Skip to content

A new version of gitlab (13.6.0) is available

FDO helm bot requested to merge upgrade-to-13.6.0 into master

current diff:

--- current-deployment.yaml
+++ future-deployment.yaml
@@ -62,7 +62,7 @@
   namespace: default
   labels:
     app: gitaly
-    chart: gitaly-4.5.2
+    chart: gitaly-4.6.0
     release: gitlab-prod
     heritage: Tiller
 spec:
@@ -80,7 +80,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
 spec:
@@ -98,7 +98,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
 spec:
@@ -112,7 +112,7 @@
 apiVersion: policy/v1beta1
 kind: PodDisruptionBudget
 metadata:
-  name: gitlab-prod-nginx-ingress-controller
+  name: gitlab-prod-nginx-ingress-controller-1
   namespace: default
   labels:
     app: nginx-ingress
@@ -126,27 +126,6 @@
       app: nginx-ingress
       release: gitlab-prod
       component: "controller"
-  minAvailable: 2
-
----
-# Source: helm-gitlab-omnibus/charts/gitlab/charts/nginx-ingress/templates/default-backend-poddisruptionbudget.yaml
-apiVersion: policy/v1beta1
-kind: PodDisruptionBudget
-metadata:
-  name: gitlab-prod-nginx-ingress-default-backend
-  namespace: default
-  labels:
-    app: nginx-ingress
-    chart: nginx-ingress-0.30.0-1
-    release: gitlab-prod
-    heritage: Tiller
-    component: "default-backend"
-spec:
-  selector:
-    matchLabels:
-      app: nginx-ingress
-      release: gitlab-prod
-      component: "default-backend"
   minAvailable: 1
 
 ---
@@ -469,7 +448,7 @@
   namespace: default
   labels:
     app: gitaly
-    chart: gitaly-4.5.2
+    chart: gitaly-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -523,7 +502,7 @@
     # location of shared secret for GitLab Shell / API interaction
     secret_file = "/etc/gitlab-secrets/shell/.gitlab_shell_secret"
     # URL of API
-    url = "http://gitlab-prod-webservice:8181/"
+    url = "http://gitlab-prod-webservice.default.svc:8181/"
 
     [gitlab.http-settings]
     # read_timeout = 300
@@ -547,7 +526,7 @@
   namespace: default
   labels:
     app: gitlab-exporter
-    chart: gitlab-exporter-4.5.2
+    chart: gitlab-exporter-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -581,7 +560,7 @@
           - probe_retries
           - probe_stats
         opts:
-          redis_url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master:6379
+          redis_url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master.default.svc:6379
           redis_enable_client: false
 
       metrics:
@@ -627,7 +606,7 @@
   labels:
     gitlab_grafana_datasource: "true"
     app: gitlab-grafana
-    chart: gitlab-grafana-4.5.2
+    chart: gitlab-grafana-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -640,7 +619,7 @@
       - name: GitLab installed Prometheus
         type: prometheus
         orgId: 1
-        url: "http://gitlab-prod-prometheus-server"
+        url: "http://gitlab-prod-prometheus-server.default.svc"
         access: proxy
         isDefault: true
         editable: false
@@ -654,7 +633,7 @@
   namespace: default
   labels:
     app: gitlab-grafana
-    chart: gitlab-grafana-4.5.2
+    chart: gitlab-grafana-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -686,7 +665,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -847,7 +826,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -875,7 +854,7 @@
     user: git
 
     # Url to gitlab instance. Used for api calls. Should end with a slash.
-    gitlab_url: "http://gitlab-prod-webservice:8181/"
+    gitlab_url: "http://gitlab-prod-webservice.default.svc:8181/"
 
     secret_file: /etc/gitlab-secrets/shell/.gitlab_shell_secret
 
@@ -911,7 +890,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -925,7 +904,7 @@
   namespace: default
   labels:
     app: task-runner
-    chart: task-runner-4.5.2
+    chart: task-runner-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -961,7 +940,7 @@
     }
   resque.yml.erb: |
     production:
-      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master:6379
+      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master.default.svc:6379
       
       id:
   
