Skip to content

feat(container)!: Update image ghcr.io/bjw-s-labs/helm/app-template (4.6.2 → 5.0.1)#3341

Open
bot-akira[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
Open

feat(container)!: Update image ghcr.io/bjw-s-labs/helm/app-template (4.6.2 → 5.0.1)#3341
bot-akira[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x

Conversation

@bot-akira

@bot-akira bot-akira Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/bjw-s-labs/helm/app-template major 4.6.25.0.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@bot-akira

bot-akira Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor Author
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: cert-manager/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: cert-manager/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: database/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: database/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: default/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: default/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: external/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: external/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: flux-system/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: flux-system/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: kube-system/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: kube-system/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: media/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: media/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: network/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: network/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: observability/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: observability/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: security/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: security/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: volsync-system/app-template

+++ kubernetes/apps Kustomization: flux-system/cluster-apps OCIRepository: volsync-system/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 

@bot-akira

bot-akira Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor Author
--- HelmRelease: media/prowlarr Deployment: media/prowlarr

+++ HelmRelease: media/prowlarr Deployment: media/prowlarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: prowlarr
         app.kubernetes.io/instance: prowlarr
         app.kubernetes.io/name: prowlarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: prowlarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/prowlarr ServiceAccount: media/prowlarr

+++ HelmRelease: media/prowlarr ServiceAccount: media/prowlarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: prowlarr
+  labels:
+    app.kubernetes.io/instance: prowlarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: prowlarr
+  namespace: media
+
--- HelmRelease: media/flaresolverr Deployment: media/flaresolverr

+++ HelmRelease: media/flaresolverr Deployment: media/flaresolverr

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: flaresolverr
         app.kubernetes.io/instance: flaresolverr
         app.kubernetes.io/name: flaresolverr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: flaresolverr
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - image: ghcr.io/flaresolverr/flaresolverr:v3.4.6@sha256:7962759d99d7e125e108e0f5e7f3cdbcd36161776d058d1d9b7153b92ef1af9e
--- HelmRelease: media/flaresolverr ServiceAccount: media/flaresolverr

+++ HelmRelease: media/flaresolverr ServiceAccount: media/flaresolverr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: flaresolverr
+  labels:
+    app.kubernetes.io/instance: flaresolverr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: flaresolverr
+  namespace: media
+
--- HelmRelease: default/home-assistant Deployment: default/home-assistant

+++ HelmRelease: default/home-assistant Deployment: default/home-assistant

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: home-assistant
         app.kubernetes.io/instance: home-assistant
         app.kubernetes.io/name: home-assistant
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: home-assistant
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/home-assistant ServiceAccount: default/home-assistant

+++ HelmRelease: default/home-assistant ServiceAccount: default/home-assistant

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: home-assistant
+  labels:
+    app.kubernetes.io/instance: home-assistant
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: home-assistant
+  namespace: default
+
--- HelmRelease: media/kapowarr Deployment: media/kapowarr

+++ HelmRelease: media/kapowarr Deployment: media/kapowarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: kapowarr
         app.kubernetes.io/instance: kapowarr
         app.kubernetes.io/name: kapowarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: kapowarr
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: media/kapowarr ServiceAccount: media/kapowarr

+++ HelmRelease: media/kapowarr ServiceAccount: media/kapowarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: kapowarr
+  labels:
+    app.kubernetes.io/instance: kapowarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: kapowarr
+  namespace: media
+
--- HelmRelease: network/cloudflare-tunnel Deployment: network/cloudflare-tunnel

+++ HelmRelease: network/cloudflare-tunnel Deployment: network/cloudflare-tunnel

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: cloudflare-tunnel
         app.kubernetes.io/instance: cloudflare-tunnel
         app.kubernetes.io/name: cloudflare-tunnel
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: cloudflare-tunnel
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 65534
         runAsNonRoot: true
         runAsUser: 65534
         seccompProfile:
           type: RuntimeDefault
--- HelmRelease: network/cloudflare-tunnel ServiceMonitor: network/cloudflare-tunnel

+++ HelmRelease: network/cloudflare-tunnel ServiceMonitor: network/cloudflare-tunnel

