Files
wbsong111 16321b52c7 dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
2026-08-06 09:42:24 +09:00

6.8 KiB

infisical-standalone

Version: 1.9.0 Type: application AppVersion: 1.0.1

A helm chart to deploy Infisical

Requirements

Repository Name Version
https://charts.bitnami.com/bitnami postgresql 14.1.3
https://charts.bitnami.com/bitnami redis 18.14.0
https://kubernetes.github.io/ingress-nginx ingress-nginx 4.0.13

Values

Key Type Default Description
fullnameOverride string "" Overrides the full name of the release, affecting resource names
infisical.affinity object {} Node affinity settings for pod placement
infisical.databaseSchemaMigrationJob.image.pullPolicy string "IfNotPresent" Pulls image only if not present on the node
infisical.databaseSchemaMigrationJob.image.repository string "ghcr.io/groundnuty/k8s-wait-for" Image repository for migration wait job
infisical.databaseSchemaMigrationJob.image.tag string "no-root-v2.0" Image tag version
infisical.deploymentAnnotations object {} Custom annotations for Infisical deployment
infisical.enabled bool true
infisical.extraContainers list [] Additional containers to run alongside the Infisical container (sidecars). Useful for running auxiliary services like HSM PKCS#11 clients
infisical.extraEnv list [] Extra environment variables to set on the Infisical container
infisical.extraInitContainers list [] Additional init containers to run before the Infisical container starts
infisical.extraVolumeMounts list [] Additional volume mounts for the Infisical container
infisical.extraVolumes list [] Additional volumes to attach to the Infisical pods
infisical.fullnameOverride string "" Override for the full name of Infisical resources in this deployment
infisical.image.imagePullSecrets list [] Secret references for pulling the image, if needed
infisical.image.pullPolicy string "IfNotPresent" Pulls image only if not already present on the node
infisical.image.repository string "infisical/infisical" Image repository for the Infisical service
infisical.image.tag string "v0.93.1-postgres" Specific version tag of the Infisical image. View the latest version here https://hub.docker.com/r/infisical/infisical
infisical.kubeSecretRef string "infisical-secrets" Kubernetes Secret reference containing Infisical root credentials
infisical.name string "infisical"
infisical.podAnnotations object {} Custom annotations for Infisical pods
infisical.replicaCount int 2 Number of pod replicas for high availability
infisical.resources.limits.memory string "600Mi" Memory limit for Infisical container
infisical.resources.requests.cpu string "350m" CPU request for Infisical container
infisical.service.annotations object {} Custom annotations for Infisical service
infisical.service.nodePort string "" Optional node port for service when using NodePort type
infisical.service.type string "ClusterIP" Service type, can be changed based on exposure needs (e.g., LoadBalancer)
infisical.serviceAccount.annotations object {} Custom annotations for the auto-created service account
infisical.serviceAccount.create bool true Creates a new service account if true, with necessary permissions for this chart. If false and serviceAccount.name is not defined, the chart will attempt to use the Default service account
infisical.serviceAccount.name string nil Optional custom service account name, if existing service account is used
ingress.annotations object {} Custom annotations for ingress resource
ingress.enabled bool true Enable or disable ingress configuration
ingress.hostName string "" Hostname for ingress access, e.g., app.example.com
ingress.ingressClassName string "" Specifies the ingress class. Defaults to "infisical-nginx" when bundled ingress-nginx is enabled, or "nginx" otherwise
ingress.nginx.enabled bool true Enable NGINX-specific settings, if using NGINX ingress controller
ingress.tls list [] TLS settings for HTTPS access
nameOverride string "" Overrides the default release name
postgresql.auth.database string "infisicalDB" Database name for Infisical
postgresql.auth.password string "root" Password for PostgreSQL database access
postgresql.auth.username string "infisical" Database username for PostgreSQL
postgresql.enabled bool true Enables an in-cluster PostgreSQL deployment. To achieve HA for Postgres, we recommend deploying https://github.com/zalando/postgres-operator instead.
postgresql.fullnameOverride string "postgresql" Full name override for PostgreSQL resources
postgresql.name string "postgresql" PostgreSQL resource name
postgresql.useExistingPostgresSecret.enabled bool false Set to true if using an existing Kubernetes secret that contains PostgreSQL connection string
postgresql.useExistingPostgresSecret.existingConnectionStringSecret.key string "" Key name in the Kubernetes secret that holds the connection string
postgresql.useExistingPostgresSecret.existingConnectionStringSecret.name string "" Kubernetes secret name containing the PostgreSQL connection string
redis.architecture string "standalone" Redis deployment type (e.g., standalone or cluster)
redis.auth.password string "mysecretpassword" Redis password
redis.cluster.enabled bool false Clustered Redis deployment
redis.enabled bool true Enables an in-cluster Redis deployment
redis.fullnameOverride string "redis" Full name override for Redis resources
redis.name string "redis" Redis resource name
redis.usePassword bool true Requires a password for Redis authentication
ingress-nginx.controller.ingressClassResource.name string "infisical-nginx" IngressClass name used by the bundled NGINX controller. Uses a unique name to avoid conflicts with existing cluster ingress controllers
ingress-nginx.controller.ingressClassResource.controllerValue string "k8s.io/infisical-nginx" Controller value for the bundled IngressClass
ingress-nginx.controller.ingressClassResource.default bool false Whether the bundled IngressClass should be set as the cluster default
ingress-nginx.controller.ingressClass string "infisical-nginx" Ingress class the bundled controller watches for