feat(container): update image ghcr.io/element-hq/ess-helm/matrix-stack ( 26.1.3 → 26.2.0 ) - #1199
Merged
Mafyuh merged 1 commit intoFeb 7, 2026
Conversation
…k ( 26.1.3 → 26.2.0 )
--- kubernetes/apps/matrix/app Kustomization: matrix/matrix OCIRepository: matrix/matrix
+++ kubernetes/apps/matrix/app Kustomization: matrix/matrix OCIRepository: matrix/matrix
@@ -11,9 +11,9 @@
spec:
interval: 15m
layerSelector:
mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
operation: copy
ref:
- tag: 26.1.3
+ tag: 26.2.0
url: oci://ghcr.io/element-hq/ess-helm/matrix-stack
|
--- HelmRelease: matrix/matrix ConfigMap: matrix/matrix-synapse-haproxy
+++ HelmRelease: matrix/matrix ConfigMap: matrix/matrix-synapse-haproxy
@@ -26,8 +26,8 @@
# A map file that is used in haproxy config to map from matrix paths to the
# named backend. The format is: path_regexp backend_name
path_map_file_get: |
# A map file that is used in haproxy config to map from matrix paths to the
# named backend. The format is: path_regexp backend_name
ess-version.json: |
- {"version": "26.1.3", "edition": "community"}
+ {"version": "26.2.0", "edition": "community"}
--- HelmRelease: matrix/matrix Deployment: matrix/matrix-haproxy
+++ HelmRelease: matrix/matrix Deployment: matrix/matrix-haproxy
@@ -6,13 +6,13 @@
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: matrix-stack
app.kubernetes.io/component: matrix-stack-ingress
app.kubernetes.io/name: haproxy
app.kubernetes.io/instance: matrix-haproxy
k8s.element.io/shared-haproxy-config-hash: e29ad3f8912601b2e5c39d88dbf417cb99e01cc1
- k8s.element.io/synapse-haproxy-config-hash: 65481f2dbb2749721c8bd2e07b8b54fc9a50f0c9
+ k8s.element.io/synapse-haproxy-config-hash: 967f62a49573d277d45b0bd0ed79a316c6af2e30
k8s.element.io/wellknowndelegation-haproxy-config-hash: 97d26ddc77a735490f3de6a2b9a88165e0aecfc2
name: matrix-haproxy
namespace: matrix
spec:
replicas: 1
selector:
@@ -29,13 +29,13 @@
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: matrix-stack
app.kubernetes.io/component: matrix-stack-ingress
app.kubernetes.io/name: haproxy
app.kubernetes.io/instance: matrix-haproxy
k8s.element.io/shared-haproxy-config-hash: e29ad3f8912601b2e5c39d88dbf417cb99e01cc1
- k8s.element.io/synapse-haproxy-config-hash: 65481f2dbb2749721c8bd2e07b8b54fc9a50f0c9
+ k8s.element.io/synapse-haproxy-config-hash: 967f62a49573d277d45b0bd0ed79a316c6af2e30
k8s.element.io/wellknowndelegation-haproxy-config-hash: 97d26ddc77a735490f3de6a2b9a88165e0aecfc2
spec:
automountServiceAccountToken: false
serviceAccountName: matrix-haproxy
securityContext:
fsGroup: 10001
--- HelmRelease: matrix/matrix Deployment: matrix/matrix-matrix-authentication-service
+++ HelmRelease: matrix/matrix Deployment: matrix/matrix-matrix-authentication-service
@@ -53,13 +53,13 @@
- pod-template-hash
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
initContainers:
- name: render-config
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -92,13 +92,13 @@
name: secret-68b67534bcd8
readOnly: true
- mountPath: /conf
name: rendered-config
readOnly: false
- name: db-wait
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
--- HelmRelease: matrix/matrix Deployment: matrix/matrix-matrix-rtc-sfu
+++ HelmRelease: matrix/matrix Deployment: matrix/matrix-matrix-rtc-sfu
@@ -52,13 +52,13 @@
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
hostNetwork: false
initContainers:
- name: render-config-keys-yaml
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -95,13 +95,13 @@
name: secret-68b67534bcd8
readOnly: true
- mountPath: /conf
name: rendered-config
readOnly: false
- name: render-config-sfu
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
--- HelmRelease: matrix/matrix StatefulSet: matrix/matrix-synapse-main
+++ HelmRelease: matrix/matrix StatefulSet: matrix/matrix-synapse-main
@@ -53,13 +53,13 @@
matchLabelKeys: []
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
initContainers:
- name: render-config
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -97,13 +97,13 @@
name: secret-68b67534bcd8
readOnly: true
- mountPath: /conf
name: rendered-config
readOnly: false
- name: db-wait
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
--- HelmRelease: matrix/matrix Job: matrix/matrix-deployment-markers-pre
+++ HelmRelease: matrix/matrix Job: matrix/matrix-deployment-markers-pre
@@ -48,13 +48,13 @@
matchLabelKeys: []
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
containers:
- name: deployment-markers
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -72,8 +72,8 @@
- deployment-markers
- -step
- pre
- -markers
- matrix-markers:MATRIX_STACK_MSC3861:delegated_auth:delegated_auth;syn2mas_migrated
- -labels
- - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=deployment-markers,app.kubernetes.io/instance=matrix-deployment-markers,app.kubernetes.io/version=0.7.1
+ - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=deployment-markers,app.kubernetes.io/instance=matrix-deployment-markers,app.kubernetes.io/version=0.7.2
--- HelmRelease: matrix/matrix Job: matrix/matrix-deployment-markers-post
+++ HelmRelease: matrix/matrix Job: matrix/matrix-deployment-markers-post
@@ -48,13 +48,13 @@
matchLabelKeys: []
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
containers:
- name: deployment-markers
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -72,8 +72,8 @@
- deployment-markers
- -step
- post
- -markers
- matrix-markers:MATRIX_STACK_MSC3861:delegated_auth:delegated_auth;syn2mas_migrated
- -labels
- - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=deployment-markers,app.kubernetes.io/instance=matrix-deployment-markers,app.kubernetes.io/version=0.7.1
+ - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=deployment-markers,app.kubernetes.io/instance=matrix-deployment-markers,app.kubernetes.io/version=0.7.2
--- HelmRelease: matrix/matrix Job: matrix/matrix-init-secrets
+++ HelmRelease: matrix/matrix Job: matrix/matrix-init-secrets
@@ -48,13 +48,13 @@
matchLabelKeys: []
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
containers:
- name: init-secrets
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
@@ -70,8 +70,8 @@
value: matrix
args:
- generate-secrets
- -secrets
- matrix-generated:POSTGRES_SYNAPSE_PASSWORD:rand32,matrix-generated:POSTGRES_MATRIX_AUTHENTICATION_SERVICE_PASSWORD:rand32,matrix-generated:POSTGRES_ADMIN_PASSWORD:rand32,matrix-generated:ELEMENT_CALL_LIVEKIT_SECRET:rand32,matrix-generated:SYNAPSE_EXTRA:extra,matrix-generated:SYNAPSE_MACAROON:rand32,matrix-generated:SYNAPSE_REGISTRATION_SHARED_SECRET:rand32,matrix-generated:SYNAPSE_SIGNING_KEY:signingkey,matrix-generated:MAS_SYNAPSE_SHARED_SECRET:rand32,matrix-generated:MAS_ENCRYPTION_SECRET:hex32,matrix-generated:MAS_RSA_PRIVATE_KEY:rsa:4096:der,matrix-generated:MAS_ECDSA_PRIME256V1_PRIVATE_KEY:ecdsaprime256v1
- -labels
- - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=init-secrets,app.kubernetes.io/instance=matrix-init-secrets,app.kubernetes.io/version=0.7.1
+ - app.kubernetes.io/managed-by=Helm,app.kubernetes.io/part-of=matrix-stack,app.kubernetes.io/component=matrix-tools,app.kubernetes.io/name=init-secrets,app.kubernetes.io/instance=matrix-init-secrets,app.kubernetes.io/version=0.7.2
--- HelmRelease: matrix/matrix Job: matrix/matrix-synapse-check-config
+++ HelmRelease: matrix/matrix Job: matrix/matrix-synapse-check-config
@@ -55,13 +55,13 @@
matchLabelKeys: []
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
initContainers:
- name: render-config
- image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.1
+ image: ghcr.io/element-hq/ess-helm/matrix-tools:0.7.2
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL |
renovate
Bot
deleted the
renovate/ghcr.io-element-hq-ess-helm-matrix-stack-26.x
branch
February 7, 2026 04:15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
26.1.3→26.2.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
element-hq/ess-helm (ghcr.io/element-hq/ess-helm/matrix-stack)
v26.2.0Compare Source
Changed
Set default permissions on Hookshot so that local users only have permissions to manage integrations and connections.
