jenkins: update to 2.568.1 LTS and chart

Change-Id: Ib6b48599a09dee669d77441c12b354240ef257b8
diff --git a/charts/jenkins/CHANGELOG.md b/charts/jenkins/CHANGELOG.md
index 7fb10f6..2420f0a 100644
--- a/charts/jenkins/CHANGELOG.md
+++ b/charts/jenkins/CHANGELOG.md
@@ -5,13 +5,1120 @@
 
 Use the following links to reference issues, PRs, and commits prior to v2.6.0.
 
-* Issue:  `https://github.com/helm/charts/issues/[issue#]`
-* PR:     `https://github.com/helm/charts/pull/[pr#]`
-* Commit: `https://github.com/helm/charts/commit/[commit]/stable/jenkins`
+- Issue: `https://github.com/helm/charts/issues/[issue#]`
+- PR: `https://github.com/helm/charts/pull/[pr#]`
+- Commit: `https://github.com/helm/charts/commit/[commit]/stable/jenkins`
 
 The changelog until v1.5.7 was auto-generated based on git commits.
 Those entries include a reference to the git commit to be able to get more details.
 
+## 5.9.40
+
+Evaluate `tpl` on `agent.image.registry`, `agent.image.repository`, and `agent.image.tag` so the default kubernetes-agent pod template can compose its jnlp image from other Helm values or named templates. Complements the `tpl`-support added for `controller.javaOpts` / `controller.jenkinsOpts` in 5.9.39.
+
+## 5.9.39
+
+Evaluate `tpl` on `controller.javaOpts` and `controller.jenkinsOpts` so values can reference other Helm values or named templates, matching the templating already supported by fields such as `controller.ingress.hostName`, `controller.secondaryIngress.hostName`, and `controller.admin.existingSecret`.
+
+## 5.9.38
+
+Allow overriding the secondary ingress path type
+
+## 5.9.37
+
+Fix [#1521](https://github.com/jenkinsci/helm-charts/issues/1521): Preserve explicit zero values for agent `runAsUser` and `runAsGroup`
+
+## 5.9.36
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.8.1`
+
+## 5.9.35
+
+Update `kubernetes` to version `4467.vf26561292824`
+
+## 5.9.34
+
+Update `configuration-as-code` to version `2100.vb_fd699d2a_09c`
+
+## 5.9.33
+
+Update `jenkins/jenkins` to version `2.568.1-jdk21`
+
+## 5.9.32
+
+Update `jenkins/inbound-agent` to version `3383.vc8881d4b_0e76-1`
+
+## 5.9.31
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.8.0`
+
+## 5.9.30
+
+Added addMasterProxyEnvVars to allow agents to use proxy env settings from the controller.
+
+## 5.9.29
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.7.4`
+
+## 5.9.28
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-23`
+
+## 5.9.27
+
+Update `configuration-as-code` to version `2089.v970a_0b_a_8cc6d`
+
+## 5.9.26
+
+Update `configuration-as-code` to version `2088.ve3b_42c663c80`
+
+## 5.9.25
+
+Update `configuration-as-code` to version `2082.vdb_db_4622e9fa_`
+
+## 5.9.24
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-22`
+
+## 5.9.23
+
+Update `jenkins/jenkins` to version `2.555.3-jdk21`
+
+## 5.9.22
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.7.3`
+
+## 5.9.21
+
+Update `configuration-as-code` to version `2077.v41f1011a_5110`
+
+## 5.9.20
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-20`
+
+## 5.9.19
+
+Update `jenkins/jenkins` to version `2.555.2-jdk21`
+
+## 5.9.18
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.6.0`
+
+## 5.9.17
+
+Update `jenkins/jenkins` to version `2.555.1-jdk21`
+
+## 5.9.16
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-19`
+
+## 5.9.15
+
+Update `configuration-as-code` to version `2074.va_57f83f7a_10b_`
+
+## 5.9.14
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-18`
+
+## 5.9.13
+
+- Fix [#1637](https://github.com/jenkinsci/helm-charts/issues/1637): Evaluate tpl values in secondary ingress host and tls hosts
+- Fix [#476](https://github.com/jenkinsci/helm-charts/issues/476): Secondary ingress template should have parameters as primary ingress
+
+## 5.9.12
+
+Update `git` to version `5.10.1`
+
+## 5.9.11
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-17`
+
+## 5.9.10
+
+Update `configuration-as-code` to version `2061.vc08919f7fc37`
+
+## 5.9.9
+
+Update `jenkins/jenkins` to version `2.541.3-jdk21`
+
+## 5.9.8
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-16`
+
+## 5.9.7
+
+Update `configuration-as-code` to version `2053.vb_0da_47381a_25`
+
+## 5.9.6
+
+Don't add `secretName: "<nil>"` to ingress if no value defined
+
+## 5.9.5
+
+Don't render `tls` ingress section if its value is `{}`
+
+## 5.9.4
+
+Fix templating in `extraObjects`
+
+## 5.9.3
+
+Allow to scale controller to zero replicas during maintenance scenarios.
+
+## 5.9.2
+
+Add support for annotations on the HTTPRoute resource
+
+## 5.9.1
+
+Fix templating in secretName for ingress
+
+## 5.9.0
+
+Added [Gateway API](https://gateway-api.sigs.k8s.io/api-types/httproute/) support
+
+## 5.8.142
+
+Update `jenkins/jenkins` to version `2.541.2-jdk21`
+
+## 5.8.141
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-14`
+
+## 5.8.140
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-13`
+
+## 5.8.139
+
+Update `git` to version `5.10.0`
+
+## 5.8.138
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-12`
+
+## 5.8.137
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-11`
+
+## 5.8.136
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-10`
+
+## 5.8.135
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-9`
+
+## 5.8.134
+
+Update `configuration-as-code` to version `2037.v8e5349845172`
+
+## 5.8.133
+
+Update `configuration-as-code` to version `2036.v0b_c2de701dcb_`
+
+## 5.8.132
+
+Update `git` to version `5.9.0`
+
+## 5.8.131
+
+Add `extraObjects`
+
+## 5.8.130
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-7`
+
+## 5.8.129
+
+Update `kubernetes` to version `4423.vb_59f230b_ce53`
+
+## 5.8.128
+
+Add `ingress.resourceRootUrl` to ingress' `spec.tls.hosts`
+
+## 5.8.127
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-6`
+
+## 5.8.126
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.5.0`
+
+## 5.8.125
+
+Update `jenkins/jenkins` to version `2.541.1-jdk21`
+
+## 5.8.124
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.4.0`
+
+## 5.8.123
+
+Update `kubernetes` to version `4419.v36079e3b_eb_5b_`
+
+## 5.8.122
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.3.0`
+
+## 5.8.121
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `2.1.4`
+
+## 5.8.120
+
+Update `configuration-as-code` to version `2031.veb_a_fdda_b_3ffd`
+
+## 5.8.119
+
+Update `kubernetes` to version `4416.v2ea_b_5372da_a_e`
+
+## 5.8.118
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-5`
+
+## 5.8.117
+
+Added value to override default ingress pathType
+
+## 5.8.116
+
+Added default fsGroupChangePolicy value, allow overriding in accordance to current deprecation plans
+
+## 5.8.115
+
+Removed controller.csrf.defaultCrumbIssuer.proxyCompatability as it is dropped in core
+
+## 5.8.114
+
+Update `kubernetes` to version `4398.vb_b_33d9e7fe23`
+
+## 5.8.113
+
+Update `git` to version `5.8.1`
+
+## 5.8.112
+
+Update `jenkins/inbound-agent` to version `3355.v388858a_47b_33-3`
+
+## 5.8.111
+
+Update `jenkins/jenkins` to version `2.528.3-jdk21`
+
+## 5.8.110
+
+Update `jenkins/inbound-agent` to version `3345.v03dee9b_f88fc-6`
+
+## 5.8.109
+
+Update `jenkins/jenkins` to version `2.528.2-jdk21`
+
+## 5.8.108
+
+Update `kubernetes` to version `4392.v19cea_fdb_5913`
+
+## 5.8.107
+
+Update `docker.io/bats/bats` to version `1.13.0`
+
+## 5.8.106
+
+Update `jenkins/inbound-agent` to version `3345.v03dee9b_f88fc-5`
+
+## 5.8.105
+
+Update `jenkins/inbound-agent` to version `3345.v03dee9b_f88fc-3`
+
+## 5.8.104
+
+Update `configuration-as-code` to version `2006.v001a_2ca_6b_574`
+
+## 5.8.103
+
+Update `jenkins/inbound-agent` to version `3345.v03dee9b_f88fc-2`
+
+## 5.8.102
+
+Update `jenkins/jenkins` to version `2.528.1-jdk21`
+
+## 5.8.101
+
+Update `jenkins/inbound-agent` to version `3345.v03dee9b_f88fc-1`
+
+## 5.8.100
+
+Add support for [custom DNS configuration](https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config) in the controller
+
+## 5.8.99
+
+Update `git` to version `5.8.0`
+
+## 5.8.98
+
+Update `jenkins/inbound-agent` to version `3341.v0766d82b_dec0-4`
+
+## 5.8.97
+
+Update `configuration-as-code` to version `1998.v3e50e6e9d9d3`
+
+## 5.8.96
+
+Update `jenkins/inbound-agent` to version `3341.v0766d82b_dec0-3`
+
+## 5.8.95
+
+Update `jenkins/inbound-agent` to version `3341.v0766d82b_dec0-2`
+
+## 5.8.94
+
+Update `kubernetes` to version `4384.v1b_6367f393d9`
+
+## 5.8.93
+
+Update `kubernetes` to version `4383.vb_76fc9d3c4dc`
+
+## 5.8.92
+
+Update `configuration-as-code` to version `1995.v540b_50a_eb_0c1`
+
+## 5.8.91
+
+Fix `docker-agent` git repository URL
+
+## 5.8.90
+
+Update `jenkins/inbound-agent` to version `3341.v0766d82b_dec0-1`
+
+## 5.8.89
+
+Fix chart deployment.
+
+## 5.8.88
+
+Update `jenkins/jenkins` to version `2.516.3-jdk21`
+
+## 5.8.87
+
+Update `jenkins/inbound-agent` to version `3327.v868139a_d00e0-8`
+
+## 5.8.86
+
+Update `kubernetes` to version `4371.vb_33b_086d54a_1`
+
+## 5.8.85
+
+Update `jenkins/inbound-agent` to version `3327.v868139a_d00e0-7`
+
+## 5.8.84
+
+Update `kubernetes` to version `4369.va_9a_89327dd35`
+
+## 5.8.83
+
+Revert `defaultConfig=false` changes, see [#1470](https://github.com/jenkinsci/helm-charts/issues/1470).
+
+## 5.8.82
+
+Update `jenkins/jenkins` to version `2.516.2-jdk21`
+
+## 5.8.81
+
+Update `jenkins/inbound-agent` to version `3327.v868139a_d00e0-6`
+
+## 5.8.80
+
+- Fix [#1435](https://github.com/jenkinsci/helm-charts/issues/1435): Ensure `controller.JCasC.defaultConfig=false` properly prevents generation of all JCasC ConfigMaps
+- Changed the conditional logic in jcasc-config.yaml to only generate ConfigMaps when defaultConfig is true
+- Moved securityRealm and authorizationStrategy configuration into configScripts for better maintainability
+
+## 5.8.79
+
+Update `jenkins/inbound-agent` to version `3327.v868139a_d00e0-5`
+
+## 5.8.78
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.7`
+
+## 5.8.77
+
+Update `configuration-as-code` to version `1985.vdda_32d0c4ea_b_`
+
+## 5.8.76
+
+Fix non-deterministic checksum calculation in unit tests by adding `renderHelmLabels: false` to "render pod annotations" test. This resolves Renovate PR failures when chart version changes.
+
+## 5.8.75
+
+Minor documentation improvements
+
+## 5.8.74
+
+unittest fix - allow helm version label to be dynamic in tests
+
+## 5.8.73
+
+Standardize labels and add extraLabels support across chart:
+
+- Standardize label application patterns throughout all template files
+- Add extraLabels configuration option for custom user-defined labels
+
+## 5.8.72
+
+Render securityRealm and authorizationStrategy as JCasC ConfigMaps when set outside configScripts (Fixes #1391)
+
+## 5.8.71
+
+Update `jenkins/inbound-agent` to version `3327.v868139a_d00e0-2`
+
+## 5.8.70
+
+Update `jenkins/inbound-agent` to version `3324.vea_eda_e98cd69-2`
+
+## 5.8.69
+
+Update `jenkins/jenkins` to version `2.516.1-jdk21`
+
+## 5.8.68
+
+Update `jenkins/inbound-agent` to version `3324.vea_eda_e98cd69-1`
+
+## 5.8.67
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-8`
+
+## 5.8.66
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-7`
+
+## 5.8.65
+
+Revert update of `docker.io/kiwigrid/k8s-sidecar` back to `1.30.3` which works due to upstream [bug](https://github.com/python/cpython/issues/135408)
+
+## 5.8.64
+
+Update `kubernetes` to version `4358.vcfd9c5a_0a_f51`
+
+## 5.8.63
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-6`
+
+## 5.8.62
+
+Update `kubernetes` to version `4356.vfa_556c21f086`
+
+## 5.8.61
+
+Update `jenkins/jenkins` to version `2.504.3-jdk21`
+
+## 5.8.60
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.5`
+
+## 5.8.59
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-5`
+
+## 5.8.58
+
+Add option to specify the agent image registry
+
+## 5.8.57
+
+Add option to disable the default jenkins controller service
+
+## 5.8.56
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-4`
+
+## 5.8.55
+
+Update `kubernetes` to version `4353.vb_47977da_9417`
+
+## 5.8.54
+
+Update `kubernetes` to version `4350.va_0283de0d6d6`
+
+## 5.8.53
+
+Update `jenkins/jenkins` to version `2.504.2-jdk21`
+
+## 5.8.52
+
+Update `configuration-as-code` to version `1971.vf9280461ea_89`
+
+## 5.8.51
+
+Update `kubernetes` to version `4349.v8fe8f2b_ee9f1`
+
+## 5.8.50
+
+Update `kubernetes` to version `4347.va_c0cf1c32f38`
+
+## 5.8.49
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-3`
+
+## 5.8.48
+
+Update `docker.io/bats/bats` to version `1.12.0`
+
+## 5.8.47
+
+Fix code styling for super-linter 7 upgrade
+
+## 5.8.46
+
+Update `kubernetes` to version `4340.v345364d31a_2a_`
+
+## 5.8.45
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-2`
+
+## 5.8.44
+
+Fix the default value for `controller.sidecars.configAutoReload.env` (change from `{}` to `[]`) to address `coalesce.go:286: warning: cannot overwrite table with non table`.
+
+## 5.8.43
+
+Update `configuration-as-code` to version `1967.va_968e15fd05b_`
+
+## 5.8.42
+
+Update `kubernetes` to version `4336.v55d9a_494db_38`
+
+## 5.8.41
+
+Update `jenkins/inbound-agent` to version `3309.v27b_9314fd1a_4-1`
+
+## 5.8.40
+
+Update `kubernetes` to version `4334.v32b_f157682d6`
+
+## 5.8.39
+
+Update `configuration-as-code` to version `1963.v24e046127a_3f`
+
+## 5.8.38
+
+Update `jenkins/jenkins` to version `2.504.1-jdk21`
+
+## 5.8.37
+
+Update `jenkins/inbound-agent` to version `3307.v632ed11b_3a_c7-2`
+
+## 5.8.36
+
+Update `configuration-as-code` to version `1958.vddc0d369b_e16`
+
+## 5.8.35
+
+Support .Values.agent.garbageCollection also in secondary clouds
+
+## 5.8.34
+
+Added .Values.agent.instanceCap to limit number of agents of each type.
+
+## 5.8.33
+
+Update `configuration-as-code` to version `1953.v148f87d74b_1e`
+
+## 5.8.32
+
+Update `jenkins/jenkins` to version `2.492.3-jdk21`
+
+## 5.8.31
+
+Update `jenkins/jenkins` to version `2.492.3-jdk17`
+
+## 5.8.30
+
+Update `jenkins/inbound-agent` to version `3301.v4363ddcca_4e7-3`
+
+## 5.8.29
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.3`
+
+## 5.8.28
+
+Update `jenkins/inbound-agent` to version `3301.v4363ddcca_4e7-2`
+
+## 5.8.27
+
+Update `jenkins/inbound-agent` to version `3301.v4363ddcca_4e7-1`
+
+## 5.8.26
+
+Update `jenkins/inbound-agent` to version `3299.v0d0d06908537-2`
+
+## 5.8.25
+
+Fix indentation in `values.yaml`
+
+## 5.8.24
+
+Update `workflow-aggregator` to version `608.v67378e9d3db_1`
+
+## 5.8.23
+
+Update `configuration-as-code` to version `1947.v7d33fe23569c`
+
+## 5.8.22
+
+Update `jenkins/inbound-agent` to version `3299.v0d0d06908537-1`
+
+## 5.8.21
+
+Update `kubernetes` to version `4324.vfec199a_33512`
+
+## 5.8.20
+
+Update `jenkins/inbound-agent` to version `3291.vb_131b_dc231fa_-1`
+
+## 5.8.19
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.2`
+
+## 5.8.18
+
+Update `jenkins/jenkins` to version `2.492.2-jdk17`
+
+## 5.8.17
+
+Update `kubernetes` to version `4314.v5b_846cf499eb_`
+
+## 5.8.16
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.1`
+
+## 5.8.15
+
+Update `kubernetes` to version `4313.va_9b_4fe2a_0e34`
+
+## 5.8.14
+
+Update `jenkins/inbound-agent` to version `3283.v92c105e0f819-9`
+
+## 5.8.13
+
+Fix `agentListenerPort` not being updated in `config.xml` when set via Helm values.
+
+## 5.8.12
+
+Update plugin count.
+
+## 5.8.11
+
+Update `jenkins/inbound-agent` to version `3283.v92c105e0f819-8`
+
+## 5.8.10
+
+Update `jenkins/jenkins` to version `2.492.1-jdk17`
+
+## 5.8.9
+
+Update `configuration-as-code` to version `1932.v75cb_b_f1b_698d`
+
+## 5.8.8
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.30.0`
+
+## 5.8.7
+
+Update `configuration-as-code` to version `1929.v036b_5a_e1f123`
+
+## 5.8.6
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.29.1`
+
+## 5.8.5
+
+Update `jenkins/inbound-agent` to version `3283.v92c105e0f819-7`
+
+## 5.8.4
+
+Allow setting [automountServiceAccountToken](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#opt-out-of-api-credential-automounting)
+
+## 5.8.3
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.29.0`
+
+## 5.8.2
+
+Update `jenkins/jenkins` to version `2.479.3-jdk17`
+
+## 5.8.1
+
+Update `configuration-as-code` to version `1915.vcdd0a_d0d2625`
+
+## 5.8.0
+
+Add option to publish not-ready addresses in controller service.
+
+## 5.7.27
+
+Update `git` to version `5.7.0`
+
+## 5.7.26
+
+Update `configuration-as-code` to version `1909.vb_b_f59a_27d013`
+
+## 5.7.25
+
+Update `kubernetes` to version `4306.vc91e951ea_eb_d`
+
+## 5.7.24
+
+Update `kubernetes` to version `4304.v1b_39d4f98210`
+
+## 5.7.23
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.28.4`
+
+## 5.7.22
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.28.3`
+
+## 5.7.21
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.28.1`
+
+## 5.7.20
+
+Update `kubernetes` to version `4302.va_756e4b_67715`
+
+## 5.7.19
+
+Update `configuration-as-code` to version `1903.v004d55388f30`
+
+## 5.7.18
+
+Update `kubernetes` to version `4300.vd82c5692b_3a_e`
+
+## 5.7.17
+
+Update `docker.io/bats/bats` to version `1.11.1`
+
+## 5.7.16
+
+Add tpl support for persistence.storageClassName in home-pvc.yaml and tpl support in controller.ingress parameters(ingressClassName, annotations, hostname) in jenkins-controller-ingress.yaml
+
+## 5.7.15
+
+Update `jenkins/jenkins` to version `2.479.2-jdk17`
+
+## 5.7.14
+
+Update `kubernetes` to version `4296.v20a_7e4d77cf6`
+
+## 5.7.13
+
+Update `configuration-as-code` to version `1897.v79281e066ea_7`
+
+## 5.7.12
+
+Update `configuration-as-code` to version `1887.v9e47623cb_043`
+
+## 5.7.11
+
+Update `git` to version `5.6.0`
+
+## 5.7.10
+
+Update `jenkins/jenkins` to version `2.479.1-jdk17`
+
+## 5.7.9
+
+Update `configuration-as-code` to version `1873.vea_5814ca_9c93`
+
+## 5.7.8
+
+Update `jenkins/inbound-agent` to version `3273.v4cfe589b_fd83-1`
+
+## 5.7.7
+
+Update `kubernetes` to version `4295.v7fa_01b_309c95`
+
+## 5.7.5
+
+Fix helm release deployment with flux revision reconciliation
+
+## 5.7.4
+
+Update `kubernetes` to version `4292.v11898cf8fa_66`
+
+## 5.7.3
+
+Update `git` to version `5.5.2`
+
+## 5.7.2
+
+Update `jenkins/jenkins` to version `2.462.3-jdk17`
+
+## 5.7.1
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.28.0`
+
+## 5.7.0
+
+Add RBAC support for using the `nonroot` and `nonroot-v2` `SecurityContextConstraints` on OpenShift.
+
+## 5.6.5
+
+Update `kubernetes` to version `4290.v93ea_4b_b_26a_61`
+
+## 5.6.4
+
+Update `git` to version `5.5.1`
+
+## 5.6.3
+
+Update `git` to version `5.5.0`
+
+## 5.6.2
+
+Update `kubernetes` to version `4288.v1719f9d0c854`
+
+## 5.6.1
+
+Documentation about OCI installation
+
+## 5.6.0
+
+Helm chart is also now deployed on GitHub packages and can be installed from `oci://ghcr.io/jenkinsci/helm-charts/jenkins`
+
+## 5.5.16
+
+Update `kubernetes` to version `4287.v73451380b_576`
+
+## 5.5.15
+
+Add support for `controller.enableServiceLinks` to disable service links in the controller pod.
+
+## 5.5.14
+
+Update `jenkins/jenkins` to version `2.462.2-jdk17`
+
+## 5.5.13
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.6`
+
+## 5.5.12
+
+Update `configuration-as-code` to version `1850.va_a_8c31d3158b_`
+
+## 5.5.11
+
+Update `configuration-as-code` to version `1849.v3a_d20568000a_`
+
+## 5.5.10
+
+Update `git` to version `5.4.1`
+
+## 5.5.9
+
+Update `git` to version `5.4.0`
+
+## 5.5.8
+
+Add `agent.garbageCollection` to support setting [kubernetes plugin garbage collection](https://plugins.jenkins.io/kubernetes/#plugin-content-garbage-collection-beta).
+
+## 5.5.7
+
+Update `kubernetes` to version `4285.v50ed5f624918`
+
+## 5.5.6
+
+Add `agent.useDefaultServiceAccount` to support omitting setting `serviceAccount` in the default pod template from `serviceAgentAccount.name`.
+Add `agent.serviceAccount` to support setting the default pod template value.
+
+## 5.5.5
+
+Update `jenkins/inbound-agent` to version `3261.v9c670a_4748a_9-1`
+
+## 5.5.4
+
+Update `jenkins/jenkins` to version `2.462.1-jdk17`
+
+## 5.5.3
+
+Update `git` to version `5.3.0`
+
+## 5.5.2
+
+Update `kubernetes` to version `4280.vd919fa_528c7e`
+
+## 5.5.1
+
+Update `kubernetes` to version `4265.v78b_d4a_1c864a_`
+
+## 5.5.0
+
+Introduce capability of set skipTlsVerify and usageRestricted flags in additionalClouds
+
+## 5.4.4
+
+Update CHANGELOG.md, README.md, and UPGRADING.md for linting
+
+## 5.4.3
+
+Update `configuration-as-code` to version `1836.vccda_4a_122a_a_e`
+
+## 5.4.2
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.5`
+
+## 5.4.1
+
+Update `jenkins/jenkins` to version `2.452.3`
+
+## 5.4.0
+
+Introduce capability of additional mountPaths and logging file paths for config reload container
+
+## 5.3.6
+
+Update `workflow-aggregator` to version `600.vb_57cdd26fdd7`
+
+## 5.3.5
+
+Update `kubernetes` to version `4253.v7700d91739e5`
+
+## 5.3.4
+
+Update `jenkins/jenkins` to version `2.452.3-jdk17`
+
+## 5.3.3
+
+Update `jenkins/inbound-agent` to version `3256.v88a_f6e922152-1`
+
+## 5.3.2
+
+Update `kubernetes` to version `4248.vfa_9517757b_b_a_`
+
+## 5.3.1
+
+Fix Tiltfile deprecated value reference
+
+## 5.3.0
+
+Add `controller.topologySpreadConstraints`
+
+## 5.2.2
+
+Update `kubernetes` to version `4246.v5a_12b_1fe120e`
+
+## 5.2.1
+
+Update `jenkins/jenkins` to version `2.452.2-jdk17`
+
+## 5.2.0
+
+Add `agent.inheritYamlMergeStrategy` to allow configuring this setting on the default agent pod template.
+
+## 5.1.31
+
+Update `kubernetes` to version `4245.vf5b_83f1fee6e`
+
+## 5.1.30
+
+Add `controller.JCasC.configMapAnnotations` to allow setting annotations on the JCasC ConfigMaps.
+
+## 5.1.29
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.4`
+
+## 5.1.28
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.3`
+
+## 5.1.27
+
+Update `kubernetes` to version `4244.v4fb_b_00994a_90`
+
+## 5.1.26
+
+Update `kubernetes` to version `4238.v41b_3ef14a_5d8`
+
+## 5.1.25
+
+Update `kubernetes` to version `4236.vc06f753c3234`
+
+## 5.1.24
+
+Update `kubernetes` to version `4234.vdf3e78112369`
+
+## 5.1.23
+
+Update `kubernetes` to version `4233.vb_67a_0e11a_039`
+
+## 5.1.22
+
+Update `configuration-as-code` to version `1810.v9b_c30a_249a_4c`
+
+## 5.1.21
+
+Update `kubernetes` to version `4231.vb_a_6b_8936497d`
+
+## 5.1.20
+
+Update `kubernetes` to version `4230.vceef11cb_ca_37`
+
+## 5.1.19
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.2`
+
+## 5.1.18
+
+Update `configuration-as-code` to version `1807.v0175eda_00a_20`
+
+## 5.1.17
+
+Update `jenkins/inbound-agent` to version `3248.v65ecb_254c298-1`
+
+## 5.1.16
+
+Update `configuration-as-code` to version `1805.v1455f39c04cf`
+
+## 5.1.15
+
+Update `jenkins/jenkins` to version `2.452.1-jdk17`
+
+## 5.1.14
+
+Update `kubernetes` to version `4219.v40ff98cfb_d6f`
+
+## 5.1.13
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.27.1`
+
+## 5.1.12
+
+Update `git` to version `5.2.2`
+
+## 5.1.11
+
+Update `kubernetes` to version `4214.vf10083a_42e70`
+
+## 5.1.10
+
+Update `kubernetes` to version `4211.v08850dd0dfa_3`
+
+## 5.1.9
+
+Update `docker.io/kiwigrid/k8s-sidecar` to version `1.26.2`
+
+## 5.1.8
+
+Update `kubernetes` to version `4209.vc646b_71e5269`
+
+## 5.1.7
+
+Update `kubernetes` to version `4208.v4017b_a_27a_d67`
+
+## 5.1.6
+
+Update `jenkins/jenkins` to version `2.440.3-jdk17`
+
 ## 5.1.5
 
 Fix Prometheus controller name.
@@ -60,7 +1167,6 @@
 
 Fixed changelog entries for previous version bumps
 
-
 ## 5.0.14
 
 Update `jenkins/jenkins` to version `2.440.1-jdk17`
@@ -75,8 +1181,8 @@
 
 ## 5.0.11
 
-* Add controller.sidecars.configAutoReload.scheme to specify protocol scheme when connecting Jenkins configuration-as-code reload endpoint
-* Add controller.sidecars.configAutoReload.skipTlsVerify to force the k8s-sidecar container to skip TLS verification when connecting to an HTTPS Jenkins configuration-as-code reload endpoint
+- Add controller.sidecars.configAutoReload.scheme to specify protocol scheme when connecting Jenkins configuration-as-code reload endpoint
+- Add controller.sidecars.configAutoReload.skipTlsVerify to force the k8s-sidecar container to skip TLS verification when connecting to an HTTPS Jenkins configuration-as-code reload endpoint
 
 ## 5.0.10
 
@@ -116,8 +1222,8 @@
 
 ## 5.0.0
 
-  > [!CAUTION]
-  > Several fields have been renamed or removed. See [UPGRADING.md](./UPGRADING.md#to-500)
+> [!CAUTION]
+> Several fields have been renamed or removed. See [UPGRADING.md](./UPGRADING.md#to-500)
 
 The Helm Chart is now updated automatically via [Renovate](https://docs.renovatebot.com/)
 
@@ -130,7 +1236,7 @@
 Add support for [generic ephemeral storage](https://github.com/jenkinsci/kubernetes-plugin/pull/1489) in `agent.volumes` and `agents.workspaceVolume`.
 
 | plugin     | old version         | new version        |
-|------------|---------------------|--------------------|
+| ---------- | ------------------- | ------------------ |
 | kubernetes | 4029.v5712230ccb_f8 | 4174.v4230d0ccd951 |
 
 ## 4.11.2
@@ -153,8 +1259,8 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.426.2
 
-
 Notes about [Artifact Hub](https://artifacthub.io/packages/helm/jenkinsci/jenkins?modal=changelog) changelog processing:
+
 - Remove empty lines
 - Keep only ASCII characters (no emojis)
 - One change per line
@@ -214,7 +1320,7 @@
 
 ## 4.7.0
 
-Runs `config-reload` as an init container, in addition to the sidecar container, to ensure that JCasC YAMLS are present before the main Jenkins container starts. This should fix some race conditions and crashes on startup.
+Runs `config-reload` as an init container, in addition to the sidecar container, to ensure that JCasC YAMLs are present before the main Jenkins container starts. This should fix some race conditions and crashes on startup.
 
 ## 4.6.7
 
@@ -250,7 +1356,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.414.1
 
-
 ## 4.5.0
 
 Added `.Values.persistence.dataSource` to allow cloning home PVC from existing dataSource.
@@ -259,7 +1364,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.401.3
 
-
 ## 4.4.1
 
 Added `.Values.agent.jnlpregistry` to allow agents to be configured with private registry.
@@ -268,7 +1372,6 @@
 
 Add config keys for liveness probes on agent containers.
 
-
 ## 4.3.30
 
 Update Jenkins version in controller test matching LTS version
@@ -277,7 +1380,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.401.2
 
-
 ## 4.3.28
 
 Allow the kubernetes API server URL to be configurable.
@@ -293,8 +1395,8 @@
 ## 4.3.25
 
 | plugin                | old version          | new version           |
-|-----------------------|----------------------|-----------------------|
-| kubernetes            | 3900.va_dce992317b_4 | 3937.vd7b_82db_e347b_ |
+| --------------------- | -------------------- | --------------------- |
+| kubernetes            | 3900.va_dce992317b_4 | 3937.vd7b*82db_e347b* |
 | configuration-as-code | 1625.v27444588cc3d   | 1647.ve39ca_b_829b_42 |
 | git                   | 5.0.0                | 5.1.0                 |
 | ldap                  | 671.v2a_9192a_7419d  | 682.v7b_544c9d1512    |
@@ -303,46 +1405,38 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.401.1
 
-
 ## 4.3.23
 
 Update Jenkins image and appVersion to jenkins lts release version 2.387.3
 
-
 ## 4.3.22
 
-
 Bump chart version.
 
 ## 4.3.21
 
-
 Document building charts for weekly releases.
 
 ## 4.3.20
 
-
 Enhance repository appearance and miscellaneous cleanup.
 
 ## 4.3.19
 
-
 Comply with superlinter rules and address ShellCheck issues.
 
 ## 4.3.18
 
-
 Bump kiwigrid/k8s-sidecar from 1.15.0 to 1.23.1.
 
 ## 4.3.17
 
-
 Bump jenkins/inbound-agent from 4.11.2-4 to 3107.v665000b_51092-5.
 
 ## 4.3.16
 
-
 Update bundled plugins:
+
 - [ldap](https://plugins.jenkins.io/ldap/): From 2.5 to 671.v2a_9192a_7419d
 - [kubernetes](https://plugins.jenkins.io/kubernetes/): From 3734.v562b_b_a_627ea_c to 3900.va_dce992317b_4
 - [workflow-aggregator](https://plugins.jenkins.io/workflow-aggregator/): From 590.v6a_d052e5a_a_b_5 to 590.v6a_d052e5a_a_b_5
@@ -350,29 +1444,24 @@
 
 ## 4.3.15
 
-
 Update bats from 1.2.1 to 1.9.0.
 
 ## 4.3.14
 
-
 Update various GH actions, typo fixes, and miscellaneous chores.
 
 ## 4.3.13
 
-
 Bump helm-unittest from 0.2.8 to 0.2.11.
 
 ## 4.3.12
 
-
 Update wording in values.yml.
 
 ## 4.3.11
 
 Update Jenkins image and appVersion to jenkins lts release version 2.387.2
 
-
 ## 4.3.10
 
 Correct incorrect env var definition
@@ -380,7 +1469,7 @@
 
 ## 4.3.9
 
-Document `.Values.agent.directConnection` in README.
+Document `.Values.agent.directConnection` in readme.
 Add default value for `.Values.agent.directConnection` to `values.yaml`
 
 ## 4.3.8
@@ -404,7 +1493,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.375.3
 
-
 ## 4.3.3
 
 Removed hardcoding of chart version in tests to make maintenance easier
@@ -414,7 +1502,6 @@
 Added `.Values.serviceAccount.extraLabels` on Service Account
 Added `.Values.serviceAccountAgent.extraLabels` on Agent's Service Account
 
-
 ## 4.3.0
 
 Moved use of `.Values.containerEnv` within `jenkins` Container to top of `env` block to allow for subsequent Environment Variables to reference these additional ones.
@@ -423,7 +1510,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.375.2
 
-
 ## 4.2.20
 
 Fixed the `controller.prometheus.metricRelabelings` being unable to convert the value to the ServiceMonitor.
@@ -442,7 +1528,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.375.1
 
-
 ## 4.2.16
 
 Fixed chart notes not rendering Jenkins URL with prefix when `controller.jenkinsUriPrefix` is set.
@@ -465,43 +1550,49 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.361.3
 
-
 ## 4.2.11
 
 Update default plugin versions
 
-| plugin                | old version           | new version            |
-|-----------------------|-----------------------|------------------------|
-| kubernetes            | 3706.vdfb_d599579f3   | 3734.v562b_b_a_627ea_c |
-| git                   | 4.11.5                | 4.13.0                 |
-| configuration-as-code | 1512.vb_79d418d5fc8   | 1569.vb_72405b_80249   |
+| plugin                | old version         | new version            |
+| --------------------- | ------------------- | ---------------------- |
+| kubernetes            | 3706.vdfb_d599579f3 | 3734.v562b_b_a_627ea_c |
+| git                   | 4.11.5              | 4.13.0                 |
+| configuration-as-code | 1512.vb_79d418d5fc8 | 1569.vb_72405b_80249   |
 
 ## 4.2.10
+
 Fix grammar and typos
 
 ## 4.2.9
+
 Update Jenkins image and appVersion to jenkins lts release version 2.361.2
 
 ## 4.2.8
+
 Modify the condition to trigger copying jenkins_config files when configAutoReload option is disabled during Jenkins initialization
 
 ## 4.2.7
+
 Support for remote URL for configuration
 
 ## 4.2.6
+
 Add option to set hostnetwork for agents
 
 ## 4.2.5
+
 Add an extra optional argument to extraPorts in order to specify targetPort
 
 ## 4.2.4
+
 Remove k8s capibility requirements when setting priority class for controller
 
 ## 4.2.3 Update plugin versions
 
 | plugin                | old version           | new version           |
 | --------------------- | --------------------- | --------------------- |
-| kubernetes            | 3600.v144b_cd192ca_a_ | 3706.vdfb_d599579f3   |
+| kubernetes            | 3600.v144b*cd192ca_a* | 3706.vdfb_d599579f3   |
 | workflow-aggregator   | 581.v0c46fa_697ffd    | 590.v6a_d052e5a_a_b_5 |
 | configuration-as-code | 1429.v09b_044a_c93de  | 1512.vb_79d418d5fc8   |
 | git                   | 4.11.3                | 4.11.5                |
@@ -525,17 +1616,14 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.361.1
 
-
 ## 4.1.17
 
 Update Jenkins casc default settings to allow `security` configs to be provided
 
-
 ## 4.1.16
 
 Update Jenkins image and appVersion to jenkins lts release version 2.346.3
 
-
 ## 4.1.15
 
 `projectNamingStrategy` is configurable in default config.
@@ -548,7 +1636,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.346.2
 
-
 ## 4.1.12
 
 If keystore is defined, it is now also made available in the initContainer.
@@ -561,7 +1648,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.346.1
 
-
 ## 4.1.9
 
 Allow setting `imagePullSecret` for backup job via `backup.imagePullSecretName`
@@ -572,7 +1658,7 @@
 
 ## 4.1.7
 
-Update README with explanation on the required environmental variable `AWS_REGION` in case of using an S3 bucket.
+Update readme with explanation on the required environmental variable `AWS_REGION` in case of using an S3 bucket.
 
 ## 4.1.6
 
@@ -580,15 +1666,18 @@
 
 ## 4.1.5
 
-Update README to fix `JAVA_OPTS` name.
+Update readme to fix `JAVA_OPTS` name.
 
 ## 4.1.4
+
 Update plugins
 
 ## 4.1.3
+
 Update jenkins-controller-statefulset projected volumes definition
 
 ## 4.1.1
+
 Added 'controller.prometheus.metricRelabelings' to allow relabling and dropping unused prometheus metrics
 
 ## 4.1.0
@@ -621,9 +1710,9 @@
 
 ## 3.11.9 Bump configuration-as-code plugin version
 
-| plugin                | old version | new version |
-| --------------------- | ----------- | ----------- |
-| configuration-as-code | 1.51        | 1414.v878271fc496f        |
+| plugin                | old version | new version        |
+| --------------------- | ----------- | ------------------ |
+| configuration-as-code | 1.51        | 1414.v878271fc496f |
 
 ## 3.11.8
 
@@ -637,7 +1726,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.332.1
 
-
 ## 3.11.5
 
 Change Backup Role name function call to match the RoleDef function call in the Backup RoleBinding
@@ -646,7 +1734,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.319.3
 
-
 ## 3.11.3
 
 Update kiwigrid/k8s-sidecar:1.15.0
@@ -660,21 +1747,19 @@
 
 Update configuration-as-code plugin to 1.55.1
 
-
 ## 3.11.0
 
 Update default plugin versions
 
-| plugin                | old version | new version |
-| --------------------- | ----------- | ----------- |
-| kubernetes            | 1.31.1      | 1.31.3      |
-| git                   | 4.10.1      | 4.10.2      |
+| plugin     | old version | new version |
+| ---------- | ----------- | ----------- |
+| kubernetes | 1.31.1      | 1.31.3      |
+| git        | 4.10.1      | 4.10.2      |
 
 ## 3.10.3
 
 Update Jenkins image and appVersion to jenkins lts release version 2.319.2
 
-
 ## 3.10.2
 
 Fix definition of startupProbe when deploying on a Kubernetes cluster < 1.16
@@ -695,7 +1780,7 @@
 
 ## 3.9.4
 
-Add JAVA_OPTIONS to the README so proxy settings get picked by jenkins-plugin-cli
+Add JAVA_OPTIONS to the readme so proxy settings get picked by jenkins-plugin-cli
 
 ## 3.9.3
 
@@ -706,9 +1791,9 @@
 Update Jenkins image and appVersion to jenkins lts release version 2.319.1
 Update following plugins:
 
-* kubernetes:1.30.11
-* git:4.10.0
-* configuration-as-code:1.54
+- kubernetes:1.30.11
+- git:4.10.0
+- configuration-as-code:1.54
 
 ## 3.9.1
 
@@ -774,33 +1859,39 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.303.2
 
-
 ## 3.6.0
+
 Support custom agent pod labels
 
 ## 3.5.20
+
 Disallow ingress on port 50000 when agent listener is disabled
 
 ## 3.5.19
+
 Add support for specifying termination-log behaviour for Jenkins controller
 
 ## 3.5.18
+
 Add support for creating a Pod Disruption Budget for Jenkins controller
 
 ## 3.5.17
+
 Update workdingDir to `/home/jenkins/agent`
 
 ## 3.5.16
+
 Update location of icon (wiki.jenkins.io is down)
 
 ## 3.5.15
+
 Add support for adding labels to the Jenkins home Persistent Volume Claim (pvc)
 
 ## 3.5.14
 
-* Updated versions of default plugins
-* Use verbose logging during plugin installation
-* download the latest version of all plugin dependencies (Fixes #442)
+- Updated versions of default plugins
+- Use verbose logging during plugin installation
+- download the latest version of all plugin dependencies (Fixes #442)
 
 ## 3.5.13
 
@@ -822,7 +1913,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.289.3
 
-
 ## 3.5.8
 
 Add parameter `backup.serviceAccount.create` to disable service account creation for backup service and `backup.serviceAccount.name` to allow change of the SA name.
@@ -853,6 +1943,7 @@
 Enable setting `controller.installLatestSpecifiedPlugins` to set whether to download the latest dependencies of any plugin that is requested to have the latest version.
 
 ## 3.5.1
+
 Fix activeDeadlineSeconds wrong type bug in jenkins-backup-cronjob template
 
 ## 3.5.0
@@ -876,43 +1967,56 @@
 Update Jenkins image and appVersion to jenkins lts release version 2.289.1
 
 ## 3.3.21
+
 `persistence.mounts` additionally mount to init container to allow custom CA certificate keystore
 
 ## 3.3.18
+
 Added `controller.overrideArgs` so any cli argument can be passed to the WAR.
 
 ## 3.3.17
+
 Correct docs on disabling plugin installation
 
 ## 3.3.16
+
 Support generating `SecretClaim` resources in order to read secrets from HashiCorp Vault into Kubernetes using `kube-vault-controller`.
 
 ## 3.3.15
+
 Prevent `controller.httpsKeyStore` from improperly being quoted, leading to an invalid location on disk
 
 ## 3.3.14
+
 Correct docs on disabling plugin installation
 
 ## 3.3.13
+
 Update plugins
 
 ## 3.3.12
+
 Add `controller.additionalExistingSecrets` property
 
 ## 3.3.11
+
 Add support for disabling the Agent listener service via `controller.agentListenerEnabled`.
 
 ## 3.3.10
+
 Update Jenkins image and appVersion to jenkins lts release version 2.277.4
 
 ## 3.3.9
-* Change helper template so user defined `agent.jenkinsUrl` value will always be used, if set
-* Simplify logic for `jenkinsUrl` and `jenkinsTunnel` generation: always use fully qualified address
+
+- Change helper template so user defined `agent.jenkinsUrl` value will always be used, if set
+- Simplify logic for `jenkinsUrl` and `jenkinsTunnel` generation: always use fully qualified address
 
 ## 3.3.8
+
 Update Jenkins image and appVersion to jenkins lts release version 2.277.3
 
 ## 3.3.7
+
 fix controller-ingress line feed bug
 
 ## 3.3.6
@@ -928,7 +2032,6 @@
 
 Update Jenkins image and appVersion to jenkins lts release version 2.277.2
 
-
 ## 3.3.3
 
 Enable setting `controller.installLatestPlugins` to set whether to download the minimum required version of all dependencies.
@@ -954,6 +2057,7 @@
 Add additional metadata `artifacthub.io/images` for artifacthub
 
 ## 3.2.4
+
 Update Jenkins image and appVersion to jenkins lts release version 2.277.1
 Update Git plugin version to v4.6.0
 Update kubernetes plugin version to v1.29.2
@@ -988,7 +2092,7 @@
 
 ## 3.1.12
 
-Added GitHub action to automate the updating of LTS releases.
+Added GitHub Action to automate the updating of LTS releases.
 
 ## 3.1.11
 
@@ -1036,8 +2140,8 @@
 
 ## 3.1.0
 
-* Added `.Values.controller.podSecurityContextOverride` and `.Values.backup.podSecurityContextOverride`.
-* Added simple default values tests for `jenkins-backup-cronjob.yaml`.
+- Added `.Values.controller.podSecurityContextOverride` and `.Values.backup.podSecurityContextOverride`.
+- Added simple default values tests for `jenkins-backup-cronjob.yaml`.
 
 ## 3.0.14
 
@@ -1065,11 +2169,11 @@
 
 ## 3.0.8
 
-* Typo in documentation
+- Typo in documentation
 
 ## 3.0.7
 
-* Add support for setting default agent workspaceVolume
+- Add support for setting default agent workspaceVolume
 
 ## 3.0.6
 
@@ -1077,47 +2181,47 @@
 
 ## 3.0.5
 
-* Update appVersion to reflect new jenkins lts release version 2.263.1
+- Update appVersion to reflect new jenkins lts release version 2.263.1
 
 ## 3.0.4
 
-* Fix documentation for additional secret mounts
+- Fix documentation for additional secret mounts
 
 ## 3.0.3
 
-* Update `README.md` with explanation on how to mount additional secrets
+- Update `README.md` with explanation on how to mount additional secrets
 
 ## 3.0.2
 
-* Fix `.Values.controller.tolerations` and `.Values.controller.nodeSelector` variable names in templates\jenkins-backup-cronjob.yaml
+- Fix `.Values.controller.tolerations` and `.Values.controller.nodeSelector` variable names in templates\jenkins-backup-cronjob.yaml
 
 ## 3.0.1
 
-* added 'runAsNonroot' to security context
+- added 'runAsNonroot' to security context
 
 ## 3.0.0
 
-* Chart uses StatefulSet instead of Deployment
-* XML configuration was removed in favor of JCasC
-* chart migrated to helm 3.0.0 (apiVersion v2)
-* offending terms have been removed
-* values have been renamed and re-ordered to make it easier to use
-* already deprecated items have been removed
-* componentName for the controller is now `jenkins-controller`
-* componentName for the agent is now `jenkins-agent`
-* container names are now
-  * `init` for the init container which downloads Jenkins plugins
-  * `jenkins` for the Jenkins controller
-  * `config-reload` for the sidecar container which automatically reloads JCasC
-* Updated UI tests to use official `bats/bats` image instead of `dduportal/bats`
+- Chart uses StatefulSet instead of Deployment
+- XML configuration was removed in favor of JCasC
+- chart migrated to helm 3.0.0 (apiVersion v2)
+- offending terms have been removed
+- values have been renamed and re-ordered to make it easier to use
+- already deprecated items have been removed
+- componentName for the controller is now `jenkins-controller`
+- componentName for the agent is now `jenkins-agent`
+- container names are now
+  - `init` for the init container which downloads Jenkins plugins
+  - `jenkins` for the Jenkins controller
+  - `config-reload` for the sidecar container which automatically reloads JCasC
+- Updated UI tests to use official `bats/bats` image instead of `dduportal/bats`
 
 For migration instructions from previous versions and additional information check README.md.
 
 ## 2.19.0
 
-* Use lts version 2.249.3
-* Update kubernetes, workflow-aggregator, git and configuration-as-code plugins.
-* Fail apply_config.sh script if an error occurs.
+- Use lts version 2.249.3
+- Update kubernetes, workflow-aggregator, git and configuration-as-code plugins.
+- Fail apply_config.sh script if an error occurs.
 
 ## 2.18.2
 
@@ -1192,7 +2296,7 @@
 
 ## 2.12.1
 
-Helm chart README update
+Helm chart readme update
 
 ## 2.12.0
 
@@ -1254,7 +2358,7 @@
 
 ## 2.6.0 First release in jenkinsci GitHub org
 
-Updated README for new location
+Updated readme for new location
 
 ## 2.5.2
 
@@ -1270,7 +2374,7 @@
 
 ## 2.4.1
 
-Reorder README parameters into sections to facilitate chart usage and maintenance
+Reorder readme parameters into sections to facilitate chart usage and maintenance
 
 ## 2.4.0 Update default agent image
 
@@ -1304,7 +2408,7 @@
 
 Value can be configured via `master.sidecars.configAutoReload.reqRetryConnect`
 
-## 2.1.2 updated README
+## 2.1.2 updated readme
 
 ## 2.1.1 update credentials-binding plugin to 1.23
 
@@ -1318,7 +2422,7 @@
 
 ## 2.0.0 Configuration as Code now default + container does not run as root anymore
 
-The README contains more details for this update.
+The readme contains more details for this update.
 Please note that the updated values contain breaking changes.
 
 ## 1.27.0 Update plugin versions & sidecar container
@@ -1483,7 +2587,7 @@
 
 ## 1.9.24
 
-Update JCasC auto-reload docs and remove stale ssh key references from version "1.8.0 JCasC auto reload works without ssh keys"
+Update JCasC auto-reload docs and remove stale SSH key references from version "1.8.0 JCasC auto reload works without SSH keys"
 
 ## 1.9.23 Support jenkinsUriPrefix when JCasC is enabled
 
@@ -1491,7 +2595,7 @@
 
 ## 1.9.22
 
-Add `master.jenkinsHome` and `master.jenkinsRef` options to use docker images derivates from Jenkins
+Add `master.jenkinsHome` and `master.jenkinsRef` options to use Docker images derivates from Jenkins
 
 ## 1.9.21
 
@@ -1517,7 +2621,7 @@
 Make `jenkins-home` attachable to Azure Disks without pvc
 
 ```yaml
- volumes:
+volumes:
   - name: jenkins-home
     azureDisk:
       kind: Managed
@@ -1546,6 +2650,7 @@
 Added documentation for `persistence.storageClass`.
 
 ## 1.9.9
+
 Make `master.deploymentAnnotation` configurable.
 
 ## 1.9.8
@@ -1555,7 +2660,7 @@
 ## 1.9.7 Update plugin versions
 
 | plugin                | old version | new version |
-|-----------------------|-------------|-------------|
+| --------------------- | ----------- | ----------- |
 | kubernetes            | 1.18.2      | 1.21.2      |
 | workflow-job          | 2.33        | 2.36        |
 | credentials-binding   | 1.19        | 1.20        |
@@ -1564,7 +2669,7 @@
 
 ## 1.9.6
 
-Enables jenkins to use keystore inorder to have native ssl support #17790 <https://wiki.jenkins.io/pages/viewpage.action?pageId=135468777>
+Enables jenkins to use keystore inorder to have native SSL support #17790 <https://wiki.jenkins.io/pages/viewpage.action?pageId=135468777>
 
 ## 1.9.5 Enable remoting security
 
@@ -1575,9 +2680,9 @@
 Google application credentials are kept in a file, which has to be mounted to a pod. You can set `gcpcredentials` in `existingSecret` as follows:
 
 ```yaml
- existingSecret:
-    jenkins-service-account:
-      gcpcredentials: application_default_credentials.json
+existingSecret:
+  jenkins-service-account:
+    gcpcredentials: application_default_credentials.json
 ```
 
 Helm template then creates the necessary volume mounts and `GOOGLE_APPLICATION_CREDENTIALS` environmental variable.
@@ -1608,7 +2713,7 @@
 
 Add `master.schedulerName` to allow setting a Kubernetes custom scheduler
 
-## 1.8.0 JCasC auto reload works without ssh keys
+## 1.8.0 JCasC auto reload works without SSH keys
 
 We make use of the fact that the Jenkins Configuration as Code Plugin can be triggered via http `POST` to `JENKINS_URL/configuration-as-code/reload`and a pre-shared key.
 The sidecar container responsible for reloading config changes is now `kiwigrid/k8s-sidecar:0.1.20` instead of it's fork `shadwell/k8s-sidecar`.
@@ -1815,7 +2920,7 @@
 
 ## 1.4.0
 
-Change the value name for docker image tags - standartise to helm preferred value name - tag; this also allows auto-deployments using weaveworks flux (#15565)
+Change the value name for Docker image tags - standartise to helm preferred value name - tag; this also allows auto-deployments using weaveworks flux (#15565)
 commit: 5c3d920e7
 
 ## 1.3.6
@@ -1996,7 +3101,7 @@
 ### Breaking changes
 
 - values have been renamed to follow helm chart best practices for naming conventions so
-  that all variables start with a lowercase letter and words are separated with camelcase
+  that all variables start with a lowercase letter and words are separated with camelCase
   <https://helm.sh/docs/chart_best_practices/#naming-conventions>
 - all resources are now using recommended standard labels
   <https://helm.sh/docs/chart_best_practices/#standard-labels>
@@ -2136,7 +3241,7 @@
 
 ## 0.32.7
 
-Fix Markdown syntax in README (#11496)
+Fix Markdown syntax in readme (#11496)
 commit: a32221a95
 
 ## 0.32.6
@@ -2246,7 +3351,7 @@
 
 ## 0.28.3
 
-fix parsing java options (#10140)
+fix parsing Java options (#10140)
 commit: 9448d0293
 
 ## 0.28.2
@@ -2366,7 +3471,7 @@
 
 ## 0.16.22
 
-avoid lint errors when adding Values.Ingress.Annotations (#7425)
+avoid linting errors when adding Values.Ingress.Annotations (#7425)
 commit: 99eacc854
 
 ## 0.16.21
@@ -2391,7 +3496,7 @@
 
 ## 0.16.17
 
-Add Master.AdminPassword in README (#6987)
+Add Master.AdminPassword in readme (#6987)
 commit: 13e754ad7
 
 ## 0.16.16
@@ -2461,7 +3566,7 @@
 
 ## 0.16.1
 
-fix typo in jenkins README (#5228)
+fix typo in jenkins readme (#5228)
 commit: 3cd3f4b8b
 
 ## 0.16.0
@@ -2582,7 +3687,7 @@
 Double retry count for Jenkins test
 commit: 129c8e824
 
-Jenkins: Update README | Master.ServiceAnnotations (#2757)
+Jenkins: Update readme | Master.ServiceAnnotations (#2757)
 commit: 6571810bc
 
 ## 0.10.0
@@ -2654,7 +3759,7 @@
 
 ## 0.8.4
 
-Add support for supplying JENKINS_OPTS and/or uri prefix (#1405)
+Add support for supplying JENKINS_OPTS and/or URI prefix (#1405)
 commit: 6a331901a
 
 ## 0.8.3
@@ -2864,7 +3969,7 @@
 Remove 'Getting Started:' from various NOTES.txt. (#181)
 commit: 2f63fd524
 
-docs(\*): update READMEs to reference chart repos (#119)
+docs(\*): update readmes to reference chart repos (#119)
 commit: c7d1bff05
 
 ## 0.1.0
diff --git a/charts/jenkins/Chart.yaml b/charts/jenkins/Chart.yaml
index 2a42c71..0b64f7f 100644
--- a/charts/jenkins/Chart.yaml
+++ b/charts/jenkins/Chart.yaml
@@ -1,14 +1,14 @@
 annotations:
   artifacthub.io/category: integration-delivery
   artifacthub.io/changes: |
-    - Fix Prometheus controller name.
+    - Evaluate `tpl` on `agent.image.registry`, `agent.image.repository`, and `agent.image.tag` so the default kubernetes-agent pod template can compose its jnlp image from other Helm values or named templates. Complements the `tpl`-support added for `controller.javaOpts` / `controller.jenkinsOpts` in 5.9.39.
   artifacthub.io/images: |
     - name: jenkins
-      image: docker.io/jenkins/jenkins:2.440.2-jdk17
+      image: docker.io/jenkins/jenkins:2.568.1-jdk21
     - name: k8s-sidecar
-      image: docker.io/kiwigrid/k8s-sidecar:1.26.1
+      image: docker.io/kiwigrid/k8s-sidecar:2.8.1
     - name: inbound-agent
-      image: jenkins/inbound-agent:3206.vb_15dcf73f6a_9-3
+      image: jenkins/inbound-agent:3383.vc8881d4b_0e76-1
   artifacthub.io/license: Apache-2.0
   artifacthub.io/links: |
     - name: Chart Source
@@ -18,9 +18,9 @@
     - name: support
       url: https://github.com/jenkinsci/helm-charts/issues
 apiVersion: v2
-appVersion: 2.440.2
+appVersion: 2.568.1
 description: 'Jenkins - Build great things at any scale! As the leading open source
-  automation server, Jenkins provides over 1800 plugins to support building, deploying
+  automation server, Jenkins provides over 2000 plugins to support building, deploying
   and automating any project. '
 home: https://www.jenkins.io/
 icon: https://get.jenkins.io/art/jenkins-logo/logo.svg
@@ -42,8 +42,8 @@
 name: jenkins
 sources:
 - https://github.com/jenkinsci/jenkins
-- https://github.com/jenkinsci/docker-inbound-agent
+- https://github.com/jenkinsci/docker-agent
 - https://github.com/maorfr/kube-tasks
 - https://github.com/jenkinsci/configuration-as-code-plugin
 type: application
-version: 5.1.5
+version: 5.9.40
diff --git a/charts/jenkins/README.md b/charts/jenkins/README.md
index 4ddd1fa..b54c28b 100644
--- a/charts/jenkins/README.md
+++ b/charts/jenkins/README.md
@@ -5,7 +5,7 @@
 [![Releases downloads](https://img.shields.io/github/downloads/jenkinsci/helm-charts/total.svg)](https://github.com/jenkinsci/helm-charts/releases)
 [![Join the chat at https://app.gitter.im/#/room/#jenkins-ci:matrix.org](https://badges.gitter.im/badge.svg)](https://app.gitter.im/#/room/#jenkins-ci:matrix.org)
 
-[Jenkins](https://www.jenkins.io/) is the leading open source automation server, Jenkins provides over 1800 plugins to support building, deploying and automating any project.
+[Jenkins](https://www.jenkins.io/) is the leading open source automation server, Jenkins provides over 2000 plugins to support building, deploying and automating any project.
 
 This chart installs a Jenkins server which spawns agents on [Kubernetes](http://kubernetes.io) utilizing the [Jenkins Kubernetes plugin](https://plugins.jenkins.io/kubernetes/).
 
@@ -23,8 +23,13 @@
 ## Install Chart
 
 ```console
-# Helm 3
-$ helm install [RELEASE_NAME] jenkins/jenkins [flags]
+helm install [RELEASE_NAME] jenkins/jenkins [flags]
+```
+
+Since version `5.6.0` the chart is available as an OCI image and can be installed using:
+
+```console
+helm install [RELEASE_NAME] oci://ghcr.io/jenkinsci/helm-charts/jenkins [flags]
 ```
 
 _See [configuration](#configuration) below._
@@ -70,7 +75,7 @@
 $ helm show values jenkins/jenkins
 ```
 
-For a summary of all configurable options, see [VALUES_SUMMARY.md](https://github.com/jenkinsci/helm-charts/blob/main/charts/jenkins/VALUES_SUMMARY.md).
+For a summary of all configurable options, see [VALUES.md](https://github.com/jenkinsci/helm-charts/blob/main/charts/jenkins/VALUES.md).
 
 ### Configure Security Realm and Authorization Strategy
 
@@ -103,7 +108,7 @@
 This chart allows the user to specify plugins which should be installed. However, for production use cases one should consider to build a custom Jenkins image which has all required plugins pre-installed.
 This way you can be sure which plugins Jenkins is using when starting up and you avoid trouble in case of connectivity issues to the Jenkins update site.
 
-The [docker repository](https://github.com/jenkinsci/docker) for the Jenkins image contains [documentation](https://github.com/jenkinsci/docker#preinstalling-plugins) how to do it.
+The [Docker repository](https://github.com/jenkinsci/docker) for the Jenkins image contains [documentation](https://github.com/jenkinsci/docker#preinstalling-plugins) how to do it.
 
 Here is an example how that can be done:
 
@@ -218,12 +223,12 @@
   jenkinsAdminEmail: example@mail.com
 ```
 
-Further JCasC examples can be found [here](https://github.com/jenkinsci/configuration-as-code-plugin/tree/master/demos).
+Further JCasC examples can be found in the [configuration-as-code repository](https://github.com/jenkinsci/configuration-as-code-plugin/tree/master/demos).
 
 #### Breaking out large Config as Code scripts
 
-Jenkins Config as Code scripts can become quite large, and maintaining all of your scripts within one yaml file can be difficult.  The Config as Code plugin itself suggests updating the `CASC_JENKINS_CONFIG` environment variable to be a comma separated list of paths for the plugin to traverse, picking up the yaml files as needed.  
-However, under the Jenkins helm chart, this `CASC_JENKINS_CONFIG` value is maintained through the templates.  A better solution is to split your `controller.JCasC.configScripts` into separate values files, and provide each file during the helm install.
+Jenkins Config as Code scripts can become quite large, and maintaining all of your scripts within one yaml file can be difficult. The Config as Code plugin itself suggests updating the `CASC_JENKINS_CONFIG` environment variable to be a comma separated list of paths for the plugin to traverse, picking up the yaml files as needed.  
+However, under the Jenkins helm chart, this `CASC_JENKINS_CONFIG` value is maintained through the templates. A better solution is to split your `controller.JCasC.configScripts` into separate values files, and provide each file during the helm install.
 
 For example, you can have a values file (e.g values_main.yaml) that defines the values described in the `VALUES_SUMMARY.md` for your Jenkins configuration:
 
@@ -242,7 +247,7 @@
   controller:
     JCasC:
       configScripts:
-        jenkinsCasc:  |
+        jenkinsCasc: |
           jenkins:
             disableRememberMe: false
             mode: NORMAL
@@ -263,7 +268,7 @@
             ...
 ```
 
-When installing, you provide all relevant yaml files (e.g `helm install -f values_main.yaml -f values_jenkins_casc.yaml -f values_jenkins_unclassified.yaml ...`).  Instead of updating the `CASC_JENKINS_CONFIG` environment variable to include multiple paths, multiple CasC yaml files will be created in the same path `var/jenkins_home/casc_configs`.
+When installing, you provide all relevant yaml files (e.g `helm install -f values_main.yaml -f values_jenkins_casc.yaml -f values_jenkins_unclassified.yaml ...`). Instead of updating the `CASC_JENKINS_CONFIG` environment variable to include multiple paths, multiple CasC yaml files will be created in the same path `var/jenkins_home/casc_configs`.
 
 #### Config as Code With or Without Auto-Reload
 
@@ -290,27 +295,36 @@
 This plugin is **not** installed by default but may be added to `controller.additionalPlugins`.
 
 ### Change max connections to Kubernetes API
+
 When using agents with containers other than JNLP, The kubernetes plugin will communicate with those containers using the Kubernetes API. this changes the maximum concurrent connections
+
 ```yaml
 agent:
   maxRequestsPerHostStr: "32"
 ```
+
 This will change the configuration of the kubernetes "cloud" (as called by jenkins) that is created automatically as part of this helm chart.
 
 ### Change container cleanup timeout API
+
 For tasks that use very large images, this timeout can be increased to avoid early termination of the task while the Kubernetes pod is still deploying.
+
 ```yaml
 agent:
   retentionTimeout: "32"
 ```
+
 This will change the configuration of the kubernetes "cloud" (as called by jenkins) that is created automatically as part of this helm chart.
 
 ### Change seconds to wait for pod to be running
+
 This will change how long Jenkins will wait (seconds) for pod to be in running state.
+
 ```yaml
 agent:
   waitForPodSec: "32"
 ```
+
 This will change the configuration of the kubernetes "cloud" (as called by jenkins) that is created automatically as part of this helm chart.
 
 ### Mounting Volumes into Agent Pods
@@ -320,9 +334,9 @@
 ```yaml
 agent:
   volumes:
-  - type: Secret
-    secretName: jenkins-mysecrets
-    mountPath: /var/run/secrets/jenkins-mysecrets
+    - type: Secret
+      secretName: jenkins-mysecrets
+      mountPath: /var/run/secrets/jenkins-mysecrets
 ```
 
 The supported volume types are: `ConfigMap`, `EmptyDir`, `HostPath`, `Nfs`, `PVC`, `Secret`.
@@ -375,11 +389,11 @@
 2. Create the PersistentVolumeClaim
 3. [Install](#install-chart) the chart, setting `persistence.existingClaim` to `PVC_NAME`
 
-#### Long Volume Attach/Mount Times
+#### Long Volume Attach-/Mount Times
 
 Certain volume type and filesystem format combinations may experience long
 attach/mount times, [10 or more minutes][K8S_VOLUME_TIMEOUT], when using
-`fsGroup`.  This issue may result in the following entries in the pod's event
+`fsGroup`. This issue may result in the following entries in the pod's event
 history:
 
 ```console
@@ -387,7 +401,7 @@
 ```
 
 In these cases, experiment with replacing `fsGroup` with
-`supplementalGroups` in the pod's `securityContext`.  This can be achieved by
+`supplementalGroups` in the pod's `securityContext`. This can be achieved by
 setting the `controller.podSecurityContextOverride` Helm chart value to
 something like:
 
@@ -419,6 +433,7 @@
 The secret may then be referenced in JCasC configuration (see [JCasC configuration](#configuration-as-code)).
 
 `values.yaml` controller section, referencing mounted secrets:
+
 ```yaml
 controller:
   # the 'name' and 'keyName' are concatenated with a '-' in between, so for example:
@@ -428,7 +443,7 @@
   # existingSecret existing secret "secret-credentials" and a key inside it named "github-username" should be used in Jcasc as ${github-username}
   # When using existingSecret no need to specify the keyName under additionalExistingSecrets.
   existingSecret: secret-credentials
-  
+
   additionalExistingSecrets:
     - name: secret-credentials
       keyName: github-username
@@ -436,7 +451,7 @@
       keyName: github-password
     - name: secret-credentials
       keyName: token
-  
+
   additionalSecrets:
     - name: client_id
       value: abc123
@@ -476,6 +491,7 @@
 These `Secrets` can then be referenced in the same manner as Additional Secrets above.
 
 This can be achieved by defining required Secret Claims within `controller.secretClaims`, as follows:
+
 ```yaml
 controller:
   secretClaims:
@@ -569,11 +585,11 @@
 
 ```yaml
 controller:
-   ingress:
-       enabled: true
-       paths: []
-       apiVersion: "extensions/v1beta1"
-       hostName: jenkins.example.com
+  ingress:
+    enabled: true
+    paths: []
+    apiVersion: "extensions/v1beta1"
+    hostName: jenkins.example.com
 ```
 
 This snippet configures an ingress rule for exposing jenkins at `jenkins.example.com`
@@ -588,20 +604,20 @@
 
 ```yaml
 controller:
-   ingress:
-       enabled: true
-       apiVersion: "extensions/v1beta1"
-       hostName: "jenkins.internal.example.com"
-       annotations:
-           kubernetes.io/ingress.class: "internal"
-   secondaryingress:
-       enabled: true
-       apiVersion: "extensions/v1beta1"
-       hostName: "jenkins-scm.example.com"
-       annotations:
-           kubernetes.io/ingress.class: "public"
-       paths:
-        - /github-webhook
+  ingress:
+    enabled: true
+    apiVersion: "extensions/v1beta1"
+    hostName: "jenkins.internal.example.com"
+    annotations:
+      kubernetes.io/ingress.class: "internal"
+  secondaryingress:
+    enabled: true
+    apiVersion: "extensions/v1beta1"
+    hostName: "jenkins-scm.example.com"
+    annotations:
+      kubernetes.io/ingress.class: "public"
+    paths:
+      - /github-webhook
 ```
 
 ## Prometheus Metrics
@@ -655,15 +671,16 @@
 
 ```yaml
 controller:
-   httpsKeyStore:
-       enable: true
-       jenkinsHttpsJksSecretName: ''
-       httpPort: 8081
-       path: "/var/jenkins_keystore"
-       fileName: "keystore.jks"
-       password: "changeit"
-       jenkinsKeyStoreBase64Encoded: ''
+  httpsKeyStore:
+    enable: true
+    jenkinsHttpsJksSecretName: ""
+    httpPort: 8081
+    path: "/var/jenkins_keystore"
+    fileName: "keystore.jks"
+    password: "changeit"
+    jenkinsKeyStoreBase64Encoded: ""
 ```
+
 ### AWS Security Group Policies
 
 To create SecurityGroupPolicies set `awsSecurityGroupPolicies.enabled` to true and add your policies. Each policy requires a `name`, array of `securityGroupIds` and a `podSelector`. Example:
@@ -673,7 +690,7 @@
   enabled: true
   policies:
     - name: "jenkins-controller"
-      securityGroupIds: 
+      securityGroupIds:
         - sg-123456789
       podSelector:
         matchExpressions:
diff --git a/charts/jenkins/UPGRADING.md b/charts/jenkins/UPGRADING.md
index 41e424d..8175d7d 100644
--- a/charts/jenkins/UPGRADING.md
+++ b/charts/jenkins/UPGRADING.md
@@ -1,6 +1,7 @@
 # Upgrade Notes
 
 ## To 5.0.0
+
 - `controller.image`, `controller.tag`, and `controller.tagLabel` have been removed. If you want to overwrite the image you now need to configure any or all of:
   - `controller.image.registry`
   - `controller.image.repository`
@@ -31,38 +32,38 @@
 - `backup.*` was unmaintained and has thus been removed. See the following page for alternatives: [Kubernetes Backup and Migrations](https://nubenetes.com/kubernetes-backup-migrations/).
 
 ## To 4.0.0
+
 Removes automatic `remotingSecurity` setting when using a container tag older than `2.326` (introduced in [`3.11.7`](./CHANGELOG.md#3117)). If you're using a version older than `2.326`, you should explicitly set `.controller.legacyRemotingSecurityEnabled` to `true`.
 
 ## To 3.0.0
 
-* Check `securityRealm` and `authorizationStrategy` and adjust it.
+- Check `securityRealm` and `authorizationStrategy` and adjust it.
   Otherwise, your configured users and permissions will be overridden.
-* You need to use helm version 3 as the `Chart.yaml` uses `apiVersion: v2`.
-* All XML configuration options have been removed.
+- You need to use helm version 3 as the `Chart.yaml` uses `apiVersion: v2`.
+- All XML configuration options have been removed.
   In case those are still in use you need to migrate to configuration as code.
   Upgrade guide to 2.0.0 contains pointers how to do that.
-* Jenkins is now using a `StatefulSet` instead of a `Deployment`
-* terminology has been adjusted that's also reflected in values.yaml
+- Jenkins is now using a `StatefulSet` instead of a `Deployment`
+- terminology has been adjusted that's also reflected in values.yaml
   The following values from `values.yaml` have been renamed:
+  - `master` => `controller`
+  - `master.useSecurity` => `controller.adminSecret`
+  - `master.slaveListenerPort` => `controller.agentListenerPort`
+  - `master.slaveHostPort` => `controller.agentListenerHostPort`
+  - `master.slaveKubernetesNamespace` => `agent.namespace`
+  - `master.slaveDefaultsProviderTemplate` => `agent.defaultsProviderTemplate`
+  - `master.slaveJenkinsUrl` => `agent.jenkinsUrl`
+  - `master.slaveJenkinsTunnel` => `agent.jenkinsTunnel`
+  - `master.slaveConnectTimeout` => `agent.kubernetesConnectTimeout`
+  - `master.slaveReadTimeout` => `agent.kubernetesReadTimeout`
+  - `master.slaveListenerServiceAnnotations` => `controller.agentListenerServiceAnnotations`
+  - `master.slaveListenerServiceType` => `controller.agentListenerServiceType`
+  - `master.slaveListenerLoadBalancerIP` => `controller.agentListenerLoadBalancerIP`
+  - `agent.slaveConnectTimeout` => `agent.connectTimeout`
 
-  * `master` => `controller`
-  * `master.useSecurity` => `controller.adminSecret`
-  * `master.slaveListenerPort` => `controller.agentListenerPort`
-  * `master.slaveHostPort` => `controller.agentListenerHostPort`
-  * `master.slaveKubernetesNamespace` => `agent.namespace`
-  * `master.slaveDefaultsProviderTemplate` => `agent.defaultsProviderTemplate`
-  * `master.slaveJenkinsUrl` => `agent.jenkinsUrl`
-  * `master.slaveJenkinsTunnel` => `agent.jenkinsTunnel`
-  * `master.slaveConnectTimeout` => `agent.kubernetesConnectTimeout`
-  * `master.slaveReadTimeout` => `agent.kubernetesReadTimeout`
-  * `master.slaveListenerServiceAnnotations` => `controller.agentListenerServiceAnnotations`
-  * `master.slaveListenerServiceType` => `controller.agentListenerServiceType`
-  * `master.slaveListenerLoadBalancerIP` => `controller.agentListenerLoadBalancerIP`
-  * `agent.slaveConnectTimeout` => `agent.connectTimeout`
-* Removed values:
-
-  * `master.imageTag`: use `controller.image` and `controller.tag` instead
-  * `slave.imageTag`: use `agent.image` and `agent.tag` instead
+- Removed values:
+  - `master.imageTag`: use `controller.image` and `controller.tag` instead
+  - `slave.imageTag`: use `agent.image` and `agent.tag` instead
 
 ## To 2.0.0
 
@@ -95,14 +96,14 @@
 
 ```yaml
 controller:
-  runAsUser: 1000         # was unset before
-  fsGroup: 1000           # was unset before
+  runAsUser: 1000 # was unset before
+  fsGroup: 1000 # was unset before
   JCasC:
-    enabled: true         # was false
-    defaultConfig: true   # was false
+    enabled: true # was false
+    defaultConfig: true # was false
   sidecars:
     configAutoReload:
-      enabled: true       # was false
+      enabled: true # was false
 ```
 
 ### Migration steps
@@ -122,7 +123,7 @@
 - Test drive those setting on a separate installation
 - Put Jenkins to Quiet Down mode so that it does not accept new jobs
   `<JENKINS_URL>/quietDown`
-- Change permissions of all files and folders to the new user and group id:
+- Change permissions of all files and folders to the new user and group ID:
 
   ```console
   kubectl exec -it <jenkins_pod> -c jenkins /bin/bash
@@ -135,7 +136,7 @@
 
 Breaking changes:
 
-- Values have been renamed to follow [helm recommended naming conventions](https://helm.sh/docs/chart_best_practices/#naming-conventions) so that all variables start with a lowercase letter and words are separated with camelcase
+- Values have been renamed to follow [helm recommended naming conventions](https://helm.sh/docs/chart_best_practices/#naming-conventions) so that all variables start with a lowercase letter and words are separated with camelCase
 - All resources are now using [helm recommended standard labels](https://helm.sh/docs/chart_best_practices/#standard-labels)
 
 As a result of the label changes also the selectors of the deployment have been updated.
diff --git a/charts/jenkins/VALUES.md b/charts/jenkins/VALUES.md
index a9a4f47..d8da7a7 100644
--- a/charts/jenkins/VALUES.md
+++ b/charts/jenkins/VALUES.md
@@ -8,296 +8,336 @@
 
 | Key | Type | Description | Default |
 |:----|:-----|:---------|:------------|
-| [additionalAgents](./values.yaml#L1138) | object | Configure additional | `{}` |
-| [additionalClouds](./values.yaml#L1163) | object |  | `{}` |
-| [agent.TTYEnabled](./values.yaml#L1058) | bool | Allocate pseudo tty to the side container | `false` |
-| [agent.additionalContainers](./values.yaml#L1091) | list | Add additional containers to the agents | `[]` |
-| [agent.alwaysPullImage](./values.yaml#L951) | bool | Always pull agent container image before build | `false` |
-| [agent.annotations](./values.yaml#L1087) | object | Annotations to apply to the pod | `{}` |
-| [agent.args](./values.yaml#L1052) | string | Arguments passed to command to execute | `"${computer.jnlpmac} ${computer.name}"` |
-| [agent.command](./values.yaml#L1050) | string | Command to execute when side container starts | `nil` |
-| [agent.componentName](./values.yaml#L919) | string |  | `"jenkins-agent"` |
-| [agent.connectTimeout](./values.yaml#L1085) | int | Timeout in seconds for an agent to be online | `100` |
-| [agent.containerCap](./values.yaml#L1060) | int | Max number of agents to launch | `10` |
-| [agent.customJenkinsLabels](./values.yaml#L916) | list | Append Jenkins labels to the agent | `[]` |
-| [agent.defaultsProviderTemplate](./values.yaml#L882) | string | The name of the pod template to use for providing default values | `""` |
-| [agent.directConnection](./values.yaml#L922) | bool |  | `false` |
-| [agent.disableDefaultAgent](./values.yaml#L1109) | bool | Disable the default Jenkins Agent configuration | `false` |
-| [agent.enabled](./values.yaml#L880) | bool | Enable Kubernetes plugin jnlp-agent podTemplate | `true` |
-| [agent.envVars](./values.yaml#L1033) | list | Environment variables for the agent Pod | `[]` |
-| [agent.hostNetworking](./values.yaml#L930) | bool | Enables the agent to use the host network | `false` |
-| [agent.idleMinutes](./values.yaml#L1065) | int | Allows the Pod to remain active for reuse until the configured number of minutes has passed since the last step was executed on it | `0` |
-| [agent.image.repository](./values.yaml#L909) | string | Repository to pull the agent jnlp image from | `"jenkins/inbound-agent"` |
-| [agent.image.tag](./values.yaml#L911) | string | Tag of the image to pull | `"3206.vb_15dcf73f6a_9-3"` |
-| [agent.imagePullSecretName](./values.yaml#L918) | string | Name of the secret to be used to pull the image | `nil` |
-| [agent.jenkinsTunnel](./values.yaml#L890) | string | Overrides the Kubernetes Jenkins tunnel | `nil` |
-| [agent.jenkinsUrl](./values.yaml#L886) | string | Overrides the Kubernetes Jenkins URL | `nil` |
-| [agent.jnlpregistry](./values.yaml#L906) | string | Custom registry used to pull the agent jnlp image from | `nil` |
-| [agent.kubernetesConnectTimeout](./values.yaml#L892) | int | The connection timeout in seconds for connections to Kubernetes API. The minimum value is 5 | `5` |
-| [agent.kubernetesReadTimeout](./values.yaml#L894) | int | The read timeout in seconds for connections to Kubernetes API. The minimum value is 15 | `15` |
-| [agent.livenessProbe](./values.yaml#L941) | object |  | `{}` |
-| [agent.maxRequestsPerHostStr](./values.yaml#L896) | string | The maximum concurrent connections to Kubernetes API | `"32"` |
-| [agent.namespace](./values.yaml#L902) | string | Namespace in which the Kubernetes agents should be launched | `nil` |
-| [agent.nodeSelector](./values.yaml#L1044) | object | Node labels for pod assignment | `{}` |
-| [agent.nodeUsageMode](./values.yaml#L914) | string |  | `"NORMAL"` |
-| [agent.podLabels](./values.yaml#L904) | object | Custom Pod labels (an object with `label-key: label-value` pairs) | `{}` |
-| [agent.podName](./values.yaml#L1062) | string | Agent Pod base name | `"default"` |
-| [agent.podRetention](./values.yaml#L960) | string |  | `"Never"` |
-| [agent.podTemplates](./values.yaml#L1119) | object | Configures extra pod templates for the default kubernetes cloud | `{}` |
-| [agent.privileged](./values.yaml#L924) | bool | Agent privileged container | `false` |
-| [agent.resources](./values.yaml#L932) | object | Resources allocation (Requests and Limits) | `{"limits":{"cpu":"512m","memory":"512Mi"},"requests":{"cpu":"512m","memory":"512Mi"}}` |
-| [agent.restrictedPssSecurityContext](./values.yaml#L957) | bool | Set a restricted securityContext on jnlp containers | `false` |
-| [agent.retentionTimeout](./values.yaml#L898) | int | Time in minutes after which the Kubernetes cloud plugin will clean up an idle worker that has not already terminated | `5` |
-| [agent.runAsGroup](./values.yaml#L928) | string | Configure container group | `nil` |
-| [agent.runAsUser](./values.yaml#L926) | string | Configure container user | `nil` |
-| [agent.secretEnvVars](./values.yaml#L1037) | list | Mount a secret as environment variable | `[]` |
-| [agent.showRawYaml](./values.yaml#L964) | bool |  | `true` |
-| [agent.sideContainerName](./values.yaml#L1054) | string | Side container name | `"jnlp"` |
-| [agent.volumes](./values.yaml#L971) | list | Additional volumes | `[]` |
-| [agent.waitForPodSec](./values.yaml#L900) | int | Seconds to wait for pod to be running | `600` |
-| [agent.websocket](./values.yaml#L921) | bool | Enables agent communication via websockets | `false` |
-| [agent.workingDir](./values.yaml#L913) | string | Configure working directory for default agent | `"/home/jenkins/agent"` |
-| [agent.workspaceVolume](./values.yaml#L1006) | object | Workspace volume (defaults to EmptyDir) | `{}` |
-| [agent.yamlMergeStrategy](./values.yaml#L1083) | string | Defines how the raw yaml field gets merged with yaml definitions from inherited pod templates. Possible values: "merge" or "override" | `"override"` |
-| [agent.yamlTemplate](./values.yaml#L1072) | string | The raw yaml of a Pod API Object to merge into the agent spec | `""` |
-| [awsSecurityGroupPolicies.enabled](./values.yaml#L1289) | bool |  | `false` |
-| [awsSecurityGroupPolicies.policies[0].name](./values.yaml#L1291) | string |  | `""` |
-| [awsSecurityGroupPolicies.policies[0].podSelector](./values.yaml#L1293) | object |  | `{}` |
-| [awsSecurityGroupPolicies.policies[0].securityGroupIds](./values.yaml#L1292) | list |  | `[]` |
-| [checkDeprecation](./values.yaml#L1286) | bool | Checks if any deprecated values are used | `true` |
+| [additionalAgents](./values.yaml#L1262) | object | Configure additional | `{}` |
+| [additionalClouds](./values.yaml#L1287) | object |  | `{}` |
+| [agent.TTYEnabled](./values.yaml#L1167) | bool | Allocate pseudo tty to the side container | `false` |
+| [agent.addMasterProxyEnvVars](./values.yaml#L972) | bool | Add the environment proxy settings form jenkins controller to the agents. | `false` |
+| [agent.additionalContainers](./values.yaml#L1215) | list | Add additional containers to the agents | `[]` |
+| [agent.alwaysPullImage](./values.yaml#L1060) | bool | Always pull agent container image before build | `false` |
+| [agent.annotations](./values.yaml#L1211) | object | Annotations to apply to the pod | `{}` |
+| [agent.args](./values.yaml#L1161) | string | Arguments passed to command to execute | `"${computer.jnlpmac} ${computer.name}"` |
+| [agent.command](./values.yaml#L1159) | string | Command to execute when side container starts | `nil` |
+| [agent.componentName](./values.yaml#L1028) | string |  | `"jenkins-agent"` |
+| [agent.connectTimeout](./values.yaml#L1209) | int | Timeout in seconds for an agent to be online | `100` |
+| [agent.containerCap](./values.yaml#L1169) | int | Max number of agents to launch for a whole cluster. | `10` |
+| [agent.customJenkinsLabels](./values.yaml#L1025) | list | Append Jenkins labels to the agent | `[]` |
+| [agent.defaultsProviderTemplate](./values.yaml#L977) | string | The name of the pod template to use for providing default values | `""` |
+| [agent.directConnection](./values.yaml#L1031) | bool |  | `false` |
+| [agent.disableDefaultAgent](./values.yaml#L1233) | bool | Disable the default Jenkins Agent configuration | `false` |
+| [agent.enabled](./values.yaml#L975) | bool | Enable Kubernetes plugin jnlp-agent podTemplate | `true` |
+| [agent.envVars](./values.yaml#L1142) | list | Environment variables for the agent Pod | `[]` |
+| [agent.garbageCollection.enabled](./values.yaml#L1178) | bool | When enabled, Jenkins will periodically check for orphan pods that have not been touched for the given timeout period and delete them. | `false` |
+| [agent.garbageCollection.namespaces](./values.yaml#L1180) | string | Namespaces to look at for garbage collection, in addition to the default namespace defined for the cloud. One namespace per line. | `""` |
+| [agent.garbageCollection.timeout](./values.yaml#L1185) | int | Timeout value for orphaned pods | `300` |
+| [agent.hostNetworking](./values.yaml#L1039) | bool | Enables the agent to use the host network | `false` |
+| [agent.idleMinutes](./values.yaml#L1188) | int | Allows the Pod to remain active for reuse until the configured number of minutes has passed since the last step was executed on it | `0` |
+| [agent.image.registry](./values.yaml#L1016) | string | Registry to pull the agent jnlp image from | `""` |
+| [agent.image.repository](./values.yaml#L1018) | string | Repository to pull the agent jnlp image from | `"jenkins/inbound-agent"` |
+| [agent.image.tag](./values.yaml#L1020) | string | Tag of the image to pull | `"3383.vc8881d4b_0e76-1"` |
+| [agent.imagePullSecretName](./values.yaml#L1027) | string | Name of the secret to be used to pull the image | `nil` |
+| [agent.inheritYamlMergeStrategy](./values.yaml#L1207) | bool | Controls whether the defined yaml merge strategy will be inherited if another defined pod template is configured to inherit from the current one | `false` |
+| [agent.instanceCap](./values.yaml#L1171) | int | Max number of agents to launch for this type of agent | `2147483647` |
+| [agent.jenkinsTunnel](./values.yaml#L993) | string | Overrides the Kubernetes Jenkins tunnel | `nil` |
+| [agent.jenkinsUrl](./values.yaml#L989) | string | Overrides the Kubernetes Jenkins URL | `nil` |
+| [agent.jnlpregistry](./values.yaml#L1013) | string | Custom registry used to pull the agent jnlp image from | `nil` |
+| [agent.kubernetesConnectTimeout](./values.yaml#L999) | int | The connection timeout in seconds for connections to Kubernetes API. The minimum value is 5 | `5` |
+| [agent.kubernetesReadTimeout](./values.yaml#L1001) | int | The read timeout in seconds for connections to Kubernetes API. The minimum value is 15 | `15` |
+| [agent.livenessProbe](./values.yaml#L1050) | object |  | `{}` |
+| [agent.maxRequestsPerHostStr](./values.yaml#L1003) | string | The maximum concurrent connections to Kubernetes API | `"32"` |
+| [agent.namespace](./values.yaml#L1009) | string | Namespace in which the Kubernetes agents should be launched | `nil` |
+| [agent.nodeSelector](./values.yaml#L1153) | object | Node labels for pod assignment | `{}` |
+| [agent.nodeUsageMode](./values.yaml#L1023) | string |  | `"NORMAL"` |
+| [agent.podLabels](./values.yaml#L1011) | object | Custom Pod labels (an object with `label-key: label-value` pairs) | `{}` |
+| [agent.podName](./values.yaml#L1173) | string | Agent Pod base name | `"default"` |
+| [agent.podRetention](./values.yaml#L1069) | string |  | `"Never"` |
+| [agent.podTemplates](./values.yaml#L1243) | object | Configures extra pod templates for the default kubernetes cloud | `{}` |
+| [agent.privileged](./values.yaml#L1033) | bool | Agent privileged container | `false` |
+| [agent.resources](./values.yaml#L1041) | object | Resources allocation (Requests and Limits) | `{"limits":{"cpu":"512m","memory":"512Mi"},"requests":{"cpu":"512m","memory":"512Mi"}}` |
+| [agent.restrictedPssSecurityContext](./values.yaml#L1066) | bool | Set a restricted securityContext on jnlp containers | `false` |
+| [agent.retentionTimeout](./values.yaml#L1005) | int | Time in minutes after which the Kubernetes cloud plugin will clean up an idle worker that has not already terminated | `5` |
+| [agent.runAsGroup](./values.yaml#L1037) | string | Configure container group | `nil` |
+| [agent.runAsUser](./values.yaml#L1035) | string | Configure container user | `nil` |
+| [agent.secretEnvVars](./values.yaml#L1146) | list | Mount a secret as environment variable | `[]` |
+| [agent.serviceAccount](./values.yaml#L985) | string | Override the default service account | `serviceAccountAgent.name` if `agent.useDefaultServiceAccount` is `true` |
+| [agent.showRawYaml](./values.yaml#L1073) | bool |  | `true` |
+| [agent.sideContainerName](./values.yaml#L1163) | string | Side container name | `"jnlp"` |
+| [agent.skipTlsVerify](./values.yaml#L995) | bool | Disables the verification of the controller certificate on remote connection. This flag correspond to the "Disable https certificate check" flag in kubernetes plugin UI | `false` |
+| [agent.usageRestricted](./values.yaml#L997) | bool | Enable the possibility to restrict the usage of this agent to specific folder. This flag correspond to the "Restrict pipeline support to authorized folders" flag in kubernetes plugin UI | `false` |
+| [agent.useDefaultServiceAccount](./values.yaml#L981) | bool | Use `serviceAccountAgent.name` as the default value for defaults template `serviceAccount` | `true` |
+| [agent.volumes](./values.yaml#L1080) | list | Additional volumes | `[]` |
+| [agent.waitForPodSec](./values.yaml#L1007) | int | Seconds to wait for pod to be running | `600` |
+| [agent.websocket](./values.yaml#L1030) | bool | Enables agent communication via websockets | `false` |
+| [agent.workingDir](./values.yaml#L1022) | string | Configure working directory for default agent | `"/home/jenkins/agent"` |
+| [agent.workspaceVolume](./values.yaml#L1115) | object | Workspace volume (defaults to EmptyDir) | `{}` |
+| [agent.yamlMergeStrategy](./values.yaml#L1205) | string | Defines how the raw yaml field gets merged with yaml definitions from inherited pod templates. Possible values: "merge" or "override" | `"override"` |
+| [agent.yamlTemplate](./values.yaml#L1194) | string | The raw yaml of a Pod API Object to merge into the agent spec | `""` |
+| [awsSecurityGroupPolicies.enabled](./values.yaml#L1420) | bool |  | `false` |
+| [awsSecurityGroupPolicies.policies[0].name](./values.yaml#L1422) | string |  | `""` |
+| [awsSecurityGroupPolicies.policies[0].podSelector](./values.yaml#L1424) | object |  | `{}` |
+| [awsSecurityGroupPolicies.policies[0].securityGroupIds](./values.yaml#L1423) | list |  | `[]` |
+| [checkDeprecation](./values.yaml#L1417) | bool | Checks if any deprecated values are used | `true` |
 | [clusterZone](./values.yaml#L21) | string | Override the cluster name for FQDN resolving | `"cluster.local"` |
-| [controller.JCasC.authorizationStrategy](./values.yaml#L533) | string | Jenkins Config as Code Authorization Strategy-section | `"loggedInUsersCanDoAnything:\n  allowAnonymousRead: false"` |
-| [controller.JCasC.configScripts](./values.yaml#L507) | object | List of Jenkins Config as Code scripts | `{}` |
-| [controller.JCasC.configUrls](./values.yaml#L504) | list | Remote URLs for configuration files. | `[]` |
-| [controller.JCasC.defaultConfig](./values.yaml#L498) | bool | Enables default Jenkins configuration via configuration as code plugin | `true` |
-| [controller.JCasC.overwriteConfiguration](./values.yaml#L502) | bool | Whether Jenkins Config as Code should overwrite any existing configuration | `false` |
-| [controller.JCasC.security](./values.yaml#L514) | object | Jenkins Config as Code security-section | `{"apiToken":{"creationOfLegacyTokenEnabled":false,"tokenGenerationOnCreationEnabled":false,"usageStatisticsEnabled":true}}` |
-| [controller.JCasC.securityRealm](./values.yaml#L522) | string | Jenkins Config as Code Security Realm-section | `"local:\n  allowsSignup: false\n  enableCaptcha: false\n  users:\n  - id: \"${chart-admin-username}\"\n    name: \"Jenkins Admin\"\n    password: \"${chart-admin-password}\""` |
-| [controller.additionalExistingSecrets](./values.yaml#L459) | list | List of additional existing secrets to mount | `[]` |
-| [controller.additionalPlugins](./values.yaml#L409) | list | List of plugins to install in addition to those listed in controller.installPlugins | `[]` |
-| [controller.additionalSecrets](./values.yaml#L468) | list | List of additional secrets to create and mount | `[]` |
-| [controller.admin.createSecret](./values.yaml#L91) | bool | Create secret for admin user | `true` |
-| [controller.admin.existingSecret](./values.yaml#L94) | string | The name of an existing secret containing the admin credentials | `""` |
-| [controller.admin.password](./values.yaml#L81) | string | Admin password created as a secret if `controller.admin.createSecret` is true | `<random password>` |
-| [controller.admin.passwordKey](./values.yaml#L86) | string | The key in the existing admin secret containing the password | `"jenkins-admin-password"` |
-| [controller.admin.userKey](./values.yaml#L84) | string | The key in the existing admin secret containing the username | `"jenkins-admin-user"` |
-| [controller.admin.username](./values.yaml#L78) | string | Admin username created as a secret if `controller.admin.createSecret` is true | `"admin"` |
-| [controller.affinity](./values.yaml#L638) | object | Affinity settings | `{}` |
-| [controller.agentListenerEnabled](./values.yaml#L318) | bool | Create Agent listener service | `true` |
-| [controller.agentListenerExternalTrafficPolicy](./values.yaml#L328) | string | Traffic Policy of for the agentListener service | `nil` |
-| [controller.agentListenerHostPort](./values.yaml#L322) | string | Host port to listen for agents | `nil` |
-| [controller.agentListenerLoadBalancerIP](./values.yaml#L358) | string | Static IP for the agentListener LoadBalancer | `nil` |
-| [controller.agentListenerLoadBalancerSourceRanges](./values.yaml#L330) | list | Allowed inbound IP for the agentListener service | `["0.0.0.0/0"]` |
-| [controller.agentListenerNodePort](./values.yaml#L324) | string | Node port to listen for agents | `nil` |
-| [controller.agentListenerPort](./values.yaml#L320) | int | Listening port for agents | `50000` |
-| [controller.agentListenerServiceAnnotations](./values.yaml#L353) | object | Annotations for the agentListener service | `{}` |
-| [controller.agentListenerServiceType](./values.yaml#L350) | string | Defines how to expose the agentListener service | `"ClusterIP"` |
-| [controller.backendconfig.annotations](./values.yaml#L738) | object | backendconfig annotations | `{}` |
-| [controller.backendconfig.apiVersion](./values.yaml#L732) | string | backendconfig API version | `"extensions/v1beta1"` |
-| [controller.backendconfig.enabled](./values.yaml#L730) | bool | Enables backendconfig | `false` |
-| [controller.backendconfig.labels](./values.yaml#L736) | object | backendconfig labels | `{}` |
-| [controller.backendconfig.name](./values.yaml#L734) | string | backendconfig name | `nil` |
-| [controller.backendconfig.spec](./values.yaml#L740) | object | backendconfig spec | `{}` |
-| [controller.cloudName](./values.yaml#L487) | string | Name of default cloud configuration. | `"kubernetes"` |
-| [controller.clusterIp](./values.yaml#L217) | string | k8s service clusterIP. Only used if serviceType is ClusterIP | `nil` |
-| [controller.componentName](./values.yaml#L34) | string | Used for label app.kubernetes.io/component | `"jenkins-controller"` |
-| [controller.containerEnv](./values.yaml#L150) | list | Environment variables for Jenkins Container | `[]` |
-| [controller.containerEnvFrom](./values.yaml#L147) | list | Environment variable sources for Jenkins Container | `[]` |
-| [controller.containerSecurityContext](./values.yaml#L205) | object | Allow controlling the securityContext for the jenkins container | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":1000}` |
-| [controller.csrf.defaultCrumbIssuer.enabled](./values.yaml#L339) | bool | Enable the default CSRF Crumb issuer | `true` |
-| [controller.csrf.defaultCrumbIssuer.proxyCompatability](./values.yaml#L341) | bool | Enable proxy compatibility | `true` |
-| [controller.customInitContainers](./values.yaml#L537) | list | Custom init-container specification in raw-yaml format | `[]` |
-| [controller.customJenkinsLabels](./values.yaml#L68) | list | Append Jenkins labels to the controller | `[]` |
-| [controller.disableRememberMe](./values.yaml#L59) | bool | Disable use of remember me | `false` |
-| [controller.disabledAgentProtocols](./values.yaml#L333) | list | Disabled agent protocols | `["JNLP-connect","JNLP2-connect"]` |
-| [controller.enableRawHtmlMarkupFormatter](./values.yaml#L429) | bool | Enable HTML parsing using OWASP Markup Formatter Plugin (antisamy-markup-formatter) | `false` |
-| [controller.executorMode](./values.yaml#L65) | string | Sets the executor mode of the Jenkins node. Possible values are "NORMAL" or "EXCLUSIVE" | `"NORMAL"` |
-| [controller.existingSecret](./values.yaml#L456) | string |  | `nil` |
-| [controller.extraPorts](./values.yaml#L388) | list | Optionally configure other ports to expose in the controller container | `[]` |
-| [controller.fsGroup](./values.yaml#L186) | int | Deprecated in favor of `controller.podSecurityContextOverride`. uid that will be used for persistent volume. | `1000` |
-| [controller.googlePodMonitor.enabled](./values.yaml#L801) | bool |  | `false` |
-| [controller.googlePodMonitor.scrapeEndpoint](./values.yaml#L806) | string |  | `"/prometheus"` |
-| [controller.googlePodMonitor.scrapeInterval](./values.yaml#L804) | string |  | `"60s"` |
-| [controller.healthProbes](./values.yaml#L248) | bool | Enable Kubernetes Probes configuration configured in `controller.probes` | `true` |
-| [controller.hostAliases](./values.yaml#L754) | list | Allows for adding entries to Pod /etc/hosts | `[]` |
-| [controller.hostNetworking](./values.yaml#L70) | bool |  | `false` |
-| [controller.httpsKeyStore.disableSecretMount](./values.yaml#L822) | bool |  | `false` |
-| [controller.httpsKeyStore.enable](./values.yaml#L813) | bool | Enables HTTPS keystore on jenkins controller | `false` |
-| [controller.httpsKeyStore.fileName](./values.yaml#L830) | string | Jenkins keystore filename which will appear under controller.httpsKeyStore.path | `"keystore.jks"` |
-| [controller.httpsKeyStore.httpPort](./values.yaml#L826) | int | HTTP Port that Jenkins should listen to along with HTTPS, it also serves as the liveness and readiness probes port. | `8081` |
-| [controller.httpsKeyStore.jenkinsHttpsJksPasswordSecretKey](./values.yaml#L821) | string | Name of the key in the secret that contains the JKS password | `"https-jks-password"` |
-| [controller.httpsKeyStore.jenkinsHttpsJksPasswordSecretName](./values.yaml#L819) | string | Name of the secret that contains the JKS password, if it is not in the same secret as the JKS file | `""` |
-| [controller.httpsKeyStore.jenkinsHttpsJksSecretKey](./values.yaml#L817) | string | Name of the key in the secret that already has ssl keystore | `"jenkins-jks-file"` |
-| [controller.httpsKeyStore.jenkinsHttpsJksSecretName](./values.yaml#L815) | string | Name of the secret that already has ssl keystore | `""` |
-| [controller.httpsKeyStore.jenkinsKeyStoreBase64Encoded](./values.yaml#L835) | string | Base64 encoded Keystore content. Keystore must be converted to base64 then being pasted here | `nil` |
-| [controller.httpsKeyStore.password](./values.yaml#L832) | string | Jenkins keystore password | `"password"` |
-| [controller.httpsKeyStore.path](./values.yaml#L828) | string | Path of HTTPS keystore file | `"/var/jenkins_keystore"` |
-| [controller.image.pullPolicy](./values.yaml#L47) | string | Controller image pull policy | `"Always"` |
-| [controller.image.registry](./values.yaml#L37) | string | Controller image registry | `"docker.io"` |
-| [controller.image.repository](./values.yaml#L39) | string | Controller image repository | `"jenkins/jenkins"` |
-| [controller.image.tag](./values.yaml#L42) | string | Controller image tag override; i.e., tag: "2.440.1-jdk17" | `nil` |
-| [controller.image.tagLabel](./values.yaml#L45) | string | Controller image tag label | `"jdk17"` |
-| [controller.imagePullSecretName](./values.yaml#L49) | string | Controller image pull secret | `nil` |
-| [controller.ingress.annotations](./values.yaml#L677) | object | Ingress annotations | `{}` |
-| [controller.ingress.apiVersion](./values.yaml#L673) | string | Ingress API version | `"extensions/v1beta1"` |
-| [controller.ingress.enabled](./values.yaml#L656) | bool | Enables ingress | `false` |
-| [controller.ingress.hostName](./values.yaml#L690) | string | Ingress hostname | `nil` |
-| [controller.ingress.labels](./values.yaml#L675) | object | Ingress labels | `{}` |
-| [controller.ingress.path](./values.yaml#L686) | string | Ingress path | `nil` |
-| [controller.ingress.paths](./values.yaml#L660) | list | Override for the default Ingress paths | `[]` |
-| [controller.ingress.resourceRootUrl](./values.yaml#L692) | string | Hostname to serve assets from | `nil` |
-| [controller.ingress.tls](./values.yaml#L694) | list | Ingress TLS configuration | `[]` |
-| [controller.initConfigMap](./values.yaml#L446) | string | Name of the existing ConfigMap that contains init scripts | `nil` |
-| [controller.initContainerEnv](./values.yaml#L141) | list | Environment variables for Init Container | `[]` |
-| [controller.initContainerEnvFrom](./values.yaml#L137) | list | Environment variable sources for Init Container | `[]` |
-| [controller.initContainerResources](./values.yaml#L128) | object | Resources allocation (Requests and Limits) for Init Container | `{}` |
-| [controller.initScripts](./values.yaml#L442) | object | Map of groovy init scripts to be executed during Jenkins controller start | `{}` |
-| [controller.initializeOnce](./values.yaml#L414) | bool | Initialize only on first installation. Ensures plugins do not get updated inadvertently. Requires `persistence.enabled` to be set to `true` | `false` |
-| [controller.installLatestPlugins](./values.yaml#L403) | bool | Download the minimum required version or latest version of all dependencies | `true` |
-| [controller.installLatestSpecifiedPlugins](./values.yaml#L406) | bool | Set to true to download the latest version of any plugin that is requested to have the latest version | `false` |
-| [controller.installPlugins](./values.yaml#L395) | list | List of Jenkins plugins to install. If you don't want to install plugins, set it to `false` | `["kubernetes:4203.v1dd44f5b_1cf9","workflow-aggregator:596.v8c21c963d92d","git:5.2.1","configuration-as-code:1775.v810dc950b_514"]` |
-| [controller.javaOpts](./values.yaml#L156) | string | Append to `JAVA_OPTS` env var | `nil` |
-| [controller.jenkinsAdminEmail](./values.yaml#L96) | string | Email address for the administrator of the Jenkins instance | `nil` |
-| [controller.jenkinsHome](./values.yaml#L101) | string | Custom Jenkins home path | `"/var/jenkins_home"` |
-| [controller.jenkinsOpts](./values.yaml#L158) | string | Append to `JENKINS_OPTS` env var | `nil` |
-| [controller.jenkinsRef](./values.yaml#L106) | string | Custom Jenkins reference path | `"/usr/share/jenkins/ref"` |
-| [controller.jenkinsUriPrefix](./values.yaml#L173) | string | Root URI Jenkins will be served on | `nil` |
-| [controller.jenkinsUrl](./values.yaml#L168) | string | Set Jenkins URL if you are not using the ingress definitions provided by the chart | `nil` |
-| [controller.jenkinsUrlProtocol](./values.yaml#L165) | string | Set protocol for Jenkins URL; `https` if `controller.ingress.tls`, `http` otherwise | `nil` |
-| [controller.jenkinsWar](./values.yaml#L109) | string |  | `"/usr/share/jenkins/jenkins.war"` |
-| [controller.jmxPort](./values.yaml#L385) | string | Open a port, for JMX stats | `nil` |
-| [controller.legacyRemotingSecurityEnabled](./values.yaml#L361) | bool | Whether legacy remoting security should be enabled | `false` |
-| [controller.lifecycle](./values.yaml#L51) | object | Lifecycle specification for controller-container | `{}` |
-| [controller.loadBalancerIP](./values.yaml#L376) | string | Optionally assign a known public LB IP | `nil` |
-| [controller.loadBalancerSourceRanges](./values.yaml#L372) | list | Allowed inbound IP addresses | `["0.0.0.0/0"]` |
-| [controller.markupFormatter](./values.yaml#L433) | string | Yaml of the markup formatter to use | `"plainText"` |
-| [controller.nodePort](./values.yaml#L223) | string | k8s node port. Only used if serviceType is NodePort | `nil` |
-| [controller.nodeSelector](./values.yaml#L625) | object | Node labels for pod assignment | `{}` |
-| [controller.numExecutors](./values.yaml#L62) | int | Set Number of executors | `0` |
-| [controller.overwritePlugins](./values.yaml#L418) | bool | Overwrite installed plugins on start | `false` |
-| [controller.overwritePluginsFromImage](./values.yaml#L422) | bool | Overwrite plugins that are already installed in the controller image | `true` |
-| [controller.podAnnotations](./values.yaml#L646) | object | Annotations for controller pod | `{}` |
-| [controller.podDisruptionBudget.annotations](./values.yaml#L312) | object |  | `{}` |
-| [controller.podDisruptionBudget.apiVersion](./values.yaml#L310) | string | Policy API version | `"policy/v1beta1"` |
-| [controller.podDisruptionBudget.enabled](./values.yaml#L305) | bool | Enable Kubernetes Pod Disruption Budget configuration | `false` |
-| [controller.podDisruptionBudget.labels](./values.yaml#L313) | object |  | `{}` |
-| [controller.podDisruptionBudget.maxUnavailable](./values.yaml#L315) | string | Number of pods that can be unavailable. Either an absolute number or a percentage | `"0"` |
-| [controller.podLabels](./values.yaml#L241) | object | Custom Pod labels (an object with `label-key: label-value` pairs) | `{}` |
-| [controller.podSecurityContextOverride](./values.yaml#L202) | string | Completely overwrites the contents of the pod security context, ignoring the values provided for `runAsUser`, `fsGroup`, and `securityContextCapabilities` | `nil` |
-| [controller.priorityClassName](./values.yaml#L643) | string | The name of a `priorityClass` to apply to the controller pod | `nil` |
-| [controller.probes.livenessProbe.failureThreshold](./values.yaml#L266) | int | Set the failure threshold for the liveness probe | `5` |
-| [controller.probes.livenessProbe.httpGet.path](./values.yaml#L269) | string | Set the Pod's HTTP path for the liveness probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
-| [controller.probes.livenessProbe.httpGet.port](./values.yaml#L271) | string | Set the Pod's HTTP port to use for the liveness probe | `"http"` |
-| [controller.probes.livenessProbe.initialDelaySeconds](./values.yaml#L280) | string | Set the initial delay for the liveness probe in seconds | `nil` |
-| [controller.probes.livenessProbe.periodSeconds](./values.yaml#L273) | int | Set the time interval between two liveness probes executions in seconds | `10` |
-| [controller.probes.livenessProbe.timeoutSeconds](./values.yaml#L275) | int | Set the timeout for the liveness probe in seconds | `5` |
-| [controller.probes.readinessProbe.failureThreshold](./values.yaml#L284) | int | Set the failure threshold for the readiness probe | `3` |
-| [controller.probes.readinessProbe.httpGet.path](./values.yaml#L287) | string | Set the Pod's HTTP path for the liveness probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
-| [controller.probes.readinessProbe.httpGet.port](./values.yaml#L289) | string | Set the Pod's HTTP port to use for the readiness probe | `"http"` |
-| [controller.probes.readinessProbe.initialDelaySeconds](./values.yaml#L298) | string | Set the initial delay for the readiness probe in seconds | `nil` |
-| [controller.probes.readinessProbe.periodSeconds](./values.yaml#L291) | int | Set the time interval between two readiness probes executions in seconds | `10` |
-| [controller.probes.readinessProbe.timeoutSeconds](./values.yaml#L293) | int | Set the timeout for the readiness probe in seconds | `5` |
-| [controller.probes.startupProbe.failureThreshold](./values.yaml#L253) | int | Set the failure threshold for the startup probe | `12` |
-| [controller.probes.startupProbe.httpGet.path](./values.yaml#L256) | string | Set the Pod's HTTP path for the startup probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
-| [controller.probes.startupProbe.httpGet.port](./values.yaml#L258) | string | Set the Pod's HTTP port to use for the startup probe | `"http"` |
-| [controller.probes.startupProbe.periodSeconds](./values.yaml#L260) | int | Set the time interval between two startup probes executions in seconds | `10` |
-| [controller.probes.startupProbe.timeoutSeconds](./values.yaml#L262) | int | Set the timeout for the startup probe in seconds | `5` |
-| [controller.projectNamingStrategy](./values.yaml#L425) | string |  | `"standard"` |
-| [controller.prometheus.alertingRulesAdditionalLabels](./values.yaml#L787) | object | Additional labels to add to the PrometheusRule object | `{}` |
-| [controller.prometheus.alertingrules](./values.yaml#L785) | list | Array of prometheus alerting rules | `[]` |
-| [controller.prometheus.enabled](./values.yaml#L770) | bool | Enables prometheus service monitor | `false` |
-| [controller.prometheus.metricRelabelings](./values.yaml#L797) | list |  | `[]` |
-| [controller.prometheus.prometheusRuleNamespace](./values.yaml#L789) | string | Set a custom namespace where to deploy PrometheusRule resource | `""` |
-| [controller.prometheus.relabelings](./values.yaml#L795) | list |  | `[]` |
-| [controller.prometheus.scrapeEndpoint](./values.yaml#L780) | string | The endpoint prometheus should get metrics from | `"/prometheus"` |
-| [controller.prometheus.scrapeInterval](./values.yaml#L776) | string | How often prometheus should scrape metrics | `"60s"` |
-| [controller.prometheus.serviceMonitorAdditionalLabels](./values.yaml#L772) | object | Additional labels to add to the service monitor object | `{}` |
-| [controller.prometheus.serviceMonitorNamespace](./values.yaml#L774) | string | Set a custom namespace where to deploy ServiceMonitor resource | `nil` |
-| [controller.resources](./values.yaml#L115) | object | Resource allocation (Requests and Limits) | `{"limits":{"cpu":"2000m","memory":"4096Mi"},"requests":{"cpu":"50m","memory":"256Mi"}}` |
-| [controller.route.annotations](./values.yaml#L749) | object | Route annotations | `{}` |
-| [controller.route.enabled](./values.yaml#L745) | bool | Enables openshift route | `false` |
-| [controller.route.labels](./values.yaml#L747) | object | Route labels | `{}` |
-| [controller.route.path](./values.yaml#L751) | string | Route path | `nil` |
-| [controller.runAsUser](./values.yaml#L183) | int | Deprecated in favor of `controller.podSecurityContextOverride`. uid that jenkins runs with. | `1000` |
-| [controller.schedulerName](./values.yaml#L621) | string | Name of the Kubernetes scheduler to use | `""` |
-| [controller.scriptApproval](./values.yaml#L437) | list | List of groovy functions to approve | `[]` |
-| [controller.secondaryingress.annotations](./values.yaml#L712) | object |  | `{}` |
-| [controller.secondaryingress.apiVersion](./values.yaml#L710) | string |  | `"extensions/v1beta1"` |
-| [controller.secondaryingress.enabled](./values.yaml#L704) | bool |  | `false` |
-| [controller.secondaryingress.hostName](./values.yaml#L719) | string |  | `nil` |
-| [controller.secondaryingress.labels](./values.yaml#L711) | object |  | `{}` |
-| [controller.secondaryingress.paths](./values.yaml#L707) | list |  | `[]` |
-| [controller.secondaryingress.tls](./values.yaml#L720) | string |  | `nil` |
-| [controller.secretClaims](./values.yaml#L480) | list | List of `SecretClaim` resources to create | `[]` |
-| [controller.securityContextCapabilities](./values.yaml#L192) | object |  | `{}` |
-| [controller.serviceAnnotations](./values.yaml#L230) | object | Jenkins controller service annotations | `{}` |
-| [controller.serviceExternalTrafficPolicy](./values.yaml#L227) | string |  | `nil` |
-| [controller.serviceLabels](./values.yaml#L236) | object | Labels for the Jenkins controller-service | `{}` |
-| [controller.servicePort](./values.yaml#L219) | int | k8s service port | `8080` |
-| [controller.serviceType](./values.yaml#L214) | string | k8s service type | `"ClusterIP"` |
-| [controller.shareProcessNamespace](./values.yaml#L124) | bool |  | `false` |
-| [controller.sidecars.additionalSidecarContainers](./values.yaml#L603) | list | Configures additional sidecar container(s) for the Jenkins controller | `[]` |
-| [controller.sidecars.configAutoReload.containerSecurityContext](./values.yaml#L598) | object | Enable container security context | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true}` |
-| [controller.sidecars.configAutoReload.enabled](./values.yaml#L550) | bool | Enables Jenkins Config as Code auto-reload | `true` |
-| [controller.sidecars.configAutoReload.env](./values.yaml#L580) | object | Environment variables for the Jenkins Config as Code auto-reload container | `{}` |
-| [controller.sidecars.configAutoReload.envFrom](./values.yaml#L578) | list | Environment variable sources for the Jenkins Config as Code auto-reload container | `[]` |
-| [controller.sidecars.configAutoReload.folder](./values.yaml#L591) | string |  | `"/var/jenkins_home/casc_configs"` |
-| [controller.sidecars.configAutoReload.image.registry](./values.yaml#L553) | string | Registry for the image that triggers the reload | `"docker.io"` |
-| [controller.sidecars.configAutoReload.image.repository](./values.yaml#L555) | string | Repository of the image that triggers the reload | `"kiwigrid/k8s-sidecar"` |
-| [controller.sidecars.configAutoReload.image.tag](./values.yaml#L557) | string | Tag for the image that triggers the reload | `"1.26.1"` |
-| [controller.sidecars.configAutoReload.imagePullPolicy](./values.yaml#L558) | string |  | `"IfNotPresent"` |
-| [controller.sidecars.configAutoReload.reqRetryConnect](./values.yaml#L573) | int | How many connection-related errors to retry on | `10` |
-| [controller.sidecars.configAutoReload.resources](./values.yaml#L559) | object |  | `{}` |
-| [controller.sidecars.configAutoReload.scheme](./values.yaml#L568) | string | The scheme to use when connecting to the Jenkins configuration as code endpoint | `"http"` |
-| [controller.sidecars.configAutoReload.skipTlsVerify](./values.yaml#L570) | bool | Skip TLS verification when connecting to the Jenkins configuration as code endpoint | `false` |
-| [controller.sidecars.configAutoReload.sleepTime](./values.yaml#L575) | string | How many seconds to wait before updating config-maps/secrets (sets METHOD=SLEEP on the sidecar) | `nil` |
-| [controller.sidecars.configAutoReload.sshTcpPort](./values.yaml#L589) | int |  | `1044` |
-| [controller.statefulSetAnnotations](./values.yaml#L648) | object | Annotations for controller StatefulSet | `{}` |
-| [controller.statefulSetLabels](./values.yaml#L232) | object | Jenkins controller custom labels for the StatefulSet | `{}` |
-| [controller.targetPort](./values.yaml#L221) | int | k8s target port | `8080` |
-| [controller.terminationGracePeriodSeconds](./values.yaml#L631) | string | Set TerminationGracePeriodSeconds | `nil` |
-| [controller.terminationMessagePath](./values.yaml#L633) | string | Set the termination message path | `nil` |
-| [controller.terminationMessagePolicy](./values.yaml#L635) | string | Set the termination message policy | `nil` |
-| [controller.testEnabled](./values.yaml#L809) | bool | Can be used to disable rendering controller test resources when using helm template | `true` |
-| [controller.tolerations](./values.yaml#L629) | list | Toleration labels for pod assignment | `[]` |
-| [controller.updateStrategy](./values.yaml#L652) | object | Update strategy for StatefulSet | `{}` |
-| [controller.usePodSecurityContext](./values.yaml#L176) | bool | Enable pod security context (must be `true` if podSecurityContextOverride, runAsUser or fsGroup are set) | `true` |
+| [controller.JCasC.authorizationStrategy](./values.yaml#L558) | string | Jenkins Config as Code Authorization Strategy-section | `"loggedInUsersCanDoAnything:\n  allowAnonymousRead: false"` |
+| [controller.JCasC.configMapAnnotations](./values.yaml#L563) | object | Annotations for the JCasC ConfigMap | `{}` |
+| [controller.JCasC.configScripts](./values.yaml#L532) | object | List of Jenkins Config as Code scripts | `{}` |
+| [controller.JCasC.configUrls](./values.yaml#L529) | list | Remote URLs for configuration files. | `[]` |
+| [controller.JCasC.defaultConfig](./values.yaml#L523) | bool | Enables default Jenkins configuration via configuration as code plugin | `true` |
+| [controller.JCasC.overwriteConfiguration](./values.yaml#L527) | bool | Whether Jenkins Config as Code should overwrite any existing configuration | `false` |
+| [controller.JCasC.security](./values.yaml#L539) | object | Jenkins Config as Code security-section | `{"apiToken":{"creationOfLegacyTokenEnabled":false,"tokenGenerationOnCreationEnabled":false,"usageStatisticsEnabled":true}}` |
+| [controller.JCasC.securityRealm](./values.yaml#L547) | string | Jenkins Config as Code Security Realm-section | `"local:\n  allowsSignup: false\n  enableCaptcha: false\n  users:\n  - id: \"${chart-admin-username}\"\n    name: \"Jenkins Admin\"\n    password: \"${chart-admin-password}\""` |
+| [controller.additionalExistingSecrets](./values.yaml#L484) | list | List of additional existing secrets to mount | `[]` |
+| [controller.additionalPlugins](./values.yaml#L434) | list | List of plugins to install in addition to those listed in controller.installPlugins | `[]` |
+| [controller.additionalSecrets](./values.yaml#L493) | list | List of additional secrets to create and mount | `[]` |
+| [controller.admin.createSecret](./values.yaml#L100) | bool | Create secret for admin user | `true` |
+| [controller.admin.existingSecret](./values.yaml#L103) | string | The name of an existing secret containing the admin credentials | `""` |
+| [controller.admin.password](./values.yaml#L90) | string | Admin password created as a secret if `controller.admin.createSecret` is true | `<random password>` |
+| [controller.admin.passwordKey](./values.yaml#L95) | string | The key in the existing admin secret containing the password | `"jenkins-admin-password"` |
+| [controller.admin.userKey](./values.yaml#L93) | string | The key in the existing admin secret containing the username | `"jenkins-admin-user"` |
+| [controller.admin.username](./values.yaml#L87) | string | Admin username created as a secret if `controller.admin.createSecret` is true | `"admin"` |
+| [controller.affinity](./values.yaml#L689) | object | Affinity settings | `{}` |
+| [controller.agentListenerEnabled](./values.yaml#L343) | bool | Create Agent listener service | `true` |
+| [controller.agentListenerExternalTrafficPolicy](./values.yaml#L353) | string | Traffic Policy of for the agentListener service | `nil` |
+| [controller.agentListenerHostPort](./values.yaml#L347) | string | Host port to listen for agents | `nil` |
+| [controller.agentListenerLoadBalancerIP](./values.yaml#L383) | string | Static IP for the agentListener LoadBalancer | `nil` |
+| [controller.agentListenerLoadBalancerSourceRanges](./values.yaml#L355) | list | Allowed inbound IP for the agentListener service | `["0.0.0.0/0"]` |
+| [controller.agentListenerNodePort](./values.yaml#L349) | string | Node port to listen for agents | `nil` |
+| [controller.agentListenerPort](./values.yaml#L345) | int | Listening port for agents | `50000` |
+| [controller.agentListenerServiceAnnotations](./values.yaml#L378) | object | Annotations for the agentListener service | `{}` |
+| [controller.agentListenerServiceType](./values.yaml#L375) | string | Defines how to expose the agentListener service | `"ClusterIP"` |
+| [controller.backendconfig.annotations](./values.yaml#L811) | object | backendconfig annotations | `{}` |
+| [controller.backendconfig.apiVersion](./values.yaml#L805) | string | backendconfig API version | `"extensions/v1beta1"` |
+| [controller.backendconfig.enabled](./values.yaml#L803) | bool | Enables backendconfig | `false` |
+| [controller.backendconfig.labels](./values.yaml#L809) | object | backendconfig labels | `{}` |
+| [controller.backendconfig.name](./values.yaml#L807) | string | backendconfig name | `nil` |
+| [controller.backendconfig.spec](./values.yaml#L813) | object | backendconfig spec | `{}` |
+| [controller.cloudName](./values.yaml#L512) | string | Name of default cloud configuration. | `"kubernetes"` |
+| [controller.clusterIp](./values.yaml#L238) | string | k8s service clusterIP. Only used if serviceType is ClusterIP | `nil` |
+| [controller.componentName](./values.yaml#L40) | string | Used for label app.kubernetes.io/component | `"jenkins-controller"` |
+| [controller.containerEnv](./values.yaml#L165) | list | Environment variables for Jenkins Container | `[]` |
+| [controller.containerEnvFrom](./values.yaml#L162) | list | Environment variable sources for Jenkins Container | `[]` |
+| [controller.containerSecurityContext](./values.yaml#L223) | object | Allow controlling the securityContext for the jenkins container | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":1000}` |
+| [controller.csrf.defaultCrumbIssuer.enabled](./values.yaml#L364) | bool | Enable the default CSRF Crumb issuer | `true` |
+| [controller.csrf.defaultCrumbIssuer.proxyCompatability](./values.yaml#L366) | bool | Enable proxy compatibility. This setting is ignored if you are not on the current LTS release and will be dropped with the next LTS. | `true` |
+| [controller.customInitContainers](./values.yaml#L566) | list | Custom init-container specification in raw-yaml format | `[]` |
+| [controller.customJenkinsLabels](./values.yaml#L78) | list | Append Jenkins labels to the controller | `[]` |
+| [controller.disableRememberMe](./values.yaml#L69) | bool | Disable use of remember me | `false` |
+| [controller.disabledAgentProtocols](./values.yaml#L358) | list | Disabled agent protocols | `["JNLP-connect","JNLP2-connect"]` |
+| [controller.dnsConfig](./values.yaml#L709) | object | DNS config for the pod | `{}` |
+| [controller.enableRawHtmlMarkupFormatter](./values.yaml#L454) | bool | Enable HTML parsing using OWASP Markup Formatter Plugin (antisamy-markup-formatter) | `false` |
+| [controller.enableServiceLinks](./values.yaml#L139) | bool |  | `false` |
+| [controller.executorMode](./values.yaml#L75) | string | Sets the executor mode of the Jenkins node. Possible values are "NORMAL" or "EXCLUSIVE" | `"NORMAL"` |
+| [controller.existingSecret](./values.yaml#L481) | string |  | `nil` |
+| [controller.extraPorts](./values.yaml#L413) | list | Optionally configure other ports to expose in the controller container | `[]` |
+| [controller.fsGroup](./values.yaml#L201) | int | Deprecated in favor of `controller.podSecurityContextOverride`. uid that will be used for persistent volume. | `1000` |
+| [controller.fsGroupChangePolicy](./values.yaml#L204) | string |  | `"OnRootMismatch"` |
+| [controller.googlePodMonitor.enabled](./values.yaml#L893) | bool |  | `false` |
+| [controller.googlePodMonitor.scrapeEndpoint](./values.yaml#L898) | string |  | `"/prometheus"` |
+| [controller.googlePodMonitor.scrapeInterval](./values.yaml#L896) | string |  | `"60s"` |
+| [controller.healthProbes](./values.yaml#L273) | bool | Enable Kubernetes Probes configuration configured in `controller.probes` | `true` |
+| [controller.hostAliases](./values.yaml#L846) | list | Allows for adding entries to Pod /etc/hosts | `[]` |
+| [controller.hostNetworking](./values.yaml#L80) | bool |  | `false` |
+| [controller.httpRoute.annotations](./values.yaml#L843) | object | HTTPRoute annotations | `{}` |
+| [controller.httpRoute.apiVersion](./values.yaml#L830) | string |  | `"gateway.networking.k8s.io/v1"` |
+| [controller.httpRoute.enabled](./values.yaml#L829) | bool |  | `false` |
+| [controller.httpRoute.extraRules](./values.yaml#L841) | list |  | `[]` |
+| [controller.httpRoute.hostnames](./values.yaml#L839) | list |  | `[]` |
+| [controller.httpRoute.kind](./values.yaml#L831) | string |  | `"HTTPRoute"` |
+| [controller.httpRoute.parentRefs](./values.yaml#L833) | list |  | `[]` |
+| [controller.httpRoute.reuseIngressConfiguration](./values.yaml#L837) | bool |  | `false` |
+| [controller.httpsKeyStore.disableSecretMount](./values.yaml#L914) | bool |  | `false` |
+| [controller.httpsKeyStore.enable](./values.yaml#L905) | bool | Enables HTTPS keystore on jenkins controller | `false` |
+| [controller.httpsKeyStore.fileName](./values.yaml#L922) | string | Jenkins keystore filename which will appear under controller.httpsKeyStore.path | `"keystore.jks"` |
+| [controller.httpsKeyStore.httpPort](./values.yaml#L918) | int | HTTP Port that Jenkins should listen to along with HTTPS, it also serves as the liveness and readiness probes port. | `8081` |
+| [controller.httpsKeyStore.jenkinsHttpsJksPasswordSecretKey](./values.yaml#L913) | string | Name of the key in the secret that contains the JKS password | `"https-jks-password"` |
+| [controller.httpsKeyStore.jenkinsHttpsJksPasswordSecretName](./values.yaml#L911) | string | Name of the secret that contains the JKS password, if it is not in the same secret as the JKS file | `""` |
+| [controller.httpsKeyStore.jenkinsHttpsJksSecretKey](./values.yaml#L909) | string | Name of the key in the secret that already has SSL keystore | `"jenkins-jks-file"` |
+| [controller.httpsKeyStore.jenkinsHttpsJksSecretName](./values.yaml#L907) | string | Name of the secret that already has SSL keystore | `""` |
+| [controller.httpsKeyStore.jenkinsKeyStoreBase64Encoded](./values.yaml#L927) | string | Base64 encoded Keystore content. Keystore must be converted to base64 then being pasted here | `nil` |
+| [controller.httpsKeyStore.password](./values.yaml#L924) | string | Jenkins keystore password | `"password"` |
+| [controller.httpsKeyStore.path](./values.yaml#L920) | string | Path of HTTPS keystore file | `"/var/jenkins_keystore"` |
+| [controller.image.pullPolicy](./values.yaml#L53) | string | Controller image pull policy | `"Always"` |
+| [controller.image.registry](./values.yaml#L43) | string | Controller image registry | `"docker.io"` |
+| [controller.image.repository](./values.yaml#L45) | string | Controller image repository | `"jenkins/jenkins"` |
+| [controller.image.tag](./values.yaml#L48) | string | Controller image tag override; i.e., tag: "2.440.1-jdk21" | `nil` |
+| [controller.image.tagLabel](./values.yaml#L51) | string | Controller image tag label | `"jdk21"` |
+| [controller.imagePullSecretName](./values.yaml#L59) | string | Controller image pull secret | `nil` |
+| [controller.ingress.annotations](./values.yaml#L737) | object | Primary Ingress annotations | `{}` |
+| [controller.ingress.apiVersion](./values.yaml#L733) | string | Primary Ingress API version | `"networking.k8s.io/v1"` |
+| [controller.ingress.enabled](./values.yaml#L713) | bool | Enables the Primary ingress | `false` |
+| [controller.ingress.hostName](./values.yaml#L753) | string | Primary Ingress hostname | `nil` |
+| [controller.ingress.ingressClassName](./values.yaml#L745) | string | Primary Ingress ingressClassName | `nil` |
+| [controller.ingress.labels](./values.yaml#L735) | object | Primary Ingress labels | `{}` |
+| [controller.ingress.path](./values.yaml#L749) | string | Primary Ingress path | `nil` |
+| [controller.ingress.pathType](./values.yaml#L728) | string | Primary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix | `"ImplementationSpecific"` |
+| [controller.ingress.paths](./values.yaml#L717) | list | Override for the default Primary Ingress paths | `[]` |
+| [controller.ingress.resourceRootUrl](./values.yaml#L755) | string | Primary Hostname to serve assets from | `nil` |
+| [controller.ingress.tls](./values.yaml#L757) | list | Primary Ingress TLS configuration | `[]` |
+| [controller.initConfigMap](./values.yaml#L471) | string | Name of the existing ConfigMap that contains init scripts | `nil` |
+| [controller.initContainerEnv](./values.yaml#L156) | list | Environment variables for Init Container | `[]` |
+| [controller.initContainerEnvFrom](./values.yaml#L152) | list | Environment variable sources for Init Container | `[]` |
+| [controller.initContainerResources](./values.yaml#L143) | object | Resources allocation (Requests and Limits) for Init Container | `{}` |
+| [controller.initScripts](./values.yaml#L467) | object | Map of groovy init scripts to be executed during Jenkins controller start | `{}` |
+| [controller.initializeOnce](./values.yaml#L439) | bool | Initialize only on first installation. Ensures plugins do not get updated inadvertently. Requires `persistence.enabled` to be set to `true` | `false` |
+| [controller.installLatestPlugins](./values.yaml#L428) | bool | Download the minimum required version or latest version of all dependencies | `true` |
+| [controller.installLatestSpecifiedPlugins](./values.yaml#L431) | bool | Set to true to download the latest version of any plugin that is requested to have the latest version | `false` |
+| [controller.installPlugins](./values.yaml#L420) | list | List of Jenkins plugins to install. If you don't want to install plugins, set it to `false` | `["kubernetes:4467.vf26561292824","workflow-aggregator:608.v67378e9d3db_1","git:5.10.1","configuration-as-code:2100.vb_fd699d2a_09c"]` |
+| [controller.javaOpts](./values.yaml#L171) | string | Append to `JAVA_OPTS` env var | `nil` |
+| [controller.jenkinsAdminEmail](./values.yaml#L105) | string | Email address for the administrator of the Jenkins instance | `nil` |
+| [controller.jenkinsHome](./values.yaml#L110) | string | Custom Jenkins home path | `"/var/jenkins_home"` |
+| [controller.jenkinsOpts](./values.yaml#L173) | string | Append to `JENKINS_OPTS` env var | `nil` |
+| [controller.jenkinsRef](./values.yaml#L115) | string | Custom Jenkins reference path | `"/usr/share/jenkins/ref"` |
+| [controller.jenkinsUriPrefix](./values.yaml#L188) | string | Root URI Jenkins will be served on | `nil` |
+| [controller.jenkinsUrl](./values.yaml#L183) | string | Set Jenkins URL if you are not using the ingress definitions provided by the chart | `nil` |
+| [controller.jenkinsUrlProtocol](./values.yaml#L180) | string | Set protocol for Jenkins URL; `https` if `controller.ingress.tls`, `http` otherwise | `nil` |
+| [controller.jenkinsWar](./values.yaml#L118) | string |  | `"/usr/share/jenkins/jenkins.war"` |
+| [controller.jmxPort](./values.yaml#L410) | string | Open a port, for JMX stats | `nil` |
+| [controller.legacyRemotingSecurityEnabled](./values.yaml#L386) | bool | Whether legacy remoting security should be enabled | `false` |
+| [controller.lifecycle](./values.yaml#L61) | object | Lifecycle specification for controller-container | `{}` |
+| [controller.loadBalancerIP](./values.yaml#L401) | string | Optionally assign a known public LB IP | `nil` |
+| [controller.loadBalancerSourceRanges](./values.yaml#L397) | list | Allowed inbound IP addresses | `["0.0.0.0/0"]` |
+| [controller.markupFormatter](./values.yaml#L458) | string | Yaml of the markup formatter to use | `"plainText"` |
+| [controller.nodePort](./values.yaml#L244) | string | k8s node port. Only used if serviceType is NodePort | `nil` |
+| [controller.nodeSelector](./values.yaml#L676) | object | Node labels for pod assignment | `{}` |
+| [controller.numExecutors](./values.yaml#L72) | int | Set Number of executors | `0` |
+| [controller.overwritePlugins](./values.yaml#L443) | bool | Overwrite installed plugins on start | `false` |
+| [controller.overwritePluginsFromImage](./values.yaml#L447) | bool | Overwrite plugins that are already installed in the controller image | `true` |
+| [controller.podAnnotations](./values.yaml#L697) | object | Annotations for controller pod | `{}` |
+| [controller.podDisruptionBudget.annotations](./values.yaml#L337) | object |  | `{}` |
+| [controller.podDisruptionBudget.apiVersion](./values.yaml#L335) | string | Policy API version | `"policy/v1beta1"` |
+| [controller.podDisruptionBudget.enabled](./values.yaml#L330) | bool | Enable Kubernetes Pod Disruption Budget configuration | `false` |
+| [controller.podDisruptionBudget.labels](./values.yaml#L338) | object |  | `{}` |
+| [controller.podDisruptionBudget.maxUnavailable](./values.yaml#L340) | string | Number of pods that can be unavailable. Either an absolute number or a percentage | `"0"` |
+| [controller.podLabels](./values.yaml#L266) | object | Custom Pod labels (an object with `label-key: label-value` pairs) | `{}` |
+| [controller.podSecurityContextOverride](./values.yaml#L220) | string | Completely overwrites the contents of the pod security context, ignoring the values provided for `runAsUser`, `fsGroup`, and `securityContextCapabilities` | `nil` |
+| [controller.priorityClassName](./values.yaml#L694) | string | The name of a `priorityClass` to apply to the controller pod | `nil` |
+| [controller.probes.livenessProbe.failureThreshold](./values.yaml#L291) | int | Set the failure threshold for the liveness probe | `5` |
+| [controller.probes.livenessProbe.httpGet.path](./values.yaml#L294) | string | Set the Pod's HTTP path for the liveness probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
+| [controller.probes.livenessProbe.httpGet.port](./values.yaml#L296) | string | Set the Pod's HTTP port to use for the liveness probe | `"http"` |
+| [controller.probes.livenessProbe.initialDelaySeconds](./values.yaml#L305) | string | Set the initial delay for the liveness probe in seconds | `nil` |
+| [controller.probes.livenessProbe.periodSeconds](./values.yaml#L298) | int | Set the time interval between two liveness probes executions in seconds | `10` |
+| [controller.probes.livenessProbe.timeoutSeconds](./values.yaml#L300) | int | Set the timeout for the liveness probe in seconds | `5` |
+| [controller.probes.readinessProbe.failureThreshold](./values.yaml#L309) | int | Set the failure threshold for the readiness probe | `3` |
+| [controller.probes.readinessProbe.httpGet.path](./values.yaml#L312) | string | Set the Pod's HTTP path for the liveness probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
+| [controller.probes.readinessProbe.httpGet.port](./values.yaml#L314) | string | Set the Pod's HTTP port to use for the readiness probe | `"http"` |
+| [controller.probes.readinessProbe.initialDelaySeconds](./values.yaml#L323) | string | Set the initial delay for the readiness probe in seconds | `nil` |
+| [controller.probes.readinessProbe.periodSeconds](./values.yaml#L316) | int | Set the time interval between two readiness probes executions in seconds | `10` |
+| [controller.probes.readinessProbe.timeoutSeconds](./values.yaml#L318) | int | Set the timeout for the readiness probe in seconds | `5` |
+| [controller.probes.startupProbe.failureThreshold](./values.yaml#L278) | int | Set the failure threshold for the startup probe | `12` |
+| [controller.probes.startupProbe.httpGet.path](./values.yaml#L281) | string | Set the Pod's HTTP path for the startup probe | `"{{ default \"\" .Values.controller.jenkinsUriPrefix }}/login"` |
+| [controller.probes.startupProbe.httpGet.port](./values.yaml#L283) | string | Set the Pod's HTTP port to use for the startup probe | `"http"` |
+| [controller.probes.startupProbe.periodSeconds](./values.yaml#L285) | int | Set the time interval between two startup probes executions in seconds | `10` |
+| [controller.probes.startupProbe.timeoutSeconds](./values.yaml#L287) | int | Set the timeout for the startup probe in seconds | `5` |
+| [controller.projectNamingStrategy](./values.yaml#L450) | string |  | `"standard"` |
+| [controller.prometheus.alertingRulesAdditionalLabels](./values.yaml#L879) | object | Additional labels to add to the PrometheusRule object | `{}` |
+| [controller.prometheus.alertingrules](./values.yaml#L877) | list | Array of prometheus alerting rules | `[]` |
+| [controller.prometheus.enabled](./values.yaml#L862) | bool | Enables prometheus service monitor | `false` |
+| [controller.prometheus.metricRelabelings](./values.yaml#L889) | list |  | `[]` |
+| [controller.prometheus.prometheusRuleNamespace](./values.yaml#L881) | string | Set a custom namespace where to deploy PrometheusRule resource | `""` |
+| [controller.prometheus.relabelings](./values.yaml#L887) | list |  | `[]` |
+| [controller.prometheus.scrapeEndpoint](./values.yaml#L872) | string | The endpoint prometheus should get metrics from | `"/prometheus"` |
+| [controller.prometheus.scrapeInterval](./values.yaml#L868) | string | How often prometheus should scrape metrics | `"60s"` |
+| [controller.prometheus.serviceMonitorAdditionalLabels](./values.yaml#L864) | object | Additional labels to add to the service monitor object | `{}` |
+| [controller.prometheus.serviceMonitorNamespace](./values.yaml#L866) | string | Set a custom namespace where to deploy ServiceMonitor resource | `nil` |
+| [controller.publishNotReadyAddresses](./values.yaml#L252) | string |  | `nil` |
+| [controller.replicas](./values.yaml#L56) | int | Number of replicas. Max 1. Can be set to 0 for maintenance scenarios. | `1` |
+| [controller.resources](./values.yaml#L124) | object | Resource allocation (Requests and Limits) | `{"limits":{"cpu":"2000m","memory":"4096Mi"},"requests":{"cpu":"50m","memory":"256Mi"}}` |
+| [controller.route.annotations](./values.yaml#L822) | object | Route annotations | `{}` |
+| [controller.route.enabled](./values.yaml#L818) | bool | Enables openshift route | `false` |
+| [controller.route.labels](./values.yaml#L820) | object | Route labels | `{}` |
+| [controller.route.path](./values.yaml#L824) | string | Route path | `nil` |
+| [controller.runAsUser](./values.yaml#L198) | int | Deprecated in favor of `controller.podSecurityContextOverride`. uid that jenkins runs with. | `1000` |
+| [controller.schedulerName](./values.yaml#L672) | string | Name of the Kubernetes scheduler to use | `""` |
+| [controller.scriptApproval](./values.yaml#L462) | list | List of groovy functions to approve | `[]` |
+| [controller.secondaryingress.annotations](./values.yaml#L782) | object | Secondary Ingress annotations | `{}` |
+| [controller.secondaryingress.apiVersion](./values.yaml#L778) | string | Secondary Ingress API version | `"networking.k8s.io/v1"` |
+| [controller.secondaryingress.enabled](./values.yaml#L768) | bool | Enables the Secondary Ingress | `false` |
+| [controller.secondaryingress.hostName](./values.yaml#L791) | string | Secondary Ingress hostname | `nil` |
+| [controller.secondaryingress.ingressClassName](./values.yaml#L788) | string | Secondary Ingress ingressClassName | `nil` |
+| [controller.secondaryingress.labels](./values.yaml#L780) | object | Secondary Ingress labels | `{}` |
+| [controller.secondaryingress.pathType](./values.yaml#L774) | string | Secondary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix | `"ImplementationSpecific"` |
+| [controller.secondaryingress.paths](./values.yaml#L772) | list | Secondary Ingress paths | `[]` |
+| [controller.secondaryingress.tls](./values.yaml#L793) | string | Secondary Ingress TLS configuration | `nil` |
+| [controller.secretClaims](./values.yaml#L505) | list | List of `SecretClaim` resources to create | `[]` |
+| [controller.securityContextCapabilities](./values.yaml#L210) | object |  | `{}` |
+| [controller.serviceAnnotations](./values.yaml#L255) | object | Jenkins controller service annotations | `{}` |
+| [controller.serviceEnabled](./values.yaml#L230) | bool | enable or disable the controller k8s service | `true` |
+| [controller.serviceExternalTrafficPolicy](./values.yaml#L248) | string |  | `nil` |
+| [controller.serviceLabels](./values.yaml#L261) | object | Labels for the Jenkins controller-service | `{}` |
+| [controller.servicePort](./values.yaml#L240) | int | k8s service port | `8080` |
+| [controller.serviceType](./values.yaml#L235) | string | k8s service type | `"ClusterIP"` |
+| [controller.shareProcessNamespace](./values.yaml#L133) | bool |  | `false` |
+| [controller.sidecars.additionalSidecarContainers](./values.yaml#L654) | list | Configures additional sidecar container(s) for the Jenkins controller | `[]` |
+| [controller.sidecars.configAutoReload.additionalVolumeMounts](./values.yaml#L599) | list | Enables additional volume mounts for the config auto-reload container | `[]` |
+| [controller.sidecars.configAutoReload.containerSecurityContext](./values.yaml#L649) | object | Enable container security context | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true}` |
+| [controller.sidecars.configAutoReload.enabled](./values.yaml#L579) | bool | Enable Jenkins Config as Code auto-reload | `true` |
+| [controller.sidecars.configAutoReload.env](./values.yaml#L631) | list | Environment variables for the Jenkins Config as Code auto-reload container | `[]` |
+| [controller.sidecars.configAutoReload.envFrom](./values.yaml#L629) | list | Environment variable sources for the Jenkins Config as Code auto-reload container | `[]` |
+| [controller.sidecars.configAutoReload.folder](./values.yaml#L642) | string |  | `"/var/jenkins_home/casc_configs"` |
+| [controller.sidecars.configAutoReload.healthPort](./values.yaml#L589) | int | Port for sidecar health probes | `8060` |
+| [controller.sidecars.configAutoReload.image.registry](./values.yaml#L582) | string | Registry for the image that triggers the reload | `"docker.io"` |
+| [controller.sidecars.configAutoReload.image.repository](./values.yaml#L584) | string | Repository of the image that triggers the reload | `"kiwigrid/k8s-sidecar"` |
+| [controller.sidecars.configAutoReload.image.tag](./values.yaml#L586) | string | Tag for the image that triggers the reload | `"2.8.1"` |
+| [controller.sidecars.configAutoReload.imagePullPolicy](./values.yaml#L587) | string |  | `"IfNotPresent"` |
+| [controller.sidecars.configAutoReload.logging](./values.yaml#L606) | object | Config auto-reload logging settings | `{"configuration":{"backupCount":3,"formatter":"JSON","logLevel":"INFO","logToConsole":true,"logToFile":false,"maxBytes":1024,"override":false}}` |
+| [controller.sidecars.configAutoReload.logging.configuration.override](./values.yaml#L610) | bool | Enables custom log config utilizing using the settings below. | `false` |
+| [controller.sidecars.configAutoReload.reqRetryConnect](./values.yaml#L624) | int | How many connection-related errors to retry on | `10` |
+| [controller.sidecars.configAutoReload.resources](./values.yaml#L590) | object |  | `{}` |
+| [controller.sidecars.configAutoReload.scheme](./values.yaml#L619) | string | The scheme to use when connecting to the Jenkins configuration as code endpoint | `"http"` |
+| [controller.sidecars.configAutoReload.skipTlsVerify](./values.yaml#L621) | bool | Skip TLS verification when connecting to the Jenkins configuration as code endpoint | `false` |
+| [controller.sidecars.configAutoReload.sleepTime](./values.yaml#L626) | string | How many seconds to wait before updating config-maps/secrets (sets METHOD=SLEEP on the sidecar) | `nil` |
+| [controller.sidecars.configAutoReload.sshTcpPort](./values.yaml#L640) | int |  | `1044` |
+| [controller.statefulSetAnnotations](./values.yaml#L699) | object | Annotations for controller StatefulSet | `{}` |
+| [controller.statefulSetLabels](./values.yaml#L257) | object | Jenkins controller custom labels for the StatefulSet | `{}` |
+| [controller.targetPort](./values.yaml#L242) | int | k8s target port | `8080` |
+| [controller.terminationGracePeriodSeconds](./values.yaml#L682) | string | Set TerminationGracePeriodSeconds | `nil` |
+| [controller.terminationMessagePath](./values.yaml#L684) | string | Set the termination message path | `nil` |
+| [controller.terminationMessagePolicy](./values.yaml#L686) | string | Set the termination message policy | `nil` |
+| [controller.testEnabled](./values.yaml#L901) | bool | Can be used to disable rendering controller test resources when using helm template | `true` |
+| [controller.tolerations](./values.yaml#L680) | list | Toleration labels for pod assignment | `[]` |
+| [controller.topologySpreadConstraints](./values.yaml#L706) | list | Topology spread constraints | `[]` |
+| [controller.updateStrategy](./values.yaml#L703) | object | Update strategy for StatefulSet | `{}` |
+| [controller.usePodSecurityContext](./values.yaml#L191) | bool | Enable pod security context (must be `true` if podSecurityContextOverride, runAsUser or fsGroup are set) | `true` |
 | [credentialsId](./values.yaml#L27) | string | The Jenkins credentials to access the Kubernetes API server. For the default cluster it is not needed. | `nil` |
+| [extraLabels](./values.yaml#L33) | object | Configures extra labels for the agent all objects | `{}` |
+| [extraObjects](./values.yaml#L36) | string | Configures extra manifests | `nil` |
 | [fullnameOverride](./values.yaml#L13) | string | Override the full resource names | `jenkins-(release-name)` or `jenkins` if the release-name is `jenkins` |
-| [helmtest.bats.image.registry](./values.yaml#L1302) | string | Registry of the image used to test the framework | `"docker.io"` |
-| [helmtest.bats.image.repository](./values.yaml#L1304) | string | Repository of the image used to test the framework | `"bats/bats"` |
-| [helmtest.bats.image.tag](./values.yaml#L1306) | string | Tag of the image to test the framework | `"1.11.0"` |
+| [helmtest.bats.image.registry](./values.yaml#L1433) | string | Registry of the image used to test the framework | `"docker.io"` |
+| [helmtest.bats.image.repository](./values.yaml#L1435) | string | Repository of the image used to test the framework | `"bats/bats"` |
+| [helmtest.bats.image.tag](./values.yaml#L1437) | string | Tag of the image to test the framework | `"1.13.0"` |
 | [kubernetesURL](./values.yaml#L24) | string | The URL of the Kubernetes API server | `"https://kubernetes.default"` |
 | [nameOverride](./values.yaml#L10) | string | Override the resource name prefix | `Chart.Name` |
 | [namespaceOverride](./values.yaml#L16) | string | Override the deployment namespace | `Release.Namespace` |
-| [networkPolicy.apiVersion](./values.yaml#L1232) | string | NetworkPolicy ApiVersion | `"networking.k8s.io/v1"` |
-| [networkPolicy.enabled](./values.yaml#L1227) | bool | Enable the creation of NetworkPolicy resources | `false` |
-| [networkPolicy.externalAgents.except](./values.yaml#L1246) | list | A list of IP sub-ranges to be excluded from the allowlisted IP range | `[]` |
-| [networkPolicy.externalAgents.ipCIDR](./values.yaml#L1244) | string | The IP range from which external agents are allowed to connect to controller, i.e., 172.17.0.0/16 | `nil` |
-| [networkPolicy.internalAgents.allowed](./values.yaml#L1236) | bool | Allow internal agents (from the same cluster) to connect to controller. Agent pods will be filtered based on PodLabels | `true` |
-| [networkPolicy.internalAgents.namespaceLabels](./values.yaml#L1240) | object | A map of labels (keys/values) that agents namespaces must have to be able to connect to controller | `{}` |
-| [networkPolicy.internalAgents.podLabels](./values.yaml#L1238) | object | A map of labels (keys/values) that agent pods must have to be able to connect to controller | `{}` |
-| [persistence.accessMode](./values.yaml#L1202) | string | The PVC access mode | `"ReadWriteOnce"` |
-| [persistence.annotations](./values.yaml#L1198) | object | Annotations for the PVC | `{}` |
-| [persistence.dataSource](./values.yaml#L1208) | object | Existing data source to clone PVC from | `{}` |
-| [persistence.enabled](./values.yaml#L1182) | bool | Enable the use of a Jenkins PVC | `true` |
-| [persistence.existingClaim](./values.yaml#L1188) | string | Provide the name of a PVC | `nil` |
-| [persistence.labels](./values.yaml#L1200) | object | Labels for the PVC | `{}` |
-| [persistence.mounts](./values.yaml#L1220) | list | Additional mounts | `[]` |
-| [persistence.size](./values.yaml#L1204) | string | The size of the PVC | `"8Gi"` |
-| [persistence.storageClass](./values.yaml#L1196) | string | Storage class for the PVC | `nil` |
-| [persistence.subPath](./values.yaml#L1213) | string | SubPath for jenkins-home mount | `nil` |
-| [persistence.volumes](./values.yaml#L1215) | list | Additional volumes | `[]` |
-| [rbac.create](./values.yaml#L1252) | bool | Whether RBAC resources are created | `true` |
-| [rbac.readSecrets](./values.yaml#L1254) | bool | Whether the Jenkins service account should be able to read Kubernetes secrets | `false` |
+| [networkPolicy.apiVersion](./values.yaml#L1356) | string | NetworkPolicy ApiVersion | `"networking.k8s.io/v1"` |
+| [networkPolicy.enabled](./values.yaml#L1351) | bool | Enable the creation of NetworkPolicy resources | `false` |
+| [networkPolicy.externalAgents.except](./values.yaml#L1371) | list | A list of IP sub-ranges to be excluded from the allowlisted IP range | `[]` |
+| [networkPolicy.externalAgents.ipCIDR](./values.yaml#L1369) | string | The IP range from which external agents are allowed to connect to controller, i.e., 172.17.0.0/16 | `nil` |
+| [networkPolicy.internalAgents.allowed](./values.yaml#L1360) | bool | Allow internal agents (from the same cluster) to connect to controller. Agent pods will be filtered based on PodLabels | `true` |
+| [networkPolicy.internalAgents.namespaceLabels](./values.yaml#L1364) | object | A map of labels (keys/values) that agents namespaces must have to be able to connect to controller | `{}` |
+| [networkPolicy.internalAgents.podLabels](./values.yaml#L1362) | object | A map of labels (keys/values) that agent pods must have to be able to connect to controller | `{}` |
+| [persistence.accessMode](./values.yaml#L1326) | string | The PVC access mode | `"ReadWriteOnce"` |
+| [persistence.annotations](./values.yaml#L1322) | object | Annotations for the PVC | `{}` |
+| [persistence.dataSource](./values.yaml#L1332) | object | Existing data source to clone PVC from | `{}` |
+| [persistence.enabled](./values.yaml#L1306) | bool | Enable the use of a Jenkins PVC | `true` |
+| [persistence.existingClaim](./values.yaml#L1312) | string | Provide the name of a PVC | `nil` |
+| [persistence.labels](./values.yaml#L1324) | object | Labels for the PVC | `{}` |
+| [persistence.mounts](./values.yaml#L1344) | list | Additional mounts | `[]` |
+| [persistence.size](./values.yaml#L1328) | string | The size of the PVC | `"8Gi"` |
+| [persistence.storageClass](./values.yaml#L1320) | string | Storage class for the PVC | `nil` |
+| [persistence.subPath](./values.yaml#L1337) | string | SubPath for jenkins-home mount | `nil` |
+| [persistence.volumes](./values.yaml#L1339) | list | Additional volumes | `[]` |
+| [rbac.create](./values.yaml#L1378) | bool | Whether RBAC resources are created | `true` |
+| [rbac.readSecrets](./values.yaml#L1380) | bool | Whether the Jenkins service account should be able to read Kubernetes secrets | `false` |
+| [rbac.useOpenShiftNonRootSCC](./values.yaml#L1382) | bool | Whether the Jenkins service account should be able to use the OpenShift "nonroot" Security Context Constraints | `false` |
 | [renderHelmLabels](./values.yaml#L30) | bool | Enables rendering of the helm.sh/chart label to the annotations | `true` |
-| [serviceAccount.annotations](./values.yaml#L1264) | object | Configures annotations for the ServiceAccount | `{}` |
-| [serviceAccount.create](./values.yaml#L1258) | bool | Configures if a ServiceAccount with this name should be created | `true` |
-| [serviceAccount.extraLabels](./values.yaml#L1266) | object | Configures extra labels for the ServiceAccount | `{}` |
-| [serviceAccount.imagePullSecretName](./values.yaml#L1268) | string | Controller ServiceAccount image pull secret | `nil` |
-| [serviceAccount.name](./values.yaml#L1262) | string |  | `nil` |
-| [serviceAccountAgent.annotations](./values.yaml#L1279) | object | Configures annotations for the agent ServiceAccount | `{}` |
-| [serviceAccountAgent.create](./values.yaml#L1273) | bool | Configures if an agent ServiceAccount should be created | `false` |
-| [serviceAccountAgent.extraLabels](./values.yaml#L1281) | object | Configures extra labels for the agent ServiceAccount | `{}` |
-| [serviceAccountAgent.imagePullSecretName](./values.yaml#L1283) | string | Agent ServiceAccount image pull secret | `nil` |
-| [serviceAccountAgent.name](./values.yaml#L1277) | string | The name of the agent ServiceAccount to be used by access-controlled resources | `nil` |
+| [serviceAccount.annotations](./values.yaml#L1392) | object | Configures annotations for the ServiceAccount | `{}` |
+| [serviceAccount.automountServiceAccountToken](./values.yaml#L1398) | bool | Auto-mount ServiceAccount token | `true` |
+| [serviceAccount.create](./values.yaml#L1386) | bool | Configures if a ServiceAccount with this name should be created | `true` |
+| [serviceAccount.extraLabels](./values.yaml#L1394) | object | Configures extra labels for the ServiceAccount | `{}` |
+| [serviceAccount.imagePullSecretName](./values.yaml#L1396) | string | Controller ServiceAccount image pull secret | `nil` |
+| [serviceAccount.name](./values.yaml#L1390) | string |  | `nil` |
+| [serviceAccountAgent.annotations](./values.yaml#L1408) | object | Configures annotations for the agent ServiceAccount | `{}` |
+| [serviceAccountAgent.automountServiceAccountToken](./values.yaml#L1414) | bool | Auto-mount ServiceAccount token | `true` |
+| [serviceAccountAgent.create](./values.yaml#L1402) | bool | Configures if an agent ServiceAccount should be created | `false` |
+| [serviceAccountAgent.extraLabels](./values.yaml#L1410) | object | Configures extra labels for the agent ServiceAccount | `{}` |
+| [serviceAccountAgent.imagePullSecretName](./values.yaml#L1412) | string | Agent ServiceAccount image pull secret | `nil` |
+| [serviceAccountAgent.name](./values.yaml#L1406) | string | The name of the agent ServiceAccount to be used by access-controlled resources | `nil` |
diff --git a/charts/jenkins/templates/_helpers.tpl b/charts/jenkins/templates/_helpers.tpl
index 8301a84..33b2d13 100644
--- a/charts/jenkins/templates/_helpers.tpl
+++ b/charts/jenkins/templates/_helpers.tpl
@@ -13,6 +13,21 @@
 {{- printf "%s-%s" (include "jenkins.name" .) .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
 {{- end -}}
 
+{{/*
+Common labels for all Jenkins resources
+*/}}
+{{- define "jenkins.labels" -}}
+"app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
+"app.kubernetes.io/managed-by": "{{ .Release.Service }}"
+"app.kubernetes.io/instance": "{{ .Release.Name }}"
+"app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+{{- if .Values.renderHelmLabels }}
+"helm.sh/chart": "{{ template "jenkins.label" .}}"
+{{- end }}
+{{- with .Values.extraLabels }}
+{{- toYaml . | nindent 0 }}
+{{- end }}
+{{- end -}}
 
 {{/*
 Allow the release namespace to be overridden for multi-namespace deployments in combined charts.
@@ -140,6 +155,14 @@
   clouds:
   - kubernetes:
       containerCapStr: "{{ .Values.agent.containerCap }}"
+      {{- if .Values.agent.garbageCollection.enabled }}
+      garbageCollection:
+        {{- if .Values.agent.garbageCollection.namespaces }}
+        namespaces: |-
+          {{- .Values.agent.garbageCollection.namespaces | nindent 10 }}
+        {{- end }}
+        timeout: "{{ .Values.agent.garbageCollection.timeout }}"
+      {{- end }}
       {{- if .Values.agent.jnlpregistry }}
       jnlpregistry: "{{ .Values.agent.jnlpregistry }}"
       {{- end }}
@@ -164,6 +187,8 @@
       webSocket: true
       {{- end }}
       {{- end }}
+      skipTlsVerify: {{ .Values.agent.skipTlsVerify | default false}}
+      usageRestricted: {{ .Values.agent.usageRestricted | default false}}
       maxRequestsPerHostStr: {{ .Values.agent.maxRequestsPerHostStr | quote }}
       retentionTimeout: {{ .Values.agent.retentionTimeout | quote }}
       waitForPodSec: {{ .Values.agent.waitForPodSec | quote }}
@@ -171,6 +196,7 @@
       namespace: "{{ template "jenkins.agent.namespace" . }}"
       restrictedPssSecurityContext: {{ .Values.agent.restrictedPssSecurityContext }}
       serverUrl: "{{ .Values.kubernetesURL }}"
+      addMasterProxyEnvVars: {{ .Values.agent.addMasterProxyEnvVars | default false }}
       credentialsId: "{{ .Values.credentialsId }}"
       {{- if .Values.agent.enabled }}
       podLabels:
@@ -189,8 +215,18 @@
       {{- $agent := .Values.agent }}
       {{- range $name, $additionalAgent := .Values.additionalAgents }}
         {{- $additionalContainersEmpty := and (hasKey $additionalAgent "additionalContainers") (empty $additionalAgent.additionalContainers)  }}
+        {{- $runAsUser := $additionalAgent.runAsUser }}
+        {{- $runAsUserSet := not (kindIs "invalid" $runAsUser) }}
+        {{- $runAsGroup := $additionalAgent.runAsGroup }}
+        {{- $runAsGroupSet := not (kindIs "invalid" $runAsGroup) }}
         {{- /* merge original .Values.agent into additional agent to ensure it at least has the default values */}}
         {{- $additionalAgent := merge $additionalAgent $agent }}
+        {{- if $runAsUserSet }}
+        {{- $_ := set $additionalAgent "runAsUser" $runAsUser }}
+        {{- end }}
+        {{- if $runAsGroupSet }}
+        {{- $_ := set $additionalAgent "runAsGroup" $runAsGroup }}
+        {{- end }}
         {{- /* clear list of additional containers in case it is configured empty for this agent (merge might have overwritten that) */}}
         {{- if $additionalContainersEmpty }}
         {{- $_ := set $additionalAgent "additionalContainers" list }}
@@ -224,6 +260,14 @@
       {{- with $newRoot}}
   - kubernetes:
       containerCapStr: "{{ .Values.agent.containerCap }}"
+      {{- if .Values.agent.garbageCollection.enabled }}
+      garbageCollection:
+        {{- if .Values.agent.garbageCollection.namespaces }}
+        namespaces: |-
+          {{- .Values.agent.garbageCollection.namespaces | nindent 10 }}
+        {{- end }}
+        timeout: "{{ .Values.agent.garbageCollection.timeout }}"
+      {{- end }}
       {{- if .Values.agent.jnlpregistry }}
       jnlpregistry: "{{ .Values.agent.jnlpregistry }}"
       {{- end }}
@@ -248,6 +292,8 @@
       webSocket: true
       {{- end }}
       {{- end }}
+      skipTlsVerify: {{ .Values.agent.skipTlsVerify | default false}}
+      usageRestricted: {{ .Values.agent.usageRestricted | default false}}
       maxRequestsPerHostStr: {{ .Values.agent.maxRequestsPerHostStr | quote }}
       retentionTimeout: {{ .Values.agent.retentionTimeout | quote }}
       waitForPodSec: {{ .Values.agent.waitForPodSec | quote }}
@@ -273,8 +319,18 @@
        {{- $agent := .Values.agent }}
        {{- range $name, $additionalAgent := .Values.additionalAgents }}
          {{- $additionalContainersEmpty := and (hasKey $additionalAgent "additionalContainers") (empty $additionalAgent.additionalContainers)  }}
+         {{- $runAsUser := $additionalAgent.runAsUser }}
+         {{- $runAsUserSet := not (kindIs "invalid" $runAsUser) }}
+         {{- $runAsGroup := $additionalAgent.runAsGroup }}
+         {{- $runAsGroupSet := not (kindIs "invalid" $runAsGroup) }}
          {{- /* merge original .Values.agent into additional agent to ensure it at least has the default values */}}
          {{- $additionalAgent := merge $additionalAgent $agent }}
+         {{- if $runAsUserSet }}
+         {{- $_ := set $additionalAgent "runAsUser" $runAsUser }}
+         {{- end }}
+         {{- if $runAsGroupSet }}
+         {{- $_ := set $additionalAgent "runAsGroup" $runAsGroup }}
+         {{- end }}
          {{- /* clear list of additional containers in case it is configured empty for this agent (merge might have overwritten that) */}}
          {{- if $additionalContainersEmpty }}
          {{- $_ := set $additionalAgent "additionalContainers" list }}
@@ -297,7 +353,8 @@
   {{- /* restore root */}}
   {{- $_ := set $ "Values" $oldRoot.Values }}
   {{- end }}
-  {{- if .Values.controller.csrf.defaultCrumbIssuer.enabled }}
+  slaveAgentPort: {{ .Values.controller.agentListenerPort }}
+  {{- if and .Values.controller.csrf.defaultCrumbIssuer.enabled (eq .Chart.AppVersion (index (splitList "-" (include "controller.image.tag" .)) 0)) (lt (atoi (index (splitList "." .Chart.AppVersion) 1)) 543) }}
   crumbIssuer:
     standard:
       excludeClientIPFromCrumb: {{ if .Values.controller.csrf.defaultCrumbIssuer.proxyCompatability }}true{{ else }}false{{- end }}
@@ -366,7 +423,11 @@
           value: "http://{{ template "jenkins.fullname" . }}.{{ template "jenkins.namespace" . }}.svc.{{.Values.clusterZone}}:{{.Values.controller.servicePort}}{{ default "/" .Values.controller.jenkinsUriPrefix }}"
           {{- end }}
         {{- end }}
-    image: "{{ .Values.agent.image.repository }}:{{ .Values.agent.image.tag }}"
+    {{- if ne .Values.agent.image.registry "" }}
+    image: "{{ tpl .Values.agent.image.registry . }}/{{ tpl .Values.agent.image.repository . }}:{{ tpl .Values.agent.image.tag . }}"
+    {{- else }}
+    image: "{{ tpl .Values.agent.image.repository . }}:{{ tpl .Values.agent.image.tag . }}"
+    {{- end }}
     {{- if .Values.agent.livenessProbe }}
     livenessProbe:
       execArgs: {{.Values.agent.livenessProbe.execArgs | quote}}
@@ -387,11 +448,11 @@
     {{- with .Values.agent.resources.requests.ephemeralStorage }}
     resourceRequestEphemeralStorage: {{.}}
     {{- end }}
-    {{- with .Values.agent.runAsUser }}
-    runAsUser: {{ . }}
+    {{- if not (kindIs "invalid" .Values.agent.runAsUser) }}
+    runAsUser: {{ .Values.agent.runAsUser }}
     {{- end }}
-    {{- with .Values.agent.runAsGroup }}
-    runAsGroup: {{ . }}
+    {{- if not (kindIs "invalid" .Values.agent.runAsGroup) }}
+    runAsGroup: {{ .Values.agent.runAsGroup }}
     {{- end }}
     ttyEnabled: {{ .Values.agent.TTYEnabled }}
     workingDir: {{ .Values.agent.workingDir }}
@@ -425,11 +486,15 @@
     resourceLimitMemory: {{ if $additionalContainers.resources }}{{ $additionalContainers.resources.limits.memory }}{{ else }}{{ $.Values.agent.resources.limits.memory }}{{ end }}
     resourceRequestCpu: {{ if $additionalContainers.resources }}{{ $additionalContainers.resources.requests.cpu }}{{ else }}{{ $.Values.agent.resources.requests.cpu }}{{ end }}
     resourceRequestMemory: {{ if $additionalContainers.resources }}{{ $additionalContainers.resources.requests.memory }}{{ else }}{{ $.Values.agent.resources.requests.memory }}{{ end }}
-    {{- if or $additionalContainers.runAsUser $.Values.agent.runAsUser }}
-    runAsUser: {{ $additionalContainers.runAsUser | default $.Values.agent.runAsUser }}
+    {{- if not (kindIs "invalid" $additionalContainers.runAsUser) }}
+    runAsUser: {{ $additionalContainers.runAsUser }}
+    {{- else if not (kindIs "invalid" $.Values.agent.runAsUser) }}
+    runAsUser: {{ $.Values.agent.runAsUser }}
     {{- end }}
-    {{- if or $additionalContainers.runAsGroup $.Values.agent.runAsGroup }}
-    runAsGroup: {{ $additionalContainers.runAsGroup | default $.Values.agent.runAsGroup }}
+    {{- if not (kindIs "invalid" $additionalContainers.runAsGroup) }}
+    runAsGroup: {{ $additionalContainers.runAsGroup }}
+    {{- else if not (kindIs "invalid" $.Values.agent.runAsGroup) }}
+    runAsGroup: {{ $.Values.agent.runAsGroup }}
     {{- end }}
     ttyEnabled: {{ $additionalContainers.TTYEnabled | default $.Values.agent.TTYEnabled }}
     workingDir: {{ $additionalContainers.workingDir | default $.Values.agent.workingDir }}
@@ -450,7 +515,7 @@
   {{- end }}
 {{- end }}
   idleMinutes: {{ .Values.agent.idleMinutes }}
-  instanceCap: 2147483647
+  instanceCap: {{ int .Values.agent.instanceCap }}
   {{- if .Values.agent.hostNetworking }}
   hostNetwork: {{ .Values.agent.hostNetworking }}
   {{- end }}
@@ -471,7 +536,10 @@
   nodeUsageMode: {{ quote .Values.agent.nodeUsageMode }}
   podRetention: {{ .Values.agent.podRetention }}
   showRawYaml: {{ .Values.agent.showRawYaml }}
-  serviceAccount: "{{ include "jenkins.serviceAccountAgentName" . }}"
+{{- $asaname := default (include "jenkins.serviceAccountAgentName" .) .Values.agent.serviceAccount -}}
+{{- if or (.Values.agent.useDefaultServiceAccount) (.Values.agent.serviceAccount) }}
+  serviceAccount: "{{ $asaname }}"
+{{- end }}
   slaveConnectTimeoutStr: "{{ .Values.agent.connectTimeout }}"
 {{- if .Values.agent.volumes }}
   volumes:
@@ -520,6 +588,7 @@
     {{- tpl (trim .Values.agent.yamlTemplate) . | nindent 4 }}
 {{- end }}
   yamlMergeStrategy: {{ .Values.agent.yamlMergeStrategy }}
+  inheritYamlMergeStrategy: {{ .Values.agent.inheritYamlMergeStrategy }}
 {{- end -}}
 
 {{- define "jenkins.kubernetes-version" -}}
@@ -607,6 +676,8 @@
           fieldPath: metadata.name
     - name: LABEL
       value: "{{ template "jenkins.fullname" $root }}-jenkins-config"
+    - name: HEALTH_PORT
+      value: "{{ $root.Values.controller.sidecars.configAutoReload.healthPort }}"
     - name: FOLDER
       value: "{{ $root.Values.controller.sidecars.configAutoReload.folder }}"
     - name: NAMESPACE
@@ -640,6 +711,10 @@
         {{- end -}}
     {{- end -}}
     {{- end }}
+    {{- if $root.Values.controller.sidecars.configAutoReload.logging.configuration.override }}
+    - name: LOG_CONFIG
+      value: "{{ $root.Values.controller.jenkinsHome }}/auto-reload/auto-reload-config.yaml"
+    {{- end }}
 
   resources:
 {{ toYaml $root.Values.controller.sidecars.configAutoReload.resources | indent 4 }}
@@ -651,5 +726,24 @@
       {{- if $root.Values.persistence.subPath }}
       subPath: {{ $root.Values.persistence.subPath }}
       {{- end }}
+    - name: tmp-volume
+      mountPath: /tmp
+    {{- if $root.Values.controller.sidecars.configAutoReload.logging.configuration.override }}
+    - name: auto-reload-config
+      mountPath: {{ $root.Values.controller.jenkinsHome }}/auto-reload
+    - name: auto-reload-config-logs
+      mountPath: {{ $root.Values.controller.jenkinsHome }}/auto-reload-logs
+    {{- end }}
+    {{- if $root.Values.controller.sidecars.configAutoReload.additionalVolumeMounts }}
+{{ (tpl (toYaml $root.Values.controller.sidecars.configAutoReload.additionalVolumeMounts) $root) | indent 4 }}
+    {{- end }}
 
 {{- end -}}
+
+{{- define "controller.replicas" -}}
+{{- $replicas := int (default 1 .Values.controller.replicas) -}}
+{{- if or (lt $replicas 0) (gt $replicas 1) -}}
+{{- fail "controller.replicas must be 0 or 1" -}}
+{{- end -}}
+{{- .Values.controller.replicas -}}
+{{- end -}}
diff --git a/charts/jenkins/templates/auto-reload-config.yaml b/charts/jenkins/templates/auto-reload-config.yaml
new file mode 100644
index 0000000..6b9ed27
--- /dev/null
+++ b/charts/jenkins/templates/auto-reload-config.yaml
@@ -0,0 +1,54 @@
+{{- if .Values.controller.sidecars.configAutoReload.logging.configuration.override }}
+apiVersion: v1
+kind: ConfigMap
+metadata:
+  name: {{ template "jenkins.fullname" . }}-auto-reload-config
+  namespace: {{ template "jenkins.namespace" . }}
+  labels:
+    {{ include "jenkins.labels" . | nindent 4 }}
+data:
+  auto-reload-config.yaml: |-
+    version: 1
+    disable_existing_loggers: false
+    root:
+      level: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.logLevel }}
+      handlers:
+        {{- if .Values.controller.sidecars.configAutoReload.logging.configuration.logToConsole}}
+        - console
+        {{- end }}
+        {{- if .Values.controller.sidecars.configAutoReload.logging.configuration.logToFile }}
+        - file
+        {{- end }}
+    handlers:
+      {{- if .Values.controller.sidecars.configAutoReload.logging.configuration.logToConsole}}
+      console:
+        class: logging.StreamHandler
+        level: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.logLevel }}
+        formatter: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.formatter }}
+      {{- end }}
+      {{- if .Values.controller.sidecars.configAutoReload.logging.configuration.logToFile }}
+      file:
+        class : logging.handlers.RotatingFileHandler
+        formatter: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.formatter }}
+        filename: {{ .Values.controller.jenkinsHome }}/auto-reload-logs/file.log
+        maxBytes: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.maxBytes }}
+        backupCount: {{ .Values.controller.sidecars.configAutoReload.logging.configuration.backupCount }}
+      {{- end }}
+    formatters:
+      JSON:
+        "()": logger.JsonFormatter
+        format: "%(levelname)s %(message)s"
+        rename_fields:
+          message: msg
+          levelname: level
+      LOGFMT:
+        "()": logger.LogfmtFormatter
+        keys:
+          - time
+          - level
+          - msg
+        mapping:
+          time: asctime
+          level: levelname
+          msg: message
+  {{- end }}
diff --git a/charts/jenkins/templates/config-init-scripts.yaml b/charts/jenkins/templates/config-init-scripts.yaml
index 7dd253c..89ed7dd 100644
--- a/charts/jenkins/templates/config-init-scripts.yaml
+++ b/charts/jenkins/templates/config-init-scripts.yaml
@@ -6,10 +6,7 @@
   name: {{ template "jenkins.fullname" . }}-init-scripts
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 data:
 {{- range $key, $val := .Values.controller.initScripts }}
   init{{ $key }}.groovy: |-
diff --git a/charts/jenkins/templates/config.yaml b/charts/jenkins/templates/config.yaml
index 5de0b9f..c49c248 100644
--- a/charts/jenkins/templates/config.yaml
+++ b/charts/jenkins/templates/config.yaml
@@ -6,10 +6,7 @@
   name: {{ template "jenkins.fullname" . }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 data:
   apply_config.sh: |-
     set -e
diff --git a/charts/jenkins/templates/extra-objects.yaml b/charts/jenkins/templates/extra-objects.yaml
new file mode 100644
index 0000000..c8b9a6e
--- /dev/null
+++ b/charts/jenkins/templates/extra-objects.yaml
@@ -0,0 +1,18 @@
+{{- if .Values.extraObjects -}}
+  {{- $extraObjects := .Values.extraObjects -}}
+
+  {{- if kindIs "map" $extraObjects -}}
+    {{- $extraObjects = values $extraObjects -}}
+  {{- end -}}
+
+  {{- range $index, $object := $extraObjects -}}
+    {{- if $object }}
+---
+      {{- if kindIs "string" $object -}}
+        {{- tpl $object $ | nindent 0 -}}
+      {{- else -}}
+        {{- tpl (toYaml $object) $ | nindent 0 -}}
+      {{- end -}}
+    {{- end -}}
+  {{- end -}}
+{{- end -}}
diff --git a/charts/jenkins/templates/home-pvc.yaml b/charts/jenkins/templates/home-pvc.yaml
index f417d23..023295b 100644
--- a/charts/jenkins/templates/home-pvc.yaml
+++ b/charts/jenkins/templates/home-pvc.yaml
@@ -10,13 +10,7 @@
   name: {{ template "jenkins.fullname" . }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.persistence.labels }}
 {{ toYaml .Values.persistence.labels | indent 4 }}
 {{- end }}
@@ -34,7 +28,7 @@
 {{- if (eq "-" .Values.persistence.storageClass) }}
   storageClassName: ""
 {{- else }}
-  storageClassName: "{{ .Values.persistence.storageClass }}"
+  storageClassName: "{{ tpl .Values.persistence.storageClass . }}"
 {{- end }}
 {{- end }}
 {{- end }}
diff --git a/charts/jenkins/templates/jcasc-config.yaml b/charts/jenkins/templates/jcasc-config.yaml
index e404194..c9fdbcb 100644
--- a/charts/jenkins/templates/jcasc-config.yaml
+++ b/charts/jenkins/templates/jcasc-config.yaml
@@ -9,14 +9,12 @@
   name: {{ template "jenkins.casc.configName" (list (printf "config-%s" $key) $ )}}
   namespace: {{ template "jenkins.namespace" $root }}
   labels:
-    "app.kubernetes.io/name": {{ template "jenkins.name" $root}}
-    {{- if $root.Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ $root.Chart.Name }}-{{ $root.Chart.Version }}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ $.Release.Service }}"
-    "app.kubernetes.io/instance": "{{ $.Release.Name }}"
-    "app.kubernetes.io/component": "{{ $.Values.controller.componentName }}"
+    {{- include "jenkins.labels" $root | nindent 4 }}
     {{ template "jenkins.fullname" $root }}-jenkins-config: "true"
+{{- if $root.Values.controller.JCasC.configMapAnnotations }}
+  annotations:
+{{ toYaml $root.Values.controller.JCasC.configMapAnnotations | indent 4 }}
+{{- end }}
 data:
   {{ $key }}.yaml: |-
 {{ tpl $val $| indent 4 }}
@@ -30,16 +28,67 @@
   name: {{ template "jenkins.casc.configName" (list "jcasc-config" $ )}}
   namespace: {{ template "jenkins.namespace" $root }}
   labels:
+    {{- include "jenkins.labels" $root | nindent 4 }}
+    {{ template "jenkins.fullname" $root }}-jenkins-config: "true"
+{{- if $root.Values.controller.JCasC.configMapAnnotations }}
+  annotations:
+{{ toYaml $root.Values.controller.JCasC.configMapAnnotations | indent 4 }}
+{{- end }}
+data:
+  jcasc-default-config.yaml: |-
+    {{- include "jenkins.casc.defaults" . | nindent 4 }}
+{{- end}}
+{{- $configScripts := toYaml .Values.controller.JCasC.configScripts }}
+{{- if and .Values.controller.JCasC.securityRealm (not (contains "securityRealm:" $configScripts)) (not .Values.controller.JCasC.defaultConfig) }}
+---
+apiVersion: v1
+kind: ConfigMap
+metadata:
+  name: {{ template "jenkins.casc.configName" (list "config-securityrealm" $ )}}
+  namespace: {{ template "jenkins.namespace" $root }}
+  labels:
     "app.kubernetes.io/name": {{ template "jenkins.name" $root}}
     {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ $root.Chart.Name }}-{{ $root.Chart.Version }}"
+    "helm.sh/chart": "{{ $root.Chart.Name }}-{{ $root.Chart.Version | replace "+" "_" }}"
     {{- end }}
     "app.kubernetes.io/managed-by": "{{ $.Release.Service }}"
     "app.kubernetes.io/instance": "{{ $.Release.Name }}"
     "app.kubernetes.io/component": "{{ $.Values.controller.componentName }}"
     {{ template "jenkins.fullname" $root }}-jenkins-config: "true"
+{{- if $root.Values.controller.JCasC.configMapAnnotations }}
+  annotations:
+{{ toYaml $root.Values.controller.JCasC.configMapAnnotations | indent 4 }}
+{{- end }}
 data:
-  jcasc-default-config.yaml: |-
-    {{- include "jenkins.casc.defaults" . | nindent 4 }}
-{{- end}}
+  securityrealm.yaml: |-
+    jenkins:
+      securityRealm:
+        {{- tpl .Values.controller.JCasC.securityRealm . | nindent 8 }}
+{{- end }}
+{{- if and .Values.controller.JCasC.authorizationStrategy (not (contains "authorizationStrategy:" $configScripts)) (not .Values.controller.JCasC.defaultConfig) }}
+---
+apiVersion: v1
+kind: ConfigMap
+metadata:
+  name: {{ template "jenkins.casc.configName" (list "config-authorizationstrategy" $ )}}
+  namespace: {{ template "jenkins.namespace" $root }}
+  labels:
+    "app.kubernetes.io/name": {{ template "jenkins.name" $root}}
+    {{- if .Values.renderHelmLabels }}
+    "helm.sh/chart": "{{ $root.Chart.Name }}-{{ $root.Chart.Version | replace "+" "_" }}"
+    {{- end }}
+    "app.kubernetes.io/managed-by": "{{ $.Release.Service }}"
+    "app.kubernetes.io/instance": "{{ $.Release.Name }}"
+    "app.kubernetes.io/component": "{{ $.Values.controller.componentName }}"
+    {{ template "jenkins.fullname" $root }}-jenkins-config: "true"
+{{- if $root.Values.controller.JCasC.configMapAnnotations }}
+  annotations:
+{{ toYaml $root.Values.controller.JCasC.configMapAnnotations | indent 4 }}
+{{- end }}
+data:
+  authorizationstrategy.yaml: |-
+    jenkins:
+      authorizationStrategy:
+        {{- tpl .Values.controller.JCasC.authorizationStrategy . | nindent 8 }}
+{{- end }}
 {{- end }}
diff --git a/charts/jenkins/templates/jenkins-agent-svc.yaml b/charts/jenkins/templates/jenkins-agent-svc.yaml
index 4440b91..10b936f 100644
--- a/charts/jenkins/templates/jenkins-agent-svc.yaml
+++ b/charts/jenkins/templates/jenkins-agent-svc.yaml
@@ -5,13 +5,7 @@
   name: {{ template "jenkins.fullname" . }}-agent
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
   {{- if .Values.controller.agentListenerServiceAnnotations }}
   annotations:
     {{- toYaml .Values.controller.agentListenerServiceAnnotations | nindent 4 }}
diff --git a/charts/jenkins/templates/jenkins-aws-security-group-policies.yaml b/charts/jenkins/templates/jenkins-aws-security-group-policies.yaml
index 2f6e7a1..6ccabef 100644
--- a/charts/jenkins/templates/jenkins-aws-security-group-policies.yaml
+++ b/charts/jenkins/templates/jenkins-aws-security-group-policies.yaml
@@ -5,6 +5,8 @@
 metadata:
   name: {{ .name }}
   namespace: {{ template "jenkins.namespace" $ }}
+  labels:
+    {{ include "jenkins.labels" $ | nindent 4 }}
 spec:
   podSelector: 
     {{- toYaml .podSelector | nindent 6}}
diff --git a/charts/jenkins/templates/jenkins-controller-alerting-rules.yaml b/charts/jenkins/templates/jenkins-controller-alerting-rules.yaml
index 3fd8061..9bbdc79 100644
--- a/charts/jenkins/templates/jenkins-controller-alerting-rules.yaml
+++ b/charts/jenkins/templates/jenkins-controller-alerting-rules.yaml
@@ -10,13 +10,7 @@
   namespace: {{ template "jenkins.namespace" . }}
 {{- end }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- range $key, $val := .Values.controller.prometheus.alertingRulesAdditionalLabels }}
     {{ $key }}: {{ $val | quote }}
     {{- end}}
diff --git a/charts/jenkins/templates/jenkins-controller-backendconfig.yaml b/charts/jenkins/templates/jenkins-controller-backendconfig.yaml
index 0e8a566..8c13fe1 100644
--- a/charts/jenkins/templates/jenkins-controller-backendconfig.yaml
+++ b/charts/jenkins/templates/jenkins-controller-backendconfig.yaml
@@ -5,13 +5,7 @@
   name: {{ .Values.controller.backendconfig.name }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.controller.backendconfig.labels }}
 {{ toYaml .Values.controller.backendconfig.labels | indent 4 }}
 {{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-httproute.yaml b/charts/jenkins/templates/jenkins-controller-httproute.yaml
new file mode 100644
index 0000000..f2dcfc1
--- /dev/null
+++ b/charts/jenkins/templates/jenkins-controller-httproute.yaml
@@ -0,0 +1,40 @@
+{{- if .Values.controller.httpRoute.enabled }}
+{{- $root := . }}
+{{- $hostnames := (list) }}
+{{- if .Values.controller.httpRoute.reuseIngressConfiguration }}
+  {{- if .Values.controller.ingress.hostName }}
+    {{- $hostnames = append $hostnames .Values.controller.ingress.hostName }}
+  {{- end }}
+  {{- if .Values.controller.ingress.resourceRootUrl }}
+     {{- $hostnames = append $hostnames .Values.controller.ingress.resourceRootUrl }}
+  {{- end }}
+{{- else }}
+  {{- $hostnames = default (list) .Values.controller.httpRoute.hostnames }}
+{{- end }}
+apiVersion: {{ .Values.controller.httpRoute.apiVersion }}
+kind: {{ .Values.controller.httpRoute.kind }}
+metadata:
+  name: {{ include "jenkins.fullname" . }}
+  labels:
+    {{- include "jenkins.labels" . | nindent 4 }}
+  {{- if .Values.controller.httpRoute.annotations }}
+  annotations:
+    {{- tpl (toYaml .Values.controller.httpRoute.annotations) . | nindent 4 }}
+  {{- end }}
+spec:
+  {{- with .Values.controller.httpRoute.parentRefs }}
+  parentRefs:
+    {{- toYaml . | nindent 4 }}
+  {{- end }}
+  hostnames:
+  {{- range $hostnames }}
+    - {{ . | quote }}
+  {{- end }}
+  rules:
+{{- if .Values.controller.httpRoute.extraRules }}
+{{- toYaml .Values.controller.httpRoute.extraRules | nindent 2 }}
+{{- end }}
+  - backendRefs:
+    - name: {{ include "jenkins.fullname" $root }}
+      port: {{ $root.Values.controller.servicePort }}
+{{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-ingress.yaml b/charts/jenkins/templates/jenkins-controller-ingress.yaml
index b3b344f..53eaa25 100644
--- a/charts/jenkins/templates/jenkins-controller-ingress.yaml
+++ b/charts/jenkins/templates/jenkins-controller-ingress.yaml
@@ -11,24 +11,18 @@
 metadata:
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.controller.ingress.labels }}
 {{ toYaml .Values.controller.ingress.labels | indent 4 }}
 {{- end }}
 {{- if .Values.controller.ingress.annotations }}
   annotations:
-{{ toYaml .Values.controller.ingress.annotations | indent 4 }}
+{{ tpl (toYaml .Values.controller.ingress.annotations) . | indent 4 }}
 {{- end }}
   name: {{ template "jenkins.fullname" . }}
 spec:
 {{- if .Values.controller.ingress.ingressClassName }}
-  ingressClassName: {{ .Values.controller.ingress.ingressClassName | quote }}
+  ingressClassName: {{ tpl .Values.controller.ingress.ingressClassName . | quote }}
 {{- end }}
   rules:
   - http:
@@ -40,7 +34,7 @@
             name: {{ template "jenkins.fullname" . }}
             port:
               number: {{ .Values.controller.servicePort }}
-        pathType: ImplementationSpecific
+        pathType: {{ .Values.controller.ingress.pathType }}
 {{- else }}
           serviceName: {{ template "jenkins.fullname" . }}
           servicePort: {{ .Values.controller.servicePort }}
@@ -63,7 +57,7 @@
             name: {{ template "jenkins.fullname" . }}
             port:
               number: {{ .Values.controller.servicePort }}
-        pathType: ImplementationSpecific
+        pathType: {{ .Values.controller.ingress.pathType }}
 {{- else }}
           serviceName: {{ template "jenkins.fullname" . }}
           servicePort: {{ .Values.controller.servicePort }}
@@ -71,7 +65,26 @@
     host: {{ tpl .Values.controller.ingress.resourceRootUrl . | quote }}
 {{- end }}
 {{- if .Values.controller.ingress.tls }}
+{{- $withTlsEntries := false }}
+{{- range .Values.controller.ingress.tls }}
+  {{- if gt (len .) 0 }}
+    {{- $withTlsEntries = true }}
+  {{- end }}
+{{- end }}
+{{- if $withTlsEntries }}
   tls:
-{{ tpl (toYaml .Values.controller.ingress.tls ) . | indent 4 }}
-{{- end -}}
+{{- range .Values.controller.ingress.tls }}
+  - hosts:
+{{- range .hosts }}
+      - {{ tpl . $ | quote }}
+{{- end }}
+{{- if $.Values.controller.ingress.resourceRootUrl }}
+      - {{ tpl $.Values.controller.ingress.resourceRootUrl $ | quote }}
+{{- end }}
+{{- if .secretName }}
+    secretName: {{ tpl (.secretName | toString) $ | quote }}
+{{- end }}
+{{- end }}
+{{- end }}
+{{- end }}
 {{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-networkpolicy.yaml b/charts/jenkins/templates/jenkins-controller-networkpolicy.yaml
index 82835f2..e281b03 100644
--- a/charts/jenkins/templates/jenkins-controller-networkpolicy.yaml
+++ b/charts/jenkins/templates/jenkins-controller-networkpolicy.yaml
@@ -5,13 +5,7 @@
   name: "{{ .Release.Name }}-{{ .Values.controller.componentName }}"
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 spec:
   podSelector:
     matchLabels:
@@ -60,13 +54,7 @@
   name: "{{ .Release.Name }}-{{ .Values.agent.componentName }}"
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 spec:
   podSelector:
     matchLabels:
diff --git a/charts/jenkins/templates/jenkins-controller-pdb.yaml b/charts/jenkins/templates/jenkins-controller-pdb.yaml
index 9dc1faf..53090e5 100644
--- a/charts/jenkins/templates/jenkins-controller-pdb.yaml
+++ b/charts/jenkins/templates/jenkins-controller-pdb.yaml
@@ -12,13 +12,7 @@
   name: {{ template "jenkins.fullname" . }}-pdb
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- if .Values.controller.podDisruptionBudget.labels -}}
     {{ toYaml .Values.controller.podDisruptionBudget.labels | nindent 4 }}
     {{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-podmonitor.yaml b/charts/jenkins/templates/jenkins-controller-podmonitor.yaml
index 9a04019..b84039c 100644
--- a/charts/jenkins/templates/jenkins-controller-podmonitor.yaml
+++ b/charts/jenkins/templates/jenkins-controller-podmonitor.yaml
@@ -10,13 +10,7 @@
   namespace: {{ template "jenkins.namespace" . }}
 {{- end }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 
 spec:
   endpoints:
diff --git a/charts/jenkins/templates/jenkins-controller-route.yaml b/charts/jenkins/templates/jenkins-controller-route.yaml
index 3550380..9144e10 100644
--- a/charts/jenkins/templates/jenkins-controller-route.yaml
+++ b/charts/jenkins/templates/jenkins-controller-route.yaml
@@ -5,12 +5,10 @@
   namespace: {{ template "jenkins.namespace" . }}
   labels:
     app: {{ template "jenkins.fullname" . }}
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
     release: "{{ .Release.Name }}"
     heritage: "{{ .Release.Service }}"
     component: "{{ .Release.Name }}-{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.controller.route.labels }}
 {{ toYaml .Values.controller.route.labels | indent 4 }}
 {{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-secondary-ingress.yaml b/charts/jenkins/templates/jenkins-controller-secondary-ingress.yaml
index c63e482..876b75d 100644
--- a/charts/jenkins/templates/jenkins-controller-secondary-ingress.yaml
+++ b/charts/jenkins/templates/jenkins-controller-secondary-ingress.yaml
@@ -13,26 +13,21 @@
 metadata:
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- if .Values.controller.secondaryingress.labels -}}
     {{ toYaml .Values.controller.secondaryingress.labels | nindent 4 }}
     {{- end }}
   {{- if .Values.controller.secondaryingress.annotations }}
-  annotations: {{ toYaml .Values.controller.secondaryingress.annotations | nindent 4 }}
+  annotations:
+{{ tpl (toYaml .Values.controller.secondaryingress.annotations) . | indent 4 }}
   {{- end }}
   name: {{ template "jenkins.fullname" . }}-secondary
 spec:
 {{- if .Values.controller.secondaryingress.ingressClassName }}
-  ingressClassName: {{ .Values.controller.secondaryingress.ingressClassName | quote }}
+  ingressClassName: {{ tpl .Values.controller.secondaryingress.ingressClassName . | quote }}
 {{- end }}
   rules:
-    - host: {{ .Values.controller.secondaryingress.hostName }}
+    - host: {{ tpl .Values.controller.secondaryingress.hostName . | quote }}
       http:
         paths:
         {{- range .Values.controller.secondaryingress.paths }}
@@ -43,14 +38,30 @@
                 name: {{ $serviceName }}
                 port:
                   number: {{ $servicePort }}
-            pathType: ImplementationSpecific
+            pathType: {{ $.Values.controller.secondaryingress.pathType }}
 {{ else }}
               serviceName: {{ $serviceName }}
               servicePort: {{ $servicePort }}
 {{ end }}
         {{- end}}
 {{- if .Values.controller.secondaryingress.tls }}
+{{- $withTlsEntries := false }}
+{{- range .Values.controller.secondaryingress.tls }}
+  {{- if gt (len .) 0 }}
+    {{- $withTlsEntries = true }}
+  {{- end }}
+{{- end }}
+{{- if $withTlsEntries }}
   tls:
-{{ toYaml .Values.controller.secondaryingress.tls | indent 4 }}
+{{- range .Values.controller.secondaryingress.tls }}
+  - hosts:
+{{- range .hosts }}
+      - {{ tpl . $ | quote }}
+{{- end }}
+{{- if .secretName }}
+    secretName: {{ tpl (.secretName | toString) $ | quote }}
+{{- end }}
+{{- end }}
+{{- end }}
 {{- end -}}
 {{- end }}
diff --git a/charts/jenkins/templates/jenkins-controller-servicemonitor.yaml b/charts/jenkins/templates/jenkins-controller-servicemonitor.yaml
index 8710b2b..bf64666 100644
--- a/charts/jenkins/templates/jenkins-controller-servicemonitor.yaml
+++ b/charts/jenkins/templates/jenkins-controller-servicemonitor.yaml
@@ -10,13 +10,7 @@
   namespace: {{ template "jenkins.namespace" . }}
 {{- end }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- range $key, $val := .Values.controller.prometheus.serviceMonitorAdditionalLabels }}
     {{ $key }}: {{ $val | quote }}
     {{- end}}
diff --git a/charts/jenkins/templates/jenkins-controller-statefulset.yaml b/charts/jenkins/templates/jenkins-controller-statefulset.yaml
index ca0edc6..80154c7 100644
--- a/charts/jenkins/templates/jenkins-controller-statefulset.yaml
+++ b/charts/jenkins/templates/jenkins-controller-statefulset.yaml
@@ -8,13 +8,7 @@
   name: {{ template "jenkins.fullname" . }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- range $key, $val := .Values.controller.statefulSetLabels }}
     {{ $key }}: {{ $val | quote }}
     {{- end}}
@@ -24,7 +18,7 @@
   {{- end }}
 spec:
   serviceName: {{ template "jenkins.fullname" . }}
-  replicas: 1
+  replicas: {{ include "controller.replicas" . }}
   selector:
     matchLabels:
       "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
@@ -36,10 +30,7 @@
   template:
     metadata:
       labels:
-        "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-        "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-        "app.kubernetes.io/instance": "{{ .Release.Name }}"
-        "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+        {{- include "jenkins.labels" . | nindent 8 }}
         {{- range $key, $val := .Values.controller.podLabels }}
         {{ $key }}: {{ $val | quote }}
         {{- end}}
@@ -67,6 +58,14 @@
       affinity:
 {{ toYaml .Values.controller.affinity | indent 8 }}
       {{- end }}
+      {{- if .Values.controller.topologySpreadConstraints }}
+      topologySpreadConstraints:
+{{ toYaml .Values.controller.topologySpreadConstraints | indent 8 }}
+      {{- end }}
+      {{- if .Values.controller.dnsConfig }}
+      dnsConfig:
+{{ toYaml .Values.controller.dnsConfig | indent 8 }}
+      {{- end }}
       {{- if quote .Values.controller.terminationGracePeriodSeconds }}
       terminationGracePeriodSeconds: {{ .Values.controller.terminationGracePeriodSeconds }}
       {{- end }}
@@ -76,6 +75,9 @@
       {{- if .Values.controller.shareProcessNamespace }}
       shareProcessNamespace: true
       {{- end }}
+      {{- if not .Values.controller.enableServiceLinks }}
+      enableServiceLinks: false
+      {{- end }}
 {{- if .Values.controller.usePodSecurityContext }}
       securityContext:
   {{- if kindIs "map" .Values.controller.podSecurityContextOverride }}
@@ -84,12 +86,14 @@
     {{/* The rest of this section should be replaced with the contents of this comment one the runAsUser, fsGroup, and securityContextCapabilities Helm chart values have been removed:
         runAsUser: 1000
         fsGroup: 1000
+        fsGroupChangePolicy: OnRootMismatch
         runAsNonRoot: true
     */}}
         runAsUser: {{ default 0 .Values.controller.runAsUser }}
     {{- if and (.Values.controller.runAsUser) (.Values.controller.fsGroup) }}
       {{- if not (eq (int .Values.controller.runAsUser) 0) }}
         fsGroup: {{ .Values.controller.fsGroup }}
+        fsGroupChangePolicy: {{ .Values.controller.fsGroupChangePolicy }}
         runAsNonRoot: true
       {{- end }}
       {{- if .Values.controller.securityContextCapabilities }}
@@ -100,6 +104,7 @@
   {{- end }}
 {{- end }}
       serviceAccountName: "{{ template "jenkins.serviceAccountName" . }}"
+      automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
 {{- if .Values.controller.hostNetworking }}
       hostNetwork: true
       dnsPolicy: ClusterFirstWithHostNet
@@ -215,10 +220,10 @@
                   fieldPath: metadata.name
             - name: JAVA_OPTS
               value: >-
-                {{ if .Values.controller.sidecars.configAutoReload.enabled }} -Dcasc.reload.token=$(POD_NAME) {{ end }}{{ default "" .Values.controller.javaOpts }}
