Skip to content

chore(deps): update helm release external-secrets to v2.10.0 - #174

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/external-secrets-2.x
Open

chore(deps): update helm release external-secrets to v2.10.0#174
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/external-secrets-2.x

Conversation

@renovate

@renovate renovate Bot commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
external-secrets minor 2.8.02.10.0

Release Notes

external-secrets/external-secrets (external-secrets)

v2.10.0

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v2.10.0
Image: ghcr.io/external-secrets/external-secrets:v2.10.0-ubi
Image: ghcr.io/external-secrets/external-secrets:v2.10.0-ubi-boringssl

What's Changed

General
Dependencies

New Contributors

Full Changelog: external-secrets/external-secrets@v2.9.0...v2.10.0

v2.9.0

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v2.9.0
Image: ghcr.io/external-secrets/external-secrets:v2.9.0-ubi
Image: ghcr.io/external-secrets/external-secrets:v2.9.0-ubi-boringssl

What's Changed

General
Dependencies

New Contributors

Full Changelog: external-secrets/external-secrets@v2.8.0...v2.9.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Aug 28, 2026

Copy link
Copy Markdown

Helm Template Diff — bitwarden2.8.02.10.0

842 changed lines
--- /tmp/old.yaml	2026-08-28 17:39:15.973176570 +0000
+++ /tmp/new.yaml	2026-08-28 17:39:15.490181258 +0000
@@ -7,10 +7,10 @@
   namespace: bitwarden
   labels:
     
-    helm.sh/chart: external-secrets-2.8.0
+    helm.sh/chart: external-secrets-2.10.0
     app.kubernetes.io/name: external-secrets-cert-controller
     app.kubernetes.io/instance: bitwarden
-    app.kubernetes.io/version: "v2.8.0"
+    app.kubernetes.io/version: "v2.10.0"
     app.kubernetes.io/managed-by: Helm
 
 ---
@@ -21,10 +21,10 @@
   name: external-secrets
   namespace: bitwarden
   labels:
-    helm.sh/chart: external-secrets-2.8.0
+    helm.sh/chart: external-secrets-2.10.0
     app.kubernetes.io/name: external-secrets
     app.kubernetes.io/instance: bitwarden
-    app.kubernetes.io/version: "v2.8.0"
+    app.kubernetes.io/version: "v2.10.0"
     app.kubernetes.io/managed-by: Helm
 
 ---
@@ -36,10 +36,10 @@
   namespace: bitwarden
   labels:
     
-    helm.sh/chart: external-secrets-2.8.0
+    helm.sh/chart: external-secrets-2.10.0
     app.kubernetes.io/name: external-secrets-webhook
     app.kubernetes.io/instance: bitwarden
-    app.kubernetes.io/version: "v2.8.0"
+    app.kubernetes.io/version: "v2.10.0"
     app.kubernetes.io/managed-by: Helm
 
 ---
@@ -51,10 +51,10 @@
   namespace: bitwarden
   labels:
     
-    helm.sh/chart: external-secrets-2.8.0
+    helm.sh/chart: external-secrets-2.10.0
     app.kubernetes.io/name: external-secrets-webhook
     app.kubernetes.io/instance: bitwarden
-    app.kubernetes.io/version: "v2.8.0"
+    app.kubernetes.io/version: "v2.10.0"
     app.kubernetes.io/managed-by: Helm
     external-secrets.io/component: webhook
 
