Description

The prow crawler looks recursively for every .yaml and .yml file from a root directory, and updates the container images declared in Prow job definitions.

It shares its implementation with the kubernetes crawler, and differs only in the document shapes it recognises.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a prow crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Supported job types

Images are read from containers and initContainers under each job’s spec:

KeyShape

presubmits

A map of repository name to a list of jobs

postsubmits

A map of repository name to a list of jobs

periodics

A list of jobs

The repository and job name are included in the generated manifest name, for example deps: bump container image "gcr.io/k8s-prow/test" for repo "org/repo" and presubmit test "test-job".

Generated manifests

Each image produces a dockerimage source for the latest tag and a yaml target that rewrites the image reference in place. When digest pinning is enabled, a dockerdigest source is added and the digest is written alongside the tag.

digest defaults to true. Set digest: false to track the tag only.

Authentication

Use auths to reach private registries, keyed by registry URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *.

The pattern is then narrowed per image using the tag currently in the file: an image on 3.17 is filtered with >=3.17, and a tagfilter regex derived from the shape of that tag is added so unrelated tag conventions are not considered.

More details on the "Version Filtering" page.

Limitations

  • files patterns are matched against the file name only, not against the path. Use .yaml, not config/.yaml.

  • Prow configuration keys other than presubmits, postsubmits, and periodics are not inspected.

Manifest

Parameters

NameTypeDescriptionRequired
authsobject

auths provides a map of registry credentials where the key is the registry URL without scheme if empty, updatecli relies on OCI credentials such as the one used by Docker.

example:

auths:
  "ghcr.io":
    token: "xxx"
  "index.docker.io":
    username: "admin"
    password: "password"
    passwordstring

password specifies the container registry password to use for authentication. Not compatible with token

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

    tokenstring

token specifies the container registry token to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with username/password

    usernamestring

username specifies the container registry username to use for authentication.

compatible: * source * condition * target

default: by default credentials are fetch from the local environment such as ~/.docker/config.json.

remark: Not compatible with token

digestbooleandigest provides parameters to specify if the generated manifest should use a digest on top of the tag.
filesarray

Files allows to specify a list of Files to analyze.

The pattern syntax is:

  pattern:
   { term }
   term:
     '*'         matches any sequence of non-Separator characters
     '?'         matches any single non-Separator character
     '[' [ '^' ] { character-range } ']' character class (must be non-empty)
     c           matches character c (c != '*', '?', '\\', '[')
     '\\' c      matches character c

character-range:
  c         matches character c (c != '\\', '-', ']')
  '\\' c    matches character c
  lo '-' hi matches character c for lo <= c <= hi

Match requires pattern to match all of name, not just a substring. The only possible returned error is ErrBadPattern, when pattern is malformed.

On Windows, escaping is disabled. Instead, \\ is treated as path separator.

ignorearrayIgnore allows to specify rule to ignore autodiscovery a specific Kubernetes manifest based on a rule
    imagesarrayImages specifies the list of container image to check
    pathstringPath specifies a Fleet bundle path pattern, the pattern requires to match all of name, not just a subpart of the path.
onlyarrayOnly allows to specify rule to only autodiscover manifest for a specific Kubernetes manifest based on a rule
    imagesarrayImages specifies the list of container image to check
    pathstringPath specifies a Fleet bundle path pattern, the pattern requires to match all of name, not just a subpart of the path.
rootdirstringRootDir defines the root directory used to recursively search for Kubernetes files
versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: semver
    pattern: minor

and its type like regex, semver, or just latest.

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: "Prow autodiscovery"
scms:
  default:
    kind: git
    spec:
      url: "https://github.com/knative/infra.git"
      branch: main
autodiscovery:
  scmid: default
  crawlers:
    prow:
      digest: true
      rootdir: prow/jobs/custom
      files:
        - infra.yaml
      ## To ignore specific images
      #ignore:
      #  - images:
      #      - "mcr.microsoft.com/dotnet/framework/sdk"
      ## To consider only specific images
      #only:
      #  - images:
      #      - "mcr.microsoft.com/dotnet/framework/sdk"