Permissions should be adjusted to give specific users the ability to administer integrations, e.g.
Update the test cluster values so that Hookshot can make requests to cluster-internal IP addresses. (#1010, #1018, #1023)
Fixed
Ingress/ not having a dedicated HookshotIngress. (#1010)Internal
pytestintegration test suite andsetup_test_cluster.shscript. (#1016, #1017)cert-managerandprometheus-operator-crds. (#1020)--rollback-on-failurehelm 4 parameter. (#1022)ESS Community Helm Chart 26.1.3 (2026-01-28)
Changed
Upgrade Element Web to v1.12.9.
Highlights:
Full Changelogs:
(#981)
Upgrade Matrix Authentication Service to v1.10.0.
Highlights:
Full Changelogs:
(#990)
Upgrade Synapse to v1.146.0.
Highlights:
m.oauthUser-Interactive Auth stage for resetting cross-signing identity with the OAuth 2.0 API./_matrix/media/v1/createbeing rate-limited for appservices even ifrate_limited: falsewas set in the registration.Full Changelogs:
(#992)
ESS Community Helm Chart 26.1.2 (2026-01-27)
Added
Add support for configuring
internalTrafficPolicyfor services behind ingresses. (#999)Add support for configuring
externalTrafficPolicyforNodePortandLoadBalancerservices behind ingresses. (#1000)Add support for configuring
externalTrafficPolicytoexposedServices. (#1001)Add support for configuring
internalTrafficPolicytoexposedServices. (#1001)Add support to customize
nodePortof exposed services.nodePortproperty ofexposedServices.*is now a string template taking two parameters:-
context: The exposed service values context*.exposedServices.<svc>root: The helm $ root values contextOn Matrix RTC values, the
nodePorttemplate defaults to{{ .context.port }}so that thenodePortis the same as
port. Setting the template to an empty string will skip settingnodePorton the service.
(#1002)
Add support for configuring
externalIPsof exposed services. (#1006)Add support for configuring annotations of Ingress services. (#1007)
Add support for configuring
externalIPsof Ingress services. (#1007)Changed
Hookshot: Disable encryption by default as it is still experimental. (#995)
Hookshot: Use appservice fully qualified domain name in the registration file. (#996)
Hookshot: Publish service unready address. (#996)
Hookshot: Enable adding widgets in rooms where it is invited by default. (#997)
Change default
externalTrafficPolicyfor the SFU exposed services fromLocalto Kubernetes defaultsCluster. (#1001)Update Hookshot to 7.3.1.
Highlights :
contrib/jsTransformationFunctions/gitlab-pipeline.jscontrib/jsTransformationFunctions/format-as-code.js!hookshot helpcommand not workingFull Changelogs:
(#1008)
Fixed
Documentation
Internal
ESS Community Helm Chart 26.1.1 (2026-01-22)
Removed / Breaking Changes
Move Synapse's Redis to a top-level shared component that can be used by multiple components of the chart.