@@ -969,7 +948,7 @@
   
   cable.yml.erb: |
     production:
-      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master:6379
+      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master.default.svc:6379
       
       id:
       adapter: redis
@@ -1025,6 +1004,8 @@
             bucket: gitlab-terraform-state
           dependency_proxy:
             bucket: gitlab-dependency-proxy
+          pages:
+            bucket: pages
       # Individual object storage backed feature properties configuration
       artifacts:
         enabled: true
@@ -1047,14 +1028,26 @@
           remote_directory: gitlab-pseudo
       
       pages:
-        enabled: false
+        enabled: true
+        access_control: false
+        artifacts_server: false
+        path: 
+        host: pages.freedesktop.org # TODO: move to "gitlab.pages.host" template
+        port: 0
+        https: false
+        secret_file: /etc/gitlab/pages/secret
+        external_http: false
+        external_https: false
+        object_store:
+          enabled: false
+          remote_directory: pages
       mattermost:
         enabled: false
       ## Registry Integration
       registry:
         enabled: true
         host: registry.freedesktop.org
-        api_url: http://gitlab-prod-registry:5000
+        api_url: http://gitlab-prod-registry.default.svc:5000
         key: /etc/gitlab/registry/gitlab-registry.key
         issuer: gitlab-issuer
       gitlab_ci:
@@ -1085,7 +1078,7 @@
         storages: # You must have at least a `default` storage path.
           gitaly-1:
             path: /var/opt/gitlab/repo
-            gitaly_address: tcp://gitlab-prod-gitaly-0.gitlab-prod-gitaly.default:8075
+            gitaly_address: tcp://gitlab-prod-gitaly-0.gitlab-prod-gitaly.default.svc:8075
           default:
             path: /var/opt/gitlab/repo
             gitaly_address: tcp://gitlab-prod-gitlab:8075
@@ -1145,7 +1138,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -1183,7 +1176,7 @@
     }
   resque.yml.erb: |
     production:
-      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master:6379
+      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master.default.svc:6379
       
       id:
   
@@ -1191,7 +1184,7 @@
   
   cable.yml.erb: |
     production:
-      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master:6379
+      url: redis://:<%= ERB::Util::url_encode(File.read("/etc/gitlab/redis/redis-password").strip) %>@gitlab-prod-redis-master.default.svc:6379
       
       id:
       adapter: redis
@@ -1253,6 +1246,8 @@
             bucket: gitlab-terraform-state
           dependency_proxy:
             bucket: gitlab-dependency-proxy
+          pages:
+            bucket: pages
       # Individual object storage backed feature properties configuration
       artifacts:
         enabled: true
@@ -1276,7 +1271,19 @@
         clientside_dsn: 
         environment: 
       pages:
-        enabled: false
+        enabled: true
+        access_control: false
+        artifacts_server: false
+        path: 
+        host: pages.freedesktop.org # TODO: move to "gitlab.pages.host" template
+        port: 0
+        https: false
+        secret_file: /etc/gitlab/pages/secret
+        external_http: false
+        external_https: false
+        object_store:
+          enabled: false
+          remote_directory: pages
       mattermost:
         enabled: false
       gitlab_ci:
@@ -1307,7 +1314,7 @@
         storages: # You must have at least a `default` storage path.
           gitaly-1:
             path: /var/opt/gitlab/repo
-            gitaly_address: tcp://gitlab-prod-gitaly-0.gitlab-prod-gitaly.default:8075
+            gitaly_address: tcp://gitlab-prod-gitaly-0.gitlab-prod-gitaly.default.svc:8075
           default:
             path: /var/opt/gitlab/repo
             gitaly_address: tcp://gitlab-prod-gitlab:8075
@@ -1343,7 +1350,7 @@
       registry:
         enabled: true
         host: registry.freedesktop.org
-        api_url: http://gitlab-prod-registry:5000
+        api_url: http://gitlab-prod-registry.default.svc:5000
         key: /etc/gitlab/registry/gitlab-registry.key
         issuer: omnibus-gitlab-issuer
       smartcard:
@@ -1380,7 +1387,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -1388,7 +1395,7 @@
     gitlab-helm-chart
   workhorse-config.toml.erb: |
     [redis]
-    URL = "redis://gitlab-prod-redis-master:6379"
+    URL = "redis://gitlab-prod-redis-master.default.svc:6379"
     Password = "<%= File.read("/etc/gitlab/redis/redis-password").strip.dump[1..-2] %>"
     <%
       require 'yaml'
@@ -1438,6 +1445,9 @@
         end
       end
     %>
+    [image_resizer]
+    max_scaler_procs = 2
+    max_filesize = 250000
   configure: |
       set -e
       mkdir -p /init-secrets-workhorse/gitlab-workhorse
@@ -2286,6 +2296,7 @@
     validation:
       disabled: true
     
