Description

The Helmfile crawler looks recursively for every .yaml and .yml file from a specific root directory, and tries to update the Helm chart version of each release it finds.

A release is picked up when its chart is written as <repository>/<chart> and that repository is declared in the same file:

repositories:
  - name: jetstack
    url: https://charts.jetstack.io
releases:
  - name: cert-manager
    chart: jetstack/cert-manager
    version: 1.14.0

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a helmfile crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Note
Every YAML file is inspected, not only files named helmfile.yaml, since Helmfile splits its releases across arbitrary file names. Files without a usable releases list simply yield nothing.

Generated manifests

Each release produces one manifest containing:

  • a helmchart source resolving the latest chart version from the repository URL,

  • a yaml condition asserting $.releases[i].chart still holds the discovered value,

  • a yaml target writing the new version to $.releases[i].version.

OCI registries

A repository declared with oci: true is rewritten to an oci:// URL, dropping any http:// or https:// scheme first, matching how Helmfile itself resolves it. Credentials can be supplied inline on the repository entry with username and password, or through the crawler’s auths parameter.

Version filtering

If unspecified, the version filter defaults to kind semver with pattern *, since Helm charts are expected to follow semantic versioning.

More details on the "Version Filtering" page.

Limitations

  • A release whose chart cannot be matched to a declared repository is skipped. In particular, a direct chart URL such as chart: oci://registry-1.docker.io/bitnamicharts/nginx produces nothing, because there is no repository entry to resolve it against.

  • Releases pinned through Helmfile templating or environment values are not resolved.

Manifest

Parameters

NameTypeDescriptionRequired
authsobject

“auths” defines the Helm repository credentials, keyed by repository host without scheme.

remark:

  • only “token” is used.

example:

auths:
  "my-helm-repo.com":
    token: "xxx"
    passwordstring

“password” defines the container registry password used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “password” requires “username”.
  • “token” cannot be combined with both “username” and “password”.
    tokenstring

“token” defines the container registry bearer token used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “token” cannot be combined with both “username” and “password”.
    usernamestring

“username” defines the container registry username used for authentication.

default: credentials are retrieved from the local environment, such as ~/.docker/config.json.

remark:

  • “username” requires “password”.
  • “token” cannot be combined with both “username” and “password”.
ignorearray

“ignore” defines rules to exclude matching releases from the autodiscovery.

remark:

  • a release is ignored when it matches at least one rule.
    chartsobject

“charts” defines the charts to match, keyed by chart name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Helmfile file path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm chart repository URLs to match.

remark:

  • a release matches when its repository URL equals one of the values.
onlyarray

“only” defines rules to restrict the autodiscovery to matching releases.

remark:

  • a release is kept only when it matches at least one rule.
    chartsobject

“charts” defines the charts to match, keyed by chart name.

remark:

  • an empty value matches any version.
  • otherwise the value is a semantic version constraint, such as “>=1.0.0”.
  • when the version or the constraint cannot be parsed, the value must equal the version.
    pathstring

“path” defines a Helmfile file path pattern.

remark:

  • the pattern must match the whole path, not just a substring.
  • the pattern follows the Go filepath.Match syntax, such as “*” or “?”.
    repositoriesarray

“repositories” defines the Helm chart repository URLs to match.

remark:

  • a release matches when its repository URL equals one of the values.
rootdirstring

“rootdir” defines the directory where the crawler starts searching for Helmfile files.

default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory.

remark:

  • a relative path is resolved from the default directory.
  • an absolute path is used as is, instead of the scm directory.
versionfilterobject

“versionfilter” defines the version filter used by the generated manifests.

default: kind “semver” with pattern “*”, the latest version.

remark:

  • with kind “semver”, “pattern” accepts:
    • “prerelease”: the latest prerelease of the current version.
    • “patch”: patch updates only.
    • “minor”: patch and minor updates.
    • “minoronly”: minor updates only.
    • “major”: patch, minor and major updates.
    • “majoronly”: major updates only.
    • a version constraint, such as “>= 1.0.0”.
  • with kind “regex”, “pattern” accepts a regular expression.
  • more examples at https://www.updatecli.io/docs/core/versionfilter/

example:

versionfilter:
  kind: semver
  pattern: minor
    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

        patternstring

“pattern” defines the regular expression matching the text to replace.

example:

  • pattern: “_”
        replacementstring

“replacement” defines the text replacing each match of “pattern”.

remark:

  • capture groups can be referenced with $1, $2, and so on.

example:

  • replacement: “.”
    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: Test Helmfile Autodiscovery

scms:
  default:
    kind: git
    spec:
      url: https://github.com/olblak/k8s-lab.git
      branch: main
    
autodiscovery:
  # scmid is applied to all crawlers
  scmid: default
  crawlers:
    helmfile:
      # To ignore specific path
      #ignore:
      #  # - path: <filepath relative to scm repository>
      #  # - path: chart/*
      only:
        - path: helmfile.d/*
#