There is no impact when using the default values, but if you have customised values under the
synapse.rediskey, you will need to update them to be under the new top-levelredisredis. (#972)Added
Add
extraInitContainerssupport to all workloads. (#971)Matrix RTC: Add support for configuring Turn TLS to help RTC traffic go through corporate Wifi networks and firewalls. (#976)
Add support for generating appservice registration files with
matrix-tools. (#979)Add support for Hookshot installation in ESS Community.
Hookshot is a Matrix Bot for connecting to external services.
It is not enabled by default, but can be enabled by setting
hookshot.enabled: true. (#979, #986)Matrix RTC: Add support for configuring UDP Turn. (#982)
Changed
matrix-toolssecret generation. (#973)matrix-tools. (#973)matrix-tools. (#973)matrixRTC.sfu.exposedServices.*.portTypeare now an enum, and only acceptsNodePort,HostPortandLoadBalancer. (#976)ClusterIPfor internal services of Matrix RTC and Synapse. (#985)Documentation
ESS Community Helm Chart 26.1.0 (2026-01-14)
Added
extraVolumesandextraVolumeMountsin components values. (#957, #965)Changed
Upgrade Element Web to v1.12.8.
Highlights:
Full Changelogs:
(#931, #960)
Adjust generated file copyright headers for 2026. (#943)
Revert change of Matrix Authentication Service deployment's
maxSurgeto 0. (#961)Upgrade Matrix Authentication Service to v1.9.0.
Highlights:
Full Changelogs:
(#961)
Upgrade Synapse to v1.145.0.
Highlights:
/_synapse/admin/v2/users/<user_id>Full Changelogs:
(#962)
Separate post-deployment hints and domains in NOTES. (#968)
Internal
Podstartup time. (#935)Ingresscontroller to be available. (#942)ESS Community Helm Chart 25.12.2 (2025-12-19)
Security
Fix critical security issue tracked as
ELEMENTSEC-2025-1670.This release is a critical security update to address an issue affecting all versions of ESS Community and ESS Pro. ESS Classic and other Synapse-based deployments are not affected.
The issue only has an impact when federation APIs are exposed to an untrusted network. Deployments that are not currently federating, or that only federate in a closed, trusted federation, are not impacted. These deployments should not enable public federation without first applying this update.
We advise you to apply the update as quickly as possible. (#943)
ESS Community Helm Chart 25.12.1 (2025-12-12)
Removed / Breaking Changes
The MatrixRTC SFU now restricts creation of calls to users on the local homeserver.
This can be changed back to allowing anyone to create calls on the SFU by by setting
matrixRTC.restrictRoomCreationToLocalUsers: false. (#926)Changed
Upgrade Synapse to v1.144.0.
Highlights:
Full Changelogs:
(#915)
Upgrade Matrix Authentication Service to v1.8.0.
Highlights:
Full Changelogs:
(#916)
Support configuring IPv4-only, IPv6-only or Dual-Stack component binds by configuring
networking.ipFamily.Defaults to
dual-stackbut if you are in a cluster where IPv6 support is either disabled at boot or compiled out you may need to set this toipv4(#921)Allow Synapse and Matrix Authentication Service to receive traffic over IPv6. (#921)
Removed some unused code from the
initSecretsgeneration container.Also complete the docs on the secret types it supports. (#927)
Upgrade Element Admin to v0.1.10.
Highlights :
Full Changelogs:
(#932)
ESS Community Helm Chart 25.12.0 (2025-12-04)
Removed / Breaking Changes
Remove
imagePullSecretsin favour ofimage.pullSecrets.As of 25.10.1
imagePullSecretswas deprecated in favour ofimage.pullSecrets.It has now been removed and attempting to use
imagePullSecretswill trigger a schemavalidation error. (#901)
Remove the ability to set
rtc.{use_external_ip,node_ip}viamatrixRTC.sfu.additionalin favour ofmatrixRTC.sfu.{useStunToDiscoverPublicIP,manualIP}.As of 25.9.1
matrixRTC.sfu.{useStunToDiscoverPublicIP,manualIP}were introduced to provide direct values for these settings. Attempting to setthese via
matrixRTC.sfu.additionalwill result in your values being ignored. (#901)Changed
Upgrade Element Web to v1.12.6.
Highlights:
Full Changelogs:
(#865, #903, #918)
Remove hard-coded
podAntiAffinityforDeploymentsthat had setreplicas > 2. (#867)Support
topologySpreadConstraintson all workloads, not just select ones. (#867)Set a soft, default
topologySpreadConstraintsfor all workloads.The can be removed by setting
topologySpreadConstraintsto[]at the top-level oroverridden on a per-component basis by setting that component's
topologySpreadConstraints. (#867)Unify management of
StatefulSet.specalong withDeployment.spec. (#872)Upgrade Synapse to v1.143.0.
Highlights:
Full Changelogs:
(#876)
Upgrade Matrix Authentication Service to v1.7.0.
Highlights:
Full Changelogs:
(#878)
Change Element Web and MatrixRTC SFU
Ingressesto targetServiceport names rather than numbers. (#879)Harmonise the hook weights and reduce the number of distinct hook weight values.
This should speed up installs and upgrades as now there are only 2 distinct pre-install/pre-upgrade hook weights. (#880)
Better handle the only worker-capable delayed-events endpoint. (#889)
Remove explicit configuration of HAProxy
maxconnat the global and backend level.This improves the compatibility with microk8s clusters that don't raise
ulimitsby default. (#890)Upgrade Element Admin to v0.1.9.
Highlights:
Full Changelogs:
(#900)
Listen for HAProxy traffic over IPv6. (#905)
Change
ipFamilyPolicytoPreferDualStackfor all services to expose them over dual-stack where possible. (#907)Change Matrix Authentication Service deployment
maxSurgeto 0.We have seen migrations race conditions happening during Matrix Authentication Service pods
rollout. This sets
maxSurgeto 0 to try to make sure only 1 pod at a time runs themigration process. (#910, #914)
Fixed
emptyDirsto be memory backed. (#894)Internal
passfilefor Synapse & MAS' Postgres configuration. (#881)emptyDirsare memory backed. (#894)init-secretsjob is not created when no secrets needs to be generated. (#896)test_pods_monitored. (#902)ESS Community Helm Chart 25.11.1 (2025-11-14)
Changed
Upgrade Matrix Authentication Service to v1.6.0.
Highlights:
Full Changelogs:
(#852)
Upgrade Synapse to v1.142.0.
Highlights:
Full Changelogs:
(#853)
Internal
Podreplicas. (#866)ESS Community Helm Chart 25.11.0 (2025-11-06)
Changed
Upgrade Element Web to v1.12.3.
Highlights:
Full Changelogs:
(#842)
Re-add the chart's icon. (#848)
Update README. (#854)
Configure experimental MSC4143 advertisement in Synapse when MatrixRTC is enabled.
This is in addition to the MSC4143 advertisement on the client well-known endpoint for now, but it is expected to replace it in time. (#855)
Update Element Web's default bug report URL to use the dedicated subdomain for bug reporting. (#856)
Fixed
Documentation
Internal
pyhelm3dependency for running tests. (#848)ESS Community Helm Chart 25.10.3 (2025-10-31)
Changed
Update
example-default-enabled-components-values.yamlto include MatrixRTC as it is enabled by default. (#516)Upgrade Element Web to v1.12.2.
Highlights:
Full Changelogs:
(#809)
Update Element Admin to v0.1.8.
Highlights:
Full Changelogs:
(#816, #843, #844)
Update Chart metadata to enhance tooling like
renovateandartifacthub.io. (#818)Update Synapse to v1.141.0.
Highlights:
Full Changelogs:
(#826)
Ensure there's at least 2 newlines at the end of the
haproxy.cfgfile. (#829)Upgrade Matrix Authentication Service to v1.5.0.
Highlights:
Full Changelogs:
(#830)
Add 'Element Creations Ltd' copyright to every file. (#835)
Fixed
Postgres: Fix the ess-updater container do not have access to the local data directory. (#817)
Prioritize
wellKnownDelegation.baseDomainRedirect.urloverelementWeb.ingress.host.Previously, whenever elementWeb was enabled, the url property was silently ignored instead of, as expected, taking precedence. (#819)
Fix a Matrix compatible JSON response not being correctly sent when a Synapse backend is down. (#829)
Documentation
serverNameunique to 1 fragment. (#806)CrashLoopBackOffissue. (#825)Internal
matrix-toolscontainers only ever setargsand notcommand. (#820)Removedchangelog sections toRemoved / Breaking Changesand make more prominent. (#828)ESS Community Helm Chart 25.10.2 (2025-10-16)
Security
Update Matrix Authentication Service to v1.4.1.
This is a security release which includes a fix for CVE-2025-62425 / GHSA-6wfp-jq3r-j9xh, which affects servers using the local password database, starting MAS 0.20.0 and later. See the advisory for details.
Full Changelogs:
(#813)
Changed
Upgrade Postgres Exporter to 0.18.1.
Full Changelogs:
(#812)
ESS Community Helm Chart 25.10.1 (2025-10-15)
Added
List deprecations in
NOTES.txtwhen runninghelm install/helm upgrade. (#796)Support overriding the default
imagePullPolicyfor every component by settingimage.pullPolicy.Per-image overrides can be set by setting
<path.to>.image.pullPolicyas before.If
image.pullPolicyor per-image overrides aren't setIfNotPresentis used by default for imagesreferenced by digest and
Alwaysis used by default images referenced by tag as previously. (#798)Changed
Update Matrix Authentication Service to v1.4.0.
Highlights:
Full Changelogs:
(#787)
Ensure consistent captured headers in HAProxy log lines, between all HTTP request processing HAProxy frontends. (#788)
Correct the handling of multiple X-Forwarded-For headers to Synapse.
This may have exhibit itself as requests being incorrectly rate-limited by Synapse.
The source IP logged by HAProxy is now always the IP connecting to HAProxy rather than
a value extracted from the X-Forwarded-For header (if present). This is usually an IP
for the ingress controller. (#788)
Log the X-Forwarded-For header and stop logging the Referer header in HAProxy. (#788)
Upgrade HAProxy to 3.2.
Release notes:
(#790)
Upgrade Element Admin to v0.1.4.
Highlights:
Full Changelogs:
(#793)
Inform chart users of the deprecations around
rtc.{use_external_ip,node_ip}that happened in 25.9.1. (#796)Move the top-level
imagePullSecretslist toimage.pullSecrets.Anyone setting
imagePullSecretsin their values files will seeschema errors if they don't restructure this setting. (#798)
Upgrade Synapse to v1.140.0.
Highlights:
GET /_matrix/client/v1/rtc/transportsendpoint for the latest draft of MSC4143: MatrixRTCFull Changelogs:
(#799)
Fixed
<component>.ingress.hostvalues not being rendered correctly inNOTES.txt. (#791)matrixRTC.sfu.additional.<name>.config. (#805)Internal
kubectlcommands inscripts/setup_test_cluster.shspecify the context. (#789)gofmt. (#792)gofmtovermatrix-tools. (#792)Pods. (#805)ESS Community Helm Chart 25.10.0 (2025-10-08)
Added
Changed
Update Element Web to v1.12.1.
Highlights:
Full Changelogs:
(#779)
Upgrade Synapse to v1.139.2.
Highlights:
CVE-2025-61672/GHSA-fh66-fcv5-jjfr. Lack of validation for device keys in Synapse before 1.139.1 allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers.Full Changelogs:
(#780, #783)
Fixed
Documentation
MISSING_MATRIX_RTC_FOCUS. (#768)Internal
ESS Community Helm Chart 25.9.3 (2025-10-02)
Fixed
Internal
ESS Community Helm Chart 25.9.2 (2025-09-30)
Added
Introducing Element Admin, a user-friendly interface to manage your ESS deployment. This is default enabled, and you need to configure
elementAdmin.ingress.hoston upgrade, as well as create its DNS and TLS.Changed
Define "matrix-tools" containers with "args" set instead of "command". (#738)
Update Element Web to v1.12.0.
Highlights:
Full Changelogs:
(#744)
Allow overriding of the Matrix Authentication Service policy configuration via additional configuration. (#745)
Remove
experimental.access_token_ttlfrom the Matrix Authentication Service config as the need for it has gone. (#745)Upgrade Synapse to v1.139.0.
Highlights:
Full Changelogs:
(#752, #755)
Update Matrix Authentication Service to v1.3.0.
Highlights:
Full Changelogs:
(#753)
Upgrade Matrix RTC SFU (LiveKit) to v1.9.1.
Full Changelogs:
(#758)
Internal
ESS Community Helm Chart 25.9.1 (2025-09-17)
Added
MatrixRTC: Add
sfu.useStunToDiscoverPublicIPandsfu.manualIPvalues to simplify networking configuration.Warning: In version 25.10, these values will override any manually set
rtc.external_ipandrtc.node_ipconfigured through
sfu.additionaladditional configuration. (#733)Changed
Update Element Web to v1.11.112.
Highlights:
Full Changelogs:
(#739)
Internal
matrix-stackchart's.helmignorefile to ignore Vim swap files. (#724)ESS Community Helm Chart 25.9.0 (2025-09-10)
Added
/_synapse/ess/versionto the Synapse ingress exposing the chart version and edition. (#715)Changed
Turn on push notifications for encrypted messages (MSC4028) support by default. (#712)
Update Element Web to v1.11.111.
Highlights:
via's or using aliasesFull Changelogs:
(#716)
Upgrade Synapse to v1.138.0.
Highlights:
Full Changelogs:
(#717)
Update Matrix Authentication Service to v1.2.0.
Highlights:
Full Changelogs:
(#718)
Use unique names for component configuration files, to prevent them from clashing against identically-named files in pods that deploy those components. (#723)
Internal
ESS Community Helm Chart 25.8.3 (2025-08-27)
Changed
Improvements to the ESS Community README. (#678)
Improved the documentation around the values file required for external vs internal PostgreSQL servers. (#688)
Update Matrix Authentication Service to v1.1.0.
Highlights:
Full Changelogs:
(#689)
Switch to stabilised Matrix Authentication Service <-> Synapse configuration.
matrixAuthenticationService.synapseOIDCClientSecrethas been removed from the valuesschema and must be removed from your values files if set. (#689)
Upgrade Synapse to v1.137.0.
Highlights:
Full Changelogs:
(#689)
Update Element Web to v1.11.110.
Highlights:
Full Changelogs:
(#690)
Support configuring a different cluster domain for internal Service references. (#692)
Documentation: Email is not required any more to set up Let's Encrypt. (#704)
Fixed
Internal
ESS Community Helm Chart 25.8.2 (2025-08-21)
Fixed
ESS Community Helm Chart 25.8.1 (2025-08-11)
Changed
Update Element Web to v1.11.109.
Highlights :
(#663)
Update Synapse to v1.135.2.
Highlights :
(#664)
Internal
test_routes_to_synapse_workers_correctlyby streaming logs from all HAProxyPods, not just the current ones. (#654, #655)ESS Community Helm Chart 25.8.0 (2025-08-06)
Added
Changed
Default Synapse to requiring TLS 1.2 or later.
This can be overridden in additional configuration. (#609)
Set Element X as app to be pointed to when accessing Element Web from a mobile browser. (#610)
Document in CI values example that
deploymentMarkersis default enabled. (#620)Upgrade Matrix Authentication Service to v0.20.0.
Highlights:
Full Changelog:
(#634)
Upgrade
lk-jwt-serviceto 0.3.0.Highlights:
Configure this through
matrixRTC.restrictRoomCreationToLocalUsers. Default to false for now until clients support this new feature.Full Changelog:
(#635)
Upgrade Element Web to v1.11.108.
Highlights:
Full Changelog:
(#638)
Introduce a
device-listsworker for Synapse. ([#639](https://redirect.github.com/element-hq/ess-helm/issConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.