Repository navigation
[jfrog-platform] 11.6.0
Platform Chart Details
| Previous | New | Status | |
|---|---|---|---|
| Chart Version | 11.5.13 |
11.6.0 |
π Updated |
| App Version | 7.146.34 |
7.161.15 |
π Updated |
Changelog (11.5.13 β 11.6.0)
- BREAKING CHANGE β nginx TLS certificate (artifactory subchart
107.161.xand later): nginx no longer auto-generates its TLS certificate. On the JFrog Platform chart, configure it under theartifactory.nginx.*values.- Fresh install (with
artifactory.nginx.https.enabled=true, the default) fails unless one of these is set:artifactory.nginx.tlsSecretName=<name>β supply your ownkubernetes.io/tlsSecret (production, recommended).artifactory.nginx.generateSelfSignedCert=trueβ opt in to a chart-generated self-signed cert (dev/test only, not from a trusted CA).artifactory.nginx.https.enabled=falseβ HTTP only, TLS terminates elsewhere.
- Upgrade: any previously auto-generated Secret is discovered via
lookup, reused, and annotatedhelm.sh/resource-policy: keep, so existing HTTPS installs keep working with no operator action. That Secret still holds a chart-generated key from earlier releases β rotate it by creating your ownkubernetes.io/tlsSecret and settingartifactory.nginx.tlsSecretNameon the next upgrade. - To generate your own
tls.crt/tls.key, see Establish TLS in Artifactory and the JFrog Platform βΊ Generate Certificates.
- Fresh install (with
- Added new dependency chart
wingmanwhich is disabled by default and setwingman.enabled: trueto enable it.
See the Wingman MCP documentation for details. - Update dependency artifactory chart version to 107.161.15
- Update dependency xray chart version to 3.150.17
- Update dependency catalog chart version to 101.42.1
- Update dependency distribution chart version to 102.52.2
- Update dependency worker chart version to 101.216.0
- Update dependency bridge chart version to 101.262.17
- Update postgresql image version to
17.10-helm-20260716
Dependency Chart Version Summary
| Dependency | Previous | New | Status |
|---|---|---|---|
| postgresql | 16.7.26 |
16.7.26 |
Unchanged |
| rabbitmq | 15.4.1 |
15.4.1 |
Unchanged |
| artifactory | 107.146.34 |
107.161.15 |
π Updated |
| xray | 103.143.34 |
103.150.17 |
π Updated |
| catalog | 101.42.1 |
101.42.1 |
Unchanged |
| distribution | 102.52.2 |
102.52.2 |
Unchanged |
| worker | 101.199.0 |
101.216.0 |
π Updated |
| bridge | 101.72.0 |
101.262.17 |
π Updated |
| wingman | none |
100.606.12 |
π Updated |
Dependency Changes
Artifactory (107.146.34 β 107.161.15)Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β π Official release notes: artifactory 7.161.15
Changelog
[107.161.15] - Jul 27, 2026
- BREAKING CHANGE β mandatory keys: Both
masterKeyandjoinKeyare now mandatory at install time (centralizes key management across the JFrog Platform).- On fresh install β both keys must be provided before running
helm install. - On upgrade β reuse the existing keys from the running cluster; do not generate new ones.
- See Install JFrog Artifactory using Helm for how to generate, retrieve, and configure the keys.
- On fresh install β both keys must be provided before running
- BREAKING CHANGE β nginx TLS certificate: The chart no longer auto-generates the nginx TLS certificate by default. You must decide how nginx serves HTTPS.
- On fresh install (with
nginx.https.enabled=true, the default), the install fails unless one of these is set:nginx.tlsSecretName=<name>β supply your ownkubernetes.io/tlsSecret (production, recommended).nginx.generateSelfSignedCert=trueβ opt in to a chart-generated self-signed certificate (dev / test only; not issued by a trusted CA).nginx.https.enabled=falseβ disable HTTPS entirely (HTTP only; TLS terminates elsewhere).
