Description

The argocd crawler looks recursively for every .yaml and .yml file from a root directory, and proposes an update for each Helm chart it finds declared in an ArgoCD application.

A source is picked up when repoURL, chart, and targetRevision are all set. It is read from any of:

  • spec.source and spec.sources[] - ArgoCD Application

  • spec.template.spec.source and spec.template.spec.sources[] - ArgoCD ApplicationSet

Multi-document YAML files are supported; each document is addressed by index in the generated manifest.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with an argocd crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Important
Matching is structural, not by resource kind. apiVersion and kind are not checked, so any YAML document exposing spec.source.repoURL, .chart, and .targetRevision is treated as an ArgoCD application. Use only or ignore to narrow the scan when that is too broad.

Generated manifests

Each discovered chart produces a helmchart source, two yaml conditions, and one yaml target:

  • Source - the latest chart version from the repository declared by repoURL.

  • Conditions - assert that .chart and .repoURL still hold the expected values, so the target is skipped if the application has been edited in the meantime.

  • Target - writes the new version to .targetRevision.

A repoURL with no URL scheme is treated as an OCI registry and rewritten to oci://<repoURL>, matching ArgoCD’s own behaviour.

Authentication

Use auths to reach private chart repositories. Entries are keyed by registry host, domain[:port] without a scheme, and accept either a token or a username/password pair. Credentials are propagated into every generated source spec.

Warning
Only the host part of the URL is used for the credential lookup, so one entry applies to every chart served by that host.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.

More details on the "Version Filtering" page.

Limitations

  • Only Helm chart sources are handled. Git, Kustomize, and directory sources have no chart field and are ignored.

  • Sources missing any of repoURL, chart, or targetRevision are skipped.

Manifest

Parameters

NameTypeDescriptionRequired
authsobject

“auths” defines the Helm repository credentials, keyed by repository host without scheme.

remark:

  • only the host part of the repository URL, such as “domain[:port]”, is used to look up credentials.

example:

auths:
  "my-helm-repo.com":
    token: "my-secret-token"
  "my-second-helm-repo.com":
    username: "username"
    password: "my-secret-password"
    passwordstring
    tokenstring
    usernamestring
ignorearray

“ignore” defines rules to exclude matching Helm charts from the autodiscovery.

remark:

  • a Helm chart is ignored when it matches at least one rule.
    chartsobject

“charts” defines the Helm charts to match, keyed by chart name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a ArgoCD manifest path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm repository URLs to match.

remark:

  • a repository URL must be identical to one of the entries.
onlyarray

“only” defines rules to restrict the autodiscovery to matching Helm charts.

remark:

  • a Helm chart is kept only when it matches at least one rule.
    chartsobject

“charts” defines the Helm charts to match, keyed by chart name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a ArgoCD manifest path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm repository URLs to match.

remark:

  • a repository URL must be identical to one of the entries.
rootdirstring

“rootdir” defines the directory where the crawler starts searching for ArgoCD manifests.

default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory.

remark:

  • a relative path is resolved from the default directory.
  • an absolute path is used as is, instead of the scm directory.
versionfilterobject

“versionfilter” defines the version filter used by the generated manifests.

default: kind “semver” with pattern “*”, the latest version.

remark:

  • with kind “semver”, “pattern” accepts:
    • “prerelease”: the latest prerelease of the current version.
    • “patch”: patch updates only.
    • “minor”: patch and minor updates.
    • “minoronly”: minor updates only.
    • “major”: patch, minor and major updates.
    • “majoronly”: major updates only.
    • a version constraint, such as “>= 1.0.0”.
  • with kind “regex”, “pattern” accepts a regular expression.
  • more examples at https://www.updatecli.io/docs/core/versionfilter/

example:

versionfilter:
  kind: semver
  pattern: minor
    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

        patternstring

“pattern” defines the regular expression matching the text to replace.

example:

  • pattern: “_”
        replacementstring

“replacement” defines the text replacing each match of “pattern”.

remark:

  • capture groups can be referenced with $1, $2, and so on.

example:

  • replacement: “.”
    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli
Note
only and ignore rules accept path (a file path pattern that must match the whole path), charts (a map of chart name to version), and repositories (a list of chart repository URLs). Conditions within a rule are combined, and rules are evaluated independently.

Example

# updatecli.d/default.yaml
name: Argocd Autodiscovery Example

autodiscovery:
  # scmid is applied to all crawlers
  scmid: default
  # actionid is applied to all crawlers
  actionid: default
  crawlers:
    argocd:
      # To ignore specific path
      ignore:
        # Ignore manifest match path "dev/*.yaml"
        - path: dev/*.yaml
        # Ignore any Helm chart named "kubewarden-crds"
        - charts:
            "kubewarden-crds": ""
        # Ignore any helm chart repository named "https://charts.jetstack.io"
        - repositories:
            - "https://charts.jetstack.io"

        # Ignore any Helm chart named "kubewarden-crds" in manifest path "dev/*.yaml"
        - path: dev/*.yaml
          charts:
            "kubewarden-crds": ""
      # Only accepts the same rule than ignore
      #only:
      #  - path: helmfile.d/*
      #  - charts:
      #      "kubewarden-crds": ""
      #  - repositories:
      #      - "https://charts.jetstack.io"
      #
scms:
  default:
    kind: github
    spec:
      owner: updatecli
      repository: updatecli
      token: '{{ requiredEnv "GITHUB_TOKEN" }}'
      branch: "main"
    
actions:
    default:
        kind: "github/pullrequest"
        spec:
            labels:
                - "dependencies"
            mergemethod: "squash"
        scmid: "default"