Helm
Description
The helm crawler looks recursively for all Helm charts from a specific root directory. A directory is treated as a chart root when it contains a Chart.yaml or Chart.yml file.
For each chart it performs two independent kinds of update:
Chart dependencies declared in
Chart.yaml. Disable withignorechartdependency: true.Container images declared in
values.yamlorvalues.yml. Disable withignorecontainer: true.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a helm crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Container image patterns
Updatecli looks for the following patterns in the chart values, where registry is optional:
image:
registry: ghcr.io
repository: updatecli/updatecli
tag: 0.37.0or
images:
backend:
repository: ghcr.io/updatecli/updatemonitor
tag: 0.1.0
front:
repository: ghcr.io/updatecli/updatemonitor-ui
tag: 0.1.0An image with no tag is assumed to be latest. An image with no repository is skipped. A digest already present in repository, such as image@sha256:…, is stripped before the lookup.
Generated manifests
Both flavours write through the helmchart target rather than editing files directly, so a chart is repackaged whenever one of its dependencies or images is bumped.
| Flavour | Manifest shape |
|---|---|
Chart dependency | A |
Container image | A |
Two parameters control what the target does to the chart itself:
skippackaging- whentrue, the chart is not repackaged.versionincrement- how the chart’s own version inChart.yamlis bumped in response to the change. Accepts a comma-separated list ofnone,major,minor,patch. Empty by default, meaning the chart version is left alone.
Digest pinning
digest defaults to true, so image updates resolve and write an immutable digest alongside the tag. Set digest: false to track the tag only.
Authentication
Use auths to reach private registries, keyed by registry URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *.
For container images the pattern is additionally narrowed per image, using the tag currently in the values file: an image on 0.37.0 is filtered with >=0.37.0, and a tagfilter regex derived from the shape of that tag is added so unrelated tag conventions are not considered.
More details on the "Version Filtering" page.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | “auths” defines the registry credentials, keyed by registry host without scheme. remark:
example: | |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| digest | boolean | “digest” defines whether the generated manifests pin the image digest in addition to the tag. default: true remark:
| |
| ignore | array | “ignore” defines rules to exclude matching chart dependencies or container images from the autodiscovery. remark:
| |
| containers | object | “containers” defines the container images to match, keyed by image name. remark:
| |
| dependencies | object | “dependencies” defines the chart dependencies to match, keyed by dependency name. remark:
| |
| path | string | “path” defines a Helm chart directory path pattern. remark:
| |
| ignorechartdependency | boolean | “ignorechartdependency” disables the chart dependency updates. default: false | |
| ignorecontainer | boolean | “ignorecontainer” disables the container image updates. default: false | |
| only | array | “only” defines rules to restrict the autodiscovery to matching chart dependencies or container images. remark:
| |
| containers | object | “containers” defines the container images to match, keyed by image name. remark:
| |
| dependencies | object | “dependencies” defines the chart dependencies to match, keyed by dependency name. remark:
| |
| path | string | “path” defines a Helm chart directory path pattern. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for Helm charts. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| skippackaging | boolean | “skippackaging” sets “skippackaging” on the generated helm targets. default: false remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default:
remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
| |
| versionincrement | string | “versionincrement” sets “versionincrement” on the generated helm targets. It defines how the chart version is bumped when the chart changes. default: minor, the helm target default. remark:
example:
|
Note | only and ignore rules accept path (a chart path pattern that must match the whole path), dependencies (a map of dependency name to version), and containers (a map of image name to tag). |
Example
# updatecli.d/default.yaml
name: "Helm autodiscovery using git scm"
scms:
epinio:
kind: git
spec:
url: https://github.com/olblak/charts.git
branch: master
autodiscovery:
# scmid is applied to all crawlers
scmid: epinio
crawlers:
helm:
ignore:
# Ignore a specific path:
- path: charts/acme/*
# Ignore a specific chart dependency:
- dependencies:
my-chart-dependency: ">0.0.1"
# Ignore a specific image reference in chart values:
- containers:
"longhornio/upgrade-responder": ""
# To include only a specific path:
#only:
# - path: charts/*