Files
wbsong111 16321b52c7 dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
2026-08-06 09:42:24 +09:00
..

frr-k8s

Version: 0.0.25 Type: application AppVersion: v0.0.25

A cloud native wrapper of FRR

Homepage: https://metallb.universe.tf

Source Code

Requirements

Kubernetes: >= 1.19.0-0

Repository Name Version
crds 0.0.25

Values

Key Type Default Description
crds.enabled bool true Enable installation of CRDs.
crds.validationFailurePolicy string "Fail" Validation failure policy for CRDs. Can be Fail or Ignore.
frrk8s.affinity object {} Affinity for pod assignment.
frrk8s.alwaysBlock string "" A comma separated list of cidrs to always block for incoming routes.
frrk8s.bgpDebounceTimeout integer nil BGP debounce timeout for FRR configuration reloads, in milliseconds. Default (when unset) is 3000 ms.This feature is experimental
frrk8s.disableCertRotation bool false Specifies whether the cert rotator works as part of the webhook.
frrk8s.frr.acceptIncomingBGPConnections bool false Allow FRR to accept incoming BGP connections.
frrk8s.frr.image.pullPolicy string nil The FRR image pull policy.
frrk8s.frr.image.repository string "quay.io/frrouting/frr" The FRR image repository.
frrk8s.frr.image.tag string "10.4.3" The FRR image tag.
frrk8s.frr.metricsBindAddress string "127.0.0.1" Bind address for FRR metrics.
frrk8s.frr.metricsPort int 7573 Port for FRR metrics.
frrk8s.frr.resources object {} Resource limits and requests for the FRR container.
frrk8s.frr.secureMetricsPort int 9141 Secure metrics port for FRR.
frrk8s.frrMetrics.resources object {} Resource limits and requests for the FRR metrics container.
frrk8s.frrStatus.pollInterval string "2m" Polling interval for FRR status updates.
frrk8s.frrStatus.resources object {} Resource limits and requests for the FRR status container.
frrk8s.image.pullPolicy string nil The frr-k8s image pull policy.
frrk8s.image.repository string "quay.io/metallb/frr-k8s" The frr-k8s image repository.
frrk8s.image.tag string nil The frr-k8s image tag. If not set, defaults to the chart appVersion.
frrk8s.labels object {"app":"frr-k8s"} Additional labels to add to the pod.
frrk8s.livenessProbe.enabled bool true Enable liveness probe.
frrk8s.livenessProbe.failureThreshold int 3 Number of failures before the probe is considered failed.
frrk8s.livenessProbe.initialDelaySeconds int 10 Number of seconds after the container has started before liveness probes are initiated.
frrk8s.livenessProbe.periodSeconds int 10 How often (in seconds) to perform the probe.
frrk8s.livenessProbe.successThreshold int 1 Minimum consecutive successes for the probe to be considered successful.
frrk8s.livenessProbe.timeoutSeconds int 1 Number of seconds after which the probe times out.
frrk8s.logLevel string "info" Controller log level that is passed as a CLI flag. Must be one of: all, debug, info, warn, error or none
frrk8s.nodeSelector object {} Node selector for pod assignment.
frrk8s.podAnnotations object {} Additional annotations to add to the pod.
frrk8s.priorityClassName string "" Priority class name for the pod.
frrk8s.readinessProbe.enabled bool true Enable readiness probe.
frrk8s.readinessProbe.failureThreshold int 3 Number of failures before the probe is considered failed.
frrk8s.readinessProbe.initialDelaySeconds int 10 Number of seconds after the container has started before readiness probes are initiated.
frrk8s.readinessProbe.periodSeconds int 10 How often (in seconds) to perform the probe.
frrk8s.readinessProbe.successThreshold int 1 Minimum consecutive successes for the probe to be considered successful.
frrk8s.readinessProbe.timeoutSeconds int 1 Number of seconds after which the probe times out.
frrk8s.reloader.resources object {} Resource limits and requests for the reloader container.
frrk8s.resources object {} Resource limits and requests for the frr-k8s controller container.
frrk8s.restartOnRotatorSecretRefresh bool false Specifies whether the pod restarts when the rotator refreshes the cert secret. Useful for webhook stability during redeployments.
frrk8s.runtimeClassName string "" Runtime class name for the pod.
frrk8s.serviceAccount.annotations object {} Additional annotations to add to the ServiceAccount.
frrk8s.serviceAccount.create bool true Specifies whether a ServiceAccount should be created.
frrk8s.serviceAccount.name string "" The name of the ServiceAccount to use. If not set and create is true, a name is generated using the fullname template.
frrk8s.startupProbe.enabled bool true Enable startup probe.
frrk8s.startupProbe.failureThreshold int 30 Number of failures before the probe is considered failed.
frrk8s.startupProbe.periodSeconds int 5 How often (in seconds) to perform the probe.
frrk8s.tolerateMaster bool true Tolerate master nodes for pod scheduling.
frrk8s.tolerations list [] Tolerations for pod assignment.
frrk8s.updateStrategy.type string "RollingUpdate" Specify the FRR-K8s daemonset update strategy.
frrk8s.webhookPort int 19443 Port for the webhook server.
fullnameOverride string "" String to override the default fully qualified app name.
nameOverride string "" String to override the default chart name.
prometheus.namespace string "" The namespace where Prometheus is deployed. Required when ".Values.prometheus.rbacPrometheus == true" and "prometheus.serviceMonitor.enabled=true".
prometheus.rbacPrometheus bool false Give Prometheus permission to scrape metallb's namespace.
prometheus.scrapeAnnotations bool false Add Prometheus metric auto-collection annotations to pods.
prometheus.secureMetricsPort int 9140 Port frr-k8s will listen on for secure metrics.
prometheus.serviceAccount string "" The service account used by Prometheus. Required when ".Values.prometheus.rbacPrometheus == true" and "prometheus.serviceMonitor.enabled=true"
prometheus.serviceMonitor.additionalLabels object {} Additional labels to add to the ServiceMonitor.
prometheus.serviceMonitor.annotations object {} Optional additional annotations for the controller serviceMonitor.
prometheus.serviceMonitor.enabled bool false Enable support for Prometheus Operator.
prometheus.serviceMonitor.interval string nil Scrape interval. If not set, the Prometheus default scrape interval is used.
prometheus.serviceMonitor.jobLabel string "app.kubernetes.io/name" Job label for scrape target.
prometheus.serviceMonitor.metricRelabelings list [] Metric relabel configs to apply to samples before ingestion.
prometheus.serviceMonitor.relabelings list [] Relabel configs to apply to samples before ingestion.
prometheus.serviceMonitor.tlsConfig.insecureSkipVerify bool true Disables SSL certificate verification
rbac.create bool true Specifies whether to install and use RBAC rules.
tls.cipherSuites string "" Comma-separated list of TLS cipher suites. If empty, uses Go defaults. Only applies to TLS 1.2.
tls.curvePreferences string "" Comma-separated list of numeric CurveID values (e.g. 29,4588). See https://pkg.go.dev/crypto/tls#CurveID. If empty, uses Go defaults.
tls.metricsTLSSecret string "" The name of the secret to be mounted in the pods to provide TLS certificates for metrics endpoints. If not present, a self-signed certificate is auto-generated.
tls.minVersion string "" Minimum TLS version (VersionTLS12 or VersionTLS13). Defaults to VersionTLS13.

Autogenerated from chart metadata using helm-docs v1.10.0