- On upgrade, the previously auto-generated Secret in the cluster is discovered via
lookup, reused, and annotatedhelm.sh/resource-policy: keep, so existing HTTPS installs keep working with no operator action. That Secret still contains a chart-generated private key from earlier releases β operators are strongly encouraged to rotate it by creating their ownkubernetes.io/tlsSecret and settingnginx.tlsSecretNameon the next upgrade, which replaces the previously auto-generated certificate with a custom one. - For how to generate your own
tls.crt/tls.key, see Establish TLS in Artifactory and the JFrog Platform βΊ Generate Certificates.
- On fresh install (with
- Block Helm deployments when
splitServicesToContainersis set tofalse. Starting with releases from 7.161.x, running all services in a single container is no longer supported; setsplitServicesToContainers: trueto proceed. - Added Evaluation Service.
- Added
ingress.backendServiceto route the Ingress object through the chart's nginx service (backendService: nginx) instead of directly to the Artifactory service. - Added support for enabling JFrog AIML mode natively through Helm.
To enable AIML, set.Values.ml.enabled: true. This setsfrontend.ml.jfrogMlAppState: VISIBLEin system.yaml. - Added observability container for jfmelt deployment
- Switch initContainer image from ubi-minimal to jfrog/echo-mini
- Removed the
jfbus.activeProfileconfiguration from the Helm chart. It is now managed internally - Platform federation is supported with all databases
- Upgraded postgres image tag version to
17.10-helm-20260716
[107.158.0] - Jun 25, 2026
- Added
onemodel.cosmoto configure the OneModel Cosmo Router (for example, the router port) viasystem.yaml. This follows OneModel's migration from Apollo Router to Cosmo Router.
[107.157.0] - Jun 10, 2026
- Added
ingressGrpc.enableServiceOnlyto support deploying the gRPC Service without an Ingress object, for environments where an external ingress controller already routes gRPC traffic
[107.156.0] - Jun 03, 2026
- Upgrade postgres image version to
17.10(17.10-helm) - Migrate bundled postgres image from
bitnami/postgresqltoechohq/postgres
[107.154.0] - May 28, 2026
- Enabled frontend as Pod by default
- Added observability container for rtfs,jfbus,apptrust,unifiedpolicy deployments
- Added support for air-gapped environments in the chart.
To configure the JFrog Platform to work in an air-gapped environment, set.Values.jfconnect.airgap.enabled: true
[107.150.0] - May 28, 2026
- Fixed filebeat container image resolution to use
filebeat.image.registrydirectly instead of being overridden byglobal.imageRegistry - Mandatory Join and Master Key functionality validation added. This enhancement focuses on standardizing and centralizing the way keys are managed and passed across the JFrog platform
[107.147.0] - May 28, 2026
- Added support for Gateway API (Gateway, HTTPRoute)
Xray (103.143.34 β 103.150.17)Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β π Official release notes: xray 3.150.17
Changelog
[103.150.17] - Jun 26, 2026
- Fix
wait-for-rabbitmq-replicas-quoruminit container exposing RabbitMQ credentials in pod logs due to bash trace mode (-x). - Added support for the rabbitmq
quorum_queue_non_votersfeature flag and increasedmax_message_sizeto 128 MB. - Update valkey.kubectl.image.repository and valkey.kubectl.image.tag to
echohq/kubectl:1.35.6
[103.148.0] - Jun 25, 2026
- Update postgresql tag version to
17.10.0-debian - Changed postgresql.image.repository to
echohq/postgres - Update rabbitmq.migration.image.repository and rabbitmq.migration.image.tag to
echohq/kubectl:1.35.6
Worker (101.199.0 β 101.216.0)Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β π Official release notes: worker 1.216.0
Changelog
[101.216.0] - Jul 8, 2026
- Updated paths to reflect changes in the docker image
[101.203.0] - Apr 21, 2026
- KEDA
ScaledObject: optionalautoscaling.targetCPUContainerNamesets the KEDA CPU triggercontainerName(per-containerContainerResourcemetrics). When empty, CPU scaling uses pod-level aggregate vs requests.
