Skip to content

feat(flux-helmrelease)!: update ghcr.io/bjw-s-labs/helm/app-template ( 4.6.2 → 5.0.1 )#1092

Open
robottoms-up[bot] wants to merge 1 commit into
masterfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
Open

feat(flux-helmrelease)!: update ghcr.io/bjw-s-labs/helm/app-template ( 4.6.2 → 5.0.1 )#1092
robottoms-up[bot] wants to merge 1 commit into
masterfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x

Conversation

@robottoms-up
Copy link
Copy Markdown
Contributor

@robottoms-up robottoms-up Bot commented May 4, 2026

This PR contains the following updates:

Package Update Change
ghcr.io/bjw-s-labs/helm/app-template major 4.6.25.0.1

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@robottoms-up
Copy link
Copy Markdown
Contributor Author

robottoms-up Bot commented May 4, 2026

--- kubernetes/homelab/apps/base/neko/app Kustomization: base/neko OCIRepository: base/neko

+++ kubernetes/homelab/apps/base/neko/app Kustomization: base/neko OCIRepository: base/neko

@@ -11,9 +11,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps/media/qbittorrent/tqm Kustomization: media/tqm OCIRepository: media/tqm

+++ kubernetes/homelab/apps/media/qbittorrent/tqm Kustomization: media/tqm OCIRepository: media/tqm

@@ -11,9 +11,9 @@

 spec:
   interval: 15m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: base/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: base/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: cert-manager/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: cert-manager/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: cilium/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: cilium/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: flux-system/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: flux-system/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: games/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: games/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: home-automation/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: home-automation/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: kube-system/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: kube-system/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: media/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: media/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: networking/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: networking/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: observability/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: observability/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: storage/app-template

+++ kubernetes/homelab/apps Kustomization: flux-system/apps OCIRepository: storage/app-template

@@ -10,9 +10,9 @@

 spec:
   interval: 5m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps/observability/unpoller/app Kustomization: observability/unpoller OCIRepository: observability/unpoller

+++ kubernetes/homelab/apps/observability/unpoller/app Kustomization: observability/unpoller OCIRepository: observability/unpoller

@@ -11,9 +11,9 @@

 spec:
   interval: 15m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps/home-automation/mosquitto/app Kustomization: home-automation/mosquitto OCIRepository: home-automation/mosquitto

+++ kubernetes/homelab/apps/home-automation/mosquitto/app Kustomization: home-automation/mosquitto OCIRepository: home-automation/mosquitto

@@ -11,9 +11,9 @@

 spec:
   interval: 15m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 
--- kubernetes/homelab/apps/media/qbittorrent/qui Kustomization: media/qui OCIRepository: media/qui

+++ kubernetes/homelab/apps/media/qbittorrent/qui Kustomization: media/qui OCIRepository: media/qui

@@ -11,9 +11,9 @@

 spec:
   interval: 15m
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 4.6.2
+    tag: 5.0.1
   url: oci://ghcr.io/bjw-s-labs/helm/app-template
 

@robottoms-up
Copy link
Copy Markdown
Contributor Author

robottoms-up Bot commented May 4, 2026

--- HelmRelease: base/neko Deployment: base/neko

+++ HelmRelease: base/neko Deployment: base/neko

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: neko
         app.kubernetes.io/instance: neko
         app.kubernetes.io/name: neko
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: neko
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: base/neko ServiceAccount: base/neko

+++ HelmRelease: base/neko ServiceAccount: base/neko

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: neko
+  labels:
+    app.kubernetes.io/instance: neko
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: neko
+  namespace: base
+
--- HelmRelease: media/prowlarr Deployment: media/prowlarr

+++ HelmRelease: media/prowlarr Deployment: media/prowlarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: prowlarr
         app.kubernetes.io/instance: prowlarr
         app.kubernetes.io/name: prowlarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: prowlarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
       hostIPC: false
--- HelmRelease: media/prowlarr ServiceAccount: media/prowlarr

+++ HelmRelease: media/prowlarr ServiceAccount: media/prowlarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: prowlarr
+  labels:
+    app.kubernetes.io/instance: prowlarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: prowlarr
+  namespace: media
+
--- HelmRelease: base/bitwarden Deployment: base/bitwarden