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: cloudflare-tunnel
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: cloudflare-tunnel
   namespace: network
 spec:
-  jobLabel: cloudflare-tunnel
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - network
   selector:
     matchLabels:
       app.kubernetes.io/service: cloudflare-tunnel
--- HelmRelease: network/cloudflare-tunnel ServiceAccount: network/cloudflare-tunnel

+++ HelmRelease: network/cloudflare-tunnel ServiceAccount: network/cloudflare-tunnel

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: cloudflare-tunnel
+  labels:
+    app.kubernetes.io/instance: cloudflare-tunnel
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: cloudflare-tunnel
+  namespace: network
+
--- HelmRelease: default/paperless Deployment: default/paperless

+++ HelmRelease: default/paperless Deployment: default/paperless

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: paperless
         app.kubernetes.io/instance: paperless
         app.kubernetes.io/name: paperless
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: paperless
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       initContainers:
       - envFrom:
--- HelmRelease: default/paperless ServiceAccount: default/paperless

+++ HelmRelease: default/paperless ServiceAccount: default/paperless

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: paperless
+  labels:
+    app.kubernetes.io/instance: paperless
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: paperless
+  namespace: default
+
--- HelmRelease: database/dragonfly-operator Deployment: database/dragonfly-operator

+++ HelmRelease: database/dragonfly-operator Deployment: database/dragonfly-operator

@@ -26,13 +26,13 @@

         app.kubernetes.io/instance: dragonfly-operator
         app.kubernetes.io/name: dragonfly-operator
         control-plane: controller-manager
     spec:
       enableServiceLinks: false
       serviceAccountName: dragonfly-operator
-      automountServiceAccountToken: true
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 65534
         runAsNonRoot: true
         runAsUser: 65534
       hostIPC: false
       hostNetwork: false
--- HelmRelease: database/dragonfly-operator ServiceMonitor: database/dragonfly-operator

+++ HelmRelease: database/dragonfly-operator ServiceMonitor: database/dragonfly-operator

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: dragonfly-operator
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: dragonfly-operator
   namespace: database
 spec:
-  jobLabel: dragonfly-operator
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - database
   selector:
     matchLabels:
       app.kubernetes.io/service: dragonfly-operator
--- HelmRelease: default/docmost Deployment: default/docmost

+++ HelmRelease: default/docmost Deployment: default/docmost

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: docmost
         app.kubernetes.io/instance: docmost
         app.kubernetes.io/name: docmost
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: docmost
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/docmost ServiceAccount: default/docmost

+++ HelmRelease: default/docmost ServiceAccount: default/docmost

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: docmost
+  labels:
+    app.kubernetes.io/instance: docmost
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: docmost
+  namespace: default
+
--- HelmRelease: default/atuin Deployment: default/atuin

+++ HelmRelease: default/atuin Deployment: default/atuin

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: atuin
         app.kubernetes.io/instance: atuin
         app.kubernetes.io/name: atuin
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: atuin
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 65534
         runAsNonRoot: true
         runAsUser: 65534
         seccompProfile:
           type: RuntimeDefault
--- HelmRelease: default/atuin ServiceAccount: default/atuin

+++ HelmRelease: default/atuin ServiceAccount: default/atuin

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: atuin
+  labels:
+    app.kubernetes.io/instance: atuin
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: atuin
+  namespace: default
+
--- HelmRelease: kube-system/onepassword-connect Deployment: kube-system/onepassword-connect

+++ HelmRelease: kube-system/onepassword-connect Deployment: kube-system/onepassword-connect

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: onepassword-connect
         app.kubernetes.io/instance: onepassword-connect
         app.kubernetes.io/name: onepassword-connect
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: onepassword-connect
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 999
         runAsNonRoot: true
         runAsUser: 999
       hostIPC: false
       hostNetwork: false
--- HelmRelease: kube-system/onepassword-connect ServiceAccount: kube-system/onepassword-connect

+++ HelmRelease: kube-system/onepassword-connect ServiceAccount: kube-system/onepassword-connect

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: onepassword-connect
+  labels:
+    app.kubernetes.io/instance: onepassword-connect
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: onepassword-connect
+  namespace: kube-system
+
--- HelmRelease: media/plex-music Deployment: media/plex-music

