From 30d2b83efe124e6599ef41b351149ee1206dd91a Mon Sep 17 00:00:00 2001 From: mr-forust Date: Sun, 27 Sep 2026 09:48:32 +0200 Subject: [PATCH] chore(reloader): manage the reloader release from the repository Reloader has been running since 23 September and is what makes the reloader.stakater.com/auto annotation on a pod template do anything, but the repository only held a namespace. It was a release someone installed by hand, so it was invisible to review, invisible to Renovate, and one reinstall away from being silently dropped. Declaring it in HELM_RELEASES pins the chart version somewhere Renovate can update it, and the active marker means the namespace is applied before the upgrade instead of only existing as a side effect of the original install. The values file sets nothing the running release does not already do, apart from resource requests and limits, which the chart leaves empty. --- .gitea/workflows/deploy-lib.sh | 2 ++ reloader/k8s/reloader-values.yaml | 20 ++++++++++++++++++++ renovate/k8s/configmap.yaml | 9 +++++++++ renovate/renovate.json | 9 +++++++++ 4 files changed, 40 insertions(+) create mode 100644 reloader/k8s/reloader-values.yaml diff --git a/.gitea/workflows/deploy-lib.sh b/.gitea/workflows/deploy-lib.sh index b893831..a815900 100644 --- a/.gitea/workflows/deploy-lib.sh +++ b/.gitea/workflows/deploy-lib.sh @@ -391,6 +391,7 @@ HELM_RELEASES=( "prometheus-stack|prometheus-community/kube-prometheus-stack|prometheus|86.2.3|prometheus-stack/k8s/grafana-values.yaml|prometheus-stack/k8s/active" "loki|grafana/loki|prometheus|7.3.0|loki/k8s/loki-values.yaml|loki/k8s/active" "alloy|grafana/alloy|prometheus|1.12.1|loki/k8s/alloy-values.yaml|loki/k8s/active" + "reloader|stakater/reloader|reloader|2.2.17|reloader/k8s/reloader-values.yaml|reloader/k8s/active" ) # "name url" for the Helm repository hosting a chart, empty if unknown. @@ -398,6 +399,7 @@ helm_repo_for() { case "$1" in prometheus-community/*) echo "prometheus-community https://prometheus-community.github.io/helm-charts" ;; grafana/*) echo "grafana https://grafana.github.io/helm-charts" ;; + stakater/*) echo "stakater https://stakater.github.io/stakater-charts" ;; esac } diff --git a/reloader/k8s/reloader-values.yaml b/reloader/k8s/reloader-values.yaml new file mode 100644 index 0000000..656e939 --- /dev/null +++ b/reloader/k8s/reloader-values.yaml @@ -0,0 +1,20 @@ +# Pinned chart: stakater/reloader 2.2.17 (app v1.4.22). +# Deployed by the deploy workflow, namespace reloader. +# Restarts pods when a ConfigMap or Secret they consume changes. Opt-in per workload +# via the reloader.stakater.com/auto: "true" pod annotation; watchGlobally because +# the workloads that need it are spread across a few dozen namespaces. + +reloader: + watchGlobally: true + + deployment: + replicas: 1 + # The chart defaults to no requests or limits, so the pod is evictable under node + # pressure and the restarts go with it. + resources: + requests: + cpu: "10m" + memory: "64Mi" + limits: + cpu: "100m" + memory: "128Mi" diff --git a/renovate/k8s/configmap.yaml b/renovate/k8s/configmap.yaml index 9a9964c..a77b0aa 100644 --- a/renovate/k8s/configmap.yaml +++ b/renovate/k8s/configmap.yaml @@ -92,6 +92,15 @@ data: "matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "yannh/kubeconform" + }, + { + "customType": "regex", + "description": "stakater/reloader chart version pinned in the deploy workflow", + "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "matchStrings": ["\\|stakater/reloader\\|reloader\\|(?[0-9.]+)\\|"], + "datasourceTemplate": "helm", + "depNameTemplate": "reloader", + "registryUrlTemplate": "https://stakater.github.io/stakater-charts" } ], "packageRules": [ diff --git a/renovate/renovate.json b/renovate/renovate.json index 1caa141..cd30501 100644 --- a/renovate/renovate.json +++ b/renovate/renovate.json @@ -81,6 +81,15 @@ "matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "yannh/kubeconform" + }, + { + "customType": "regex", + "description": "stakater/reloader chart version pinned in the deploy workflow", + "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "matchStrings": ["\\|stakater/reloader\\|reloader\\|(?[0-9.]+)\\|"], + "datasourceTemplate": "helm", + "depNameTemplate": "reloader", + "registryUrlTemplate": "https://stakater.github.io/stakater-charts" } ], "packageRules": [