Ko
Description
The ko crawler looks recursively for every .ko.yaml file from a root directory, and updates the base images it declares.
Two keys are read:
# .ko.yaml
defaultBaseImage: gcr.io/distroless/static:nonroot
baseImageOverrides:
github.com/example/cmd/app: gcr.io/distroless/base:debugOverride the file name with the files parameter. Note the leading dot in the default: ko.yaml without it is not matched.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a ko crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
Each base image produces a dockerimage source for the latest tag and a yaml target that rewrites the reference in place. When digest pinning is enabled, a dockerdigest source is added and the digest is written alongside the tag.
digest defaults to true. Set digest: false to track the tag only.
Tip | Base images are commonly pinned to a non-version tag such as nonroot or debug. There is no newer version to find for those, so the generated manifest tracks only the digest (which is usually what you want, since it still picks up rebuilds of the same tag). |
Authentication
Use auths to reach private registries, keyed by registry URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.
Version filtering
If unspecified, the version filter defaults to kind semver with pattern *.
More details on the "Version Filtering" page.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | “auths” defines the registry credentials, keyed by registry host without scheme. remark:
example: | |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| digest | boolean | “digest” defines whether the generated manifests pin the image digest in addition to the tag. default: true | |
| files | array | “files” defines the file name patterns the crawler searches for. The pattern syntax is: default: remark:
| |
| ignore | array | “ignore” defines rules to exclude matching container images from the autodiscovery. remark:
| |
| images | array | “images” defines the container image names to match. remark:
| |
| path | string | “path” defines a Ko file path pattern. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching container images. remark:
| |
| images | array | “images” defines the container image names to match. remark:
| |
| path | string | “path” defines a Ko file path pattern. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for Ko files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default:
kind “semver” with pattern “>= remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Example
# updatecli.d/default.yaml
name: "Ko autodiscovery"
scms:
default:
kind: git
spec:
url: "https://github.com/updatecli-test/knative-serving.git"
branch: main
autodiscovery:
scmid: default
crawlers:
ko:
digest: true
versionfilter:
kind: semver
pattern: minoronly
## To ignore specific path
#ignore:
# - images:
# - "gcr.io/distroless/static"
#only:
# - images:
# - "gcr.io/distroless/static"