Flux
Description
The flux crawler looks recursively for every .yaml and .yml file from a root directory, and updates two kinds of Flux resource:
HelmRelease- the chart version is updated when aHelmRepositorymatching the release’ssourceRefis found in the same namespace. Disable withhelmrelease: false.OCIRepository- the artifact tag is updated. Disable withocirepository: false.
Both are enabled by default. Override the scanned file names with the files parameter.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a flux crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
| Resource | Manifest shape |
|---|---|
| A |
| A |
digest defaults to true for OCI repositories. Set digest: false to track the tag only.
Authentication
Use auths to reach private registries and chart repositories, keyed by URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *.
More details on the "Version Filtering" page.
Limitations
GitRepositorysources are not updated yet. Feel free to open an issue if you need it.A
HelmReleasewhoseHelmRepositorylives in a different namespace, or is not present in the scanned tree, is skipped.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | auths provides a map of registry credentials where the key is the registry URL without scheme | |
| password | string | password specifies the container registry password to use for authentication. Not compatible with token compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| token | string | token specifies the container registry token to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with username/password | |
| username | string | username specifies the container registry username to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| digest | boolean | digest allows to specify if the generated manifest should use OCI digest on top of the tag default: true | |
| files | array | files allows to override default flux files default: | |
| helmrelease | boolean | helmRelease define if helmrelease file should be updated or not default: true | |
| ignore | array | ignore allows to specify rule to ignore autodiscovery a specific Flux helmrelease based on a rule default: empty | |
| artifacts | object | Artifacts specifies the list of artifacts to check The key is the artifact name and the value is the artifact version An artifact can be a Helm Chart when used in the context of Helmrelease or an OCIRepository when used in the context of OCIRepository If the value is empty, then the artifact name is enough to match If the value is a valid semver constraint, then the artifact version must match the constraint | |
| path | string | Path specifies a Flux filepath pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| repositories | array | Repositories specifies the list of Helm Chart repository to check | |
| ocirepository | boolean | OCIRepository allows to specify if OCI repository files should be updated default: true | |
| only | array | only allows to specify rule to only autodiscover manifest for a specific Flux helm release based on a rule default: empty | |
| artifacts | object | Artifacts specifies the list of artifacts to check The key is the artifact name and the value is the artifact version An artifact can be a Helm Chart when used in the context of Helmrelease or an OCIRepository when used in the context of OCIRepository If the value is empty, then the artifact name is enough to match If the value is a valid semver constraint, then the artifact version must match the constraint | |
| path | string | Path specifies a Flux filepath pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| repositories | array | Repositories specifies the list of Helm Chart repository to check | |
| rootdir | string | rootDir defines the root directory used to recursively search for Flux files default: . (current working directory) or scm root directory | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example: and its type like regex, semver, or just latest. More examples can be found at https://www.updatecli.io/docs/core/versionfilter/ | |
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
# updatecli.d/default.yaml
name: "Flux Autodiscovery"
scms:
default:
kind: git
spec:
url: "https://github.com/updatecli-test/flux2-multi-tenancy.git"
branch: main
autodiscovery:
scmid: default
crawlers:
flux:
digest: true
versionfilter:
kind: semver
pattern: minoronly