+    reporting:
     profiling:
     storage:
       maintenance:
@@ -2373,8 +2384,13 @@
     # Gitlab runner secret
     generate_secret_if_needed "gitlab-prod-gitlab-runner-secret" --from-literal=runner-registration-token=$(gen_random 'a-zA-Z0-9' 64) --from-literal=runner-token=""
     
+    # GitLab pages secret
     
+    generate_secret_if_needed "gitlab-prod-gitlab-pages-secret" --from-literal="shared_secret"=$(gen_random 'a-zA-Z0-9' 32 | base64)
     
+    
+    
+    
     # Registry certificates
     mkdir -p certs
     openssl req -new -newkey rsa:4096 -subj "/CN=gitlab-issuer" -nodes -x509 -keyout certs/registry-example-com.key -out certs/registry-example-com.crt -days 3650
@@ -2452,12 +2468,12 @@
   namespace: default
   labels:
     app: gitlab
-    chart: gitlab-4.5.2
+    chart: gitlab-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
-  gitlabVersion: "13.5.2"
-  gitlabChartVersion: "4.5.2"
+  gitlabVersion: "13.6.0"
+  gitlabChartVersion: "4.6.0"
 
 ---
 # Source: helm-gitlab-omnibus/charts/gitlab/templates/initdb-configmap.yaml
@@ -2468,7 +2484,7 @@
   namespace: default
   labels:
     app: gitlab
-    chart: gitlab-4.5.2
+    chart: gitlab-4.6.0
     release: gitlab-prod
     heritage: Tiller
 data:
@@ -11084,7 +11100,7 @@
   namespace: default
   labels:
     app: gitaly
-    chart: gitaly-4.5.2
+    chart: gitaly-4.6.0
     release: gitlab-prod
     heritage: Tiller
     
@@ -11116,7 +11132,7 @@
   namespace: default
   labels:
     app: gitlab-exporter
-    chart: gitlab-exporter-4.5.2
+    chart: gitlab-exporter-4.6.0
     release: gitlab-prod
     heritage: Tiller
     
@@ -11142,7 +11158,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
     
@@ -11169,7 +11185,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
     
@@ -11614,14 +11630,14 @@
 apiVersion: v1
 kind: Pod
 metadata:
-  name: gitlab-prod-webservice-test-runner-p2bgo
+  name: gitlab-prod-webservice-test-runner-xeot3
   namespace: default
   annotations:
     "helm.sh/hook": test-success
 spec:
   containers:
   - name: test-runner
-    image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.5.2
+    image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.6.0
     command: ['sh', '/tests/test_login']
     volumeMounts:
       - name: tests
@@ -11673,7 +11689,7 @@
           requests:
             memory: "50Gi"
             cpu: "12"
-        image: gitlab/gitlab-ce:13.5.2-ce.0
+        image: gitlab/gitlab-ce:13.6.0-ce.0
         imagePullPolicy: IfNotPresent
         command: ["/bin/bash", "-c",
           "sed -i \"s/environment ({'GITLAB_ROOT_PASSWORD' => initial_root_password }) if initial_root_password/environment ({'GITLAB_ROOT_PASSWORD' => initial_root_password, 'GITLAB_SHARED_RUNNERS_REGISTRATION_TOKEN' => node['gitlab']['gitlab-rails']['initial_shared_runners_registration_token'] })/g\" /opt/gitlab/embedded/cookbooks/gitlab/recipes/database_migrations.rb && exec /assets/wrapper"]
@@ -11806,7 +11822,7 @@
             gitlab_rails['db_database'] = ENV['POSTGRES_DB']
 
             redis['enable'] = false
-            gitlab_rails['redis_host'] = 'gitlab-prod-redis-master'
+            gitlab_rails['redis_host'] = 'gitlab-prod-redis-master.default.svc'
             gitlab_rails['redis_password'] = ENV['REDIS_PASSWORD']
 
             # disable grafana
@@ -11841,7 +11857,7 @@
             }
             redis_exporter['enable'] = true
             redis_exporter['flags'] = {
-              'redis.addr' => "gitlab-prod-redis-master:6379",
+              'redis.addr' => "gitlab-prod-redis-master.default.svc:6379",
             }
 
             gitlab_rails['gitlab_default_can_create_group'] = false
@@ -12168,7 +12184,7 @@
   namespace: default
   labels:
     app: gitlab-exporter
-    chart: gitlab-exporter-4.5.2
+    chart: gitlab-exporter-4.6.0
     release: gitlab-prod
     heritage: Tiller
   annotations:
@@ -12186,7 +12202,7 @@
         release: gitlab-prod
         
       annotations:
-        checksum/config: 223c8bd64c1b11914405bccf93efe4023245d02fa82a0f8ee42b1dfe3861c540
+        checksum/config: e3e583ab9729523e3df351decea6530caffefaa31a592814b0f662b2a3495744
         gitlab.com/prometheus_path: /metrics
         gitlab.com/prometheus_port: "9168"
         gitlab.com/prometheus_scrape: "true"
@@ -12212,7 +12228,7 @@
         
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           
           env:
           
@@ -12330,7 +12346,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
   annotations:
@@ -12347,15 +12363,15 @@
         release: gitlab-prod
         
       annotations:
-        checksum/config: fec9e28036ed7a8013d3d8e01b6df56473b8f671414aa1dc5da64793da027478
-        checksum/config-sshd: 36ad3405fb2df1c33498b0993ea1fbefd82007a6750e6965f2698ddef91f9bb2
+        checksum/config: f1f0dcfbf7f6252dd621b8632bd5cc5b597ec79ecc0158da93df4fe1aec97709
+        checksum/config-sshd: cfc51173b8934aee33309c40925d21de51d68558d072600ccf139179715da66d
         cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
     spec:
       initContainers:
         
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           
           env:
           
@@ -12403,7 +12419,7 @@
       containers:
         
         - name: gitlab-shell
-          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v13.11.0"
+          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v13.13.0"
           
           ports:
             - containerPort: 2222
@@ -12441,10 +12457,14 @@
             timeoutSeconds: 3
             successThreshold: 1
             failureThreshold: 3
-          # readinessProbe:
-          #   httpGet:
-          #     path: /
-          #     port: 2222
+          readinessProbe:
+            tcpSocket:
+              port: 2222
+            initialDelaySeconds: 10
+            periodSeconds: 5
+            timeoutSeconds: 3
+            successThreshold: 1
+            failureThreshold: 2
           resources:
             requests:
               cpu: 0
@@ -12488,7 +12508,7 @@
   namespace: default
   labels:
     app: task-runner
-    chart: task-runner-4.5.2
+    chart: task-runner-4.6.0
     release: gitlab-prod
     heritage: Tiller
   annotations:
@@ -12509,7 +12529,7 @@
         release: gitlab-prod
         
       annotations:
-        checksum/config: 3e36d6060c5275641a1d8c89de07210559578a9c3344854ba9330e917f5a800e
+        checksum/config: 834fdf1e583f2f840169898ddee9029e0ebe7cea9270b8c127bf202c6c99018a
         cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
     spec:
       securityContext:
@@ -12519,7 +12539,7 @@
         
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           
           env:
           
@@ -12571,7 +12591,7 @@
             - /bin/bash
             - -c
             - sh /var/opt/gitlab/templates/configure-gsutil && while sleep 3600; do :; done
-          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-task-runner-ce:v13.5.2"
+          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-task-runner-ce:v13.6.0"
           
           env:
             - name: ARTIFACTS_BUCKET_NAME
@@ -12688,6 +12708,12 @@
                 - key: connection
                   path: objectstorage/connection
           
+          - secret:
+              name: "gitlab-prod-gitlab-pages-secret"
+              items:
+                - key: "shared_secret"
+                  path: pages/secret
+          
           # mount secret for minio
           # mount secret for object_store
           - secret:
@@ -12748,7 +12774,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
   annotations:
@@ -12766,7 +12792,7 @@
         release: gitlab-prod
         
       annotations:
-        checksum/config: 08f8bfadbd12f53a856be9ba648fbc36dbc57d5b71e6aae1b3cd2a1fddfda629
+        checksum/config: d3d1e8ad782b3c78d5014b1a7748d24d03bad991fb16981a75c439037ad309b9
         cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
         gitlab.com/prometheus_path: /-/metrics
         gitlab.com/prometheus_port: "8080"
@@ -12793,7 +12819,7 @@
         
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           
           env:
           
@@ -12838,7 +12864,7 @@
               cpu: 50m
             
         - name: dependencies
-          image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.5.2
+          image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.6.0
           
           args:
             - /scripts/wait-for-deps
@@ -12872,7 +12898,7 @@
       containers:
         
         - name: webservice
-          image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.5.2
+          image: registry.gitlab.com/gitlab-org/build/cng/gitlab-webservice-ce:v13.6.0
           
           ports:
             - containerPort: 8080
@@ -12964,10 +12990,10 @@
           resources:
             requests:
               cpu: 300m
-              memory: 1.5G
+              memory: 2.5G
             
         - name: gitlab-workhorse
-          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ce:v13.5.2"
+          image: "registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ce:v13.6.0"
           
           ports:
             - containerPort: 8181
@@ -13084,6 +13110,12 @@
                 - key: "shared_secret"
                   path: gitlab-workhorse/secret
           
+          - secret:
+              name: "gitlab-prod-gitlab-pages-secret"
+              items:
+                - key: "shared_secret"
+                  path: pages/secret
+          
           # mount secret for minio
           # mount secret for object_store
           - secret:
@@ -13318,7 +13350,7 @@
   annotations:
     
 spec:
-  replicas: 3
+  replicas: 2
   revisionHistoryLimit: 10
   strategy:
     {}
@@ -13442,7 +13474,7 @@
   annotations:
     
 spec:
-  replicas: 2
+  replicas: 1
   revisionHistoryLimit: 10
   selector:
     matchLabels:
@@ -13603,7 +13635,7 @@
         release: gitlab-prod
         
       annotations:
-        checksum/configmap: 1372396d4dcd61ebcf9b6300637847ae4049d2782d5e1480c87fb25486a05652
+        checksum/configmap: b18b3f7cb1b88ee9b572916c7081232634b55f516cc865826dd3973a9a82550b
         cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
     spec:
       securityContext:
@@ -13622,7 +13654,7 @@
       initContainers:
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           imagePullPolicy: "IfNotPresent"
           env:
           
@@ -13724,7 +13756,7 @@
   namespace: default
   labels:
     app: gitlab-shell
-    chart: gitlab-shell-4.5.2
+    chart: gitlab-shell-4.6.0
     release: gitlab-prod
     heritage: Tiller
 spec:
@@ -13748,7 +13780,7 @@
   namespace: default
   labels:
     app: webservice
-    chart: webservice-4.5.2
+    chart: webservice-4.6.0
     release: gitlab-prod
     heritage: Tiller
 spec:
@@ -13815,14 +13847,14 @@
         release: gitlab-prod
         
       annotations:
-        checksum/config: 390f5ec5aac64a7b2550f3f06d4911726990f583d923cbcabbbc9aeaeea3894e
+        checksum/config: ee8693f85884bb9f47bbe4943763418b6e59595115d5ebc777bbc8d8881b4e44
     spec:
       terminationGracePeriodSeconds: 30
       initContainers:
         
         
         - name: certificates
-          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20171114-r3"
+          image: "registry.gitlab.com/gitlab-org/build/cng/alpine-certificates:20191127-r2"
           
           env:
           
@@ -13873,7 +13905,7 @@
       containers:
         
         - name: gitaly
-          image: "registry.gitlab.com/gitlab-org/build/cng/gitaly:v13.5.2"
+          image: "registry.gitlab.com/gitlab-org/build/cng/gitaly:v13.6.0"
           
           ports:
             - containerPort: 8075
@@ -14354,7 +14386,7 @@
 apiVersion: batch/v1
 kind: Job
 metadata:
-  name: gitlab-prod-shared-secrets-0-3lv
+  name: gitlab-prod-shared-secrets-0-eb6
   namespace: default
   labels:
     app: shared-secrets
@@ -14801,7 +14833,7 @@
   namespace: default
   labels:
     app: gitlab-grafana
-    chart: gitlab-grafana-4.5.2
+    chart: gitlab-grafana-4.6.0
     release: gitlab-prod
     heritage: Tiller
   annotations:
@@ -14917,6 +14949,10 @@
 # Source: helm-gitlab-omnibus/charts/gitlab/charts/gitlab/charts/gitlab-shell/templates/serviceaccount.yaml
 
 ---
+# Source: helm-gitlab-omnibus/charts/gitlab/charts/gitlab/charts/kas/templates/configmap.yaml
+
+
+---
 # Source: helm-gitlab-omnibus/charts/gitlab/charts/gitlab/charts/kas/templates/deployment.yaml
 
 
@@ -15121,6 +15157,10 @@
 
 ---
 # Source: helm-gitlab-omnibus/charts/gitlab/charts/nginx-ingress/templates/controller-hpa.yaml
+
+
+---
+# Source: helm-gitlab-omnibus/charts/gitlab/charts/nginx-ingress/templates/default-backend-poddisruptionbudget.yaml
 
 
 ---
Edited by Daniel Stone

Merge request reports