@@ -201,8 +201,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -543,8 +543,8 @@
                     audiences:
                       description: |-
                         Audience specifies the `aud` claim for the service account token
-                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                        then this audiences will be appended to the list
+                        Some providers automatically extend the audience field based on well-known annotations for workload
+                        identity (e.g. IRSA or GCP Workload Identity)
                       items:
                         type: string
                       type: array
@@ -671,15 +671,13 @@
                               which secret (version/property/..) to fetch.
                             properties:
                               conversionStrategy:
-                                default: Default
-                                description: Used to define a conversion Strategy
+                                description: Used to define a conversion Strategy. Defaults to Default when omitted.
                                 enum:
                                   - Default
                                   - Unicode
                                 type: string
                               decodingStrategy:
-                                default: None
-                                description: Used to define a decoding Strategy
+                                description: Used to define a decoding Strategy. Defaults to None when omitted.
                                 enum:
                                   - Auto
                                   - Base64
@@ -690,7 +688,6 @@
                                 description: Key is the key used in the Provider, mandatory
                                 type: string
                               metadataPolicy:
-                                default: None
                                 description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
                                 enum:
                                   - None
@@ -806,15 +803,13 @@
                               Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
                             properties:
                               conversionStrategy:
-                                default: Default
-                                description: Used to define a conversion Strategy
+                                description: Used to define a conversion Strategy. Defaults to Default when omitted.
                                 enum:
                                   - Default
                                   - Unicode
                                 type: string
                               decodingStrategy:
-                                default: None
-                                description: Used to define a decoding Strategy
+                                description: Used to define a decoding Strategy. Defaults to None when omitted.
                                 enum:
                                   - Auto
                                   - Base64
@@ -825,7 +820,6 @@
                                 description: Key is the key used in the Provider, mandatory
                                 type: string
                               metadataPolicy:
-                                default: None
                                 description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
                                 enum:
                                   - None
@@ -852,15 +846,13 @@
                               Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
                             properties:
                               conversionStrategy:
-                                default: Default
-                                description: Used to define a conversion Strategy
+                                description: Used to define a conversion Strategy. Defaults to Default when omitted.
                                 enum:
                                   - Default
                                   - Unicode
                                 type: string
                               decodingStrategy:
-                                default: None
-                                description: Used to define a decoding Strategy
+                                description: Used to define a decoding Strategy. Defaults to None when omitted.
                                 enum:
                                   - Auto
                                   - Base64
@@ -1304,13 +1296,15 @@
                                     default: Data
                                     description: |-
                                       Target specifies where to place the template result.
-                                      For Secret resources, common values are: "Data", "Annotations", "Labels".
+                                      For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
+                                      any other value is rejected because it would allow writes to privileged Secret fields.
                                       For custom resources (when spec.target.manifest is set), this supports
                                       nested paths like "spec.database.config" or "data".
                                     type: string
                                   valuesDecodingStrategy:
-                                    default: None
-                                    description: Used to define a decoding Strategy for the rendered template values.
+                                    description: |-
+                                      Used to define a decoding Strategy for the rendered template values.
+                                      Defaults to None when omitted.
                                     enum:
                                       - Auto
                                       - Base64
@@ -2364,8 +2358,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -2601,8 +2595,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -2646,8 +2640,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -2840,8 +2834,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -2969,8 +2963,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -3379,8 +3373,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -3447,8 +3441,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -3831,8 +3825,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -3877,8 +3871,8 @@
                                             audiences:
                                               description: |-
                                                 Audience specifies the `aud` claim for the service account token
-                                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                                then this audiences will be appended to the list
+                                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                                identity (e.g. IRSA or GCP Workload Identity)
                                               items:
                                                 type: string
                                               type: array
@@ -3922,8 +3916,8 @@
                                             audiences:
                                               description: |-
                                                 Audience specifies the `aud` claim for the service account token
-                                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                                then this audiences will be appended to the list
+                                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                                identity (e.g. IRSA or GCP Workload Identity)
                                               items:
                                                 type: string
                                               type: array
@@ -4084,8 +4078,8 @@
                                             audiences:
                                               description: |-
                                                 Audience specifies the `aud` claim for the service account token
-                                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                                then this audiences will be appended to the list
+                                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                                identity (e.g. IRSA or GCP Workload Identity)
                                               items:
                                                 type: string
                                               type: array
@@ -4207,8 +4201,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -5364,13 +5358,15 @@
                                 default: Data
                                 description: |-
                                   Target specifies where to place the template result.
-                                  For Secret resources, common values are: "Data", "Annotations", "Labels".
+                                  For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
+                                  any other value is rejected because it would allow writes to privileged Secret fields.
                                   For custom resources (when spec.target.manifest is set), this supports
                                   nested paths like "spec.database.config" or "data".
                                 type: string
                               valuesDecodingStrategy:
-                                default: None
-                                description: Used to define a decoding Strategy for the rendered template values.
+                                description: |-
+                                  Used to define a decoding Strategy for the rendered template values.
+                                  Defaults to None when omitted.
                                 enum:
                                   - Auto
                                   - Base64
@@ -5649,8 +5645,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -5773,8 +5769,8 @@
                                 audiences:
                                   description: |-
                                     Audience specifies the `aud` claim for the service account token