+++ HelmRelease: media/plex-music Deployment: media/plex-music

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: plex-music
         app.kubernetes.io/instance: plex-music
         app.kubernetes.io/name: plex-music
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: plex-music
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 65534
         runAsNonRoot: true
         runAsUser: 65534
       hostIPC: false
       hostNetwork: false
--- HelmRelease: media/plex-music ServiceAccount: media/plex-music

+++ HelmRelease: media/plex-music ServiceAccount: media/plex-music

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: plex-music
+  labels:
+    app.kubernetes.io/instance: plex-music
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: plex-music
+  namespace: media
+
--- HelmRelease: default/glance Deployment: default/glance

+++ HelmRelease: default/glance Deployment: default/glance

@@ -27,13 +27,13 @@

         app.kubernetes.io/controller: glance
         app.kubernetes.io/instance: glance
         app.kubernetes.io/name: glance
     spec:
       enableServiceLinks: false
       serviceAccountName: glance
-      automountServiceAccountToken: true
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/karakeep Deployment: default/karakeep-meilisearch

+++ HelmRelease: default/karakeep Deployment: default/karakeep-meilisearch

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: meilisearch
         app.kubernetes.io/instance: karakeep
         app.kubernetes.io/name: karakeep
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: karakeep
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/karakeep Deployment: default/karakeep-chrome

+++ HelmRelease: default/karakeep Deployment: default/karakeep-chrome

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: chrome
         app.kubernetes.io/instance: karakeep
         app.kubernetes.io/name: karakeep
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: karakeep
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/karakeep Deployment: default/karakeep

+++ HelmRelease: default/karakeep Deployment: default/karakeep

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: karakeep
         app.kubernetes.io/instance: karakeep
         app.kubernetes.io/name: karakeep
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: karakeep
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: default/karakeep ServiceAccount: default/karakeep

+++ HelmRelease: default/karakeep ServiceAccount: default/karakeep

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: karakeep
+  labels:
+    app.kubernetes.io/instance: karakeep
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: karakeep
+  namespace: default
+
--- HelmRelease: media/radarr Deployment: media/radarr

+++ HelmRelease: media/radarr Deployment: media/radarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: radarr
         app.kubernetes.io/instance: radarr
         app.kubernetes.io/name: radarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: radarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/radarr ServiceAccount: media/radarr

+++ HelmRelease: media/radarr ServiceAccount: media/radarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: radarr
+  labels:
+    app.kubernetes.io/instance: radarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: radarr
+  namespace: media
+
--- HelmRelease: media/seerr Deployment: media/seerr

+++ HelmRelease: media/seerr Deployment: media/seerr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: seerr
         app.kubernetes.io/instance: seerr
         app.kubernetes.io/name: seerr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: seerr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/seerr ServiceAccount: media/seerr

+++ HelmRelease: media/seerr ServiceAccount: media/seerr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: seerr
+  labels:
+    app.kubernetes.io/instance: seerr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: seerr
+  namespace: media
+
--- HelmRelease: media/sonarr Deployment: media/sonarr

+++ HelmRelease: media/sonarr Deployment: media/sonarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: sonarr
         app.kubernetes.io/instance: sonarr
         app.kubernetes.io/name: sonarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: sonarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/sonarr ServiceAccount: media/sonarr

+++ HelmRelease: media/sonarr ServiceAccount: media/sonarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: sonarr
+  labels:
+    app.kubernetes.io/instance: sonarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: sonarr
+  namespace: media
+
--- HelmRelease: media/plex Deployment: media/plex

+++ HelmRelease: media/plex Deployment: media/plex

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: plex
         app.kubernetes.io/instance: plex
         app.kubernetes.io/name: plex
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: plex
+      automountServiceAccountToken: false
       priorityClassName: system-cluster-critical
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
--- HelmRelease: media/plex ServiceAccount: media/plex

+++ HelmRelease: media/plex ServiceAccount: media/plex

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: plex
+  labels:
+    app.kubernetes.io/instance: plex
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: plex
+  namespace: media
+
--- HelmRelease: media/komga Deployment: media/komga

