CatalogServiceUpdateRequest carries optional field updates. Empty string fields are ignored — name is taken from the URL, not the body. Settings and SecretTypes are replaced when non-nil; pass nil to leave untouched.
HelmRepoRequest mirrors the on-cluster CR HelmRepo, including the Secret reference used to resolve credentials. Used by catalog service write requests; auth values themselves are never accepted in the request body.