sonarqube
- Upgrade Chart's version to 2026.5.1000
- Decouple the chart's
versionfromappVersion: it now follows<SonarQube major>.<minor>.<patch counter>, with the counter starting at1000per minor line - Upgrade SonarQube Server to 2026.5.0
- Upgrade SonarQube Community build to 26.9.0.129388
- Breaking: The chart now manages liveness/readiness probe handlers; legacy
exec/httpGet/tcpSocket/grpcvalues are ignored, useoverrideCommandinstead - Set a default MCP pod
securityContext(fsGroup: 0),HOME=/dataand an optionalmcp.initContainershook so the non-root MCP server can write to/data - Breaking: Remove the deprecated
ingress-nginx.enabled/nginx.enabledbundled ingress-nginx controller subchart dependency.ingress.enabledremains supported for use with a self-managed ingress controller;httproute.enabled(Gateway API) is also available - Add
gateway-api-migration-scripts/nginx-to-istio-migration.shto help migrate from the bundled ingress-nginx controller to Gateway API - Update MCP image to
sonarsource/sonarqube-mcp:2026.5.0 - Add the Agent Orchestrator image
sonarsource/sonarqube-agent-orchestrator:2026.5.0 - Add the Hunter Agent image
sonarsource/sonarqube-hunter-agent:2026.5.0 - Add the Remediation Agent image
sonarsource/sonarqube-remediation-agent:2026.5.0 - Add the Vortex image
sonarsource/sonar-vortex:2026.5.0 - Add optional gVisor (runsc) sandboxing for the agent runtimes
- Add the SonarQube Agent Orchestrator, Hunter Agent and Remediation Agent via
agentOrchestrator.enabled,hunterAgent.enabledandremediationAgent.enabled; the agent runtimes get their own ServiceAccount by default (<hunterAgent|remediationAgent>.serviceAccount.create), not the top-level one - Set the Hunter Agent's
SCRIPT_PATH(detection mode) fromhunterAgent.scriptPath - Default the Hunter Agent's
PLAYBOOK_KEY/PLAYBOOK_VERSIONtoappsec/stableviahunterAgent.playbookKey/playbookVersion - Add
agentOrchestrator.env/extraVolumes/extraVolumeMountsand a FILESYSTEM/NFS backend for the shared agentic job storage (agentOrchestrator.storage.type) - Add autoscaling for the Agent Orchestrator (CPU/memory HPA) and the Hunter/Remediation Agent runtimes (KEDA
ScaledObject) via<component>.autoscaling - Add an optional KEDA operator subchart dependency (
keda.enabled) to install KEDA together with the release - Ship default resource requests and limits for the Hunter Agent and Vortex so neither runs in the BestEffort QoS class
- Point the Agent Orchestrator and agent runtime probes at
/readyz//livezinstead of/health, and addagentOrchestrator.terminationGracePeriodSeconds - Add
<hunterAgent|remediationAgent>.storageto scope each agent runtime to its own subtree of a shared FILESYSTEM/NFS job storage - Upgrade the bundled JMX Prometheus Exporter to 1.6.0; versions 1.1.0 and later download from GitHub Releases, earlier ones from Maven Central
- Add
prometheusExporter.metricsPath(default/metrics) and optionalprometheusExporter.sha256download verification - Default exporter downloads from GitHub require access to
github.comandrelease-assets.githubusercontent.com - Breaking: Built-in JVM metrics use OpenMetrics names (e.g.
