Skip to content

feat(deps): update flux group ( v2.8.8 → v2.9.6 ) - #3011

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/flux
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/flux

Conversation

@renovate

@renovate renovate Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
fluxcd/flux2 Kustomization minor v2.8.8 → v2.9.6
ghcr.io/fluxcd/flux-manifests minor v2.8.8 → v2.9.6
ghcr.io/fluxcd/flux-manifests minor v2.5.1 → v2.9.6

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

fluxcd/flux2 (fluxcd/flux2)

v2.9.6

Compare Source

Highlights

Flux v2.9.6 is a patch release that stops helm-controller from reapplying chart CRDs on every upgrade when server-side apply is enabled, and recovers HelmReleases left with a drifted Ready=Unknown condition after a failed status patch. source-controller normalizes Azure Blob listing ETags so unchanged containers are no longer re-downloaded on every reconcile, and evicts stale Helm repository index entries from the cache so repositories with frequently changing indexes no longer fail with "Cache is full". kustomize-controller extends SOPS decryption error redaction to spec.postBuild.substituteFrom values, so substituted secrets echoed back in API validation errors are masked out of status conditions and events, and adds the opt-in DisableCommitStatusEvent feature gate. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Stop reapplying chart CRDs on upgrades when using server-side apply with the default Create policy (helm-controller)
  • Recover HelmReleases stranded with a drifted Ready=Unknown condition after a failed status patch (helm-controller)
  • Ignore NotFound when deleting the HelmChart (helm-controller)
  • Normalize Azure Blob listing ETags so unchanged containers are not re-downloaded on every reconcile (source-controller)
  • Evict stale Helm repository index entries from the cache to avoid "Cache is full" errors (source-controller)
  • Extend SOPS decryption error redaction to spec.postBuild.substituteFrom values (kustomize-controller)

Improvements:

  • Add the opt-in DisableCommitStatusEvent feature gate (kustomize-controller)

Components changelog

CLI changelog

Full Changelog: fluxcd/flux2@v2.9.5...v2.9.6

v2.9.5

Compare Source

Highlights

Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g. ${VAR:2:-1}, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Validate kubeconfigs from .spec.kubeConfig Secrets, rejecting local file references in certificate-authority, tokenFile, client-certificate and client-key; credentials and certificates must be embedded inline (helm-controller, kustomize-controller)
  • Purge temporary directories at startup (kustomize-controller)
  • Fix panic on negative-length substring expressions in post-build substitution (kustomize-controller, flux CLI)

Improvements:

  • Move back to upstream Helm v4.2.4, dropping the Flux fork (helm-controller, source-controller)
  • Update fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4 (all controllers, flux CLI)

Components changelog

CLI changelog

Full Changelog: fluxcd/flux2@v2.9.4...v2.9.5

v2.9.4

Compare Source

Highlights

Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, Bucket error handling and GCS static authentication in source-controller. On the CLI side, flux migrate -f now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.

Note that this release contains CRD schema changes for ArtifactGenerator and ImageUpdateAutomation; both CRDs must be updated along with the controllers.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Confine tarball extraction and bound glob expansion (source-watcher)
  • Disallow force-update and deletion via refspecs (image-automation-controller)
  • Unify HTTP server request limits (notification-controller)
  • Align Helm repository index loading with upstream Helm v4 (source-controller)
  • Improve error handling in Bucket reconciliation (source-controller)
  • Pin OCI chart verification by digest (source-controller)
  • Limit GCS static authentication to service account keys (source-controller)
  • Restrict the allow-webhooks network policy to the receiver port (flux CLI)

Improvements:

  • Add support for migrating repositories to 2.9 in flux migrate -f (flux CLI)
  • Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI)
  • Update Bitbucket Cloud receiver guidance (notification-controller)

Components changelog

CLI changelog

Full Changelog: fluxcd/flux2@v2.9.3...v2.9.4

v2.9.3

Compare Source

Highlights

Flux v2.9.3 is a patch release. It fixes empty lines vanishing from rendered Helm chart manifests, HelmReleases being marked as tested when their Helm test hooks never ran, and spec.images entries that set only some image fields discarding the remaining fields already declared for the same image in the kustomization.yaml. The latter affects both kustomize-controller and the flux build|diff kustomization commands. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix empty lines vanishing from rendered chart manifests (helm-controller)
  • Fix HasBeenTested for all corner cases, where a release could be marked as tested although its Helm test hooks never ran (helm-controller)
  • Fix a spec.images entry setting only some of the image fields discarding the remaining fields already declared for the same image in the kustomization.yaml at spec.path, e.g. overriding only newName produced an untagged image reference (kustomize-controller, flux CLI)

Improvements:

  • Update fluxcd/pkg dependencies
  • Include source-watcher in the OCI flux-manifests artifact

Components changelog

CLI changelog

Full Changelog: fluxcd/flux2@v2.9.2...v2.9.3

v2.9.2

Compare Source

Highlights

Flux v2.9.2 is a patch release. The main fix addresses a regression introduced in
v2.9.1 where a Kustomization with openapi.path pointing to a URL failed to
reconcile with failed to read OpenAPI schema. This release also corrects several
CRD field descriptions that contained inaccurate or leaked content. Users are
encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix a regression where a Kustomization with openapi.path pointing to a URL failed to reconcile with failed to read OpenAPI schema (kustomize-controller)
  • Fix the HelmChart CRD description for .status.url, which pointed users at BucketStatus.Artifact instead of HelmChartStatus.Artifact (source-controller)
  • Fix the ImageRepository CRD description for .status.observedExclusionList, which referred to spec.lastScanResult instead of status.lastScanResult (image-reflector-controller)
  • Fix the ImageUpdateAutomation CRD description for .status.observedSourceRevision, which had a stray Go struct declaration leaking into it (image-automation-controller)

Improvements:

  • Update fluxcd/pkg dependencies
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.1...v2.9.2

v2.9.1

Compare Source

v2.9.0

Compare Source

Highlights

Flux v2.9.0 is a feature release. Users are encouraged to upgrade for the best experience.

For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.9 GA blog post.

Overview of the new features:

  • Flux CLI Plugin System with the Mirror and Schema plugins (flux plugin)
  • Server-Side Apply field ignore rules for fine-grained drift control (Kustomization)
  • SOPS decryption with the Age post-quantum cipher (Kustomization)
  • Kubernetes Workload Identity authentication for OpenBao and Vault (Kustomization)
  • Helm post-render strategies, including chart hooks support (HelmRelease)
  • Literal mode for Helm values references mirroring helm --set-literal (HelmRelease)
  • Allow empty kind in CEL health check expressions (Kustomization, HelmRelease)
  • Git commit signing and verification with SSH keys (GitRepository, ImageUpdateAutomation)
  • AWS CodeCommit authentication using Workload Identity (GitRepository)
  • Custom Sigstore trusted root for keyless verification in air-gapped environments (OCIRepository)
  • Path pattern directory discovery for monorepos (ArtifactGenerator)
  • Secret-less, OIDC-secured webhook Receivers (Receiver)

❤️ Big thanks to all the Flux contributors that helped us with this release!

Kubernetes compatibility

This release is compatible with the following Kubernetes versions:

Kubernetes version Minimum required
v1.34 >= 1.34.1
v1.35 >= 1.35.0
v1.36 >= 1.36.0

[!NOTE]
Note that the Flux project offers support only for the latest three minor versions of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors such as
ControlPlane that provide enterprise support for Flux.

OpenShift compatibility

Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.

Upgrade procedure

⚠️ The Flux APIs image.toolkit.fluxcd.io/v1beta2 and notification.toolkit.fluxcd.io/v1beta2
have reached end-of-life and have been removed from the CRDs.

Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.9.

Components changelog
CLI changelog
New Contributors

Full Changelog: fluxcd/flux2@v2.8.0...v2.9.0


Configuration

📅 Schedule: (in timezone Europe/Moscow)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@mglants-bot

mglants-bot Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
--- kubernetes/berries/flux Kustomization: flux-system/cluster OCIRepository: flux-system/flux-manifests

+++ kubernetes/berries/flux Kustomization: flux-system/cluster OCIRepository: flux-system/flux-manifests

@@ -7,9 +7,9 @@

     kustomize.toolkit.fluxcd.io/namespace: flux-system
   name: flux-manifests
   namespace: flux-system
 spec:
   interval: 10m
   ref:
-    tag: v2.5.1
+    tag: v2.9.6
   url: oci://ghcr.io/fluxcd/flux-manifests

@mglants-bot

mglants-bot Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
--- kubernetes/subterra/flux Kustomization: flux-system/cluster OCIRepository: flux-system/flux-manifests

+++ kubernetes/subterra/flux Kustomization: flux-system/cluster OCIRepository: flux-system/flux-manifests

@@ -7,9 +7,9 @@

     kustomize.toolkit.fluxcd.io/namespace: flux-system
   name: flux-manifests
   namespace: flux-system
 spec:
   interval: 10m
   ref:
-    tag: v2.8.8
+    tag: v2.9.6
   url: oci://ghcr.io/fluxcd/flux-manifests

@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.0 ) feat(deps): update flux group ( v2.8.8 → v2.9.1 ) Jul 7, 2026
@renovate
renovate Bot force-pushed the renovate/flux branch from ec71a1b to 4fa789d Compare July 7, 2026 15:04
@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.1 ) feat(deps): update flux group ( v2.8.8 → v2.9.2 ) Jul 13, 2026
@renovate
renovate Bot force-pushed the renovate/flux branch from 4fa789d to 80d1af5 Compare July 13, 2026 15:55
@renovate
renovate Bot force-pushed the renovate/flux branch 2 times, most recently from 2bf9f0f to f736603 Compare July 23, 2026 17:03
@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.2 ) feat(deps): update flux group ( v2.8.8 → v2.9.3 ) Jul 23, 2026
@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.3 ) feat(deps): update flux group ( v2.8.8 → v2.9.4 ) Aug 7, 2026
@renovate
renovate Bot force-pushed the renovate/flux branch 2 times, most recently from c8bd7ff to 6e8e3ec Compare August 12, 2026 03:53
@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.4 ) feat(deps): update flux group ( v2.8.8 → v2.9.5 ) Aug 31, 2026
@renovate
renovate Bot force-pushed the renovate/flux branch 3 times, most recently from 88dda86 to c850d97 Compare September 7, 2026 17:21
@renovate
renovate Bot force-pushed the renovate/flux branch 3 times, most recently from 0015b54 to 46561ff Compare September 16, 2026 10:06
@renovate renovate Bot changed the title feat(deps): update flux group ( v2.8.8 → v2.9.5 ) feat(deps): update flux group ( v2.8.8 → v2.9.6 ) Oct 1, 2026
| datasource  | package                       | from   | to     |
| ----------- | ----------------------------- | ------ | ------ |
| github-tags | fluxcd/flux2                  | v2.8.8 | v2.9.6 |
| docker      | ghcr.io/fluxcd/flux-manifests | v2.8.8 | v2.9.6 |
| docker      | ghcr.io/fluxcd/flux-manifests | v2.5.1 | v2.9.6 |
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants