Description

The flux crawler looks recursively for every .yaml and .yml file from a root directory, and updates two kinds of Flux resource:

  • HelmRelease - the chart version is updated when a HelmRepository matching the release’s sourceRef is found in the same namespace. Disable with helmrelease: false.

  • OCIRepository - the artifact tag is updated. Disable with ocirepository: false.

Both are enabled by default. Override the scanned file names with the files parameter.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a flux crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Generated manifests

ResourceManifest shape

HelmRelease

A helmchart source resolving the latest chart version from the HelmRepository URL, yaml conditions asserting the chart and its source reference still match, and a yaml target writing the chart version.

OCIRepository

A dockerimage source for the latest tag and a yaml target writing spec.ref.tag. When digest pinning is enabled, a dockerdigest source is added and the digest is written too.

digest defaults to true for OCI repositories. Set digest: false to track the tag only.

Authentication

Use auths to reach private registries and chart repositories, keyed by URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *.

More details on the "Version Filtering" page.

Limitations

  • GitRepository sources are not updated yet. Feel free to open an issue if you need it.

  • A HelmRelease whose HelmRepository lives in a different namespace, or is not present in the scanned tree, is skipped.

Manifest

Parameters

NameTypeDescriptionRequired
authsobject

“auths” defines the registry credentials, keyed by registry host without scheme.

remark:

  • when empty, Updatecli uses the local OCI credentials, such as the Docker ones.
  • for a HelmRelease chart, only the “token” is used, looked up by the Helm repository host.

example:

auths:
  "ghcr.io":
    token: "xxx"
  "index.docker.io":
    username: "admin"
    password: "password"
    passwordstring

“password” defines the container registry password used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “password” requires “username”.
  • “token” cannot be combined with both “username” and “password”.
    tokenstring

“token” defines the container registry bearer token used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “token” cannot be combined with both “username” and “password”.
    usernamestring

“username” defines the container registry username used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “username” requires “password”.
  • “token” cannot be combined with both “username” and “password”.
digestboolean

“digest” defines whether the generated manifests pin the OCIRepository artifact digest in addition to the tag.

default: true

filesarray

“files” defines the file name patterns the crawler searches for.

default:

files:
  - "*.yaml"
  - "*.yml"

remark:

  • the pattern is matched against the file name only, not against its path.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
helmreleaseboolean

“helmrelease” defines whether HelmRelease resources are updated.

default: true

ignorearray

“ignore” defines rules to exclude matching artifacts from the autodiscovery.

remark:

  • a artifact is ignored when it matches at least one rule.
    artifactsobject

“artifacts” defines the artifacts to match, keyed by artifact name.

remark:

  • an artifact is the Helm chart of a HelmRelease, or the artifact of an OCIRepository.
  • an OCIRepository artifact name is its URL without the “oci://” prefix.
  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Flux manifest path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm repository URLs to match.

remark:

  • a repository URL must be identical to one of the entries.
  • an OCIRepository artifact has no Helm repository, so a rule setting “repositories” never matches it.
ocirepositoryboolean

“ocirepository” defines whether OCIRepository resources are updated.

default: true

onlyarray

“only” defines rules to restrict the autodiscovery to matching artifacts.

remark:

  • a artifact is kept only when it matches at least one rule.
    artifactsobject

“artifacts” defines the artifacts to match, keyed by artifact name.

remark:

  • an artifact is the Helm chart of a HelmRelease, or the artifact of an OCIRepository.
  • an OCIRepository artifact name is its URL without the “oci://” prefix.
  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Flux manifest path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm repository URLs to match.

remark:

  • a repository URL must be identical to one of the entries.
  • an OCIRepository artifact has no Helm repository, so a rule setting “repositories” never matches it.
rootdirstring

“rootdir” defines the directory where the crawler starts searching for Flux manifests.

default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory.

remark:

  • a relative path is resolved from the default directory.
  • an absolute path is used as is, instead of the scm directory.
versionfilterobject

“versionfilter” defines the version filter used by the generated manifests.

default:

  • for a HelmRelease chart, kind “semver” with pattern “*”, the latest version.
  • for an OCIRepository artifact, kind “semver” with pattern “>=”, combined with a tag filter derived from the current tag.

remark:

  • with kind “semver”, “pattern” accepts:
    • “prerelease”: the latest prerelease of the current version.
    • “patch”: patch updates only.
    • “minor”: patch and minor updates.
    • “minoronly”: minor updates only.
    • “major”: patch, minor and major updates.
    • “majoronly”: major updates only.
    • a version constraint, such as “>= 1.0.0”.
  • with kind “regex”, “pattern” accepts a regular expression.
  • more examples at https://www.updatecli.io/docs/core/versionfilter/

example:

versionfilter:
  kind: semver
  pattern: minor
    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

        patternstring

“pattern” defines the regular expression matching the text to replace.

example:

  • pattern: “_”
        replacementstring

“replacement” defines the text replacing each match of “pattern”.

remark:

  • capture groups can be referenced with $1, $2, and so on.

example:

  • replacement: “.”
    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: "Flux Autodiscovery"
scms:
  default:
    kind: git
    spec:
      url: "https://github.com/updatecli-test/flux2-multi-tenancy.git"
      branch: main
autodiscovery:
  scmid: default
  crawlers:
    flux:
      digest: true
      versionfilter:
        kind: semver
        pattern: minoronly