chore(deps): update ironbank
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| gluon | patch | 1.1.7 → 1.1.8 |
| minio-instance (source) | patch | 7.1.1-bb.20 → 7.1.1-bb.24 |
| postgresql (source) | patch | 18.11.1 → 18.11.3 |
| registry1.dso.mil/ironbank/opensource/kubernetes/kubectl (source) | minor | v1.36 → v1.37 |
| registry1.dso.mil/ironbank/opensource/mattermost/mattermost (source) | minor | 11.10.1 → 11.11.0 |
Complete MR checklist
Assignee
- Followed upgrade instructions outlined in docs/DEVELOPMENT_MAINTENANCE.md
- Update Docs with new/updated steps as needed (no chart documentation change required)
- Tested and Validated Changes made with supporting info like logs or screenshots from test pipelines
Add supporting info below
Validation (MR head 7b9b6f3): package pipeline 5634200 and downstream pipeline 5634216 passed all four clean-install and upgrade lanes, including SSO. Local Helm lint and render checks passed.
In dedicated k3d-dev (mattermost), deployed main chart 11.10.1-bb.2, then upgraded the same release to this MR chart 11.11.0-bb.0. Flux reported UpgradeSucceeded; all 13 HelmReleases were Ready and Mattermost pods were Running with zero restarts. Using the package SSO test profile, the documented test account signed in through Keycloak, posted to Town Square, and About Mattermost reported server 11.11.0. The existing four-server MinIO Tenant pool was preserved during the SSO UI check with a temporary dev-only server-count override; no Tenant was replaced. Local hosts entries used for browser routing were restored after capture.
Reviewer only
- Tested and Validated changes
Configuration
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
- If you want to rebase/retry this MR, check this box
This MR was automatically generated by Renovate Bot.
Upgrade Notices
FIPS deployments: Before upgrading to 11.11.0, ensure the PostgreSQL password in Mattermost SqlSettings.DataSource is at least 14 ASCII characters. If shorter, rotate it in PostgreSQL and Mattermost first. Standard non-FIPS builds are unaffected. Upstream upgrade notes.
If your SSO provider resolves to a private address, allowlist only its hostname in Mattermost ServiceSettings.AllowedUntrustedInternalConnections; outbound OAuth requests now enforce this restriction. Upstream changelog.
Linked issues
Closes: #298 (closed)