+                {{ if .Values.controller.sidecars.configAutoReload.enabled }} -Dcasc.reload.token=$(POD_NAME) {{ end }}{{ tpl (default "" .Values.controller.javaOpts) . }}
             - name: JENKINS_OPTS
               value: >-
-                {{ if .Values.controller.jenkinsUriPrefix }}--prefix={{ .Values.controller.jenkinsUriPrefix }} {{ end }} --webroot=/var/jenkins_cache/war {{ default "" .Values.controller.jenkinsOpts}}
+                {{ if .Values.controller.jenkinsUriPrefix }}--prefix={{ .Values.controller.jenkinsUriPrefix }} {{ end }} --webroot=/var/jenkins_cache/war {{ tpl (default "" .Values.controller.jenkinsOpts) . }}
             - name: JENKINS_SLAVE_AGENT_PORT
               value: "{{ .Values.controller.agentListenerPort }}"
             {{- if .Values.controller.httpsKeyStore.enable }}
@@ -321,6 +326,13 @@
 {{- if .Values.persistence.volumes }}
 {{ tpl (toYaml .Values.persistence.volumes | indent 6) . }}
 {{- end }}
+      {{- if .Values.controller.sidecars.configAutoReload.logging.configuration.override }}
+      - name: auto-reload-config
+        configMap:
+          name: {{ template "jenkins.fullname" . }}-auto-reload-config
+      - name: auto-reload-config-logs
+        emptyDir: {}
+      {{- end }}
       {{- if .Values.controller.installPlugins }}
       {{- if .Values.controller.overwritePluginsFromImage }}
       - name: plugins
diff --git a/charts/jenkins/templates/jenkins-controller-svc.yaml b/charts/jenkins/templates/jenkins-controller-svc.yaml
index a83466c..3cf9e78 100644
--- a/charts/jenkins/templates/jenkins-controller-svc.yaml
+++ b/charts/jenkins/templates/jenkins-controller-svc.yaml
@@ -1,16 +1,11 @@
+{{- if .Values.controller.serviceEnabled }}
 apiVersion: v1
 kind: Service
 metadata:
   name: {{template "jenkins.fullname" . }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
     {{- if .Values.controller.serviceLabels }}
 {{ toYaml .Values.controller.serviceLabels | indent 4 }}
     {{- end }}
@@ -41,6 +36,9 @@
       targetPort: {{ $port.port }}
       {{- end -}}
 {{- end }}
+  {{- if .Values.controller.publishNotReadyAddresses }}
+  publishNotReadyAddresses: true
+  {{- end }}
   selector:
     "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
     "app.kubernetes.io/instance": "{{ .Release.Name }}"
@@ -54,3 +52,4 @@
   loadBalancerIP: {{.Values.controller.loadBalancerIP}}
   {{end}}
   {{end}}
+{{- end }}
diff --git a/charts/jenkins/templates/rbac.yaml b/charts/jenkins/templates/rbac.yaml
index 581cb8d..48ba8ab 100644
--- a/charts/jenkins/templates/rbac.yaml
+++ b/charts/jenkins/templates/rbac.yaml
@@ -8,13 +8,7 @@
   name: {{ $serviceName }}-schedule-agents
   namespace: {{ template "jenkins.agent.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 rules:
 - apiGroups: [""]
   resources: ["pods", "pods/exec", "pods/log", "persistentvolumeclaims", "events"]
@@ -33,13 +27,7 @@
   name: {{ $serviceName }}-schedule-agents
   namespace: {{ template "jenkins.agent.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 roleRef:
   apiGroup: rbac.authorization.k8s.io
   kind: Role
@@ -60,13 +48,7 @@
   name: {{ template "jenkins.fullname" . }}-read-secrets
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 rules:
   - apiGroups: [""]
     resources: ["secrets"]
@@ -80,13 +62,7 @@
   name: {{ $serviceName }}-read-secrets
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 roleRef:
   apiGroup: rbac.authorization.k8s.io
   kind: Role
@@ -99,6 +75,43 @@
 ---
 {{- end}}
 
+{{- if .Values.rbac.useOpenShiftNonRootSCC }}
+# This is needed if you are running on OpenShift and using the default
+# containerSecurityContext in the chart. It grants the Jenkins service account
+# permission to use the "nonroot" and "nonroot-v2" SecurityContextConstraints.
+apiVersion: rbac.authorization.k8s.io/v1
+kind: Role
+metadata:
+  name: {{ $serviceName }}-use-nonroot-scc
+  namespace: {{ template "jenkins.namespace" . }}
+  labels:
+    {{- include "jenkins.labels" . | nindent 4 }}
+rules:
+  - apiGroups: ["security.openshift.io"]
+    resources: ["securitycontextconstraints"]
+    resourceNames: ["nonroot", "nonroot-v2"]
+    verbs: ["use"]
+---
+
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+  name: {{ $serviceName }}-use-nonroot-scc
+  namespace: {{ template "jenkins.namespace" . }}
+  labels:
+    {{- include "jenkins.labels" . | nindent 4 }}
+roleRef:
+  apiGroup: rbac.authorization.k8s.io
+  kind: Role
+  name: {{ template "jenkins.fullname" . }}-use-nonroot-scc
+subjects:
+  - kind: ServiceAccount
+    name: {{ template "jenkins.serviceAccountName" . }}
+    namespace: {{ template "jenkins.namespace" . }}
+
+---
+{{- end}}
+
 {{- if .Values.controller.sidecars.configAutoReload.enabled }}
 # The sidecar container which is responsible for reloading configuration changes
 # needs permissions to watch ConfigMaps
@@ -108,13 +121,7 @@
   name: {{ template "jenkins.fullname" . }}-casc-reload
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 rules:
 - apiGroups: [""]
   resources: ["configmaps"]
@@ -128,13 +135,7 @@
   name: {{ $serviceName }}-watch-configmaps
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 roleRef:
   apiGroup: rbac.authorization.k8s.io
   kind: Role
diff --git a/charts/jenkins/templates/secret-additional.yaml b/charts/jenkins/templates/secret-additional.yaml
index d1908aa..9504b3b 100644
--- a/charts/jenkins/templates/secret-additional.yaml
+++ b/charts/jenkins/templates/secret-additional.yaml
@@ -6,13 +6,7 @@
   name: {{ template "jenkins.fullname" . }}-additional-secrets
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 type: Opaque
 data:
 {{- range .Values.controller.additionalSecrets }}
diff --git a/charts/jenkins/templates/secret-claims.yaml b/charts/jenkins/templates/secret-claims.yaml
index e8b6d6c..b47c7bd 100644
--- a/charts/jenkins/templates/secret-claims.yaml
+++ b/charts/jenkins/templates/secret-claims.yaml
@@ -1,7 +1,5 @@
 {{- if .Values.controller.secretClaims -}}
-{{- $r := .Release -}}
-{{- $v := .Values -}}
-{{- $chart := printf "%s-%s" .Chart.Name .Chart.Version -}}
+{{- $root := . -}}
 {{- $namespace := include "jenkins.namespace" . -}}
 {{- $serviceName := include "jenkins.fullname" . -}}
 {{ range .Values.controller.secretClaims }}
@@ -12,13 +10,9 @@
   name: {{ $serviceName }}-{{ .name | default .path | lower }}
   namespace: {{ $namespace }}
   labels:
-    "app.kubernetes.io/name": '{{ $serviceName }}'
-    {{- if $v.renderHelmLabels }}
-    "helm.sh/chart": "{{ $chart }}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ $r.Service }}"
-    "app.kubernetes.io/instance": "{{ $r.Name }}"
-    "app.kubernetes.io/component": "{{ $v.controller.componentName }}"
+    {{- $baseLabels := include "jenkins.labels" $root | fromYaml }}
+    {{- $overrideLabels := dict "app.kubernetes.io/name" $serviceName }}
+    {{- toYaml (merge $overrideLabels $baseLabels) | nindent 4 }}
 spec:
   type: {{ .type | default "Opaque" }}
   path: {{ .path }}
@@ -26,4 +20,4 @@
   renew: {{ .renew }}
 {{- end }}
 {{- end }}
-{{- end }}
\ No newline at end of file
+{{- end }}
diff --git a/charts/jenkins/templates/secret-https-jks.yaml b/charts/jenkins/templates/secret-https-jks.yaml
index 5348de4..244e1a5 100644
--- a/charts/jenkins/templates/secret-https-jks.yaml
+++ b/charts/jenkins/templates/secret-https-jks.yaml
@@ -5,13 +5,7 @@
   name: {{ template "jenkins.fullname" . }}-https-jks
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 type: Opaque
 data:
   jenkins-jks-file: |
diff --git a/charts/jenkins/templates/secret.yaml b/charts/jenkins/templates/secret.yaml
index cc6ace1..a3000d1 100644
--- a/charts/jenkins/templates/secret.yaml
+++ b/charts/jenkins/templates/secret.yaml
@@ -6,13 +6,7 @@
   name: {{ template "jenkins.fullname" . }}
   namespace: {{ template "jenkins.namespace" . }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{ include "jenkins.labels" . | nindent 4 }}
 type: Opaque
 data:
   jenkins-admin-password: {{ template "jenkins.password" . }}
diff --git a/charts/jenkins/templates/service-account-agent.yaml b/charts/jenkins/templates/service-account-agent.yaml
index 48f08ba..42df234 100644
--- a/charts/jenkins/templates/service-account-agent.yaml
+++ b/charts/jenkins/templates/service-account-agent.yaml
@@ -1,6 +1,7 @@
 {{ if .Values.serviceAccountAgent.create }}
 apiVersion: v1
 kind: ServiceAccount
+automountServiceAccountToken: {{ .Values.serviceAccountAgent.automountServiceAccountToken }}
 metadata:
   name: {{ include "jenkins.serviceAccountAgentName" . }}
   namespace: {{ template "jenkins.agent.namespace" . }}
@@ -9,13 +10,7 @@
 {{ tpl (toYaml .Values.serviceAccountAgent.annotations) . | indent 4 }}
 {{- end }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.serviceAccountAgent.extraLabels }}
 {{ tpl (toYaml .Values.serviceAccountAgent.extraLabels) . | indent 4 }}
 {{- end }}
diff --git a/charts/jenkins/templates/service-account.yaml b/charts/jenkins/templates/service-account.yaml
index b44eb48..c868af5 100644
--- a/charts/jenkins/templates/service-account.yaml
+++ b/charts/jenkins/templates/service-account.yaml
@@ -1,6 +1,7 @@
 {{ if .Values.serviceAccount.create }}
 apiVersion: v1
 kind: ServiceAccount
+automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
 metadata:
   name: {{ include "jenkins.serviceAccountName" . }}
   namespace: {{ template "jenkins.namespace" . }}
@@ -9,13 +10,7 @@
 {{ tpl (toYaml .Values.serviceAccount.annotations) . | indent 4 }}
 {{- end }}
   labels:
-    "app.kubernetes.io/name": '{{ template "jenkins.name" .}}'
-    {{- if .Values.renderHelmLabels }}
-    "helm.sh/chart": "{{ template "jenkins.label" .}}"
-    {{- end }}
-    "app.kubernetes.io/managed-by": "{{ .Release.Service }}"
-    "app.kubernetes.io/instance": "{{ .Release.Name }}"
-    "app.kubernetes.io/component": "{{ .Values.controller.componentName }}"
+    {{- include "jenkins.labels" . | nindent 4 }}
 {{- if .Values.serviceAccount.extraLabels }}
 {{ tpl (toYaml .Values.serviceAccount.extraLabels) . | indent 4 }}
 {{- end }}
diff --git a/charts/jenkins/values.yaml b/charts/jenkins/values.yaml
index 754a01c..4dfadc2 100644
--- a/charts/jenkins/values.yaml
+++ b/charts/jenkins/values.yaml
@@ -29,6 +29,12 @@
 # -- Enables rendering of the helm.sh/chart label to the annotations
 renderHelmLabels: true
 
+# -- Configures extra labels for the agent all objects
+extraLabels: {}
+
+# -- Configures extra manifests
+extraObjects:
+
 controller:
   # -- Used for label app.kubernetes.io/component
   componentName: "jenkins-controller"
@@ -38,13 +44,17 @@
     # -- Controller image repository
     repository: "jenkins/jenkins"
 
-    # -- Controller image tag override; i.e., tag: "2.440.1-jdk17"
+    # -- Controller image tag override; i.e., tag: "2.440.1-jdk21"
     tag:
 
     # -- Controller image tag label
-    tagLabel: jdk17
+    tagLabel: jdk21
     # -- Controller image pull policy
     pullPolicy: "Always"
+
+  # -- Number of replicas. Max 1. Can be set to 0 for maintenance scenarios.
+  replicas: 1
+
   # -- Controller image pull secret
   imagePullSecretName:
   # -- Lifecycle specification for controller-container
@@ -73,7 +83,6 @@
   # If you disable the non-Jenkins identity store and instead use the Jenkins internal one,
   # you should revert controller.admin.username to your preferred admin user:
   admin:
-
     # -- Admin username created as a secret if `controller.admin.createSecret` is true
     username: "admin"
     # -- Admin password created as a secret if `controller.admin.createSecret` is true
@@ -123,6 +132,12 @@
   # Share process namespace to allow sidecar containers to interact with processes in other containers in the same pod
   shareProcessNamespace: false
 
+  # Service links might cause issue if running in a namespace with a large amount of services
+  # that might cause a slow startup when plugins are copied from ref to volume
+  # Set to true to keep previous behavior
+  # See https://github.com/kubernetes/kubernetes/issues/121787
+  enableServiceLinks: false
+
   # Overrides the init container default values
   # -- Resources allocation (Requests and Limits) for Init Container
   initContainerResources: {}
@@ -185,6 +200,9 @@
   # -- Deprecated in favor of `controller.podSecurityContextOverride`. uid that will be used for persistent volume.
   fsGroup: 1000
 
+  #  -- Deprecated in favor of `controller.podSecurityContextOverride`. fsGroupChangePolicy for the pod security context
+  fsGroupChangePolicy: OnRootMismatch
+
   # If you have PodSecurityPolicies that require dropping of capabilities as suggested by CIS K8s benchmark, put them here
   # securityContextCapabilities:
   #  drop:
@@ -208,6 +226,9 @@
     readOnlyRootFilesystem: true
     allowPrivilegeEscalation: false
 
+  # -- enable or disable the controller k8s service
+  serviceEnabled: true
+
   # For minikube, set this to NodePort, elsewhere uses LoadBalancer
   # Use ClusterIP if your setup includes ingress controller
   # -- k8s service type
@@ -226,6 +247,10 @@
   # but risks potentially imbalanced traffic spreading.
   serviceExternalTrafficPolicy:
 
+  # If enabled, the controller is available through its service before its pods reports ready. Makes startup screen and
+  # auto-reload on restart feature possible.
+  publishNotReadyAddresses:
+
   # -- Jenkins controller service annotations
   serviceAnnotations: {}
   # -- Jenkins controller custom labels for the StatefulSet
@@ -328,7 +353,7 @@
   agentListenerExternalTrafficPolicy:
   # -- Allowed inbound IP for the agentListener service
   agentListenerLoadBalancerSourceRanges:
-  - 0.0.0.0/0
+    - 0.0.0.0/0
   # -- Disabled agent protocols
   disabledAgentProtocols:
     - JNLP-connect
@@ -337,7 +362,7 @@
     defaultCrumbIssuer:
       # -- Enable the default CSRF Crumb issuer
       enabled: true
-      # -- Enable proxy compatibility
+      # -- Enable proxy compatibility. This setting is ignored if you are not on the current LTS release and will be dropped with the next LTS.
       proxyCompatability: true
 
   # Kubernetes service type for the JNLP agent service
@@ -370,7 +395,7 @@
   # set allowed inbound rules on the security group assigned to the controller load balancer
   # -- Allowed inbound IP addresses
   loadBalancerSourceRanges:
-  - 0.0.0.0/0
+    - 0.0.0.0/0
 
   # -- Optionally assign a known public LB IP
   loadBalancerIP:
@@ -393,10 +418,10 @@
   # Plugins will be installed during Jenkins controller start
   # -- List of Jenkins plugins to install. If you don't want to install plugins, set it to `false`
   installPlugins:
-    - kubernetes:4203.v1dd44f5b_1cf9
-    - workflow-aggregator:596.v8c21c963d92d
-    - git:5.2.1
-    - configuration-as-code:1810.v9b_c30a_249a_4c
+    - kubernetes:4467.vf26561292824
+    - workflow-aggregator:608.v67378e9d3db_1
+    - git:5.10.1
+    - configuration-as-code:2100.vb_fd699d2a_09c
 
   # If set to false, Jenkins will download the minimum required version of all dependencies.
   # -- Download the minimum required version or latest version of all dependencies
@@ -533,6 +558,10 @@
     authorizationStrategy: |-
       loggedInUsersCanDoAnything:
         allowAnonymousRead: false
+
+    # -- Annotations for the JCasC ConfigMap
+    configMapAnnotations: {}
+
   # -- Custom init-container specification in raw-yaml format
   customInitContainers: []
   # - name: custom-init
@@ -546,7 +575,7 @@
       # If false or not-specified, JCasC changes will cause a reboot and will only be applied at the subsequent start-up.
       # Auto-reload uses the http://<jenkins_url>/reload-configuration-as-code endpoint to reapply config when changes to
       # the configScripts are detected.
-      # -- Enables Jenkins Config as Code auto-reload
+      # -- Enable Jenkins Config as Code auto-reload
       enabled: true
       image:
         # -- Registry for the image that triggers the reload
@@ -554,15 +583,37 @@
         # -- Repository of the image that triggers the reload
         repository: kiwigrid/k8s-sidecar
         # -- Tag for the image that triggers the reload
-        tag: 1.26.1
+        tag: 2.8.1
       imagePullPolicy: IfNotPresent
-      resources: {}
+      # -- Port for sidecar health probes
+      healthPort: 8060
+      resources:
+        {}
         #   limits:
         #     cpu: 100m
         #     memory: 100Mi
         #   requests:
         #     cpu: 50m
         #     memory: 50Mi
+      # -- Enables additional volume mounts for the config auto-reload container
+      additionalVolumeMounts:
+        []
+        #   - name: auto-reload-config
+        #     mountPath: /var/config/logger
+        #   - name: auto-reload-logs
+        #     mountPath: /var/log/auto_reload
+      # -- Config auto-reload logging settings
+      logging:
+        # See default settings https://github.com/kiwigrid/k8s-sidecar/blob/master/src/logger.py
+        configuration:
+          # -- Enables custom log config utilizing using the settings below.
+          override: false
+          logLevel: INFO
+          formatter: JSON
+          logToConsole: true
+          logToFile: false
+          maxBytes: 1024
+          backupCount: 3
 
       # -- The scheme to use when connecting to the Jenkins configuration as code endpoint
       scheme: http
@@ -577,7 +628,7 @@
       # -- Environment variable sources for the Jenkins Config as Code auto-reload container
       envFrom: []
       # -- Environment variables for the Jenkins Config as Code auto-reload container
-      env: {}
+      env: []
       #   - name: REQ_TIMEOUT
       #     value: "30"
 
@@ -651,12 +702,18 @@
   # -- Update strategy for StatefulSet
   updateStrategy: {}
 
+  # -- Topology spread constraints
+  topologySpreadConstraints: []
+
+  # -- DNS config for the pod
+  dnsConfig: {}
+
   ingress:
-    # -- Enables ingress
+    # -- Enables the Primary ingress
     enabled: false
 
     # Override for the default paths that map requests to the backend
-    # -- Override for the default Ingress paths
+    # -- Override for the default Primary Ingress paths
     paths: []
     # - backend:
     #     serviceName: ssl-redirect
@@ -667,30 +724,36 @@
     #     # Don't use string here, use only integer value!
     #     servicePort: 8080
 
+    # -- Primary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix
+    pathType: ImplementationSpecific
+
     # For Kubernetes v1.14+, use 'networking.k8s.io/v1beta1'
     # For Kubernetes v1.19+, use 'networking.k8s.io/v1'
-    # -- Ingress API version
-    apiVersion: "extensions/v1beta1"
-    # -- Ingress labels
+    # -- Primary Ingress API version
+    apiVersion: "networking.k8s.io/v1"
+    # -- Primary Ingress labels
     labels: {}
-    # -- Ingress annotations
-    annotations: {}
+    # -- Primary Ingress annotations
+    annotations:
+      {}
       # kubernetes.io/ingress.class: nginx
       # kubernetes.io/tls-acme: "true"
     # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
     # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
     # ingressClassName: nginx
+    # -- Primary Ingress ingressClassName
+    ingressClassName:
 
     # Set this path to jenkinsUriPrefix above or use annotations to rewrite path
-    # -- Ingress path
+    # -- Primary Ingress path
     path:
 
     # configures the hostname e.g. jenkins.example.com
-    # -- Ingress hostname
+    # -- Primary Ingress hostname
     hostName:
-    # -- Hostname to serve assets from
+    # -- Primary Hostname to serve assets from
     resourceRootUrl:
-    # -- Ingress TLS configuration
+    # -- Primary Ingress TLS configuration
     tls: []
     # - secretName: jenkins.cluster.local
     #   hosts:
@@ -701,22 +764,32 @@
   # A secondary ingress will let you expose different urls
   # with a different configuration
   secondaryingress:
+    # -- Enables the Secondary Ingress
     enabled: false
     # paths you want forwarded to the backend
     # ex /github-webhook
+    # -- Secondary Ingress paths
     paths: []
+    # -- Secondary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix
+    pathType: ImplementationSpecific
     # For Kubernetes v1.14+, use 'networking.k8s.io/v1beta1'
     # For Kubernetes v1.19+, use 'networking.k8s.io/v1'
-    apiVersion: "extensions/v1beta1"
+    # -- Secondary Ingress API version
+    apiVersion: "networking.k8s.io/v1"
+    # -- Secondary Ingress labels
     labels: {}
+    # -- Secondary Ingress annotations
     annotations: {}
     # kubernetes.io/ingress.class: nginx
     # kubernetes.io/tls-acme: "true"
     # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
     # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
-    # ingressClassName: nginx
+    # -- Secondary Ingress ingressClassName
+    ingressClassName:
     # configures the hostname e.g., jenkins-external.example.com
+    # -- Secondary Ingress hostname
     hostName:
+    # -- Secondary Ingress TLS configuration
     tls:
     # - secretName: jenkins-external.example.com
     #   hosts:
@@ -750,6 +823,25 @@
     # -- Route path
     path:
 
+  # Gateway API HTTPRoute
+  httpRoute:
+    # Toggle to create an HTTPRoute resource alongside the existing ingress definition
+    enabled: false
+    apiVersion: "gateway.networking.k8s.io/v1"
+    kind: HTTPRoute
+    # specify the Gateway instance to bind the HTTPRoute to.
+    parentRefs: []
+    # - name: envoy-gateway-bundle
+    #   namespace: envoy-gateway-system
+    # Reuse ingress host information if true; set to false to manage hostnames below
+    reuseIngressConfiguration: false
+    # Hostnames to use for the http route, only used if reuseIngressConfiguration is false.
+    hostnames: []
+    # Extra HTTPRoute rules that will be appended before the default backend
+    extraRules: []
+    # -- HTTPRoute annotations
+    annotations: {}
+
   # -- Allows for adding entries to Pod /etc/hosts
   hostAliases: []
   # ref: https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
@@ -811,9 +903,9 @@
   httpsKeyStore:
     # -- Enables HTTPS keystore on jenkins controller
     enable: false
-    # -- Name of the secret that already has ssl keystore
+    # -- Name of the secret that already has SSL keystore
     jenkinsHttpsJksSecretName: ""
-    # -- Name of the key in the secret that already has ssl keystore
+    # -- Name of the key in the secret that already has SSL keystore
     jenkinsHttpsJksSecretKey: "jenkins-jks-file"
     # -- Name of the secret that contains the JKS password, if it is not in the same secret as the JKS file
     jenkinsHttpsJksPasswordSecretName: ""
@@ -876,11 +968,22 @@
 #        hYAzODo1Jt59pcqqKJEas0C/lFJEB3frw4ImNx5fNlJYOpx+ijfQs9m39CevDq0=
 
 agent:
+  # -- Add the environment proxy settings form jenkins controller to the agents.
+  addMasterProxyEnvVars: false
+
   # -- Enable Kubernetes plugin jnlp-agent podTemplate
   enabled: true
   # -- The name of the pod template to use for providing default values
   defaultsProviderTemplate: ""
 
+  # Useful for not including a serviceAccount in the template if `false`
+  # -- Use `serviceAccountAgent.name` as the default value for defaults template `serviceAccount`
+  useDefaultServiceAccount: true
+
+  # -- Override the default service account
+  # @default -- `serviceAccountAgent.name` if `agent.useDefaultServiceAccount` is `true`
+  serviceAccount:
+
   # For connecting to the Jenkins controller
   # -- Overrides the Kubernetes Jenkins URL
   jenkinsUrl:
@@ -888,6 +991,10 @@
   # connects to the specified host and port, instead of connecting directly to the Jenkins controller
   # -- Overrides the Kubernetes Jenkins tunnel
   jenkinsTunnel:
+  # -- Disables the verification of the controller certificate on remote connection. This flag correspond to the "Disable https certificate check" flag in kubernetes plugin UI
+  skipTlsVerify: false
+  # -- Enable the possibility to restrict the usage of this agent to specific folder. This flag correspond to the "Restrict pipeline support to authorized folders" flag in kubernetes plugin UI
+  usageRestricted: false
   # -- The connection timeout in seconds for connections to Kubernetes API. The minimum value is 5
   kubernetesConnectTimeout: 5
   # -- The read timeout in seconds for connections to Kubernetes API. The minimum value is 15
@@ -905,10 +1012,12 @@
   # -- Custom registry used to pull the agent jnlp image from
   jnlpregistry:
   image:
+    # -- Registry to pull the agent jnlp image from
+    registry: ""
     # -- Repository to pull the agent jnlp image from
     repository: "jenkins/inbound-agent"
     # -- Tag of the image to pull
-    tag: "3206.vb_15dcf73f6a_9-3"
+    tag: "3383.vc8881d4b_0e76-1"
   # -- Configure working directory for default agent
   workingDir: "/home/jenkins/agent"
   nodeUsageMode: "NORMAL"
@@ -939,12 +1048,12 @@
       memory: "512Mi"
       # ephemeralStorage:
   livenessProbe: {}
-#    execArgs: "cat /tmp/healthy"
-#    failureThreshold: 3
-#    initialDelaySeconds: 0
-#    periodSeconds: 10
-#    successThreshold: 1
-#    timeoutSeconds: 1
+  #  execArgs: "cat /tmp/healthy"
+  #  failureThreshold: 3
+  #  initialDelaySeconds: 0
+  #  periodSeconds: 10
+  #  successThreshold: 1
+  #  timeoutSeconds: 1
 
   # You may want to change this to true while testing a new image
   # -- Always pull agent container image before build
@@ -1056,15 +1165,28 @@
   # Doesn't allocate pseudo TTY by default
   # -- Allocate pseudo tty to the side container
   TTYEnabled: false
-  # -- Max number of agents to launch
+  # -- Max number of agents to launch for a whole cluster.
   containerCap: 10
+  # -- Max number of agents to launch for this type of agent
+  instanceCap: 2147483647
   # -- Agent Pod base name
   podName: "default"
 
+  # Enables garbage collection of orphan pods for this Kubernetes cloud. (beta)
+  garbageCollection:
+    # -- When enabled, Jenkins will periodically check for orphan pods that have not been touched for the given timeout period and delete them.
+    enabled: false
+    # -- Namespaces to look at for garbage collection, in addition to the default namespace defined for the cloud. One namespace per line.
+    namespaces: ""
+    # namespaces: |-
+    #   namespaceOne
+    #   namespaceTwo
+    # -- Timeout value for orphaned pods
+    timeout: 300
+
   # -- Allows the Pod to remain active for reuse until the configured number of minutes has passed since the last step was executed on it
   idleMinutes: 0
 
-
   # The raw yaml of a Pod API Object, for example, this allows usage of toleration for agent pods.
   # https://github.com/jenkinsci/kubernetes-plugin#using-yaml-to-define-pod-templates
   # https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
@@ -1081,6 +1203,8 @@
 
   # -- Defines how the raw yaml field gets merged with yaml definitions from inherited pod templates. Possible values: "merge" or "override"
   yamlMergeStrategy: "override"
+  # -- Controls whether the defined yaml merge strategy will be inherited if another defined pod template is configured to inherit from the current one
+  inheritYamlMergeStrategy: false
   # -- Timeout in seconds for an agent to be online
   connectTimeout: 100
   # -- Annotations to apply to the pod
@@ -1237,13 +1361,15 @@
     # -- A map of labels (keys/values) that agent pods must have to be able to connect to controller
     podLabels: {}
     # -- A map of labels (keys/values) that agents namespaces must have to be able to connect to controller
-    namespaceLabels: {}
+    namespaceLabels:
+      {}
       # project: myproject
   externalAgents:
     # -- The IP range from which external agents are allowed to connect to controller, i.e., 172.17.0.0/16
     ipCIDR:
     # -- A list of IP sub-ranges to be excluded from the allowlisted IP range
-    except: []
+    except:
+      []
       # - 172.17.1.0/24
 
 ## Install Default RBAC roles and bindings
@@ -1252,6 +1378,8 @@
   create: true
   # -- Whether the Jenkins service account should be able to read Kubernetes secrets
   readSecrets: false
+  # -- Whether the Jenkins service account should be able to use the OpenShift "nonroot" Security Context Constraints
+  useOpenShiftNonRootSCC: false
 
 serviceAccount:
   # -- Configures if a ServiceAccount with this name should be created
@@ -1266,7 +1394,8 @@
   extraLabels: {}
   # -- Controller ServiceAccount image pull secret
   imagePullSecretName:
-
+  # -- Auto-mount ServiceAccount token
+  automountServiceAccountToken: true
 
 serviceAccountAgent:
   # -- Configures if an agent ServiceAccount should be created
@@ -1281,6 +1410,8 @@
   extraLabels: {}
   # -- Agent ServiceAccount image pull secret
   imagePullSecretName:
+  # -- Auto-mount ServiceAccount token
+  automountServiceAccountToken: true
 
 # -- Checks if any deprecated values are used
 checkDeprecation: true
@@ -1303,4 +1434,4 @@
       # -- Repository of the image used to test the framework
       repository: "bats/bats"
       # -- Tag of the image to test the framework
-      tag: "1.11.0"
+      tag: "1.13.0"