ArgoCD
Description
The argocd crawler looks recursively for every .yaml and .yml file from a root directory, and proposes an update for each Helm chart it finds declared in an ArgoCD application.
A source is picked up when repoURL, chart, and targetRevision are all set. It is read from any of:
spec.sourceandspec.sources[]- ArgoCDApplicationspec.template.spec.sourceandspec.template.spec.sources[]- ArgoCDApplicationSet
Multi-document YAML files are supported; each document is addressed by index in the generated manifest.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with an argocd crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Important | Matching is structural, not by resource kind. apiVersion and kind are not checked, so any YAML document exposing spec.source.repoURL, .chart, and .targetRevision is treated as an ArgoCD application. Use only or ignore to narrow the scan when that is too broad. |
Generated manifests
Source - the latest chart version from the repository declared by
repoURL.Conditions - assert that
.chartand.repoURLstill hold the expected values, so the target is skipped if the application has been edited in the meantime.Target - writes the new version to
.targetRevision.
A repoURL with no URL scheme is treated as an OCI registry and rewritten to oci://<repoURL>, matching ArgoCD’s own behaviour.
Authentication
Use auths to reach private chart repositories. Entries are keyed by registry host, domain[:port] without a scheme, and accept either a token or a username/password pair. Credentials are propagated into every generated source spec.
Warning | Only the host part of the URL is used for the credential lookup, so one entry applies to every chart served by that host. |
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.
More details on the "Version Filtering" page.
Limitations
Only Helm chart sources are handled. Git, Kustomize, and directory sources have no
chartfield and are ignored.Sources missing any of
repoURL,chart, ortargetRevisionare skipped.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | “auths” defines the Helm repository credentials, keyed by repository host without scheme. remark:
example: | |
| password | string | ||
| token | string | ||
| username | string | ||
| ignore | array | “ignore” defines rules to exclude matching Helm charts from the autodiscovery. remark:
| |
| charts | object | “charts” defines the Helm charts to match, keyed by chart name. remark:
| |
| path | string | “path” defines a ArgoCD manifest path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm repository URLs to match. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching Helm charts. remark:
| |
| charts | object | “charts” defines the Helm charts to match, keyed by chart name. remark:
| |
| path | string | “path” defines a ArgoCD manifest path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm repository URLs to match. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for ArgoCD manifests. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default: kind “semver” with pattern “*”, the latest version. remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Note | only and ignore rules accept path (a file path pattern that must match the whole path), charts (a map of chart name to version), and repositories (a list of chart repository URLs). Conditions within a rule are combined, and rules are evaluated independently. |
Example
# updatecli.d/default.yaml
name: Argocd Autodiscovery Example
autodiscovery:
# scmid is applied to all crawlers
scmid: default
# actionid is applied to all crawlers
actionid: default
crawlers:
argocd:
# To ignore specific path
ignore:
# Ignore manifest match path "dev/*.yaml"
- path: dev/*.yaml
# Ignore any Helm chart named "kubewarden-crds"
- charts:
"kubewarden-crds": ""
# Ignore any helm chart repository named "https://charts.jetstack.io"
- repositories:
- "https://charts.jetstack.io"
# Ignore any Helm chart named "kubewarden-crds" in manifest path "dev/*.yaml"
- path: dev/*.yaml
charts:
"kubewarden-crds": ""
# Only accepts the same rule than ignore
#only:
# - path: helmfile.d/*
# - charts:
# "kubewarden-crds": ""
# - repositories:
# - "https://charts.jetstack.io"
#
scms:
default:
kind: github
spec:
owner: updatecli
repository: updatecli
token: '{{ requiredEnv "GITHUB_TOKEN" }}'
branch: "main"
actions:
default:
kind: "github/pullrequest"
spec:
labels:
- "dependencies"
mergemethod: "squash"
scmid: "default"