apiVersion: helm.toolkit.fluxcd.io/v2 kind: HelmRelease metadata: name: cms-plugins-production namespace: flux-system spec: interval: 5m chart: spec: chart: ./deploy/helm sourceRef: kind: GitRepository name: cms-plugins-production namespace: flux-system reconcileStrategy: Revision releaseName: cms-plugins-production targetNamespace: kotkan install: disableWait: true remediation: retries: 3 upgrade: disableWait: true remediation: retries: 3 values: existingSecret: cms-plugins-production-secrets image: # `tag` stays human-readable. The chart prefers `digest` when set # and renders `repository@` — that's what actually pins # the pod. Without digest pinning, helm upgrade would see no spec # change when CI retags the floating `production` tag. tag: production digest: "" # {"$imagepolicy": "kotkan:cms-plugins-production:digest"} pullPolicy: Always ingress: host: cms-plugins-production.kotkanagrilli.fi nodeSelector: kubernetes.io/hostname: kotkan persistence: size: 10Gi resources: requests: cpu: 100m memory: 384Mi limits: cpu: "1" memory: 1Gi