+++ HelmRelease: base/bitwarden Deployment: base/bitwarden

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: bitwarden
         app.kubernetes.io/instance: bitwarden
         app.kubernetes.io/name: bitwarden
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: bitwarden
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
       hostIPC: false
--- HelmRelease: base/bitwarden ServiceAccount: base/bitwarden

+++ HelmRelease: base/bitwarden ServiceAccount: base/bitwarden

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: bitwarden
+  labels:
+    app.kubernetes.io/instance: bitwarden
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: bitwarden
+  namespace: base
+
--- HelmRelease: media/jellyseerr Deployment: media/jellyseerr

+++ HelmRelease: media/jellyseerr Deployment: media/jellyseerr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: jellyseerr
         app.kubernetes.io/instance: jellyseerr
         app.kubernetes.io/name: jellyseerr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: jellyseerr
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: media/jellyseerr ServiceAccount: media/jellyseerr

+++ HelmRelease: media/jellyseerr ServiceAccount: media/jellyseerr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: jellyseerr
+  labels:
+    app.kubernetes.io/instance: jellyseerr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: jellyseerr
+  namespace: media
+
--- HelmRelease: home-automation/zigbee2mqtt Deployment: home-automation/zigbee2mqtt

+++ HelmRelease: home-automation/zigbee2mqtt Deployment: home-automation/zigbee2mqtt

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: zigbee2mqtt
         app.kubernetes.io/instance: zigbee2mqtt
         app.kubernetes.io/name: zigbee2mqtt
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: zigbee2mqtt
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: home-automation/zigbee2mqtt ServiceAccount: home-automation/zigbee2mqtt

+++ HelmRelease: home-automation/zigbee2mqtt ServiceAccount: home-automation/zigbee2mqtt

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: zigbee2mqtt
+  labels:
+    app.kubernetes.io/instance: zigbee2mqtt
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: zigbee2mqtt
+  namespace: home-automation
+
--- HelmRelease: media/radarr Deployment: media/radarr

+++ HelmRelease: media/radarr Deployment: media/radarr

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: radarr
         app.kubernetes.io/instance: radarr
         app.kubernetes.io/name: radarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: radarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
       hostIPC: false
--- HelmRelease: media/radarr ServiceAccount: media/radarr

+++ HelmRelease: media/radarr ServiceAccount: media/radarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: radarr
+  labels:
+    app.kubernetes.io/instance: radarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: radarr
+  namespace: media
+
--- HelmRelease: media/betanin Deployment: media/betanin

+++ HelmRelease: media/betanin Deployment: media/betanin

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: betanin
         app.kubernetes.io/instance: betanin
         app.kubernetes.io/name: betanin
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: betanin
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
--- HelmRelease: media/betanin ServiceAccount: media/betanin

+++ HelmRelease: media/betanin ServiceAccount: media/betanin

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: betanin
+  labels:
+    app.kubernetes.io/instance: betanin
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: betanin
+  namespace: media
+
--- HelmRelease: media/qbittorrent-exporter Deployment: media/qbittorrent-exporter

+++ HelmRelease: media/qbittorrent-exporter Deployment: media/qbittorrent-exporter

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: qbittorrent-exporter
         app.kubernetes.io/instance: qbittorrent-exporter
         app.kubernetes.io/name: qbittorrent-exporter
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: qbittorrent-exporter
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
       hostIPC: false
       hostNetwork: false
--- HelmRelease: media/qbittorrent-exporter ServiceMonitor: media/qbittorrent-exporter

+++ HelmRelease: media/qbittorrent-exporter ServiceMonitor: media/qbittorrent-exporter

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: qbittorrent-exporter
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: qbittorrent-exporter
   namespace: media
 spec:
-  jobLabel: qbittorrent-exporter
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - media
   selector:
     matchLabels:
       app.kubernetes.io/service: qbittorrent-exporter
--- HelmRelease: media/qbittorrent-exporter ServiceAccount: media/qbittorrent-exporter

+++ HelmRelease: media/qbittorrent-exporter ServiceAccount: media/qbittorrent-exporter

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: qbittorrent-exporter
+  labels:
+    app.kubernetes.io/instance: qbittorrent-exporter
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: qbittorrent-exporter
+  namespace: media
+
--- HelmRelease: media/sonarr-exporter Deployment: media/sonarr-exporter

+++ HelmRelease: media/sonarr-exporter Deployment: media/sonarr-exporter

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: sonarr-exporter
         app.kubernetes.io/instance: sonarr-exporter
         app.kubernetes.io/name: sonarr-exporter
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: sonarr-exporter
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
       hostIPC: false
       hostNetwork: false
--- HelmRelease: media/sonarr-exporter ServiceMonitor: media/sonarr-exporter

+++ HelmRelease: media/sonarr-exporter ServiceMonitor: media/sonarr-exporter

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: sonarr-exporter
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: sonarr-exporter
   namespace: media
 spec:
-  jobLabel: sonarr-exporter
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - media
   selector:
     matchLabels:
       app.kubernetes.io/service: sonarr-exporter
--- HelmRelease: media/sonarr-exporter ServiceAccount: media/sonarr-exporter

+++ HelmRelease: media/sonarr-exporter ServiceAccount: media/sonarr-exporter

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: sonarr-exporter
+  labels:
+    app.kubernetes.io/instance: sonarr-exporter
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: sonarr-exporter
+  namespace: media
+
--- HelmRelease: networking/multus DaemonSet: networking/multus

+++ HelmRelease: networking/multus DaemonSet: networking/multus

@@ -23,13 +23,13 @@

         app.kubernetes.io/controller: multus
         app.kubernetes.io/instance: multus
         app.kubernetes.io/name: multus
     spec:
       enableServiceLinks: false
       serviceAccountName: multus
-      automountServiceAccountToken: true
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: true
       hostPID: false
       dnsPolicy: ClusterFirstWithHostNet
       initContainers:
       - image: ghcr.io/home-operations/cni-plugins:1.9.1@sha256:56222d9cf686632f0951103a400adeeec8d982aaf8cbf4d21588da17a41dd228
--- HelmRelease: home-automation/zwave Deployment: home-automation/zwave

+++ HelmRelease: home-automation/zwave Deployment: home-automation/zwave

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: zwave
         app.kubernetes.io/instance: zwave
         app.kubernetes.io/name: zwave
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: zwave
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: home-automation/zwave ServiceAccount: home-automation/zwave

+++ HelmRelease: home-automation/zwave ServiceAccount: home-automation/zwave

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: zwave
+  labels:
+    app.kubernetes.io/instance: zwave
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: zwave
+  namespace: home-automation
+
--- HelmRelease: home-automation/mosquitto Deployment: home-automation/mosquitto

+++ HelmRelease: home-automation/mosquitto Deployment: home-automation/mosquitto

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: mosquitto
         app.kubernetes.io/instance: mosquitto
         app.kubernetes.io/name: mosquitto
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: mosquitto
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: home-automation/mosquitto ServiceAccount: home-automation/mosquitto

+++ HelmRelease: home-automation/mosquitto ServiceAccount: home-automation/mosquitto

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: mosquitto
+  labels:
+    app.kubernetes.io/instance: mosquitto
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: mosquitto
+  namespace: home-automation
+
--- HelmRelease: media/audiobookshelf Deployment: media/audiobookshelf

+++ HelmRelease: media/audiobookshelf Deployment: media/audiobookshelf

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: audiobookshelf
         app.kubernetes.io/instance: audiobookshelf
         app.kubernetes.io/name: audiobookshelf
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: audiobookshelf
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1001
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1001
         runAsNonRoot: true
         runAsUser: 1001
--- HelmRelease: media/audiobookshelf ServiceAccount: media/audiobookshelf

+++ HelmRelease: media/audiobookshelf ServiceAccount: media/audiobookshelf

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: audiobookshelf
+  labels:
+    app.kubernetes.io/instance: audiobookshelf
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: audiobookshelf
+  namespace: media
+
--- HelmRelease: media/wizarr Deployment: media/wizarr

+++ HelmRelease: media/wizarr Deployment: media/wizarr

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: wizarr
         app.kubernetes.io/instance: wizarr
         app.kubernetes.io/name: wizarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: wizarr
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       containers:
       - env:
--- HelmRelease: media/wizarr ServiceAccount: media/wizarr

+++ HelmRelease: media/wizarr ServiceAccount: media/wizarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: wizarr
+  labels:
+    app.kubernetes.io/instance: wizarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: wizarr
+  namespace: media
+
--- HelmRelease: observability/kromgo Deployment: observability/kromgo