Bridge (101.72.0 β 101.262.17)
Changelog
[101.213.0] - Jun 30, 2026
- Switch initContainer image to echo-mini:20260629
[101.96.0] - May 26, 2026
- Added
serviceMonitor.additionalLabelsto merge extra labels into ServiceMonitor metadata (e.g. to satisfykube-prometheus-stack'sserviceMonitorSelector) - Added
serviceMonitor.relabelingsapplied to every endpoint (bridge, router, observability) to allow Prometheus relabeling rules
[101.77.0] - Apr 20, 2026
- Renamed router sidecar container port
httptohttp-router-into avoid duplicate port name warning during Helm install
Wingman (none β 100.606.12)
Changelog
No changelog entry for 100.606.12.
Image Version Summary
Artifactory (107.146.34 β 107.161.15)
Images
| Image (repository) | Previous Tag | Current Tag | Status | Digest |
|---|---|---|---|---|
InitContainers (jfrog/echo-mini) |
9.8.1779809423 |
20260716 |
π Updated | sha256:1d41ca84e71f3be4deff268ba723cc1187f0e64d141328ecbaf25254f5aec1d6 |
Router (jfrog/router) |
7.320.46 |
7.729.15 |
π Updated | sha256:83b24ef132e16a66ae3d59cf335e06060911d3ab2cff18e18f2d6f15d9af7e7e |
Artifactory (jfrog/artifactory-pro) |
7.146.34 |
7.161.15 |
π Updated | sha256:c18ff9b9e6141f54fdaa91d2485077ae4d7743609703aaae7440c7dcda68e29b |
Frontend (jfrog/frontend) |
1.456.30 |
1.652.18 |
π Updated | sha256:28400119a094fdbffe132542fc7cb256a4fdc538bc07f6b5513aae076435371c |
Observability (jfrog/observability) |
2.33.3 |
2.47.3 |
π Updated | sha256:75b1789939e86773dc35dde64e0698e1ec0bc41ec920996da094a3e22bf48530 |
Nginx (jfrog/nginx-artifactory-pro) |
7.146.34 |
7.161.15 |
π Updated | sha256:d7cb1ce213e616f1bf62007d5140894ce64f8f2be0d36ae64f33530666026927 |
Postgresql (echohq/postgres) |
17.6.0-debian-12-r2 |
17.10-helm-20260716 |
π Updated | sha256:3d89ab4d17fbc09d532db88a05b4d83cc21fde0b6a7f8b4717ee3c118915e7c4 |
Filebeat (beats/filebeat) |
7.16.2 |
7.16.2 |
Unchanged | unavailable |
Rtfs (jfrog/artifactory-federation) |
2.0.31 |
2.126.10 |
π Updated | sha256:d755b6d0bf519848828769c2a2d696c7dc26266e7d1444ade5d2c9e156c60d1b |
Apptrust (jfrog/apptrust) |
1.59.16 |
1.86.5 |
π Updated | sha256:3ef8f21c725ef7777bfa4fd0ef13d2671db07d79c4f6a938cf67462698943c93 |
Jfbus (jfrog/jfbus-service) |
1.52.7 |
1.386.2 |
π Updated | sha256:242bff1b04b683d57fb7a839c2e23466d9078d03710272cb42aca31f47d6df71 |
Jfmelt (jfrog/jfmelt) |
none |
1.12.3 |
π Updated | sha256:13285f28e59e529bf09dd5343b8a9cb97737dc3d366520deeb22c74dc450e967 |
Unifiedpolicy (jfrog/unifiedpolicy) |
1.45.18 |
1.70.6 |
π Updated | sha256:9fd2bd3556d76d9b331413981ab94957e6d5d8d6c2edf578723450aac65d7933 |
Evaluation (jfrog/evaluation) |
none |
1.27.8 |
π Updated | sha256:4e52967cd86b4e8f7b39305de724cf1d535e0756d508129ff9a4419ef498d4d6 |
Platformfederation (jfrog/platformfederation) |
1.615.40 |
1.1328.8 |
π Updated | sha256:6c38f41ed51ea82e5089a62581951f61cdfcf6e211c97d8c1dee0965a4113338 |