-                                    If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                    then this audiences will be appended to the list
+                                    Some providers automatically extend the audience field based on well-known annotations for workload
+                                    identity (e.g. IRSA or GCP Workload Identity)
                                   items:
                                     type: string
                                   type: array
@@ -5868,8 +5864,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -6244,8 +6240,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -7122,8 +7118,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -7282,8 +7278,8 @@
                                 audiences:
                                   description: |-
                                     Audience specifies the `aud` claim for the service account token
-                                    If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                    then this audiences will be appended to the list
+                                    Some providers automatically extend the audience field based on well-known annotations for workload
+                                    identity (e.g. IRSA or GCP Workload Identity)
                                   items:
                                     type: string
                                   type: array
@@ -7594,8 +7590,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -7894,8 +7890,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -8021,8 +8017,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -8063,7 +8059,7 @@
                       type: object
                     github:
                       description: |-
-                        Github configures this store to push GitHub Actions secrets using the GitHub API provider.
+                        Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
                         Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
                       properties:
                         appID:
@@ -8127,6 +8123,15 @@
                         repository:
                           description: repository will be used to fetch secrets from the Github repository within an organization
                           type: string
+                        secretType:
+                          default: Actions
+                          description: |-
+                            secretType specifies which GitHub secret service to use.
+                            Defaults to Actions for backwards compatibility.
+                          enum:
+                            - Actions
+                            - Dependabot
+                          type: string
                         uploadURL:
                           description: Upload URL for enterprise instances. Default to URL.
                           type: string
@@ -8140,6 +8145,9 @@
                         - installationID
                         - organization
                       type: object
+                      x-kubernetes-validations:
+                        - message: Dependabot secrets do not support environments
+                          rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
                     gitlab:
                       description: GitLab configures this store to sync secrets using GitLab Variables provider
                       properties:
@@ -9217,8 +9225,8 @@
                                 audiences:
                                   description: |-
                                     Audience specifies the `aud` claim for the service account token
-                                    If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                    then this audiences will be appended to the list
+                                    Some providers automatically extend the audience field based on well-known annotations for workload
+                                    identity (e.g. IRSA or GCP Workload Identity)
                                   items:
                                     type: string
                                   type: array
@@ -9427,10 +9435,56 @@
                                   pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
                                   type: string
                               type: object
+                            workloadIdentity:
+                              description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
+                              properties:
+                                iamServiceAccountID:
+                                  description: |-
+                                    IAMServiceAccountID is the Nebius IAM service account identifier that the
+                                    federated Kubernetes service account should impersonate during token exchange.
+                                  example: serviceaccount-e00example
+                                  minLength: 1
+                                  pattern: ^serviceaccount-[a-z][a-z0-9]{2}
+                                  type: string
+                                serviceAccountRef:
+                                  description: |-
+                                    ServiceAccountRef references a Kubernetes ServiceAccount used to request a
+                                    temporary JWT via the TokenRequest API. The JWT is then exchanged for a
+                                    Nebius IAM token using workload federation.
+                                  properties:
+                                    audiences:
+                                      description: |-
+                                        Audience specifies the `aud` claim for the service account token
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
+                                      items:
+                                        type: string
+                                      type: array
+                                    name:
+                                      description: The name of the ServiceAccount resource being referred to.
+                                      maxLength: 253
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
+                                      type: string
+                                    namespace:
+                                      description: |-
+                                        Namespace of the resource being referred to.
+                                        Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
+                                      maxLength: 63
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
+                                      type: string
+                                  required:
+                                    - name
+                                  type: object
+                              required:
+                                - iamServiceAccountID
+                                - serviceAccountRef
+                              type: object
                           type: object
                           x-kubernetes-validations:
-                            - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
-                              rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
+                            - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
+                              rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
                         caProvider:
                           description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
                           properties:
@@ -9716,6 +9770,12 @@
                                 Format: duration string (e.g., "5m", "1h", "30s")
                               type: string
                           type: object
+                        environment:
+                          description: |-
+                            Environment defines the 1Password Environment ID to read variables from.
+                            Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
+                            Mutually exclusive with Vault.
+                          type: string
                         integrationInfo:
                           description: |-
                             IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
@@ -9731,12 +9791,16 @@
                               type: string
                           type: object
                         vault:
-                          description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
+                          description: |-
+                            Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
+                            Mutually exclusive with Environment.
                           type: string
                       required:
                         - auth
-                        - vault
                       type: object
+                      x-kubernetes-validations:
+                        - message: at most one of the fields in [vault environment] may be set
+                          rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
                     openBao:
                       description: OpenBao configures this store to sync secrets using the OpenBao provider.
                       properties:
@@ -9829,6 +9893,93 @@
                               x-kubernetes-validations:
                                 - message: exactly one of the fields in [roleId roleRef] must be set
                                   rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
+                            kubernetes:
+                              description: |-
+                                Kubernetes authenticates with OpenBao by passing a ServiceAccount
+                                token to the [Kubernetes auth mechanism].
+
+                                [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
+                              properties:
+                                path:
+                                  default: kubernetes
+                                  description: |-
+                                    Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
+                                    "kubernetes"
+                                  type: string
+                                role:
+                                  description: |-
+                                    A required field containing the OpenBao Role to assume. A Role binds a