jvm_memory_bytes_usedis nowjvm_memory_used_bytes);config.rulesmetrics are unaffected - Breaking: The default exporter scrape path is now
/metricsinstead of/; setprometheusExporter.metricsPath: /to keep the old path - Sandbox the agent runtimes with Kata Containers instead of gVisor on OpenShift via
OpenShift.agentRuntimeClassName(defaultkata); the RuntimeClass must exist - Target
openshift-dnson port 5353 (UDP/TCP) in the NetworkPolicy DNS egress rules whenOpenShift.enabledistrue; thekube-dnsrule never matched there - Add KEDA-based autoscaling for Vortex (
vortexAnalysis.autoscaling) on its concurrent-request metric; requires KEDA>= 2.20.0 - Allow a fractional
vortexAnalysis.autoscaling.targetConcurrentRequests(e.g.1.5), as KEDA parses it as a float - Stop emitting the Vortex
ScaledObject'sspec.fallbackwithaggregateAcrossReplicas: false, where KEDA < 2.17 scaled the fleet down on scrape failure - Fix
caCerts.configMapmounting a single certificate; omittingconfigMap.key/pathnow imports every key, andpathwithoutkeyfails fast - Add
istio.enabledto run every chart-owned workload under STRICT mTLS, andistio.meshSidecar.enabledto give sandboxed agent runtimes a mesh identity - Add
mcp.nodeSelector/affinity/tolerations(falling back to the chart-wide values) andmcp.topologySpreadConstraints;priorityClassNamenow also applies to MCP - Add
topologySpreadConstraintsfor Vortex, the Agent Orchestrator and the agent runtimes, and apply the chart-widepriorityClassNameto them - Fix
jvmOpts/jvmCeOptsbeing dropped instead of merged whensonar.web.javaOpts/sonar.ce.javaOptsis also set insonarProperties - Raise the default probe
timeoutSecondsto5so thesh/curlexec probe is not killed under CPU contention - Agent runtimes reach the Agent Egress Proxy by ClusterIP instead of DNS, dropping their kube-dns egress; recreating the proxy Service requires restarting them
- Add
istio.istiodClusterIP(defaultauto) to pin istiod's address in agent runtime pods and drop their kube-dns egress;helm templateneeds it set - Add
istio.revisionto target a revisioned (canary) Istio control plane'sistiod-<revision>Service vortexAnalysis.enablednow defaults totruewhenremediationAgent.enabledistrue- Raise the Remediation Agent's default
runAsUser/runAsGroupfrom1000to10001, fixing incomplete generated PR content - Support Oracle and Microsoft SQL Server for the Agent Orchestrator: it now gets the full JDBC URL (
CORE_DB_JDBC_URL, overridable withagentOrchestrator.coreDb.jdbcUrl), and the Oracle driver fromjdbcOverwrite.oracleJdbcDriver.urlis installed in its pod - Fix the
install-oracle-jdbc-driverinit container keepingrunAsUser/runAsGroupon OpenShift, which kept the restricted-v2 SCC from admitting the SonarQube pod - Raise the default
resources.requests.memoryto4096Mandresources.limits.memoryto10240Mto fit the higher SonarQube Server 2026.5 Web/CE heap defaults - Supported Kubernetes versions are now 1.34 to 1.37 and OpenShift 4.19 to 4.22
sonarqube-dce
- Upgrade Chart's version to 2026.5.1000
- Decouple the chart's
versionfromappVersion: it now follows<SonarQube major>.<minor>.<patch counter>, with the counter starting at1000per minor line - Upgrade SonarQube Server to 2026.5.0
- Fail DCE upgrades across an Elasticsearch major while search pods are still running; scale
searchNodes.replicaCountto 0 first - Breaking: The chart now manages Application node liveness/readiness probe handlers; legacy
exec/httpGet/tcpSocket/grpcvalues are ignored, useoverrideCommandinstead - Set a default MCP pod
securityContext(fsGroup: 0),HOME=/dataand an optionalmcp.initContainershook so the non-root MCP server can write to/data - Breaking: Remove the deprecated
ingress-nginx.enabled/nginx.enabledbundled ingress-nginx controller subchart dependency.ingress.enabledremains supported for use with a self-managed ingress controller;httproute.enabled(Gateway API) is also available - Add
gateway-api-migration-scripts/nginx-to-istio-migration.shto help migrate from the bundled ingress-nginx controller to Gateway API - Update MCP image to
sonarsource/sonarqube-mcp:2026.5.0 - Add the Agent Orchestrator image
sonarsource/sonarqube-agent-orchestrator:2026.5.0 - Add the Hunter Agent image
sonarsource/sonarqube-hunter-agent:2026.5.0 - Add the Remediation Agent image
sonarsource/sonarqube-remediation-agent:2026.5.0 - Add the Vortex image
sonarsource/sonar-vortex:2026.5.0 - Add optional gVisor (runsc) sandboxing for the agent runtimes
- Add the SonarQube Agent Orchestrator, Hunter Agent and Remediation Agent via
agentOrchestrator.enabled,hunterAgent.enabledandremediationAgent.enabled; the agent runtimes get their own ServiceAccount by default (<hunterAgent|remediationAgent>.serviceAccount.create), not the top-level one - Set the Hunter Agent's
SCRIPT_PATH(detection mode) fromhunterAgent.scriptPath - Default the Hunter Agent's
PLAYBOOK_KEY/PLAYBOOK_VERSIONtoappsec/stableviahunterAgent.playbookKey/playbookVersion - Add
agentOrchestrator.env/extraVolumes/extraVolumeMountsand a FILESYSTEM/NFS backend for the shared agentic job storage (agentOrchestrator.storage.type) - Mount the
sonarSecretKeysecret into the Agent Orchestrator and expose its path asAGENTIC_SECRET_KEY_PATH - Add autoscaling for the Agent Orchestrator (CPU/memory HPA) and the Hunter/Remediation Agent runtimes (KEDA
ScaledObject) via<component>.autoscaling - Add an optional KEDA operator subchart dependency (
keda.enabled) to install KEDA together with the release - Ship default resource requests and limits for the Hunter Agent and Vortex so neither runs in the BestEffort QoS class
- Point the Agent Orchestrator and agent runtime probes at
/readyz//livezinstead of/health, and addagentOrchestrator.terminationGracePeriodSeconds - Add
<hunterAgent|remediationAgent>.storageto scope each agent runtime to its own subtree of a shared FILESYSTEM/NFS job storage - Upgrade the bundled JMX Prometheus Exporter to 1.6.0; versions 1.1.0 and later download from GitHub Releases, earlier ones from Maven Central
- Add
applicationNodes.prometheusExporter.metricsPath(default/metrics) and optionalapplicationNodes.prometheusExporter.sha256download verification - Default exporter downloads from GitHub require access to
github.comandrelease-assets.githubusercontent.com - Breaking: Built-in JVM metrics use OpenMetrics names (e.g.
jvm_memory_bytes_usedis nowjvm_memory_used_bytes);config.rulesmetrics are unaffected - Breaking: The default exporter scrape path is now
/metricsinstead of/; setapplicationNodes.prometheusExporter.metricsPath: /to keep the old path - Sandbox the agent runtimes with Kata Containers instead of gVisor on OpenShift via
OpenShift.agentRuntimeClassName(defaultkata); the RuntimeClass must exist - Target
openshift-dnson port 5353 (UDP/TCP) in the NetworkPolicy DNS egress rules whenOpenShift.enabledistrue; thekube-dnsrule never matched there - Add KEDA-based autoscaling for Vortex (
vortexAnalysis.autoscaling) on its concurrent-request metric; requires KEDA>= 2.20.0 - Allow a fractional
vortexAnalysis.autoscaling.targetConcurrentRequests(e.g.1.5), as KEDA parses it as a float - Stop emitting the Vortex
ScaledObject'sspec.fallbackwithaggregateAcrossReplicas: false, where KEDA < 2.17 scaled the fleet down on scrape failure - Fix
caCerts.configMapmounting a single certificate; omittingconfigMap.key/pathnow imports every key, andpathwithoutkeyfails fast - Add
istio.enabledto run every chart-owned workload under STRICT mTLS, andistio.meshSidecar.enabledto give sandboxed agent runtimes a mesh identity - Add
mcp.nodeSelector/affinity/tolerations(falling back to the chart-wide values) andmcp.topologySpreadConstraints;priorityClassNamenow also applies to MCP - Add
topologySpreadConstraintsfor Vortex, the Agent Orchestrator and the agent runtimes, and apply the chart-widepriorityClassNameto them - Fix
applicationNodes.jvmOpts/jvmCeOptsbeing dropped instead of merged whensonar.web.javaOpts/sonar.ce.javaOptsis set insonarProperties - Raise the default probe
timeoutSecondsto5on search and application nodes, andapplicationNodes.livenessProbe.failureThresholdto8 - Agent runtimes reach the Agent Egress Proxy by ClusterIP instead of DNS, dropping their kube-dns egress; recreating the proxy Service requires restarting them
- Add
istio.istiodClusterIP(defaultauto) to pin istiod's address in agent runtime pods and drop their kube-dns egress;helm templateneeds it set - Add
istio.revisionto target a revisioned (canary) Istio control plane'sistiod-<revision>Service vortexAnalysis.enablednow defaults totruewhenremediationAgent.enabledistrue- Raise the Remediation Agent's default
runAsUser/runAsGroupfrom1000to10001, fixing incomplete generated PR content - Support Oracle and Microsoft SQL Server for the Agent Orchestrator: it now gets the full JDBC URL (
CORE_DB_JDBC_URL, overridable withagentOrchestrator.coreDb.jdbcUrl), and the Oracle driver fromjdbcOverwrite.oracleJdbcDriver.urlis installed in its pod - Fix the
install-oracle-jdbc-driverinit container keepingrunAsUser/runAsGroupon OpenShift, which kept the restricted-v2 SCC from admitting the application pods - Raise the default
applicationNodes.resourcesmemory request and limit to8192Mto fit the higher SonarQube Server 2026.5 Web/CE heap defaults - Supported Kubernetes versions are now 1.34 to 1.37 and OpenShift 4.19 to 4.22