+++ HelmRelease: observability/kromgo Deployment: observability/kromgo

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: kromgo
         app.kubernetes.io/instance: kromgo
         app.kubernetes.io/name: kromgo
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: kromgo
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
       hostIPC: false
       hostNetwork: false
--- HelmRelease: observability/kromgo ServiceAccount: observability/kromgo

+++ HelmRelease: observability/kromgo ServiceAccount: observability/kromgo

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: kromgo
+  labels:
+    app.kubernetes.io/instance: kromgo
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: kromgo
+  namespace: observability
+
--- HelmRelease: home-automation/home-assistant Deployment: home-automation/home-assistant

+++ HelmRelease: home-automation/home-assistant Deployment: home-automation/home-assistant

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: home-assistant
         app.kubernetes.io/instance: home-assistant
         app.kubernetes.io/name: home-assistant
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: home-assistant
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 568
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
--- HelmRelease: home-automation/home-assistant ServiceAccount: home-automation/home-assistant

+++ HelmRelease: home-automation/home-assistant ServiceAccount: home-automation/home-assistant

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: home-assistant
+  labels:
+    app.kubernetes.io/instance: home-assistant
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: home-assistant
+  namespace: home-automation
+
--- HelmRelease: media/qbittorrent Deployment: media/qbittorrent

+++ HelmRelease: media/qbittorrent Deployment: media/qbittorrent

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: qbittorrent
         app.kubernetes.io/instance: qbittorrent
         app.kubernetes.io/name: qbittorrent
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: qbittorrent
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
       hostIPC: false
--- HelmRelease: media/qbittorrent ServiceAccount: media/qbittorrent

+++ HelmRelease: media/qbittorrent ServiceAccount: media/qbittorrent

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: qbittorrent
+  labels:
+    app.kubernetes.io/instance: qbittorrent
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: qbittorrent
+  namespace: media
+
--- HelmRelease: networking/cloudflared Deployment: networking/cloudflared

+++ HelmRelease: networking/cloudflared Deployment: networking/cloudflared

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: cloudflared
         app.kubernetes.io/instance: cloudflared
         app.kubernetes.io/name: cloudflared
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: cloudflared
+      automountServiceAccountToken: false
       hostIPC: false
       hostNetwork: false
       hostPID: false
       dnsPolicy: ClusterFirst
       topologySpreadConstraints:
       - labelSelector:
--- HelmRelease: networking/cloudflared ServiceMonitor: networking/cloudflared

+++ HelmRelease: networking/cloudflared ServiceMonitor: networking/cloudflared

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: cloudflared
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: cloudflared
   namespace: networking
 spec:
-  jobLabel: cloudflared
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - networking
   selector:
     matchLabels:
       app.kubernetes.io/service: cloudflared
--- HelmRelease: networking/cloudflared ServiceAccount: networking/cloudflared

+++ HelmRelease: networking/cloudflared ServiceAccount: networking/cloudflared

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: cloudflared
+  labels:
+    app.kubernetes.io/instance: cloudflared
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: cloudflared
+  namespace: networking
+
--- HelmRelease: media/qui Deployment: media/qui

+++ HelmRelease: media/qui Deployment: media/qui

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: qui
         app.kubernetes.io/instance: qui
         app.kubernetes.io/name: qui
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: qui
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/qui ServiceAccount: media/qui

+++ HelmRelease: media/qui ServiceAccount: media/qui

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: qui
+  labels:
+    app.kubernetes.io/instance: qui
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: qui
+  namespace: media
+
--- HelmRelease: media/recyclarr CronJob: media/recyclarr

+++ HelmRelease: media/recyclarr CronJob: media/recyclarr

@@ -27,14 +27,14 @@

           labels:
             app.kubernetes.io/controller: recyclarr
             app.kubernetes.io/instance: recyclarr
             app.kubernetes.io/name: recyclarr
         spec:
           enableServiceLinks: false
-          serviceAccountName: default
-          automountServiceAccountToken: true
+          serviceAccountName: recyclarr
+          automountServiceAccountToken: false
           securityContext:
             fsGroup: 568
             fsGroupChangePolicy: OnRootMismatch
             runAsGroup: 568
             runAsNonRoot: true
             runAsUser: 568
--- HelmRelease: media/recyclarr ServiceAccount: media/recyclarr