Xray (103.143.34 β 103.150.17)
Images
| Image (repository) | Previous Tag | Current Tag | Status | Digest |
|---|---|---|---|---|
InitContainers (jfrog/echo-mini) |
20260723 |
20260723 |
Unchanged | sha256:4f9a319a8eaf856e8bda207277ed29a87260563b0697e09b56236d0ef8ed6d94 |
Postgresql (echohq/postgres) |
17.8.0-debian |
17.10-helm |
π Updated | sha256:3f6423127b2cfa4cd7fa24e997ffce2ef4a079b6989ed3ca92a521b82878cd50 |
Rabbitmq (bitnami/rabbitmq) |
3.13.7-debian-12-r6 |
3.13.7-debian-12-r6 |
Unchanged | sha256:fc552f869ddedbba09e78a546f876c8712bed53ce887f9e78acd7dba705bba0e |
Rabbitmq.migration (echohq/kubectl) |
1.33.1 |
1.35.6 |
π Updated | sha256:59b0cb0b7384bdd45837a7264f4980c2403c1af6577e38b437377a2eb66e4bdd |
Valkey (bitnami/valkey) |
8.1.2-debian-12-r0 |
8.1.6-echo |
π Updated | sha256:edf97f1a567850432a41f420a429b85465e62ec629565f436023e9b7d4a1fc0d |
Valkey.sentinel (bitnami/valkey-sentinel) |
none |
8.1-echo |
π Updated | sha256:f15039056c9337629c750cfe943e00accd98276f213b4242890837a21e032b8c |
Valkey.kubectl (echohq/kubectl) |
none |
1.35.6 |
π Updated | sha256:59b0cb0b7384bdd45837a7264f4980c2403c1af6577e38b437377a2eb66e4bdd |
Analysis (jfrog/xray-analysis) |
3.143.34 |
3.150.17 |
π Updated | sha256:2a4b5054a9b9ba7aa0fee584f567d48658cea77ef0560c1607598df151a4daab |
Sbom (jfrog/xray-sbom) |
3.143.34 |
3.150.17 |
π Updated | sha256:4e4bcc56e552f4d0924b6e9c7681341b8d08f513b54b28400f930510e6c7cffd |
Jascontextual (jfrog/xray-jascontextual) |
none |
3.150.17 |
π Updated | sha256:5a9ce5baf12eb6d267e2c1f3d043ce57a84b7e3ce1952de0ff6b2961b7d3b6f7 |
Jasexposures (jfrog/xray-jasexposures) |
none |
3.150.17 |
π Updated | sha256:b48e0e70ce6179a28dfba2f61629b0dfbf3f0555c49510c7452117abafe7af06 |
Aiscanner (jfrog/xray-aiscanner) |
none |
3.150.17 |
π Updated | sha256:710b3533c8c7437da0fb1d629faf452dad796dab828cd3cc0a4027d59ada25ed |
Policyenforcer (jfrog/xray-policyenforcer) |
3.143.34 |
3.150.17 |
π Updated | sha256:d7a9486df046207c301c9591963d7c86eb5105a7d086129e22dc8e9802bb9708 |
Indexer (jfrog/xray-indexer) |
3.143.34 |
3.150.17 |
π Updated | sha256:03c7f99f4f0339c65cf58daffd0faa7abd0678e205d109792ce09c9be978b198 |
Persist (jfrog/xray-persist) |
3.143.34 |
3.150.17 |
π Updated | sha256:f107bffa2d15be3d570a062781481a77239e2366feb22033116a8cbf7e77ea01 |
Curation (jfrog/xray-curation) |
3.143.34 |
3.150.17 |
π Updated | sha256:b2ba138b096b2ac4c1e30a92e91ca94dbf1ad1a05fc9feed6d0114c0179e819b |
Reporting (jfrog/xray-reporting) |
none |
3.150.17 |
π Updated | sha256:139c75ae2ac325a96a0ac936cc79b02dc4014eab54afadd57e162d08fc208a43 |
Server (jfrog/xray-server) |
3.143.34 |
3.150.17 |
π Updated | sha256:0997766b8fb8e68ffa2910311ec10f38350e7fb4722704e93ad46ffd2fc013ee |
ContextualAnalysis (jfrog/xray-jas-contextual-analysis) |
3.143.34 |
3.150.17 |
π Updated | sha256:5b0708a6c29ead2a8485a3eea459e5c62f048c6f597b1a6df115bb3b3dbb4e8c |
Exposures (jfrog/xray-jas-exposures) |
3.143.34 |
3.150.17 |
π Updated | sha256:f2814406c48ab802ca03092aad95ddeda10a6393f55aa7e8259cb94f813cb981 |
Router (jfrog/router) |
7.729.15 |
7.729.22 |
π Updated | sha256:a7f1f8ab8aeb36fb107ed6948f8a77b11e0c734d3c67da106b70719c3096af36 |
Observability (jfrog/observability) |
2.53.0 |
2.53.0 |
Unchanged | sha256:52168cbbc8e24988eb1d967873af3da3e849643d313b9290ac537aa2069fbb19 |
Filebeat (beats/filebeat) |
7.16.2 |
7.16.2 |
Unchanged | unavailable |
Worker (101.199.0 β 101.216.0)
Images
| Image (repository) | Previous Tag | Current Tag | Status | Digest |
|---|---|---|---|---|
Worker (jfrog/worker) |
1.199.0 |
1.216.0 |
π Updated | sha256:014d87ee47ba3e77f0ee5ea1b04798e3c80b69a9c21f5d274aaaebde1e044464 |
Router (jfrog/router) |
7.205.10 |
7.320.44 |
π Updated | sha256:b862703ce7803310717feb2f4afd440543b3d08cddfb8e4a163ebcd1405d7dcd |
InitContainers (jfrog/echo-mini) |
9.7.1773939694 |
20260709 |
π Updated | sha256:ca0dcf25f81690a6502c93317e14e768d31ad0561149ba99ffb5895d00842598 |
Filebeat (beats/filebeat) |
7.17.29 |
7.17.29 |
Unchanged | unavailable |
Observability (jfrog/observability) |
2.32.0 |
2.49.2 |
π Updated | sha256:12a7548b841f31fba69cb3d5ad107465b7b098cdd1775d576594b416c3b0fb5b |
Bridge (101.72.0 β 101.262.17)
Images
| Image (repository) | Previous Tag | Current Tag | Status | Digest |
|---|---|---|---|---|
Bridge (jfrog/bridge) |
1.72.0 |
1.262.17 |
π Updated | sha256:1b509a6d7d775c9cac4f0ecf0a324dae4415329921dd2d579a344f6f18b57027 |
Router (jfrog/router) |
7.205.10 |
7.320.45 |
π Updated | sha256:b023fbbd001b6e0174551f3db5fec4f42e82b3ae31a06ed59f458a1f0d8f74c9 |
InitContainers (jfrog/echo-mini) |
9.7.1773939694 |
20260720 |
π Updated | sha256:da7795ab19f34b181df1b3a1a9bf0d9c46de3f584d7f69fe98f251f7cbb6f65c |
Filebeat (beats/filebeat) |
7.17.29 |
7.17.29 |
Unchanged | unavailable |
Observability (jfrog/observability) |
2.32.0 |
2.49.2 |
π Updated | sha256:12a7548b841f31fba69cb3d5ad107465b7b098cdd1775d576594b416c3b0fb5b |
Wingman (none β 100.606.12)
Images
| Image (repository) | Previous Tag | Current Tag | Status | Digest |
|---|---|---|---|---|
Wingman (jfrog/wingman) |
none |
0.606.12 |
π Updated | sha256:589a3de69c954b5a544c67f488ceaca1eea4dbd1aad03aff53830d734497499e |
InitContainers (ubi9/ubi-minimal) |
none |
9.8.1782366411 |
π Updated | sha256:11216931d4eb51aa6366bf3282e59b42cf689e52dc9c051b4d8b642468611456 |
Postgresql (echohq/postgres) |
none |
17.10-helm-20260621 |
π Updated | sha256:4f375f685ecda157c3980f02dd98a3c7a113f0e2cf78047c970780345ef0db10 |
Router (jfrog/router) |
none |
7.320.44 |
π Updated | sha256:b862703ce7803310717feb2f4afd440543b3d08cddfb8e4a163ebcd1405d7dcd |
Observability (jfrog/observability) |
none |
2.53.0 |
π Updated | sha256:52168cbbc8e24988eb1d967873af3da3e849643d313b9290ac537aa2069fbb19 |