Description

The flux crawler looks recursively for every .yaml and .yml file from a root directory, and updates two kinds of Flux resource:

  • HelmRelease - the chart version is updated when a HelmRepository matching the release’s sourceRef is found in the same namespace. Disable with helmrelease: false.

  • OCIRepository - the artifact tag is updated. Disable with ocirepository: false.

Both are enabled by default. Override the scanned file names with the files parameter.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a flux crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Generated manifests

ResourceManifest shape

HelmRelease

A helmchart source resolving the latest chart version from the HelmRepository URL, yaml conditions asserting the chart and its source reference still match, and a yaml target writing the chart version.

OCIRepository

A dockerimage source for the latest tag and a yaml target writing spec.ref.tag. When digest pinning is enabled, a dockerdigest source is added and the digest is written too.

digest defaults to true for OCI repositories. Set digest: false to track the tag only.

Authentication

Use auths to reach private registries and chart repositories, keyed by URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *.

More details on the "Version Filtering" page.

Limitations

  • GitRepository sources are not updated yet. Feel free to open an issue if you need it.

  • A HelmRelease whose HelmRepository lives in a different namespace, or is not present in the scanned tree, is skipped.

Manifest

Parameters

NameTypeDescriptionRequired
authsobjectauths provides a map of registry credentials where the key is the registry URL without scheme
    passwordstring

password specifies the container registry password to use for authentication. Not compatible with token

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

    tokenstring

token specifies the container registry token to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with username/password

    usernamestring

username specifies the container registry username to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

digestboolean

digest allows to specify if the generated manifest should use OCI digest on top of the tag

default: true

filesarray

files allows to override default flux files

default: ["*.yaml", "*.yml"]

helmreleaseboolean

helmRelease define if helmrelease file should be updated or not

default: true

ignorearray

ignore allows to specify rule to ignore autodiscovery a specific Flux helmrelease based on a rule

default: empty

    artifactsobject

Artifacts specifies the list of artifacts to check

The key is the artifact name and the value is the artifact version

An artifact can be a Helm Chart when used in the context of Helmrelease or an OCIRepository when used in the context of OCIRepository

If the value is empty, then the artifact name is enough to match If the value is a valid semver constraint, then the artifact version must match the constraint

    pathstringPath specifies a Flux filepath pattern, the pattern requires to match all of name, not just a subpart of the path.
    repositoriesarrayRepositories specifies the list of Helm Chart repository to check
ocirepositoryboolean

OCIRepository allows to specify if OCI repository files should be updated

default: true

onlyarray

only allows to specify rule to only autodiscover manifest for a specific Flux helm release based on a rule

default: empty

    artifactsobject

Artifacts specifies the list of artifacts to check

The key is the artifact name and the value is the artifact version

An artifact can be a Helm Chart when used in the context of Helmrelease or an OCIRepository when used in the context of OCIRepository

If the value is empty, then the artifact name is enough to match If the value is a valid semver constraint, then the artifact version must match the constraint

    pathstringPath specifies a Flux filepath pattern, the pattern requires to match all of name, not just a subpart of the path.
    repositoriesarrayRepositories specifies the list of Helm Chart repository to check
rootdirstring

rootDir defines the root directory used to recursively search for Flux files

default: . (current working directory) or scm root directory

versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: semver
    pattern: minor

and its type like regex, semver, or just latest.

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: "Flux Autodiscovery"
scms:
  default:
    kind: git
    spec:
      url: "https://github.com/updatecli-test/flux2-multi-tenancy.git"
      branch: main
autodiscovery:
  scmid: default
  crawlers:
    flux:
      digest: true
      versionfilter:
        kind: semver
        pattern: minoronly