Flux
Description
The flux crawler looks recursively for every .yaml and .yml file from a root directory, and updates two kinds of Flux resource:
HelmRelease- the chart version is updated when aHelmRepositorymatching the release’ssourceRefis found in the same namespace. Disable withhelmrelease: false.OCIRepository- the artifact tag is updated. Disable withocirepository: false.
Both are enabled by default. Override the scanned file names with the files parameter.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a flux crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
| Resource | Manifest shape |
|---|---|
| A |
| A |
digest defaults to true for OCI repositories. Set digest: false to track the tag only.
Authentication
Use auths to reach private registries and chart repositories, keyed by URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *.
More details on the "Version Filtering" page.
Limitations
GitRepositorysources are not updated yet. Feel free to open an issue if you need it.A
HelmReleasewhoseHelmRepositorylives in a different namespace, or is not present in the scanned tree, is skipped.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | “auths” defines the registry credentials, keyed by registry host without scheme. remark:
example: | |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| digest | boolean | “digest” defines whether the generated manifests pin the OCIRepository artifact digest in addition to the tag. default: true | |
| files | array | “files” defines the file name patterns the crawler searches for. default: remark:
| |
| helmrelease | boolean | “helmrelease” defines whether HelmRelease resources are updated. default: true | |
| ignore | array | “ignore” defines rules to exclude matching artifacts from the autodiscovery. remark:
| |
| artifacts | object | “artifacts” defines the artifacts to match, keyed by artifact name. remark:
| |
| path | string | “path” defines a Flux manifest path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm repository URLs to match. remark:
| |
| ocirepository | boolean | “ocirepository” defines whether OCIRepository resources are updated. default: true | |
| only | array | “only” defines rules to restrict the autodiscovery to matching artifacts. remark:
| |
| artifacts | object | “artifacts” defines the artifacts to match, keyed by artifact name. remark:
| |
| path | string | “path” defines a Flux manifest path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm repository URLs to match. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for Flux manifests. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default:
remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Example
# updatecli.d/default.yaml
name: "Flux Autodiscovery"
scms:
default:
kind: git
spec:
url: "https://github.com/updatecli-test/flux2-multi-tenancy.git"
branch: main
autodiscovery:
scmid: default
crawlers:
flux:
digest: true
versionfilter:
kind: semver
pattern: minoronly