Description

The Helmfile crawler looks recursively for every .yaml and .yml file from a specific root directory, and tries to update the Helm chart version of each release it finds.

A release is picked up when its chart is written as <repository>/<chart> and that repository is declared in the same file:

repositories:
  - name: jetstack
    url: https://charts.jetstack.io
releases:
  - name: cert-manager
    chart: jetstack/cert-manager
    version: 1.14.0

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a helmfile crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Note
Every YAML file is inspected, not only files named helmfile.yaml, since Helmfile splits its releases across arbitrary file names. Files without a usable releases list simply yield nothing.

Generated manifests

Each release produces one manifest containing:

  • a helmchart source resolving the latest chart version from the repository URL,

  • a yaml condition asserting $.releases[i].chart still holds the discovered value,

  • a yaml target writing the new version to $.releases[i].version.

OCI registries

A repository declared with oci: true is rewritten to an oci:// URL, dropping any http:// or https:// scheme first, matching how Helmfile itself resolves it. Credentials can be supplied inline on the repository entry with username and password, or through the crawler’s auths parameter.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.

More details on the "Version Filtering" page.

Limitations

  • A release whose chart cannot be matched to a declared repository is skipped. In particular, a direct chart URL such as chart: oci://registry-1.docker.io/bitnamicharts/nginx produces nothing, because there is no repository entry to resolve it against.

  • Releases pinned through Helmfile templating or environment values are not resolved.

Manifest

Parameters

NameTypeDescriptionRequired
authsobjectAuths provides a map of registry credentials where the key is the registry URL without scheme
    passwordstring

password specifies the container registry password to use for authentication. Not compatible with token

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

    tokenstring

token specifies the container registry token to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with username/password

    usernamestring

username specifies the container registry username to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

ignorearrayIgnore allows to specify rule to ignore autodiscovery a specific Helmfile based on a rule
    chartsobjectCharts specifies the list of Helm Chart repository to check
    pathstringPath specifies a Helmfile chart path pattern, the pattern requires to match all of name, not just a subpart of the path.
    repositoriesarrayRepositories specifies the list of Helm Chart repository to check
onlyarrayOnly allows to specify rule to only autodiscovery manifest for a specific Helmfile based on a rule
    chartsobjectCharts specifies the list of Helm Chart repository to check
    pathstringPath specifies a Helmfile chart path pattern, the pattern requires to match all of name, not just a subpart of the path.
    repositoriesarrayRepositories specifies the list of Helm Chart repository to check
rootdirstringrootdir defines the root directory used to recursively search for Helmfile manifest
versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: semver
    pattern: minor

and its type like regex, semver, or just latest.

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: Test Helmfile Autodiscovery

scms:
  default:
    kind: git
    spec:
      url: https://github.com/olblak/k8s-lab.git
      branch: main
    
autodiscovery:
  # scmid is applied to all crawlers
  scmid: default
  crawlers:
    helmfile:
      # To ignore specific path
      #ignore:
      #  # - path: <filepath relative to scm repository>
      #  # - path: chart/*
      only:
        - path: helmfile.d/*
#