Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions charts/infra/Chart.lock
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
dependencies:
- name: cert-manager
repository: oci://quay.io/jetstack/charts
version: 1.20.2
version: 1.20.4
- name: trust-manager
repository: oci://quay.io/jetstack/charts
version: 0.22.1
- name: crd-check
repository: oci://ghcr.io/openhands/helm-charts
version: 0.1.0
digest: sha256:ee6c9e0ba7c097cc59f0dc12409169a11831b548283b77ec7f8f90a94869ebf5
generated: "2026-05-27T10:31:04.277099-04:00"
digest: sha256:e7419549335a41e224763cb379806d3c8482a4f84de46fa18aaa3ec2a63837e3
generated: "2026-10-10T08:31:38.51937-06:00"
2 changes: 1 addition & 1 deletion charts/infra/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ maintainers:
- name: all-hands-ai
dependencies:
- name: cert-manager
version: 1.20.2
version: 1.20.4
repository: oci://quay.io/jetstack/charts
condition: cert-manager.enabled
- name: trust-manager
Expand Down
5 changes: 4 additions & 1 deletion charts/infra/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,9 @@ trust-manager:
app:
trust:
namespace: cert-manager
# Chart default is :20230311-deb12u1.6; .7 is a rebuild of the same CA data.
defaultPackageImage:
tag: "20230311-deb12u1.7"
resources:
requests:
cpu: 10m
Expand All @@ -69,7 +72,7 @@ crdCheck:
enabled: false
image:
repository: docker.io/rancher/kubectl
tag: v1.33.0
tag: v1.33.13
pullPolicy: IfNotPresent
timeout: 120s
backoffLimit: 6
Expand Down
2 changes: 1 addition & 1 deletion charts/openhands/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -703,7 +703,7 @@ Note: This will not delete any PVCs or secrets created. You'll need to delete th

### Budget policy changes

The bundled LiteLLM proxy uses unmodified 1.100.1 pinned by digest and
The bundled LiteLLM proxy uses unmodified 1.100.5 pinned by digest and
`litellm-helm.proxy_config.general_settings.user_api_key_cache_ttl: 0`.
Both are required for a budget change (including disabling a user's limit)
to affect the next request using an existing key. Older proxies can keep enforcing
Expand Down
4 changes: 2 additions & 2 deletions charts/openhands/charts/agent-canvas/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,12 +8,12 @@
# screen.

image:
repository: ghcr.io/openhands/patched/agent-canvas
repository: ghcr.io/openhands/agent-canvas
# Pinned to a semver release tag (agent-canvas publishes release-tagged
# images via Release Please). Environments that want a specific build can
# override this, but the default should track a published release so the
# chart ships a known-good version out of the box.
tag: "1.23.0-patched@sha256:63b7824a3a1a67bab899eb65d1daa2fceaa2739dff5ac5f7c9eac02a2773cc14"
tag: "1.23.0-r1@sha256:7f024e6802eaa0e7ca54b8f6134b57941bf370436b22f9d61e13488cf267da5a"
pullPolicy: IfNotPresent

imagePullSecrets: []
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ spec:
{{- if .Values.database.createDatabaseUser }}
# Create automation database and user in an existing PostgreSQL instance
- name: create-db-user
image: postgres:14
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
env:
- name: PGPASSWORD
valueFrom:
Expand Down Expand Up @@ -124,7 +124,7 @@ spec:
{{- else if .Values.postgresql.enabled }}
# Wait for the automation's own PostgreSQL subchart to be ready
- name: wait-for-postgres
image: bitnamilegacy/postgresql:latest
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand Down
9 changes: 7 additions & 2 deletions charts/openhands/charts/automation/values.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
image:
repository: ghcr.io/openhands/patched/automation
repository: ghcr.io/openhands/automation
# You must use a stable, semver tag. Do not use sha-based tags.
# If you are hotfixing, you MUST create a patch release and use the semver tag.
tag: "1.14.0-patched@sha256:e0963f3cac040087fa7bcb829a9d17c53a49fab6871c3c5522c7d206627f5697"
tag: "1.14.0-r1@sha256:6c2c8bd220c92d6fc2c981a361b52e74207578a16ebacd6ac54fce82c47a6001"

imagePullSecrets: []

Expand Down Expand Up @@ -207,6 +207,11 @@ postgresql:
enabled: false

global:
# psql/pg_isready image for the database init containers and jobs. The openhands
# umbrella's global wins; this default only applies when rendering the subchart alone.
postgresClientImage:
repository: docker.io/alpine/psql
tag: 18.6@sha256:08f354a83552fcefa508116268463b371717577fe49d3fcb7b82cf8d2be464b8
security:
# This allows using the bitnamilegacy image repo
allowInsecureImages: true
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ spec:
# Create database and user in PostgreSQL. Disable this when the database
# and user are provisioned outside the chart.
- name: create-db-user
image: postgres:14
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
env:
- name: PGPASSWORD
valueFrom:
Expand Down Expand Up @@ -109,7 +109,7 @@ spec:
{{- else if .Values.postgresql.enabled }}
# Wait for the service's own PostgreSQL subchart to be ready
- name: wait-for-postgres
image: bitnamilegacy/postgresql:latest
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand Down
5 changes: 5 additions & 0 deletions charts/openhands/charts/integrations-hub/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -171,6 +171,11 @@ postgresql:
enabled: false

global:
# psql/pg_isready image for the database init containers and jobs. The openhands
# umbrella's global wins; this default only applies when rendering the subchart alone.
postgresClientImage:
repository: docker.io/alpine/psql
tag: 18.6@sha256:08f354a83552fcefa508116268463b371717577fe49d3fcb7b82cf8d2be464b8
security:
# This allows using the bitnamilegacy image repo
allowInsecureImages: true
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{{- define "plugin-directory.dbInitContainers" }}
{{- if .Values.databaseMigrations.waitForDatabase }}
- name: wait-for-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand All @@ -16,7 +16,7 @@
{{- end }}
{{- if .Values.databaseMigrations.createDatabases }}
- name: create-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand Down
13 changes: 9 additions & 4 deletions charts/openhands/charts/plugin-directory/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,8 @@ databaseMigrations:
# Client container configuration (React Router SSR)
client:
image:
repository: ghcr.io/openhands/patched/plugin-directory-client
tag: "1.2.0-patched@sha256:667252f537f005dd9da6e52a20398c87276cb18608996d734e0a070f395f818c"
repository: ghcr.io/openhands/plugin-directory-client
tag: "1.2.0-r1@sha256:8d74aa59e423d50aaa8bb4558a4aab8325463de7bccb761f10ed55c823358aff"
resources:
requests:
memory: 256Mi
Expand All @@ -26,10 +26,10 @@ client:
# Server container configuration (FastAPI backend)
server:
image:
repository: ghcr.io/openhands/patched/plugin-directory-server
repository: ghcr.io/openhands/plugin-directory-server
# You must use a stable, semver tag. Do not use sha-based tags.
# If you are hotfixing, you MUST create a patch release and use the semver tag.
tag: "1.2.0-patched@sha256:463981dfb39efa6574f7ccaf1dfa40363330cbc2123ef0f793314eef94993640"
tag: "1.2.0-r1@sha256:bf35b82bdcdcf37abba673ef5b40bdbed22ccc3af67b4793c7bcb21fdf11aa4d"
resources:
requests:
memory: 256Mi
Expand Down Expand Up @@ -160,6 +160,11 @@ datadog:
env: {}

global:
# psql/pg_isready image for the database init containers and jobs. The openhands
# umbrella's global wins; this default only applies when rendering the subchart alone.
postgresClientImage:
repository: docker.io/alpine/psql
tag: 18.6@sha256:08f354a83552fcefa508116268463b371717577fe49d3fcb7b82cf8d2be464b8
scheduling:
# Affinity applied to this chart's pods when `affinity` above is empty. The
# openhands umbrella sets this once for every chart it owns; this default
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{{- define "runtime-api.dbInitContainers" }}
{{- if .Values.databaseMigrations.waitForDatabase }}
- name: wait-for-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand All @@ -18,7 +18,7 @@
{{- end }}
{{- if .Values.databaseMigrations.createDatabases }}
- name: create-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
{{- end }}
containers:
- name: create-user
image: postgres:14
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
env:
- name: PGPASSWORD
valueFrom:
Expand Down
13 changes: 9 additions & 4 deletions charts/openhands/charts/runtime-api/values.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
image:
repository: ghcr.io/openhands/patched/runtime-api
repository: ghcr.io/openhands/runtime-api
# You must use a stable, semver tag. Do not use sha-based tags.
# If you are hotfixing, you MUST create a patch release and use the semver tag.
tag: "0.10.0-patched@sha256:bae96ecbe18e30bd1e6e67e92b8932919141b7e8dc9a813814540efb24267638"
tag: "0.10.0-r1@sha256:cdb63c3fca733796d1f1b846fcafc3eafa574969f547c15f9bcb75d32c8ede27"
pullPolicy: Always

nameOverride: ""
Expand Down Expand Up @@ -353,12 +353,17 @@ replicated:
enabled: false

global:
# psql/pg_isready image for the database init containers and jobs. The openhands
# umbrella's global wins; this default only applies when rendering the subchart alone.
postgresClientImage:
repository: docker.io/alpine/psql
tag: 18.6@sha256:08f354a83552fcefa508116268463b371717577fe49d3fcb7b82cf8d2be464b8
# Canonical agent-server image. Defaults any warm-runtime configsByName entry
# that omits its own `image`. In the openhands umbrella the parent chart's
# global wins; this default only applies when rendering the subchart alone.
agentServerImage:
repository: ghcr.io/openhands/patched/agent-server
tag: "1.49.5-python-patched@sha256:c143d7113ba6df06caeb2be61a2c5a119c05074889a633b1f36e99d435eaac28"
repository: ghcr.io/openhands/agent-server
tag: "1.49.5-r1-python@sha256:5f2919fbfc33934c023092926fc79a5da9acecc809d5773e582b44b8093d8d3f"
security:
# This allows using the bitnamilegacy image repo.
# See: https://github.com/bitnami/containers/issues/83267
Expand Down
4 changes: 2 additions & 2 deletions charts/openhands/templates/_init-containers.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{{- define "openhands.dbInitContainers" }}
{{- if .Values.databaseMigrations.waitForDatabase }}
- name: wait-for-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand All @@ -18,7 +18,7 @@
{{- end }}
{{- if .Values.databaseMigrations.createDatabases }}
- name: create-db
image: "bitnamilegacy/postgresql:latest"
image: "{{ .Values.global.postgresClientImage.repository }}:{{ .Values.global.postgresClientImage.tag }}"
command: ['sh', '-c']
args:
- |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ analyticsHost: {{ $lamFrontIng.hostname | default "" | quote }}
routingMode: {{ $rtApiEnv.RUNTIME_ROUTING_MODE | default "" | quote }}
rtSeparator: {{ $rtApiEnv.RUNTIME_URL_SEPARATOR | default "." | quote }}
analyticsEnabled: {{ $lam.enabled | default false }}
probeImage: {{ printf "%s/docker.io/alpine/openssl:3.5.6" (trimSuffix "/ghcr.io/openhands/enterprise-server" (trimSuffix "/ghcr.io/openhands/patched/enterprise-server" $repo)) | quote }}
probeImage: {{ printf "%s/docker.io/alpine/openssl:3.5.9" (trimSuffix "/ghcr.io/openhands/enterprise-server" $repo) | quote }}
{{- end -}}

{{- define "troubleshoot.collectors.tlsHostname" -}}
Expand Down
Loading
Loading