+++ HelmRelease: media/komga Deployment: media/komga

@@ -27,14 +27,14 @@

       labels:
         app.kubernetes.io/controller: komga
         app.kubernetes.io/instance: komga
         app.kubernetes.io/name: komga
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: komga
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: media/komga ServiceAccount: media/komga

+++ HelmRelease: media/komga ServiceAccount: media/komga

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: komga
+  labels:
+    app.kubernetes.io/instance: komga
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: komga
+  namespace: media
+
--- HelmRelease: database/postgres-backup CronJob: database/postgres-backup

+++ HelmRelease: database/postgres-backup CronJob: database/postgres-backup

@@ -25,14 +25,14 @@

           labels:
             app.kubernetes.io/controller: postgres-backup
             app.kubernetes.io/instance: postgres-backup
             app.kubernetes.io/name: postgres-backup
         spec:
           enableServiceLinks: false
-          serviceAccountName: default
-          automountServiceAccountToken: true
+          serviceAccountName: postgres-backup
+          automountServiceAccountToken: false
           securityContext:
             fsGroup: 1000
             runAsGroup: 1000
             runAsUser: 1000
           hostIPC: false
           hostNetwork: false
--- HelmRelease: database/postgres-backup ServiceAccount: database/postgres-backup

+++ HelmRelease: database/postgres-backup ServiceAccount: database/postgres-backup

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: postgres-backup
+  labels:
+    app.kubernetes.io/instance: postgres-backup
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: postgres-backup
+  namespace: database
+
--- HelmRelease: media/recyclarr CronJob: media/recyclarr

+++ HelmRelease: media/recyclarr CronJob: media/recyclarr

@@ -27,14 +27,14 @@

           labels:
             app.kubernetes.io/controller: recyclarr
             app.kubernetes.io/instance: recyclarr
             app.kubernetes.io/name: recyclarr
         spec:
           enableServiceLinks: false
-          serviceAccountName: default
-          automountServiceAccountToken: true
+          serviceAccountName: recyclarr
+          automountServiceAccountToken: false
           securityContext:
             fsGroup: 1000
             fsGroupChangePolicy: OnRootMismatch
             runAsGroup: 1000
             runAsNonRoot: true
             runAsUser: 1000
--- HelmRelease: media/recyclarr ServiceAccount: media/recyclarr

+++ HelmRelease: media/recyclarr ServiceAccount: media/recyclarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: recyclarr
+  labels:
+    app.kubernetes.io/instance: recyclarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: recyclarr
+  namespace: media
+
--- HelmRelease: media/tautulli Deployment: media/tautulli

+++ HelmRelease: media/tautulli Deployment: media/tautulli

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: tautulli
         app.kubernetes.io/instance: tautulli
         app.kubernetes.io/name: tautulli
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: tautulli
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/tautulli ServiceAccount: media/tautulli

+++ HelmRelease: media/tautulli ServiceAccount: media/tautulli

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: tautulli
+  labels:
+    app.kubernetes.io/instance: tautulli
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: tautulli
+  namespace: media
+
--- HelmRelease: media/sabnzbd Deployment: media/sabnzbd

+++ HelmRelease: media/sabnzbd Deployment: media/sabnzbd

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: sabnzbd
         app.kubernetes.io/instance: sabnzbd
         app.kubernetes.io/name: sabnzbd
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: sabnzbd
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/sabnzbd ServiceAccount: media/sabnzbd

+++ HelmRelease: media/sabnzbd ServiceAccount: media/sabnzbd

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: sabnzbd
+  labels:
+    app.kubernetes.io/instance: sabnzbd
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: sabnzbd
+  namespace: media
+
--- HelmRelease: network/echo Deployment: network/echo

+++ HelmRelease: network/echo Deployment: network/echo

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: echo
         app.kubernetes.io/instance: echo
         app.kubernetes.io/name: echo
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: echo
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 65534
         runAsNonRoot: true
         runAsUser: 65534
       hostIPC: false
       hostNetwork: false
--- HelmRelease: network/echo ServiceMonitor: network/echo

+++ HelmRelease: network/echo ServiceMonitor: network/echo

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: echo
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: echo
   namespace: network
 spec:
-  jobLabel: echo
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - network
   selector:
     matchLabels:
       app.kubernetes.io/service: echo
--- HelmRelease: network/echo ServiceAccount: network/echo

