Helmfile
Description
The Helmfile crawler looks recursively for every .yaml and .yml file from a specific root directory, and tries to update the Helm chart version of each release it finds.
A release is picked up when its chart is written as <repository>/<chart> and that repository is declared in the same file:
repositories:
- name: jetstack
url: https://charts.jetstack.io
releases:
- name: cert-manager
chart: jetstack/cert-manager
version: 1.14.0This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a helmfile crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Note | Every YAML file is inspected, not only files named helmfile.yaml, since Helmfile splits its releases across arbitrary file names. Files without a usable releases list simply yield nothing. |
Generated manifests
Each release produces one manifest containing:
OCI registries
A repository declared with oci: true is rewritten to an oci:// URL, dropping any http:// or https:// scheme first, matching how Helmfile itself resolves it. Credentials can be supplied inline on the repository entry with username and password, or through the crawler’s auths parameter.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.
More details on the "Version Filtering" page.
Limitations
A release whose
chartcannot be matched to a declared repository is skipped. In particular, a direct chart URL such aschart: oci://registry-1.docker.io/bitnamicharts/nginxproduces nothing, because there is no repository entry to resolve it against.Releases pinned through Helmfile templating or environment values are not resolved.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | “auths” defines the Helm repository credentials, keyed by repository host without scheme. remark:
example: | |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| ignore | array | “ignore” defines rules to exclude matching releases from the autodiscovery. remark:
| |
| charts | object | “charts” defines the charts to match, keyed by chart name. remark:
| |
| path | string | “path” defines a Helmfile file path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm chart repository URLs to match. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching releases. remark:
| |
| charts | object | “charts” defines the charts to match, keyed by chart name. remark:
| |
| path | string | “path” defines a Helmfile file path pattern. remark:
| |
| repositories | array | “repositories” defines the Helm chart repository URLs to match. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for Helmfile files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default: kind “semver” with pattern “*”, the latest version. remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Example
# updatecli.d/default.yaml
name: Test Helmfile Autodiscovery
scms:
default:
kind: git
spec:
url: https://github.com/olblak/k8s-lab.git
branch: main
autodiscovery:
# scmid is applied to all crawlers
scmid: default
crawlers:
helmfile:
# To ignore specific path
#ignore:
# # - path: <filepath relative to scm repository>
# # - path: chart/*
only:
- path: helmfile.d/*
#