+++ HelmRelease: media/recyclarr ServiceAccount: media/recyclarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: recyclarr
+  labels:
+    app.kubernetes.io/instance: recyclarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: recyclarr
+  namespace: media
+
--- HelmRelease: media/jellyfin Deployment: media/jellyfin

+++ HelmRelease: media/jellyfin Deployment: media/jellyfin

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: jellyfin
         app.kubernetes.io/instance: jellyfin
         app.kubernetes.io/name: jellyfin
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: jellyfin
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: media/jellyfin ServiceAccount: media/jellyfin

+++ HelmRelease: media/jellyfin ServiceAccount: media/jellyfin

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: jellyfin
+  labels:
+    app.kubernetes.io/instance: jellyfin
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: jellyfin
+  namespace: media
+
--- HelmRelease: media/prowlarr-exporter Deployment: media/prowlarr-exporter

+++ HelmRelease: media/prowlarr-exporter Deployment: media/prowlarr-exporter

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: prowlarr-exporter
         app.kubernetes.io/instance: prowlarr-exporter
         app.kubernetes.io/name: prowlarr-exporter
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: prowlarr-exporter
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
       hostIPC: false
       hostNetwork: false
--- HelmRelease: media/prowlarr-exporter ServiceMonitor: media/prowlarr-exporter

+++ HelmRelease: media/prowlarr-exporter ServiceMonitor: media/prowlarr-exporter

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: prowlarr-exporter
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: prowlarr-exporter
   namespace: media
 spec:
-  jobLabel: prowlarr-exporter
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - media
   selector:
     matchLabels:
       app.kubernetes.io/service: prowlarr-exporter
--- HelmRelease: media/prowlarr-exporter ServiceAccount: media/prowlarr-exporter

+++ HelmRelease: media/prowlarr-exporter ServiceAccount: media/prowlarr-exporter

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: prowlarr-exporter
+  labels:
+    app.kubernetes.io/instance: prowlarr-exporter
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: prowlarr-exporter
+  namespace: media
+
--- HelmRelease: observability/idrac-exporter Deployment: observability/idrac-exporter

+++ HelmRelease: observability/idrac-exporter Deployment: observability/idrac-exporter

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: idrac-exporter
         app.kubernetes.io/instance: idrac-exporter
         app.kubernetes.io/name: idrac-exporter
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: idrac-exporter
+      automountServiceAccountToken: false
       priorityClassName: high-priority
       securityContext:
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
       hostIPC: false
--- HelmRelease: observability/idrac-exporter ServiceMonitor: observability/idrac-exporter

+++ HelmRelease: observability/idrac-exporter ServiceMonitor: observability/idrac-exporter

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: idrac-exporter
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: idrac-exporter
   namespace: observability
 spec:
-  jobLabel: idrac-exporter
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - observability
   selector:
     matchLabels:
       app.kubernetes.io/service: idrac-exporter
--- HelmRelease: observability/idrac-exporter ServiceAccount: observability/idrac-exporter

+++ HelmRelease: observability/idrac-exporter ServiceAccount: observability/idrac-exporter

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: idrac-exporter
+  labels:
+    app.kubernetes.io/instance: idrac-exporter
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: idrac-exporter
+  namespace: observability
+
--- HelmRelease: media/sonarr Deployment: media/sonarr

+++ HelmRelease: media/sonarr Deployment: media/sonarr

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: sonarr
         app.kubernetes.io/instance: sonarr
         app.kubernetes.io/name: sonarr
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: sonarr
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 0
         runAsGroup: 0
         runAsNonRoot: false
         runAsUser: 0
       hostIPC: false
--- HelmRelease: media/sonarr ServiceAccount: media/sonarr

+++ HelmRelease: media/sonarr ServiceAccount: media/sonarr

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: sonarr
+  labels:
+    app.kubernetes.io/instance: sonarr
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: sonarr
+  namespace: media
+
--- HelmRelease: observability/unpoller Deployment: observability/unpoller

+++ HelmRelease: observability/unpoller Deployment: observability/unpoller

@@ -24,14 +24,14 @@

       labels:
         app.kubernetes.io/controller: unpoller
         app.kubernetes.io/instance: unpoller
         app.kubernetes.io/name: unpoller
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: unpoller
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
       hostIPC: false
       hostNetwork: false
--- HelmRelease: observability/unpoller ServiceMonitor: observability/unpoller