+                                    Kubernetes ServiceAccount with a set of OpenBao policies.
+                                  minLength: 1
+                                  type: string
+                                secretRef:
+                                  description: |-
+                                    Optional secret field containing a Kubernetes ServiceAccount JWT used
+                                    for authenticating with OpenBao. If a name is specified without a key,
+                                    `token` is the default.
+                                  properties:
+                                    key:
+                                      description: |-
+                                        A key in the referenced Secret.
+                                        Some instances of this field may be defaulted, in others it may be required.
+                                      maxLength: 253
+                                      minLength: 1
+                                      pattern: ^[-._a-zA-Z0-9]+$
+                                      type: string
+                                    name:
+                                      description: The name of the Secret resource being referred to.
+                                      maxLength: 253
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
+                                      type: string
+                                    namespace:
+                                      description: |-
+                                        The namespace of the Secret resource being referred to.
+                                        Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
+                                      maxLength: 63
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
+                                      type: string
+                                  type: object
+                                serviceAccountRef:
+                                  description: |-
+                                    Optional service account field containing the name of a Kubernetes ServiceAccount.
+                                    If the service account is specified, a token will be requested from the Kubernetes
+                                    TokenRequest API for authenticating with OpenBao.
+                                    Any configured audiences will be passed to the TokenRequest as-is.
+                                  properties:
+                                    audiences:
+                                      description: |-
+                                        Audience specifies the `aud` claim for the service account token
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
+                                      items:
+                                        type: string
+                                      type: array
+                                    name:
+                                      description: The name of the ServiceAccount resource being referred to.
+                                      maxLength: 253
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
+                                      type: string
+                                    namespace:
+                                      description: |-
+                                        Namespace of the resource being referred to.
+                                        Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
+                                      maxLength: 63
+                                      minLength: 1
+                                      pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
+                                      type: string
+                                  required:
+                                    - name
+                                  type: object
+                              required:
+                                - path
+                                - role
+                              type: object
+                              x-kubernetes-validations:
+                                - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
+                                  rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
                             namespace:
                               description: |-
                                 Name of the [OpenBao Namespace] to authenticate to. This can be different
@@ -9918,8 +10069,8 @@
                               type: object
                           type: object
                           x-kubernetes-validations:
-                            - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
-                              rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
+                            - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
+                              rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
                         caBundle:
                           description: |-
                             PEM encoded CA bundle used to validate the OpenBao server certificate. If
@@ -10106,8 +10257,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -10601,8 +10752,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -10783,6 +10934,11 @@
                             - name
                             - type
                           type: object
+                        disableSiteIDValidation:
+                          description: |-
+                            DisableSiteIDValidation permits a missing site ID for new secrets.
+                            The provider sends 0 if no site ID is set.
+                          type: boolean
                         domain:
                           description: Domain is the secret server domain.
                           type: string
@@ -10830,6 +10986,13 @@
                             ServerURL
                             URL to your secret server installation
                           type: string
+                        siteId:
+                          description: |-
+                            SiteID is the ID of the Secret Server site for new secrets.
+                            PushSecret metadata can override this value for one secret.
+                            The provider uses 1 if this field is not set.
+                          minimum: 1
+                          type: integer
                         token:
                           description: |-
                             Token is an access token used to authenticate to the secret server,
@@ -11181,8 +11344,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -11227,8 +11390,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -11272,8 +11435,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -11434,8 +11597,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -11557,8 +11720,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -12570,8 +12733,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -12842,8 +13005,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -13162,8 +13325,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -13737,8 +13900,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -14138,8 +14301,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -14609,8 +14772,8 @@
                                 audiences:
                                   description: |-
                                     Audience specifies the `aud` claim for the service account token
-                                    If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                    then this audiences will be appended to the list
+                                    Some providers automatically extend the audience field based on well-known annotations for workload
+                                    identity (e.g. IRSA or GCP Workload Identity)
                                   items:
                                     type: string
                                   type: array
@@ -14989,8 +15152,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -15624,8 +15787,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -15786,8 +15949,8 @@
                                         audiences:
                                           description: |-
                                             Audience specifies the `aud` claim for the service account token
-                                            If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                            then this audiences will be appended to the list
+                                            Some providers automatically extend the audience field based on well-known annotations for workload
+                                            identity (e.g. IRSA or GCP Workload Identity)
                                           items:
                                             type: string
                                           type: array
@@ -15909,8 +16072,8 @@
                                     audiences:
                                       description: |-
                                         Audience specifies the `aud` claim for the service account token
-                                        If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                        then this audiences will be appended to the list
+                                        Some providers automatically extend the audience field based on well-known annotations for workload
+                                        identity (e.g. IRSA or GCP Workload Identity)
                                       items:
                                         type: string
                                       type: array
@@ -16659,8 +16822,8 @@
                             audiences:
                               description: |-
                                 Audience specifies the `aud` claim for the service account token
-                                If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
-                                then this audiences will be appended to the list
+                                Some providers automatically extend the audience field based on well-known annotations for workload
+                                identity (e.g. IRSA or GCP Workload Identity)
                               items:
                                 type: string
                               type: array
@@ -16872,15 +17035,13 @@
                   
... (truncated, diff exceeds 60000 chars)

lunarys commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Renovate Review: external-secrets 2.8.0 → 2.9.0 (minor, bitwarden app)

Risk: 🟢 LOW

Check Result
Inputs Complete — Release Notes section present with the full What's Changed list; diff comment present for the one affected app (bitwarden, slug 03-apps-apps-bitwarden), no coverage gap.
Description vs. diff Consistent — table says 2.8.02.9.0 (minor); the only changed file is 03_apps/apps/bitwarden/app.yaml, a single-line version: 2.8.02.9.0 bump inside the helm: block. Scope matches exactly, no fleet-wide default touched.
Rendered diff Full, no truncation (196 changed lines, no line/char-cap notice) — cosmetic label/version bumps (helm.sh/chart, app.kubernetes.io/version) plus additive CRD schema changes: a new optional environment field on the 1Password provider CRD schema (mutually exclusive with vault), reworded/expanded descriptions on existing decodingStrategy/conversionStrategy fields, and a validation-message tightening around accepted PushSecret target values. No resource additions/removals, no render errors.
RBAC No RBAC objects appear anywhere in the diff (no Role/ClusterRole/RoleBinding lines) — the existing external-secrets ClusterRoles are unchanged.
Changelog vs. config No overlap — bitwarden's only ClusterSecretStores (03_apps/apps/bitwarden/resources/05_bitwarden_secret-stores.yaml) use the webhook provider exclusively; the new/changed CRD fields are all on the 1Password SDK provider path, which this app does not use.

Details:

  • Checked 03_apps/apps/bitwarden/values.yaml (only fullnameOverride: "external-secrets") and app.yaml — no overrides exist that could interact with any of the changelog items.
  • The PushSecret target-field validation tightening (from chore(fix): template abuse for secret values, #6730) only matters for apps using PushSecret; bitwarden only defines ClusterSecretStores for pulling, not pushing — unaffected.

Why LOW: minor version bump, diff is cosmetic-plus-additive-CRD-fields only, no RBAC changes, and the one changelog item touching CRD schema (1Password environment field) hits a provider path this app doesn't use.


Generated by Claude Code

@renovate renovate Bot changed the title chore(deps): update helm release external-secrets to v2.9.0 chore(deps): update helm release external-secrets to v2.10.0 Aug 28, 2026
@renovate
renovate Bot force-pushed the renovate/external-secrets-2.x branch from 9634da1 to 2f6108c Compare August 28, 2026 17:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant