba2f098b7e59) (Matheus Pimenta)
- chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 [`48e2b7d`](https://github.com/helm/helm/commit/48e2b7ddd4e960b768fe5daee34a33cb89852a6e) (dependabot\[bot])
- Update pkg/chart/common/util/coalesce.go [`a8e2497`](https://github.com/helm/helm/commit/a8e249714f5311b9aff44c4bd2bfc433ab1ab952) (Evans Mungai)
- test(values): Add test for nil cleanup in partially overridden subchart maps [`52fc971`](https://github.com/helm/helm/commit/52fc971da37cf34aa26e7d7c460f2430dfb01b26) (Johannes Lohmer)
- fix(values): do not copy chart-default nils into coalesced values [`0063877`](https://github.com/helm/helm/commit/00638773d1366dc962c785de3d297cf0279b9a0d) (Johannes Lohmer)
- test(values): add test for subchart nil producing %!s(<nil>) [`6eb4ebf`](https://github.com/helm/helm/commit/6eb4ebf0e1afb0c63d748bf116145a5b9e0842b7) (Johannes Lohmer)
- test(values): add tests for subchart nil value regressions [`5cb4e7d`](https://github.com/helm/helm/commit/5cb4e7d992d85d372f5d86c238330102d936bfe5) (Johannes Lohmer)
- chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 [`b5c7c80`](https://github.com/helm/helm/commit/b5c7c80de317643e383ca2926ebc0ad884021bba) (dependabot\[bot])
- fix(templating): fix wrong YAML separator parsing for post-renderers ([#&#8203;31941](https://github.com/helm/helm/issues/31941)) [`a27f1ad`](https://github.com/helm/helm/commit/a27f1add79c6c02459413dbb60f8438d8051cf06) (Matheus Pimenta)
- fix: add debug logging to HTTP getter for helm pull [`c26be60`](https://github.com/helm/helm/commit/c26be60d81e5cb6a147d6088477cf86fd5aaf1f0) (Cairon)
- chore(deps): bump golang.org/x/crypto from 0.49.0 to 0.50.0 [`953f5f0`](https://github.com/helm/helm/commit/953f5f031bb7fa8f3eccdea6520e09fd44fe3923) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 [`10fc5f3`](https://github.com/helm/helm/commit/10fc5f335b5fbb09f5d04cb0450839790ae15634) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.35.0 to 0.36.0 [`d89e7c6`](https://github.com/helm/helm/commit/d89e7c60762910204044c4215c7bb2f43ac3ef8f) (dependabot\[bot])
- chore: Update release notes script for Helm v4 [`8a95461`](https://github.com/helm/helm/commit/8a954619255a82890a08b7d1fa9e86a437c4cebb) (George Jenkins)
- refactor(cli): share RetryingRoundTripper via pkg/kubeenv [`213c869`](https://github.com/helm/helm/commit/213c869a988f2c7390c65673e3d677970d6220fd) (Sumit Solanki)
- chore(deps): bump github.com/lib/pq from 1.12.2 to 1.12.3 [`bd5027a`](https://github.com/helm/helm/commit/bd5027a9cf07993d7bfe4b60702b1a489fe8783e) (dependabot\[bot])
- fix: unnecessary-format lint issues from merge [`087736b`](https://github.com/helm/helm/commit/087736b66e97393ccaa0bdf1e5df13dcc9d88340) (George Jenkins)
- fix: Plugin missing provenance bypass [`586eb57`](https://github.com/helm/helm/commit/586eb57338d848e65686a3a9616e2776e87cfd1e) (George Jenkins)
- chore(deps): bump github.com/fluxcd/cli-utils [`c8c5dfa`](https://github.com/helm/helm/commit/c8c5dfad630cd7b238236c619c466488a547725c) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp [`998466c`](https://github.com/helm/helm/commit/998466cfcfee189ce7e3df5be8ffe79ed5f1f097) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp [`b0cec58`](https://github.com/helm/helm/commit/b0cec589f50a7e16d942ad3385598a6dda2b0a20) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp [`6ebfb29`](https://github.com/helm/helm/commit/6ebfb29dbf006ce78e9af8878008bda3578dcd3e) (dependabot\[bot])
- test(kube): fix flaky WaitForDelete test by avoiding informer sync race [`a7f8443`](https://github.com/helm/helm/commit/a7f84439aacd3864b40055b60a3c3e54292d1646) (Terry Howe)
- test(kube): fix flaky WaitForDelete timing in status wait tests [`4c0d21f`](https://github.com/helm/helm/commit/4c0d21f53f2ca78b525e31dbbf9cc9cfb818a2e3) (Terry Howe)
- chore(deps): bump github.com/distribution/distribution/v3 [`08dea9c`](https://github.com/helm/helm/commit/08dea9c140084b5d9fecb59a45a05f417415b591) (dependabot\[bot])
- Minor nit: fix import instructions to comply with canonical import paths [`de58531`](https://github.com/helm/helm/commit/de58531ca7ff557342acaa2c906082e58521ef47) (Anmol Virdi)
- chore(deps): bump github.com/distribution/distribution/v3 [`9b1ad4c`](https://github.com/helm/helm/commit/9b1ad4cf027452b828affb07318db2e931e734a5) (dependabot\[bot])
- fix(action): return correct error variable in prepareUpgrade [`8ef2d45`](https://github.com/helm/helm/commit/8ef2d45934ba1b9ca341818f1157112fcf7cdf1d) (Rhys McNeill)
- chore(deps): bump github.com/lib/pq from 1.12.1 to 1.12.2 [`cd7cf76`](https://github.com/helm/helm/commit/cd7cf76a174e856fd171b391995d9a65f97a79d3) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.30.7 to 4.35.1 [`45ee55b`](https://github.com/helm/helm/commit/45ee55b83f8ad23798c84560ff65686e2ab298af) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.12.0 to 1.12.1 [`9a06741`](https://github.com/helm/helm/commit/9a0674188412d1dcb2e7f018730aaa71781bd03b) (dependabot\[bot])
- chore(deps): bump actions/setup-go from 6.2.0 to 6.4.0 [`d1e31ca`](https://github.com/helm/helm/commit/d1e31ca507412d770a602e722060e6d7379f4f1a) (dependabot\[bot])
- fix(kube): clarify server-side apply patch errors [`f257c95`](https://github.com/helm/helm/commit/f257c95c783f5595e36cb5a7dcc862cc1f6266b5) (abhay1999)
- fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow [`7025480`](https://github.com/helm/helm/commit/7025480397d8b6b7fd8cdb5e083dc37b62dbd3d8) (Terry Howe)
- refactor(cli): decouple EnvSettings from pkg/kube [`64f1d0a`](https://github.com/helm/helm/commit/64f1d0af5b53f0a9292af2ba1efc42a46a57ed00) (Sumit Solanki)
- docs(registry): fix incorrect and improve clarity of comments in client.go [`85bf56e`](https://github.com/helm/helm/commit/85bf56ea82fd21452e53cae91b380b0afb3e8b83) (Debasish Mohanty)
- refactor(cli): decouple EnvSettings from pkg/kube to avoid import cycles [`1549937`](https://github.com/helm/helm/commit/154993723aadf45601d124c6750e8f4ae3b9f2fd) (Sumit Solanki)
- chore(deps): bump github.com/ProtonMail/go-crypto from 1.3.0 to 1.4.1 [`c7a75b1`](https://github.com/helm/helm/commit/c7a75b16cb8b0859bf32bf74ae98300e5b55361b) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.0 [`3a7573a`](https://github.com/helm/helm/commit/3a7573a81ed5be2e00dfb74fa8d95c0cbe1c4f0d) (dependabot\[bot])
- chore(deps): bump github.com/fatih/color from 1.18.0 to 1.19.0 [`0229da1`](https://github.com/helm/helm/commit/0229da1803a29671b1becc4561c77f85db609aac) (dependabot\[bot])
- docs(engine): fix misleading toTOML doc comment [`c1a5a6e`](https://github.com/helm/helm/commit/c1a5a6e260bd070bce9a8299795400340e10c468) (Ilya Kiselev)
- feat(engine): add mustToToml template function [`b075f7a`](https://github.com/helm/helm/commit/b075f7a35d25ec0a4414b011142744f8f1821b47) (Ilya Kiselev)
- chore: fix unnecessary-format issues from revive [`7edfff3`](https://github.com/helm/helm/commit/7edfff33ebcb0f5d961afec34393c222de92de12) (Matthieu MOREL)
- chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 [`37185d2`](https://github.com/helm/helm/commit/37185d2ea6a091b93d2e71cc55ab16b2c0f3f9e9) (dependabot\[bot])
- chore: fix bool-compare issues from testifylint [`071558d`](https://github.com/helm/helm/commit/071558d69ffbb408dcb56403d387a1aa90a7d3a8) (Matthieu MOREL)
- chore: enable perfsprint linter [`6249489`](https://github.com/helm/helm/commit/62494896e9a105b63df2c76c638c53304a37121e) (Matthieu MOREL)
- ignore error plugin loads (cli, getter) [`47a0840`](https://github.com/helm/helm/commit/47a084091eeb1c5de221e061866b319f5b5f99f5) (George Jenkins)
- chore(deps): bump golang.org/x/crypto from 0.48.0 to 0.49.0 [`3d06fd1`](https://github.com/helm/helm/commit/3d06fd1feb37f11d050e78f7c17df3c713fcd344) (dependabot\[bot])
- fix(kube): remove legacy import comments from test files [`e64d628`](https://github.com/helm/helm/commit/e64d628a139fab8c876a1d2f4c2928096b286bed) (Terry Howe)
- pkg/kube: remove legacy import comments [`d7cdc9e`](https://github.com/helm/helm/commit/d7cdc9e8fb20c42d19a2371f37ee719be6be6b94) (abhay1999)
- fix: Plugin version path traversal [`36dcc27`](https://github.com/helm/helm/commit/36dcc27ca3c0cd6d0d08713b03dca82f43d7c5f9) (George Jenkins)
- chore(deps): bump golang.org/x/term from 0.40.0 to 0.41.0 [`c4be7af`](https://github.com/helm/helm/commit/c4be7af2a14c1a01f21231ebb5dd41806fcb0797) (dependabot\[bot])
- chore: fix some minor issues in the comments [`259f181`](https://github.com/helm/helm/commit/259f181808f267493d56eccd7f6191f78225a6fa) (tsinglua)
- fix: Chart dot-name path bug [`6018499`](https://github.com/helm/helm/commit/60184996e5332d26e0b6390cefbf86776829dc46) (George Jenkins)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.23.1 to 0.23.3 [`74e7cf8`](https://github.com/helm/helm/commit/74e7cf877a4a674b65f7b7894d2dfde2832e39b1) (dependabot\[bot])
- fix: insert newline after doc separators glued to content by template trimming [`af94abf`](https://github.com/helm/helm/commit/af94abf976ce69dd635aaf086a0bb4b17bd95bc1) (Matheus Pimenta)
- chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 [`16073b1`](https://github.com/helm/helm/commit/16073b1e3c7b90cda41ed70c8192eb6d16816723) (dependabot\[bot])
- chore: enable modernize linter ([#&#8203;31860](https://github.com/helm/helm/issues/31860)) [`e31a078`](https://github.com/helm/helm/commit/e31a078e6e0667dde72ff3bf4b5dfb625127076f) (Matthieu MOREL)
- Restored --atomic flag on install command [`16573f8`](https://github.com/helm/helm/commit/16573f87f5aebf8c2f9c40e67cc3cbe5eb93e733) (Travis Leeden)
- fix: bump go.opentelemetry.io/otel/sdk to v1.40.0 for GO-2026-4394 [`b550ce9`](https://github.com/helm/helm/commit/b550ce90946b3b47cecd290fc5d0eee637ddb531) (Terry Howe)
- fix: bump fluxcd/cli-utils to v0.37.2-flux.1 [`1dfa77e`](https://github.com/helm/helm/commit/1dfa77ed8ba6f9e26542064248bc9eab40c1a662) (Terry Howe)
- Update pkg/cmd/status.go [`5d40f17`](https://github.com/helm/helm/commit/5d40f17011a477620841edb740d381a012716ae8) (Matthieu MOREL)
- chore(internal): enable perfsprint linter ([#&#8203;31871](https://github.com/helm/helm/issues/31871)) [`d4f6193`](https://github.com/helm/helm/commit/d4f6193a7ec7ae9ea479da3372eeaf22b445ebcc) (Matthieu MOREL)
- chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 [`82d9bed`](https://github.com/helm/helm/commit/82d9bedea7d3e342011d82e2e11ff83b396dffbe) (dependabot\[bot])
- chore(pkg): fix perfsprint linter issues part 6 [`dc0e3f1`](https://github.com/helm/helm/commit/dc0e3f10c3ba8f25aa71c523d2e273690d338a17) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`e3c74fd`](https://github.com/helm/helm/commit/e3c74fd9fae52c85899ee0ca9a0c1422d59e2bc2) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`1d2d63c`](https://github.com/helm/helm/commit/1d2d63cc4330fcac786e70926f805b69c0b49ca2) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`63f03c0`](https://github.com/helm/helm/commit/63f03c0f5c41b53de3d432b446da9430da99f5bd) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`c25c988`](https://github.com/helm/helm/commit/c25c988cfb7bbe3b139dec39cad1db4be33b13c6) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`0fecfd0`](https://github.com/helm/helm/commit/0fecfd04c2f9a748046a8421595f3b9da6c895c7) (Matthieu MOREL)
- chore(internal): enable perfsprint linter [`6524162`](https://github.com/helm/helm/commit/6524162a0e39bed187a16b692243703d78735471) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`6c2cb2f`](https://github.com/helm/helm/commit/6c2cb2f54784b5ef6158dca0660f428a3baf75f5) (Matthieu MOREL)
- chore(internal): enable perfsprint linter [`9409226`](https://github.com/helm/helm/commit/9409226e15b26d05621f0b263f4ad6f597dfb7aa) (Matthieu MOREL)
- Replace unneeded use of t.Fatalf with t.Fatal [`36cb3a2`](https://github.com/helm/helm/commit/36cb3a2fe92a4564d2d7d79141f209af19b45d40) (Mads Jensen)
- fix: enable nolinlint linter [`5b6c6bb`](https://github.com/helm/helm/commit/5b6c6bbfc7ca9850c69d3823ca1e21b445e75c0d) (Matthieu MOREL)
- fixup `strings.Cut` variables [`b667317`](https://github.com/helm/helm/commit/b6673174220a2633fe97b5cd70a8386b79103464) (George Jenkins)
- chore: Improve `AGENTS.md` [`956c724`](https://github.com/helm/helm/commit/956c7245c346fc304c24ace930dada5f2c99f2b1) (George Jenkins)
- chore:  fixes [`92b64e8`](https://github.com/helm/helm/commit/92b64e87ad6245d64d5b49bbbbf8dead83faac22) (George Jenkins)
- fix: correct import comment in statuswait.go from v3 to v4 [`c59c140`](https://github.com/helm/helm/commit/c59c140ce07ce973f16fe50c0c5e991e1d6308a6) (rohansood10)
- fix: handle OCI digest algorithm prefix in chart downloader ([#&#8203;31601](https://github.com/helm/helm/issues/31601)) [`ee01860`](https://github.com/helm/helm/commit/ee018608f6fbf381fac1bae9759164a65c6a0b1f) (Evans Mungai)
- chore(deps): bump actions/stale from 10.1.1 to 10.2.0 [`304d25f`](https://github.com/helm/helm/commit/304d25ffd34fafccbcb81713cb3cfff1be595ae5) (dependabot\[bot])
- chore(deps): bump the k8s-io group with 7 updates [`0b13436`](https://github.com/helm/helm/commit/0b134362f442fec44ace35e9cfae6760a6b4e005) (dependabot\[bot])
- feat(release): add internal/release/v2 package for chart v3 support ([#&#8203;31709](https://github.com/helm/helm/issues/31709)) [`4a91f3a`](https://github.com/helm/helm/commit/4a91f3ad5cc0c1521f6d4dcb5681e2da4baaa157) (Evans Mungai)
- chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 [`7823853`](https://github.com/helm/helm/commit/782385397ce1871f4c8a4d2e3c857937bd8988c9) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 [`aec7ace`](https://github.com/helm/helm/commit/aec7aced38d053a2df5d0973abdf21848778a722) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 [`a23b638`](https://github.com/helm/helm/commit/a23b6388ac74984460fd4055de5120d2fc03d841) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 [`5cddc95`](https://github.com/helm/helm/commit/5cddc95bed0572b8d63a910843f0a70477a4ce33) (dependabot\[bot])
- chore(deps): bump sigs.k8s.io/kustomize/kyaml from 0.21.0 to 0.21.1 [`2e266c3`](https://github.com/helm/helm/commit/2e266c3ec9d70a6e656f8041bb31475e25e9eb22) (dependabot\[bot])
- fix(pkg): errorlint linter [`259f76a`](https://github.com/helm/helm/commit/259f76a849391e6ff60a9a2e95ce7310d958c602) (Matthieu MOREL)
- fix(internal): errorlint linter [`0254182`](https://github.com/helm/helm/commit/025418291a7911441e7962895ba4bc24b72b55b3) (Matthieu MOREL)
- fix(pkg): errorlint linter [`6d1490e`](https://github.com/helm/helm/commit/6d1490ed1ea5968235087658d03bb440e4014a36) (Matthieu MOREL)
- fix(pkg): errorlint linter [`4d0ae7f`](https://github.com/helm/helm/commit/4d0ae7f33a09093f8f52d02b952e3822c87b8c5f) (Matthieu MOREL)
- fix(internal): errorlint linter [`abecafa`](https://github.com/helm/helm/commit/abecafa0f507a69888877b9ddb714095714b64c8) (Matthieu MOREL)
- fix(pkg): errorlint linter [`4330bde`](https://github.com/helm/helm/commit/4330bdea0409f428e75145f15532bfa0e2bc945c) (Matthieu MOREL)
- fix(pkg): errorlint linter [`c8989d9`](https://github.com/helm/helm/commit/c8989d984ff69e8ad21b27d6ac6193dd3150b1a7) (Matthieu MOREL)
- fix(cmd): errorlint linter [`edbd705`](https://github.com/helm/helm/commit/edbd705bd034246700cc0998016caa303cff42dc) (Matthieu MOREL)
- chore: new KEYS entry for George Jenkins [`5638c35`](https://github.com/helm/helm/commit/5638c35399464b6432ba81b92a341218991efa5c) (George Jenkins)
- fix(downloader): safely handle concurrent file writes on Windows [`76eb37c`](https://github.com/helm/helm/commit/76eb37c01aaece271343039f44d7803017dd5c81) (Orgad Shaneh)
- fix(install): check nil for restClientGetter and fix tests [`9817a68`](https://github.com/helm/helm/commit/9817a68618245370e98e09d7f06c7cc1cefe8a62) (Manuel Alonso)
- feat(create): add --chart-api-version flag (when HELM\_EXPERIMENTAL\_CHART\_V3 env var is set) ([#&#8203;31592](https://github.com/helm/helm/issues/31592)) [`5aac320`](https://github.com/helm/helm/commit/5aac32077f87ed8cd80da1648abbd323320d4a0b) (Evans Mungai)
- chore(pkg): fix modernize linter [`0d75d86`](https://github.com/helm/helm/commit/0d75d8611d3daa6b820d94fc95347a069b062f72) (Matthieu MOREL)
- chore(internal): fix modernize linter [`859292e`](https://github.com/helm/helm/commit/859292e31bd4ceb170050eaa49e727bcd69572e2) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`5cc2e55`](https://github.com/helm/helm/commit/5cc2e55714d20e6d1bd2663878a00571c084d6c2) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`ba38159`](https://github.com/helm/helm/commit/ba38159313d4f09280591ba7f860ef0523716220) (Matthieu MOREL)
- chore(internal): fix modernize linter [`e2d184c`](https://github.com/helm/helm/commit/e2d184c79e9049c19bcc466bfe1289ccc6b73717) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`111d4e6`](https://github.com/helm/helm/commit/111d4e6e0e86af6ba25a355be1a7599f5258ee58) (Matthieu MOREL)
- add image index test [`e8f386b`](https://github.com/helm/helm/commit/e8f386b5aac232c114a036598c2e3015fe296edc) (Pedro Tôrres)
- fix pulling charts from OCI indices [`d983696`](https://github.com/helm/helm/commit/d983696e354a9e0605cbb3034937dc84af42995c) (Pedro Tôrres)
- chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 [`9c9c3a6`](https://github.com/helm/helm/commit/9c9c3a6b5c0f1cd1e4c4e9f002aa411c58dd656a) (dependabot\[bot])
- Revert "Consider GroupVersionKind when matching resources" [`787b61c`](https://github.com/helm/helm/commit/787b61cedb933d22011e1da1368d0e615ea60ffe) (Matheus Pimenta)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.23.0 to 0.23.1 [`becf9bf`](https://github.com/helm/helm/commit/becf9bf7e33867a3f26affac34e9d51e277767bf) (dependabot\[bot])
- fix(template): deprecate unused --hide-notes and --render-subchart-notes flags [`6d5f56f`](https://github.com/helm/helm/commit/6d5f56fa6e7c8e4462d80895fcce87b926e4b8ce) (Scott Rigby)
- chore(deps): bump github.com/fluxcd/cli-utils [`b53198e`](https://github.com/helm/helm/commit/b53198e7eee04dab651c15cb7b3b6b77dd92553c) (dependabot\[bot])
- chore(deps): bump actions/checkout from 6.0.1 to 6.0.2 [`b59e533`](https://github.com/helm/helm/commit/b59e533b7675122631e0733adbfd6b35dd3515a6) (dependabot\[bot])
- whitespace [`ec07265`](https://github.com/helm/helm/commit/ec0726523e52448eb05c8b5b3faae969e3a79266) (Austin Abro)
- fix(copystructure): handle nil elements in slice copying [`e3829eb`](https://github.com/helm/helm/commit/e3829ebbbb833e159926c6193e474eb9d067ef75) (Philipp Born)
- use logger with waiter [`63b40a7`](https://github.com/helm/helm/commit/63b40a7a5e0d3f00ef2b4c1de9f50fb7d6df4ead) (Austin Abro)
- feat(kstatus): fine-grained context options for waiting [`b0b35f1`](https://github.com/helm/helm/commit/b0b35f1231b0b885b1624c5586938cfa69d30995) (Matheus Pimenta)
- Apply suggestions from code review [`26e28e8`](https://github.com/helm/helm/commit/26e28e846af1ceaf63e16c4f2e52bbfbab411ba1) (George Jenkins)
- Remove legacy sync-repo.sh script [`97fd007`](https://github.com/helm/helm/commit/97fd00786f16ebc3b68164bff7133592f19f70b6) (Jeevan Yewale)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.22.4 to 0.23.0 [`5262007`](https://github.com/helm/helm/commit/52620076e21ad6afd0f48df6772001b1466c966b) (dependabot\[bot])
- docs: document uninstall using cascade foreground flag [`e70d59d`](https://github.com/helm/helm/commit/e70d59de7cd7ea2a501d809b3245ebfa0412e0ec) (Evans Mungai)
- bugfix(kstatus): do not wait forever on failed resources [`bbec77c`](https://github.com/helm/helm/commit/bbec77c1f762c4d92678e7f455951757a2e036a3) (Matheus Pimenta)
- Modernize Helm v3 CONTRIBUTING.md [`443a2a6`](https://github.com/helm/helm/commit/443a2a6924fc384e87ff4251e5ac9c077d607f0f) (George Jenkins)
- chore(defaults): server-side apply SDK defaults should always match the CLI defaults [`c1cc625`](https://github.com/helm/helm/commit/c1cc6253232d697ad2ae29957cc49de223306b62) (Matheus Pimenta)
- chore: clarify --wait flag help text [`828038a`](https://github.com/helm/helm/commit/828038a8fe2142599ec557da2d12bb88b76fa0dd) (Evans Mungai)
- chore(deps): bump actions/setup-go from 6.1.0 to 6.2.0 [`e223771`](https://github.com/helm/helm/commit/e22377124dbca4b032c55f522358def0415a0e8a) (dependabot\[bot])
- chore(refactor): better testing and functionality for installing crd [`6501ef4`](https://github.com/helm/helm/commit/6501ef490a45e9b7edfed1432702532c5b11c6d2) (Manuel Alonso)
- bugfix(storage): fix storage not getting logger from driver [`a8eb527`](https://github.com/helm/helm/commit/a8eb5278478c940c615741312ca9f4fec0d84c1a) (Matheus Pimenta)
- chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 [`da1d68a`](https://github.com/helm/helm/commit/da1d68adea91ab13b308c059c39381d48045a73a) (dependabot\[bot])
- fix(test): fix tests and check nil for restclient [`0f949a9`](https://github.com/helm/helm/commit/0f949a92c149cf11e5bb19caf4d19d05567be6eb) (Manuel Alonso)
- fix(test): merge fix correctly [`561410a`](https://github.com/helm/helm/commit/561410ae1d09c2aa289ff8d8cad5b7fa979cd135) (Manuel Alonso Gonzalez)
- Remove refactorring changes from coalesce\_test.go [`0298b2f`](https://github.com/helm/helm/commit/0298b2ffd0823eead74c75e1b890b0bf47d0db62) (Evans Mungai)
- Fix import [`b8937ad`](https://github.com/helm/helm/commit/b8937ad1922bca47be8bbf8e6274608ebc34a778) (Evans Mungai)
- Update pkg/chart/common/util/coalesce\_test.go [`a333bba`](https://github.com/helm/helm/commit/a333bbaf273645bf53fb873228040ca8edde849a) (Evans Mungai)
- Fix rollback for missing resources [`374aeb4`](https://github.com/helm/helm/commit/374aeb4b4e0463f72e3a0175138ed4bf7e87a156) (Feruzjon Muyassarov)
- fix(install): add more tests and check nil file data [`00f0a48`](https://github.com/helm/helm/commit/00f0a48a7dae379c2b6bd0dea43984d42b27a494) (Manuel Alonso)
- fix(test): no check empty resources [`0357e8d`](https://github.com/helm/helm/commit/0357e8d0f7eab074252ca49e1ca3aded834a001d) (Manuel Alonso)
- fix(install): check lenght and file nil, add tests [`52235cc`](https://github.com/helm/helm/commit/52235cc0bf7d0c8faf17c7dc8cddd77f93434aea) (Manuel Alonso)
- fix(action): crd resources can be empty [`268593b`](https://github.com/helm/helm/commit/268593bf2e9769ef4b75328b33dfb4195e6e9e5a) (Manuel Alonso)
- fix: casing issue fixed [`1709114`](https://github.com/helm/helm/commit/170911459bc4f2b5efea7e549e09bd45c7578cc4) (Mujib Ahasan)
- fix: error handled correctly [`9486062`](https://github.com/helm/helm/commit/94860626ce9c83a9227b5bce02a5c03a050816ac) (Mujib Ahasan)
- fix: doc string added [`12e8b71`](https://github.com/helm/helm/commit/12e8b715aa0732b613c3a9896fa6af29b3201536) (Mujib Ahasan)
- Fix lint warning [`3416dd5`](https://github.com/helm/helm/commit/3416dd5f215a6421a70c6ab22340a96312ce8c0b) (Evans Mungai)
- Preserve nil values in chart already [`679f051`](https://github.com/helm/helm/commit/679f0519804afeaa5ce8b930a30976ade2860fe0) (Evans Mungai)
- fix(values): preserve nil values when chart default is empty map [`292fe70`](https://github.com/helm/helm/commit/292fe702193e8ba9ce4c8ffffdd90cdfa761501c) (Evans Mungai)
- update: test coverage added for helper function validateNameAndGenerateName [`1154099`](https://github.com/helm/helm/commit/115409976b5c3fd94c893eabde114e655c01c573) (Mujib Ahasan)
- update: helper function added for the business logic [`522d2fe`](https://github.com/helm/helm/commit/522d2fe61508639cfe8f06a43235e7c3eaea3b9a) (Mujib Ahasan)
- generateName is also considered in logic [`6769fb6`](https://github.com/helm/helm/commit/6769fb6fb6704e29fe1215c802ecf0ea62b39715) (Mujib Ahasan)
- fxi: test concurrency download index [`64bae71`](https://github.com/helm/helm/commit/64bae717c58e80f05a60b84ddcd1f78387b4caee) (Terry Howe)
- update: business logic respected for skipping object missing name [`b357bca`](https://github.com/helm/helm/commit/b357bcae8640508f110b7e63a8dfacd865c27b6e) (Mujib Ahasan)
- fixed: --dry-run=server now respect generateName [`2820ebe`](https://github.com/helm/helm/commit/2820ebe8c97b7d7b8a447375b74c9cb3741a4ffa) (Mujib Ahasan)
- Make error message instructional for the case of lock file being out of date [`1836c59`](https://github.com/helm/helm/commit/1836c598f06377fd1571702fb2e0642f004cedef) (Andreas Sommer)

#### New Contributors

- [@&#8203;JeevanYewale](https://github.com/JeevanYewale) made their first contribution in [#&#8203;31742](https://github.com/helm/helm/pull/31742)
- [@&#8203;tamcore](https://github.com/tamcore) made their first contribution in [#&#8203;31751](https://github.com/helm/helm/pull/31751)
- [@&#8203;orgads](https://github.com/orgads) made their first contribution in [#&#8203;31128](https://github.com/helm/helm/pull/31128)
- [@&#8203;manute](https://github.com/manute) made their first contribution in [#&#8203;31578](https://github.com/helm/helm/pull/31578)
- [@&#8203;Mujib-Ahasan](https://github.com/Mujib-Ahasan) made their first contribution in [#&#8203;31563](https://github.com/helm/helm/pull/31563)
- [@&#8203;rohansood10](https://github.com/rohansood10) made their first contribution in [#&#8203;31852](https://github.com/helm/helm/pull/31852)
- [@&#8203;tleed5](https://github.com/tleed5) made their first contribution in [#&#8203;31901](https://github.com/helm/helm/pull/31901)
- [@&#8203;tsinglua](https://github.com/tsinglua) made their first contribution in [#&#8203;31921](https://github.com/helm/helm/pull/31921)
- [@&#8203;abhay1999](https://github.com/abhay1999) made their first contribution in [#&#8203;31931](https://github.com/helm/helm/pull/31931)
- [@&#8203;Mentigen](https://github.com/Mentigen) made their first contribution in [#&#8203;31957](https://github.com/helm/helm/pull/31957)
- [@&#8203;Debasish-87](https://github.com/Debasish-87) made their first contribution in [#&#8203;31973](https://github.com/helm/helm/pull/31973)
- [@&#8203;AnmolVirdi](https://github.com/AnmolVirdi) made their first contribution in [#&#8203;32014](https://github.com/helm/helm/pull/32014)
- [@&#8203;Y0-L0](https://github.com/Y0-L0) made their first contribution in [#&#8203;31979](https://github.com/helm/helm/pull/31979)
- [@&#8203;MohitSalvi16](https://github.com/MohitSalvi16) made their first contribution in [#&#8203;32057](https://github.com/helm/helm/pull/32057)
- [@&#8203;rhysmcneill](https://github.com/rhysmcneill) made their first contribution in [#&#8203;32008](https://github.com/helm/helm/pull/32008)
- [@&#8203;cairon-ab](https://github.com/cairon-ab) made their first contribution in [#&#8203;32034](https://github.com/helm/helm/pull/32034)
- [@&#8203;gaganhr94](https://github.com/gaganhr94) made their first contribution in [#&#8203;31923](https://github.com/helm/helm/pull/31923)
- [@&#8203;isumitsolanki](https://github.com/isumitsolanki) made their first contribution in [#&#8203;31970](https://github.com/helm/helm/pull/31970)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.1.0...v4.2.0>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/48
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 07:06:48 +00:00
2026-05-31 20:48:25 +02:00
2026-09-23 20:30:09 +02:00
2026-04-27 11:33:24 +02:00
2026-08-01 12:10:50 +02:00
2026-04-24 08:48:53 +00:00
2026-04-28 20:38:59 +02:00
2026-04-18 18:14:00 +00:00
2026-04-25 11:49:17 +02:00
2026-05-29 15:48:28 +00:00
2026-06-29 17:02:50 +02:00
2026-04-28 20:38:59 +02:00
2026-05-29 15:48:28 +00:00
2026-09-27 22:11:47 +00:00

Kubernetes Cluster - GitOps Configuration

Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)

GitOps Kubernetes


📚 Complete Documentation

New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:

🎯 START HERE: Documentation Index

Document Description Audience
GitOps Architecture System architecture, repository structure, GitOps workflows, security model Everyone (start here)
Developer Guide Local setup, deploying apps, managing secrets, troubleshooting Developers
Operations Runbook Cluster bootstrap, day-to-day operations, incident response, maintenance Platform Engineers, SREs
Technical Reference Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs Everyone (reference)

🚀 Quick Start

For New Developers

# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git

# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md

# 3. Deploy your first app (see Developer Guide)

For Operators

# 1. Bootstrap new cluster
./bootstrap.sh

# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces

# 3. Read Operations Runbook for day-to-day tasks

📋 Overview

This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.

What's Inside

  • Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
  • Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
  • Policies: Kyverno security policies for secret management, namespace controls, pod verification
  • Monitoring: Full observability stack with metrics, logs, traces, and alerting
  • Secrets: Sealed Secrets for secure Git storage

Key Features

✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration


🗂️ Repository Structure

.
├── bootstrap.sh                # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/                     # Infrastructure provisioning (OpenTofu)
│   ├── platforms/             # Per-platform IaC (one dir per cloud)
│   │   ├── aks/               # Azure AKS (modules/ + dev/ + prod/ + workload/)
│   │   ├── eks/               # AWS EKS
│   │   ├── gke/               # GCP GKE
│   │   └── upc/               # UpCloud
│   ├── configs/               # Platform credentials (git-ignored)
│   │   └── *.env.example      # Template for each platform
│   └── scripts/               # Cluster lifecycle scripts
│       ├── setup-cluster.sh   # Create cluster: ./setup-cluster.sh aks-dev
│       ├── teardown-cluster.sh
│       └── get-kubeconfig.sh
│
├── clusters/                  # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/                     # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│   ├── base/                  # Base ArgoCD Application manifests (one dir per component)
│   │   ├── kustomization.yaml # Aggregates all component subdirectories
│   │   ├── traefik-application/
│   │   │   ├── kustomization.yaml
│   │   │   └── traefik-application.yaml
│   │   ├── keycloak/
│   │   │   ├── kustomization.yaml
│   │   │   └── keycloak.yaml
│   │   ├── grafana/
│   │   ├── prometheus/
│   │   ├── ...               # Each component in its own subdirectory
│   │   └── secrets/
│   ├── overlays/              # Per-cluster overrides (Kustomize)
│   │   ├── upc-dev/           # UpCloud Dev — includes all base components
│   │   ├── upc-prod/         # UpCloud Prod — all components + patches
│   │   ├── aks-dev/          # Azure AKS Dev — selective components only
│   │   ├── aks-prod/         # Azure AKS Prod
│   │   ├── eks-dev/           # AWS EKS Dev
│   │   ├── eks-prod/         # AWS EKS Prod
│   │   ├── gke-dev/          # GCP GKE Dev
│   │   └── gke-prod/         # GCP GKE Prod
│   ├── dashboards/            # Grafana dashboard ConfigMaps
│   └── values/                # Helm value overrides
│       ├── base/              # Shared cloud-agnostic values
│       ├── upc-dev/           # UpCloud Dev (storage, LB, pricing)
│       ├── upc-prod/         # UpCloud Prod
│       ├── eks-dev/           # AWS EKS Dev
│       ├── eks-prod/         # AWS EKS Prod
│       ├── aks-dev/        # Azure AKS Dev
│       ├── aks-prod/       # Azure AKS Prod
│       ├── gke-dev/          # GCP GKE Dev
│       └── gke-prod/         # GCP GKE Prod
│
├── apps/                      # Business Applications (Kustomize, same pattern as infra)
│   ├── base/                  # One subdirectory per app
│   │   ├── kustomization.yaml
│   │   ├── musicman/
│   │   ├── mcp10x/
│   │   ├── dot-ai-stack/
│   │   ├── ts-mcp/
│   │   └── argo-mcp/
│   └── overlays/              # Per-cluster: cherry-pick or include all
│       ├── upc-dev/           # All apps
│       ├── upc-prod/         # All apps + patches
│       └── aks-dev/          # Selective apps only
│
├── cluster-resources/         # Cluster-wide Kubernetes resources
│   ├── letsencrypt-issuer.yaml
│   ├── kyverno-config.yaml
│   ├── *-sealed.yaml          # Sealed secrets
│   └── policies/              # Kyverno policies
│       ├── secret-cloner.yaml
│       ├── default-ns-blocker.yaml
│       ├── bare-pod-cleaner.yaml
│       └── auth-sidecar-injector.yaml
│
├── secrets/                   # Application secrets (sealed)
│   └── *-credentials-sealed.yaml
│
├── private/                   # Local-only files (Git-ignored)
│   └── *.yaml                 # Unsealed secrets (never committed)
│
└── docs/                      # 📚 Comprehensive documentation
    ├── README.md              # Documentation index
    ├── GITOPS-ARCHITECTURE.md # Architecture guide
    ├── DEVELOPER-GUIDE.md     # Developer onboarding
    ├── OPERATIONS-RUNBOOK.md  # Operations procedures
    └── REFERENCE.md           # Technical reference

See GitOps Architecture - Repository Structure for detailed explanation.


🏗️ Architecture

Three-Repository Pattern

Repository Purpose Who Edits How Often
launchpad (this repo) ArgoCD Applications, cluster resources Platform / DevOps engineers ✅ Often
forte-helm Generic Helm chart templates Platform engineers ❌ Rarely
helm-prod-values App-specific configuration & versions Developers / CI pipelines ✅ Sometimes

GitOps Workflow

Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster

Learn more: GitOps Architecture - GitOps Workflow


🔧 Common Tasks

Deploy a New Application

See detailed guide: Developer Guide - Deploying Your First Application

Quick version:

  1. Create apps/myapp.yaml (ArgoCD Application manifest)
  2. Create helm-prod-values/myapp/values.yaml (configuration)
  3. Create sealed secrets if needed
  4. Commit and push - ArgoCD auto-syncs!

Update an Existing Application

See detailed guide: Developer Guide - Updating an Existing Application

Quick version:

  • Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
  • Update config: Edit helm-prod-values/myapp/values.yaml → commit → push

Manage Secrets

See detailed guide: Developer Guide - Working with Secrets

# Create plain secret
kubectl create secret generic myapp-creds \
  --from-literal=KEY=value \
  --dry-run=client -o yaml > private/myapp-creds.yaml

# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
  < private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml

# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push

Enable Authentication

See detailed guide: Developer Guide - Enabling Authentication

Quick version:

# In helm-prod-values/myapp/values.yaml

# Token-based auth (simple)
auth:
  enabled: true
  type: token
  tokens:
  - your-secret-token-here

# OIDC auth (SSO)
auth:
  enabled: true
  type: oidc
  oidc:
    authority: https://auth.example.com/realms/master
    clientId: myapp

Then create OIDC secret (if using OIDC):

kubectl create secret generic auth-oidc \
  --from-literal=client-secret=your-oidc-secret \
  --from-literal=cookie-secret=$(openssl rand -hex 32) \
  --namespace=myapp | \
  kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
  kubectl apply -f -

Bootstrap Cluster

See detailed guide: Operations Runbook - Cluster Bootstrap

# Initialize new cluster
./bootstrap.sh

# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces

🛠️ Quick Reference

Monitor Applications

# List all ArgoCD applications
kubectl get applications -n argocd

# Watch sync status
kubectl get applications -n argocd -w

# Check specific application
kubectl describe application myapp -n argocd

# View application logs
kubectl logs -n myapp <pod-name>

Access UIs

# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)

# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000

# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090

Troubleshooting

# Check pod status
kubectl get pods -n myapp

# View pod logs
kubectl logs -n myapp <pod-name>

# Check pod events
kubectl describe pod -n myapp <pod-name>

# Check ArgoCD sync errors
kubectl describe application myapp -n argocd

# Force sync
kubectl patch application myapp -n argocd \
  --type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'

Full troubleshooting guide: Developer Guide - Troubleshooting


🔐 Security

Secret Management

  • ✅ Sealed Secrets for Git storage
  • ✅ Kyverno auto-clones secrets to namespaces
  • ❌ Never commit plain secrets

Network Security

  • ✅ All traffic TLS-encrypted (Let's Encrypt)
  • ✅ HTTP → HTTPS redirect
  • ✅ Traefik IngressRoute per application

Policy Enforcement

  • ✅ Kyverno policies for security
  • ✅ Default namespace blocked
  • ✅ Bare pods not allowed
  • ✅ Optional authentication sidecar injection

Learn more: GitOps Architecture - Security Model


📊 Infrastructure Components

Component Purpose Namespace Replicas
ArgoCD GitOps controller argocd 1
Traefik Ingress controller traefik 2
Cert-Manager TLS certificates cert-manager 1
Kyverno Policy engine kyverno 1
Sealed Secrets Secret encryption kube-system 1
Prometheus Metrics monitoring 1
Grafana Dashboards monitoring 1
Loki Logs monitoring 1
Tempo Distributed tracing monitoring 1
Fluent-Bit Log shipping monitoring DaemonSet
OpenCost Cost monitoring monitoring 1
Renovate Dependency updates renovate CronJob

Full specs: Technical Reference - Infrastructure Components


🌐 Domains & Networking

  • Local development: *.127.0.0.1.nip.io
  • Production: *.forteapps.net
  • DNS: Manual configuration (contact platform team)
  • TLS: Automatic via Let's Encrypt

📖 Key Concepts

App-of-Apps Pattern

_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.

Multi-Source Pattern

Applications reference both:

  1. Helm charts from forte-helm (templates)
  2. Values from helm-prod-values (configuration)

This separates reusable templates from environment-specific config.

Sync Waves

Applications deploy in order using argocd.argoproj.io/sync-wave:

  • Wave -1: Namespaces
  • Wave 0: Kyverno (policies)
  • Wave 1: Infrastructure
  • Wave 2+: Applications

Auto-Sync & Self-Heal

  • Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
  • Self-Heal: Manual cluster changes are reverted to match Git
  • Prune: Deleted resources in Git are removed from cluster

Learn more: GitOps Architecture - GitOps Workflow


⚙️ Configuration

ArgoCD Settings

  • Reconciliation: Every 60 seconds
  • Sync timeout: 5 minutes per application
  • Retry policy: 5 attempts with exponential backoff
  • Authentication: Disabled (internal use only)

Application Defaults

  • Auto-sync: Enabled
  • Self-heal: Enabled
  • Prune: Enabled
  • Validation: Server-side validation enabled
  • Server-side apply: Enabled

Full configuration: Technical Reference - ArgoCD Configuration


🆘 Getting Help

Documentation

  1. Start here: Documentation Index
  2. For development: Developer Guide
  3. For operations: Operations Runbook
  4. For reference: Technical Reference

Support

  • Slack: #platform-support
  • Issues: Contact platform team
  • Emergencies: Escalate via Slack

Common Questions

Question Answer
How do I deploy an app? Developer Guide - Deploying Your First Application
How do I manage secrets? Developer Guide - Working with Secrets
App won't sync? Developer Guide - Troubleshooting
How do I bootstrap a cluster? Operations Runbook - Cluster Bootstrap
Where are the logs? Operations Runbook - Monitoring & Alerting

🤝 Contributing

Adding a New Application

  1. Read Developer Guide - Deploying Your First Application
  2. Create ArgoCD Application manifest in apps/
  3. Create Helm values in helm-prod-values/
  4. Create sealed secrets if needed
  5. Commit and push - ArgoCD handles the rest!

Modifying Infrastructure

  1. Read Operations Runbook
  2. Update relevant files in infra/ or cluster-resources/
  3. Test changes in isolated namespace if possible
  4. Commit and push
  5. Monitor sync status in Slack/ArgoCD UI

Updating Documentation

Documentation lives in docs/. To update:

  1. Edit relevant markdown file
  2. Update "Last Updated" date
  3. Submit PR or push directly
  4. Notify team of significant changes

📝 Notes

Current Environment

  • Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
  • Active clusters: UpCloud (upc-dev, upc-prod)
  • Environment: Production (internal use only)
  • Auth: Disabled for ArgoCD (internal access)
  • Backup: Gitea daily backup to S3-compatible storage

Known Limitations

  • Secret rotation not automated
  • DNS management is manual

Future improvements: See Operations Runbook - Disaster Recovery


📚 Additional Resources

External Documentation

  • forte-helm - Helm chart templates
  • helm-prod-values - Application values

📄 License

Internal use only. Not for public distribution.


👥 Maintainers

Platform Team

  • Contact: #platform-support on Slack
  • Issues: Create issue in repository or contact team directly

Last Updated: 2026-04-22 Documentation Version: 1.0.0

🚀 Ready to get started? Check out the Documentation Index!

S
Description
k8s launchpad
Readme
2.5 MiB
Languages
HCL 64.1%
Shell 35.9%