+++ HelmRelease: network/echo ServiceAccount: network/echo

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: echo
+  labels:
+    app.kubernetes.io/instance: echo
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: echo
+  namespace: network
+
--- HelmRelease: volsync-system/kopia Deployment: volsync-system/kopia

+++ HelmRelease: volsync-system/kopia Deployment: volsync-system/kopia

@@ -28,14 +28,14 @@

       labels:
         app.kubernetes.io/controller: kopia
         app.kubernetes.io/instance: kopia
         app.kubernetes.io/name: kopia
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: kopia
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: volsync-system/kopia ServiceAccount: volsync-system/kopia

+++ HelmRelease: volsync-system/kopia ServiceAccount: volsync-system/kopia

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: kopia
+  labels:
+    app.kubernetes.io/instance: kopia
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: kopia
+  namespace: volsync-system
+
--- HelmRelease: observability/gatus Deployment: observability/gatus

+++ HelmRelease: observability/gatus Deployment: observability/gatus

@@ -27,13 +27,13 @@

         app.kubernetes.io/controller: gatus
         app.kubernetes.io/instance: gatus
         app.kubernetes.io/name: gatus
     spec:
       enableServiceLinks: false
       serviceAccountName: gatus
-      automountServiceAccountToken: true
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
       hostIPC: false
       hostNetwork: false
--- HelmRelease: observability/gatus ServiceMonitor: observability/gatus

+++ HelmRelease: observability/gatus ServiceMonitor: observability/gatus

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: gatus
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: gatus
   namespace: observability
 spec:
-  jobLabel: gatus
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - observability
   selector:
     matchLabels:
       app.kubernetes.io/service: gatus
--- HelmRelease: observability/gatus ServiceAccount: observability/gatus

+++ HelmRelease: observability/gatus ServiceAccount: observability/gatus

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: gatus
+  labels:
+    app.kubernetes.io/instance: gatus
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: gatus
+  namespace: observability
+
--- HelmRelease: observability/kromgo Deployment: observability/kromgo

+++ HelmRelease: observability/kromgo Deployment: observability/kromgo

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: kromgo
         app.kubernetes.io/instance: kromgo
         app.kubernetes.io/name: kromgo
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: kromgo
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
       hostIPC: false
       hostNetwork: false
--- HelmRelease: observability/kromgo ServiceAccount: observability/kromgo

+++ HelmRelease: observability/kromgo ServiceAccount: observability/kromgo

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: kromgo
+  labels:
+    app.kubernetes.io/instance: kromgo
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: kromgo
+  namespace: observability
+
--- HelmRelease: media/unpackerr Deployment: media/unpackerr

+++ HelmRelease: media/unpackerr Deployment: media/unpackerr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: unpackerr
         app.kubernetes.io/instance: unpackerr
         app.kubernetes.io/name: unpackerr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: unpackerr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/unpackerr ServiceMonitor: media/unpackerr

+++ HelmRelease: media/unpackerr ServiceMonitor: media/unpackerr

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: unpackerr
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: unpackerr
   namespace: media
 spec:
-  jobLabel: unpackerr
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - media
   selector:
     matchLabels:
       app.kubernetes.io/service: unpackerr
--- HelmRelease: media/unpackerr ServiceAccount: media/unpackerr

+++ HelmRelease: media/unpackerr ServiceAccount: media/unpackerr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: unpackerr
+  labels:
+    app.kubernetes.io/instance: unpackerr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: unpackerr
+  namespace: media
+

…4.6.2 → 5.0.1)

Signed-off-by: bot-akira[bot] <159718293+bot-akira[bot]@users.noreply.github.com>
@bot-akira bot-akira Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 4ea11ee to 0f42bab Compare May 14, 2026 18:29
@bot-akira bot-akira Bot changed the title feat(container)!: Update image ghcr.io/bjw-s-labs/helm/app-template (4.6.2 → 5.0.0) feat(container)!: Update image ghcr.io/bjw-s-labs/helm/app-template (4.6.2 → 5.0.1) May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants