An Ingress that points at a Service which the chart does not render is broken by definition: the backend reference cannot resolve and the ingress controller reports the rule as unavailable. The render condition therefore now also requires `service.http.enabled` and lives in the new `gitea.ingress.enabled` helper, so the same rule can be reused by other templates instead of being duplicated. The namespace is taken from `.Release.Namespace` again. The `namespace` value is not a documented chart parameter, and letting a single resource opt out of the release namespace breaks `helm uninstall` and Argo CD pruning, because neither tracks objects outside the release namespace. The `ingress.className` default changes from an empty string to `nginx`. An empty class makes the cluster fall back to the default IngressClass, which silently produces a different result per cluster; naming the controller the chart is tested against makes the rendered output predictable. The scattered ingress suites are consolidated into a single `unittests/helm/ingress/ingress.yaml` that pins the release name, namespace and appVersion, as required by the testing conventions, and covers the enable/disable matrix, annotations, labels, TLS and a custom HTTP port. BREAKING CHANGE: The Ingress is no longer rendered when `service.http.enabled` is `false`. `ingress.className` now defaults to `nginx` instead of the cluster's default IngressClass. The undocumented `namespace` value no longer applies to the Ingress. Co-authored-by: Copilot <copilot@github.com>