+++ HelmRelease: observability/unpoller ServiceMonitor: observability/unpoller

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: unpoller
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: unpoller
   namespace: observability
 spec:
-  jobLabel: unpoller
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - observability
   selector:
     matchLabels:
       app.kubernetes.io/service: unpoller
--- HelmRelease: observability/unpoller ServiceAccount: observability/unpoller

+++ HelmRelease: observability/unpoller ServiceAccount: observability/unpoller

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: unpoller
+  labels:
+    app.kubernetes.io/instance: unpoller
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: unpoller
+  namespace: observability
+
--- HelmRelease: observability/gatus StatefulSet: observability/gatus

+++ HelmRelease: observability/gatus StatefulSet: observability/gatus

@@ -29,13 +29,13 @@

         app.kubernetes.io/controller: gatus
         app.kubernetes.io/instance: gatus
         app.kubernetes.io/name: gatus
     spec:
       enableServiceLinks: false
       serviceAccountName: gatus
-      automountServiceAccountToken: true
+      automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 1000
         runAsNonRoot: true
         runAsUser: 1000
--- HelmRelease: observability/gatus ServiceMonitor: observability/gatus

+++ HelmRelease: observability/gatus ServiceMonitor: observability/gatus

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: gatus
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: gatus
   namespace: observability
 spec:
-  jobLabel: gatus
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - observability
   selector:
     matchLabels:
       app.kubernetes.io/service: gatus
--- HelmRelease: media/tqm CronJob: media/tqm

+++ HelmRelease: media/tqm CronJob: media/tqm

@@ -26,14 +26,14 @@

           labels:
             app.kubernetes.io/controller: tqm
             app.kubernetes.io/instance: tqm
             app.kubernetes.io/name: tqm
         spec:
           enableServiceLinks: false
-          serviceAccountName: default
-          automountServiceAccountToken: true
+          serviceAccountName: tqm
+          automountServiceAccountToken: false
           securityContext:
             runAsGroup: 1000
             runAsNonRoot: true
             runAsUser: 1000
             supplementalGroups:
             - 65537
--- HelmRelease: media/tqm ServiceAccount: media/tqm

+++ HelmRelease: media/tqm ServiceAccount: media/tqm

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: tqm
+  labels:
+    app.kubernetes.io/instance: tqm
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: tqm
+  namespace: media
+
--- HelmRelease: media/radarr-exporter Deployment: media/radarr-exporter

+++ HelmRelease: media/radarr-exporter Deployment: media/radarr-exporter

@@ -26,14 +26,14 @@

       labels:
         app.kubernetes.io/controller: radarr-exporter
         app.kubernetes.io/instance: radarr-exporter
         app.kubernetes.io/name: radarr-exporter
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
-      automountServiceAccountToken: true
+      serviceAccountName: radarr-exporter
+      automountServiceAccountToken: false
       securityContext:
         runAsGroup: 568
         runAsNonRoot: true
         runAsUser: 568
       hostIPC: false
       hostNetwork: false
--- HelmRelease: media/radarr-exporter ServiceMonitor: media/radarr-exporter

+++ HelmRelease: media/radarr-exporter ServiceMonitor: media/radarr-exporter

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: radarr-exporter
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: radarr-exporter
   namespace: media
 spec:
-  jobLabel: radarr-exporter
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - media
   selector:
     matchLabels:
       app.kubernetes.io/service: radarr-exporter
--- HelmRelease: media/radarr-exporter ServiceAccount: media/radarr-exporter

+++ HelmRelease: media/radarr-exporter ServiceAccount: media/radarr-exporter

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: radarr-exporter
+  labels:
+    app.kubernetes.io/instance: radarr-exporter
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: radarr-exporter
+  namespace: media
+

@robottoms-up robottoms-up Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 964f7d9 to aef95f4 Compare May 14, 2026 19:16
@robottoms-up robottoms-up Bot changed the title feat(flux-helmrelease)!: update ghcr.io/bjw-s-labs/helm/app-template ( 4.6.2 → 5.0.0 ) feat(flux-helmrelease)!: update ghcr.io/bjw-s-labs/helm/app-template ( 4.6.2 → 5.0.1 ) May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants