Update dependency fluxcd/flux2 to v2.9.5 - #126
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
February 20, 2025 16:02
a80bb7a to
bd8c59d
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
February 25, 2025 19:09
bd8c59d to
bb791ec
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
May 29, 2025 15:38
bb791ec to
7c4762e
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
June 5, 2025 22:17
7c4762e to
2ed273b
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
June 16, 2025 14:48
2ed273b to
5401c7d
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
June 27, 2025 11:48
5401c7d to
d638eea
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
July 8, 2025 11:58
d638eea to
adc7ebd
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
September 30, 2025 15:46
adc7ebd to
92f192f
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
October 6, 2025 18:34
92f192f to
bcaaa88
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
October 8, 2025 18:59
bcaaa88 to
e062e9b
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
October 28, 2025 21:48
e062e9b to
92b83ca
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
November 24, 2025 18:27
92b83ca to
ac91fea
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
November 27, 2025 15:37
ac91fea to
9c51eff
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
February 24, 2026 13:49
9c51eff to
4a02b2c
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
February 27, 2026 13:49
4a02b2c to
369b3f3
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
March 12, 2026 18:33
369b3f3 to
b4f336c
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
March 16, 2026 17:33
b4f336c to
e3f0add
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
April 7, 2026 17:38
e3f0add to
7fcffe7
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
April 7, 2026 21:28
7fcffe7 to
3eeaf1a
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
April 21, 2026 14:13
3eeaf1a to
432d690
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
May 12, 2026 12:36
432d690 to
47252a3
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
May 20, 2026 12:48
47252a3 to
9fdf934
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
June 30, 2026 18:52
9fdf934 to
41ca298
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
July 7, 2026 19:42
41ca298 to
9bd290d
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
July 13, 2026 15:01
9bd290d to
e582c26
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
July 23, 2026 18:58
e582c26 to
1e40290
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
August 7, 2026 16:44
1e40290 to
6e199af
Compare
renovate
Bot
force-pushed
the
renovate/fluxcd-flux2-2.x
branch
from
August 31, 2026 21:44
6e199af to
cd1a998
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.3.0→v2.9.5v2.4.0→v2.9.5Release Notes
fluxcd/flux2 (fluxcd/flux2)
v2.9.5Compare Source
Highlights
Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g.
${VAR:2:-1}, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience.ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
.spec.kubeConfigSecrets, rejecting local file references incertificate-authority,tokenFile,client-certificateandclient-key; credentials and certificates must be embedded inline (helm-controller, kustomize-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.9.4...v2.9.5
v2.9.4Compare Source
Highlights
Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by
ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning,Bucketerror handling and GCS static authentication in source-controller. On the CLI side,flux migrate -fnow supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.Note that this release contains CRD schema changes for
ArtifactGeneratorandImageUpdateAutomation; both CRDs must be updated along with the controllers.ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
Bucketreconciliation (source-controller)allow-webhooksnetwork policy to the receiver port (flux CLI)Improvements:
flux migrate -f(flux CLI)Components changelog
CLI changelog
migrate -fby @fluxcdbot in #6021allow-webhooksnetpol to receiver port by @fluxcdbot in #6029Full Changelog: fluxcd/flux2@v2.9.3...v2.9.4
v2.9.3Compare Source
Highlights
Flux v2.9.3 is a patch release. It fixes empty lines vanishing from rendered Helm chart manifests, HelmReleases being marked as tested when their Helm test hooks never ran, and
spec.imagesentries that set only some image fields discarding the remaining fields already declared for the same image in thekustomization.yaml. The latter affects both kustomize-controller and theflux build|diff kustomizationcommands. Users are encouraged to upgrade for the best experience.ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
HasBeenTestedfor all corner cases, where a release could be marked as tested although its Helm test hooks never ran (helm-controller)spec.imagesentry setting only some of the image fields discarding the remaining fields already declared for the same image in thekustomization.yamlatspec.path, e.g. overriding onlynewNameproduced an untagged image reference (kustomize-controller, flux CLI)Improvements:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.9.2...v2.9.3
v2.9.2Compare Source
Highlights
Flux v2.9.2 is a patch release. The main fix addresses a regression introduced in
v2.9.1 where a Kustomization with
openapi.pathpointing to a URL failed toreconcile with
failed to read OpenAPI schema. This release also corrects severalCRD field descriptions that contained inaccurate or leaked content. Users are
encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
openapi.pathpointing to a URL failed to reconcile withfailed to read OpenAPI schema(kustomize-controller)HelmChartCRD description for.status.url, which pointed users atBucketStatus.Artifactinstead ofHelmChartStatus.Artifact(source-controller)ImageRepositoryCRD description for.status.observedExclusionList, which referred tospec.lastScanResultinstead ofstatus.lastScanResult(image-reflector-controller)ImageUpdateAutomationCRD description for.status.observedSourceRevision, which had a stray Go struct declaration leaking into it (image-automation-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.9.1...v2.9.2
v2.9.1Compare Source
v2.9.0Compare Source
Highlights
Flux v2.9.0 is a feature release. Users are encouraged to upgrade for the best experience.
For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.9 GA blog post.
Overview of the new features:
flux plugin)Kustomization)Kustomization)Kustomization)HelmRelease)helm --set-literal(HelmRelease)Kustomization,HelmRelease)GitRepository,ImageUpdateAutomation)GitRepository)OCIRepository)ArtifactGenerator)Receiver)❤️ Big thanks to all the Flux contributors that helped us with this release!
Kubernetes compatibility
This release is compatible with the following Kubernetes versions:
v1.34>= 1.34.1v1.35>= 1.35.0v1.36>= 1.36.0OpenShift compatibility
Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.
Upgrade procedure
image.toolkit.fluxcd.io/v1beta2andnotification.toolkit.fluxcd.io/v1beta2have reached end-of-life and have been removed from the CRDs.
Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.9.
Components changelog
CLI changelog
--show-sourcetoflux get ksandflux get hrby @rafaelperoco in #5828flux create secret receivercommand by @stefanprodan in #5835--in-memory-buildtoflux build ksandflux diff ksby @rycli in #5794--ignore-not-foundtoflux diff ksby @rycli in #5845flux plugin installby @Iam-Karan-Suresh in #5872--ns-follows-kube-contextglobal flag for using the kubeconfig context namespace by @jtyr in #5831flux trigger receiverby @matheuscscp in #5908flux bootstrap gitby @taraspos in #5868flux build ksby @raffis in #5906ks.spec.postBuild.substituteStrategyby @matheuscscp in #5945type!=statusin get --status-selector by @3uzbcqje in #5952flux get all --status-selectorfor empty results and notification resources by @matheuscscp in #5954New Contributors
Full Changelog: fluxcd/flux2@v2.8.0...v2.9.0
v2.8.8Compare Source
Highlights
Flux v2.8.8 is a patch release that includes CVE fixes via go-git v5.19.1 (source-controller, image-automation-controller), reliability fixes in helm-controller and source-controller, the move of Helm back to upstream v4.2.0, support for GCP sovereign cloud artifact registries, and dependency updates. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
crds/directory (helm-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.7...v2.8.8
v2.8.7Compare Source
Highlights
Flux v2.8.7 is a patch release that includes a bug fix in kustomize-controller, a CVE fix in source-controller and image-automation-controller via go-git v5.19.0, and dependency updates. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
kustomize.toolkit.fluxcd.io/ssa: IfNotPresentwhere non-namespaced resources were being deleted and recreated on each reconciliation (kustomize-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.6...v2.8.7
v2.8.6Compare Source
Highlights
Flux v2.8.6 is a patch release that includes bug fixes and improvements across helm-controller, image-automation-controller, kustomize-controller, notification-controller, and source-controller. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
audiencefield on the GCR Receiver secret for tighter verification — will become mandatory in Flux v2.9 (notification-controller)Improvements:
MigrateAPIVersionfeature gate for migrating the API version of resources in managed field entries (kustomize-controller)Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.5...v2.8.6
v2.8.5Compare Source
Highlights
Flux v2.8.5 is a patch release that includes bug fixes and improvements across kustomize-controller, source-controller, and notification-controller. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
Improvements:
emailandaudiencefields to the GCR Receiver for tighter verification (notification-controller)Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.4...v2.8.5
v2.8.4Compare Source
Highlights
Flux v2.8.4 is a patch release that includes fixes for the Flux CLI. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
flux build ksandflux diff kson Windows--sourceflag validation increate kustomizationcommandCLI changelog
Full Changelog: fluxcd/flux2@v2.8.3...v2.8.4
v2.8.3Compare Source
Highlights
Flux v2.8.3 is a patch release that fixes a regression in helm-controller. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
---in the content, e.g. YAML separators, embedded scripts, CAs inside ConfigMaps (helm-controller)Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.2...v2.8.3
v2.8.2Compare Source
Highlights
Flux v2.8.2 is a patch release that comes with various fixes. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
---getting concatenated toapiVersion:by updating to Helm 4.1.3 (helm-controller)DefaultToRetryOnFailurethat improves the experience when theCancelHealthCheckOnNewRevisionis enabled (helm-controller)Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.1...v2.8.2
v2.8.1Compare Source
Highlights
Flux v2.8.1 is a patch release that comes with various fixes. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
Components changelog
CLI changelog
Full Changelog: fluxcd/flux2@v2.8.0...v2.8.1
v2.8.0Compare Source
Highlights
Flux v2.8.0 is a feature release. Users are encouraged to upgrade for the best experience.
For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.8 GA blog post.
Overview of the new features:
HelmRelease)HelmRelease).status.inventory(HelmRelease)CancelHealthCheckOnNewRevisionfeature gate (Kustomization,HelmRelease)Provider)Kustomization)GitRepository,ImageUpdateAutomation,Provider)OCIRepository)ArtifactGenerator)DirectSourceFetchfeature gate (Kustomization,HelmRelease,ArtifactGenerator)❤️ Big thanks to all the Flux contributors that helped us with this release!
Kubernetes compatibility
This release is compatible with the following Kubernetes versions:
v1.33>= 1.32.0v1.34>= 1.34.1v1.35>= 1.35.0OpenShift compatibility
Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.
Upgrade procedure
v1beta2andv2beta2(deprecated in 2024) have reached end-of-life and have been removed from the CRDs.Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.8.
Components changelog
CLI changelog
GITHUB_TOKENin therelease-flux-manifestsworkflow by @stefanprodan in #5547flux push artifactnot working with--providerby @matheuscscp in #5551flux migrateto work with local files by @matheuscscp in #5554flux migratefor live cluster migrations by @stefanprodan in #5558flux migrate -fcommand to work with comments by @matheuscscp in #5560flux migrate -fnot considering kind comments by @matheuscscp in #5563Kustomizationresource into unstructured map only once during variable substitution by @ramasai1 in #5566--storage-adv-addrand--events-addrflags by @stefanprodan in #5574flux get source externalby @dgunzy in #5555flux export source externalby @dgunzy in #5583flux migrate -fby @matheuscscp in #5713Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.