Description

The helm crawler looks recursively for all Helm charts from a specific root directory. A directory is treated as a chart root when it contains a Chart.yaml or Chart.yml file.

For each chart it performs two independent kinds of update:

  • Chart dependencies declared in Chart.yaml. Disable with ignorechartdependency: true.

  • Container images declared in values.yaml or values.yml. Disable with ignorecontainer: true.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a helm crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Container image patterns

Updatecli looks for the following patterns in the chart values, where registry is optional:

image:
  registry: ghcr.io
  repository: updatecli/updatecli
  tag: 0.37.0

or

images:
  backend:
      repository: ghcr.io/updatecli/updatemonitor
      tag: 0.1.0
  front:
      repository: ghcr.io/updatecli/updatemonitor-ui
      tag: 0.1.0

An image with no tag is assumed to be latest. An image with no repository is skipped. A digest already present in repository, such as image@sha256:…​, is stripped before the lookup.

Generated manifests

Both flavours write through the helmchart target rather than editing files directly, so a chart is repackaged whenever one of its dependencies or images is bumped.

FlavourManifest shape

Chart dependency

A helmchart source for the latest dependency version, yaml conditions asserting the dependency name and repository still match, and a helmchart target writing $.dependencies[i].version.

Container image

A dockerimage source for the latest tag, yaml conditions asserting the registry and repository, and a helmchart target writing the tag. When digest pinning is enabled a dockerdigest source is added and the digest is written too.

Two parameters control what the target does to the chart itself:

  • skippackaging - when true, the chart is not repackaged.

  • versionincrement - how the chart’s own version in Chart.yaml is bumped in response to the change. Accepts a comma-separated list of none, major, minor, patch. Empty by default, meaning the chart version is left alone.

Digest pinning

digest defaults to true, so image updates resolve and write an immutable digest alongside the tag. Set digest: false to track the tag only.

Authentication

Use auths to reach private registries, keyed by registry URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *.

For container images the pattern is additionally narrowed per image, using the tag currently in the values file: an image on 0.37.0 is filtered with >=0.37.0, and a tagfilter regex derived from the shape of that tag is added so unrelated tag conventions are not considered.

More details on the "Version Filtering" page.

Manifest

Parameters

NameTypeDescriptionRequired
authsobject

“auths” defines the registry credentials, keyed by registry host without scheme.

remark:

  • when empty, Updatecli uses the local OCI credentials, such as the Docker ones.

example:

auths:
  "ghcr.io":
    token: "xxx"
  "index.docker.io":
    username: "admin"
    password: "password"
    passwordstring

“password” defines the container registry password used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “password” requires “username”.
  • “token” cannot be combined with both “username” and “password”.
    tokenstring

“token” defines the container registry bearer token used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “token” cannot be combined with both “username” and “password”.
    usernamestring

“username” defines the container registry username used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “username” requires “password”.
  • “token” cannot be combined with both “username” and “password”.
digestboolean

“digest” defines whether the generated manifests pin the image digest in addition to the tag.

default: true

remark:

  • it applies to container images only.
ignorearray

“ignore” defines rules to exclude matching chart dependencies or container images from the autodiscovery.

remark:

  • a chart dependency or container image is ignored when it matches at least one rule.
    containersobject

“containers” defines the container images to match, keyed by image name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
  • the value is compared with the image tag.
    dependenciesobject

“dependencies” defines the chart dependencies to match, keyed by dependency name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Helm chart directory path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
ignorechartdependencyboolean

“ignorechartdependency” disables the chart dependency updates.

default: false

ignorecontainerboolean

“ignorecontainer” disables the container image updates.

default: false

onlyarray

“only” defines rules to restrict the autodiscovery to matching chart dependencies or container images.

remark:

  • a chart dependency or container image is kept only when it matches at least one rule.
    containersobject

“containers” defines the container images to match, keyed by image name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
  • the value is compared with the image tag.
    dependenciesobject

“dependencies” defines the chart dependencies to match, keyed by dependency name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Helm chart directory path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
rootdirstring

“rootdir” defines the directory where the crawler starts searching for Helm charts.

default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory.

remark:

  • a relative path is resolved from the default directory.
  • an absolute path is used as is, instead of the scm directory.
skippackagingboolean

“skippackaging” sets “skippackaging” on the generated helm targets.

default: false

remark:

  • see the “skippackaging” field of the helm resource.
versionfilterobject

“versionfilter” defines the version filter used by the generated manifests.

default:

  • chart dependencies: kind “semver” with pattern “*”, the latest version.
  • container images: kind “semver” with pattern “>=”, combined with a tag filter derived from the current tag.

remark:

  • with kind “semver”, “pattern” accepts:
    • “prerelease”: the latest prerelease of the current version.
    • “patch”: patch updates only.
    • “minor”: patch and minor updates.
    • “minoronly”: minor updates only.
    • “major”: patch, minor and major updates.
    • “majoronly”: major updates only.
    • a version constraint, such as “>= 1.0.0”.
  • with kind “regex”, “pattern” accepts a regular expression.
  • more examples at https://www.updatecli.io/docs/core/versionfilter/

example:

versionfilter:
  kind: semver
  pattern: minor
    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

        patternstring

“pattern” defines the regular expression matching the text to replace.

example:

  • pattern: “_”
        replacementstring

“replacement” defines the text replacing each match of “pattern”.

remark:

  • capture groups can be referenced with $1, $2, and so on.

example:

  • replacement: “.”
    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.
versionincrementstring

“versionincrement” sets “versionincrement” on the generated helm targets.

It defines how the chart version is bumped when the chart changes.

default: minor, the helm target default.

remark:

  • accepted values are a comma separated list of “major”, “minor” and “patch”, or one of “auto” or “none” on its own.

example:

  • versionincrement: patch
  • versionincrement: none
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli
Note
only and ignore rules accept path (a chart path pattern that must match the whole path), dependencies (a map of dependency name to version), and containers (a map of image name to tag).

Example

# updatecli.d/default.yaml
name: "Helm autodiscovery using git scm"
scms:
  epinio:
    kind: git
    spec:
      url: https://github.com/olblak/charts.git
      branch: master
    
autodiscovery:
  # scmid is applied to all crawlers
  scmid: epinio
  crawlers:
    helm:
      ignore:
        # Ignore a specific path:
        - path: charts/acme/*
        # Ignore a specific chart dependency:
        - dependencies:
            my-chart-dependency: ">0.0.1"
        # Ignore a specific image reference in chart values:
        - containers:
            "longhornio/upgrade-responder": ""
      
      # To include only a specific path:
      #only:
      #  - path: charts/*