Helmfile
Description
The Helmfile crawler looks recursively for every .yaml and .yml file from a specific root directory, and tries to update the Helm chart version of each release it finds.
A release is picked up when its chart is written as <repository>/<chart> and that repository is declared in the same file:
repositories:
- name: jetstack
url: https://charts.jetstack.io
releases:
- name: cert-manager
chart: jetstack/cert-manager
version: 1.14.0This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a helmfile crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Note | Every YAML file is inspected, not only files named helmfile.yaml, since Helmfile splits its releases across arbitrary file names. Files without a usable releases list simply yield nothing. |
Generated manifests
Each release produces one manifest containing:
OCI registries
A repository declared with oci: true is rewritten to an oci:// URL, dropping any http:// or https:// scheme first, matching how Helmfile itself resolves it. Credentials can be supplied inline on the repository entry with username and password, or through the crawler’s auths parameter.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.
More details on the "Version Filtering" page.
Limitations
A release whose
chartcannot be matched to a declared repository is skipped. In particular, a direct chart URL such aschart: oci://registry-1.docker.io/bitnamicharts/nginxproduces nothing, because there is no repository entry to resolve it against.Releases pinned through Helmfile templating or environment values are not resolved.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | Auths provides a map of registry credentials where the key is the registry URL without scheme | |
| password | string | password specifies the container registry password to use for authentication. Not compatible with token compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| token | string | token specifies the container registry token to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with username/password | |
| username | string | username specifies the container registry username to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| ignore | array | Ignore allows to specify rule to ignore autodiscovery a specific Helmfile based on a rule | |
| charts | object | Charts specifies the list of Helm Chart repository to check | |
| path | string | Path specifies a Helmfile chart path pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| repositories | array | Repositories specifies the list of Helm Chart repository to check | |
| only | array | Only allows to specify rule to only autodiscovery manifest for a specific Helmfile based on a rule | |
| charts | object | Charts specifies the list of Helm Chart repository to check | |
| path | string | Path specifies a Helmfile chart path pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| repositories | array | Repositories specifies the list of Helm Chart repository to check | |
| rootdir | string | rootdir defines the root directory used to recursively search for Helmfile manifest | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example: and its type like regex, semver, or just latest. More examples can be found at https://www.updatecli.io/docs/core/versionfilter/ | |
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
# updatecli.d/default.yaml
name: Test Helmfile Autodiscovery
scms:
default:
kind: git
spec:
url: https://github.com/olblak/k8s-lab.git
branch: main
autodiscovery:
# scmid is applied to all crawlers
scmid: default
crawlers:
helmfile:
# To ignore specific path
#ignore:
# # - path: <filepath relative to scm repository>
# # - path: chart/*
only:
- path: helmfile.d/*
#