- Add certVolume.existingSecret to mount a TLS Secret (cert-manager)
- Fix image repository to netbirdio/reverse-proxy
- Gate ACME HTTP port on http-01 challenge in service, deployment, networkpolicy
- Require proxyToken when existingSecret is not provided
- Allow Role/RoleBinding when serviceAccount.name is set without create
- Treat PDB minAvailable/maxUnavailable 0 as valid and fail on mutual exclusivity
- Omit HPA metrics block when no targets are set
- Document crowdsec.existingSecret requirement when top-level existingSecret is used