What's new in chart-v0.26.3
A chart-only release that changes where the chart and its image are published, and nothing else. The repository joined the Institut du Numérique Responsable, so the chart is now pushed to oci://ghcr.io/institut-du-numerique-responsable/charts/perf-sentinel and image.repository defaults to ghcr.io/institut-du-numerique-responsable/perf-sentinel. appVersion is intentionally held at 0.26.2 because the binary did not change. The chart version advances to 0.26.3 on its own, and the next application release is 0.26.4.
The same bytes at a new address
Every image and chart version published under ghcr.io/robintra was copied to the new namespace with its digest unchanged, and the chart signatures and the image attestations came along. A tag or digest pinned today resolves at both addresses. Only the new one receives new releases, the old namespace stays at 0.26.2. The Docker Hub image keeps its name, robintrassard/perf-sentinel.
Changed
image.repositorydefaults toghcr.io/institut-du-numerique-responsable/perf-sentinel.home,sources,iconand the Artifact Hub links point at the repository's new home.
Upgrade impact
- Pods roll once, on the image reference alone. The
image:field moves fromghcr.io/robintra/perf-sentinel:0.26.2toghcr.io/institut-du-numerique-responsable/perf-sentinel:0.26.2. Both resolve to the same digest,sha256:908c9b31…, so the daemon that comes back is the one that left. - A values file that sets
image.repositorykeeps pulling from where it points. Point it at the new namespace, or at a mirror synced from it, to receive the next releases. - Registry mirrors and allow-lists that name
ghcr.io/robintraneed the new namespace. checksum/configmoves, and not because your configuration changed. The renderedperf-sentinel.tomlis identical, but the ConfigMap carries ahelm.sh/chartlabel that bumps with the chart.- No
values.yamlkey is added or removed, no template changes, and the shippedPrometheusRuleis untouched.
Verifying this chart
Charts signed before the move carry the original account's identity, so the regex accepts both owners:
cosign verify \
--certificate-identity-regexp '^https://github.com/(robintra|Institut-du-Numerique-Responsable)/perf-sentinel/\.github/workflows/helm-release\.yml@refs/tags/chart-v' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
ghcr.io/institut-du-numerique-responsable/charts/perf-sentinel:0.26.3
helm pull oci://ghcr.io/institut-du-numerique-responsable/charts/perf-sentinel --version 0.26.3
gh attestation verify perf-sentinel-0.26.3.tgz \
--repo Institut-du-Numerique-Responsable/perf-sentinelcosign 3.0 or newer is required, the signature is an OCI 1.1 referrer bundle.
Install
The chart is published as an OCI artifact on GHCR, install it directly with no helm repo add step:
helm install perf-sentinel oci://ghcr.io/institut-du-numerique-responsable/charts/perf-sentinel --version 0.26.3Upgrade an existing release:
helm upgrade perf-sentinel oci://ghcr.io/institut-du-numerique-responsable/charts/perf-sentinel --version 0.26.3Read docs/HELM-DEPLOYMENT.md for the ServiceMonitor section, sizing and Ingress postures.
If you are upgrading from chart-v0.23.0 or earlier, read the chart-v0.24.0 notes first: that release raises the default workload.statefulset.persistence.size to 2Gi, which an existing StatefulSet does not pick up on its own. From chart-v0.18.0 or earlier, read the chart-v0.19.0 notes as well: that release adds a grouping label to five metrics and is breaking for an unaggregated alert on any of them. From chart-v0.16.0 or earlier, the chart-v0.17.0 notes change the shipped PrometheusRule.
Full Changelog: chart-v0.26.2...chart-v0.26.3