Update dependency fluxcd/flux2 to v2.9.0 #348

Merged
Lumpiasty merged 1 commits from renovate/fluxcd-flux2-2.x into fresh-start 2026-07-04 21:03:02 +00:00
Collaborator

This PR contains the following updates:

Package Update Change
fluxcd/flux2 minor v2.8.8v2.9.0

Release Notes

fluxcd/flux2 (fluxcd/flux2)

v2.9.0

Compare Source

Highlights

Flux v2.9.0 is a feature release. Users are encouraged to upgrade for the best experience.

For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.9 GA blog post.

Overview of the new features:

  • Flux CLI Plugin System with the Mirror and Schema plugins (flux plugin)
  • Server-Side Apply field ignore rules for fine-grained drift control (Kustomization)
  • SOPS decryption with the Age post-quantum cipher (Kustomization)
  • Kubernetes Workload Identity authentication for OpenBao and Vault (Kustomization)
  • Helm post-render strategies, including chart hooks support (HelmRelease)
  • Literal mode for Helm values references mirroring helm --set-literal (HelmRelease)
  • Allow empty kind in CEL health check expressions (Kustomization, HelmRelease)
  • Git commit signing and verification with SSH keys (GitRepository, ImageUpdateAutomation)
  • AWS CodeCommit authentication using Workload Identity (GitRepository)
  • Custom Sigstore trusted root for keyless verification in air-gapped environments (OCIRepository)
  • Path pattern directory discovery for monorepos (ArtifactGenerator)
  • Secret-less, OIDC-secured webhook Receivers (Receiver)

❤️ Big thanks to all the Flux contributors that helped us with this release!

Kubernetes compatibility

This release is compatible with the following Kubernetes versions:

Kubernetes version Minimum required
v1.34 >= 1.34.1
v1.35 >= 1.35.0
v1.36 >= 1.36.0

[!NOTE]
Note that the Flux project offers support only for the latest three minor versions of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors such as
ControlPlane that provide enterprise support for Flux.

OpenShift compatibility

Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.

Upgrade procedure

⚠️ The Flux APIs image.toolkit.fluxcd.io/v1beta2 and notification.toolkit.fluxcd.io/v1beta2
have reached end-of-life and have been removed from the CRDs.

Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.9.

Components changelog

CLI changelog

New Contributors

Full Changelog: https://github.com/fluxcd/flux2/compare/v2.8.0...v2.9.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [fluxcd/flux2](https://github.com/fluxcd/flux2) | minor | `v2.8.8` → `v2.9.0` | --- ### Release Notes <details> <summary>fluxcd/flux2 (fluxcd/flux2)</summary> ### [`v2.9.0`](https://github.com/fluxcd/flux2/releases/tag/v2.9.0) [Compare Source](https://github.com/fluxcd/flux2/compare/v2.8.8...v2.9.0) #### Highlights Flux v2.9.0 is a feature release. Users are encouraged to upgrade for the best experience. For a compressive overview of new features and API changes included in this release, please refer to the [Announcing Flux 2.9 GA blog post](https://fluxcd.io/blog/2026/06/flux-v2.9.0/). Overview of the new features: - Flux CLI Plugin System with the Mirror and Schema plugins (`flux plugin`) - Server-Side Apply field ignore rules for fine-grained drift control (`Kustomization`) - SOPS decryption with the Age post-quantum cipher (`Kustomization`) - Kubernetes Workload Identity authentication for OpenBao and Vault (`Kustomization`) - Helm post-render strategies, including chart hooks support (`HelmRelease`) - Literal mode for Helm values references mirroring `helm --set-literal` (`HelmRelease`) - Allow empty kind in CEL health check expressions (`Kustomization`, `HelmRelease`) - Git commit signing and verification with SSH keys (`GitRepository`, `ImageUpdateAutomation`) - AWS CodeCommit authentication using Workload Identity (`GitRepository`) - Custom Sigstore trusted root for keyless verification in air-gapped environments (`OCIRepository`) - Path pattern directory discovery for monorepos (`ArtifactGenerator`) - Secret-less, OIDC-secured webhook Receivers (`Receiver`) ❤️ Big thanks to all the Flux contributors that helped us with this release! ##### Kubernetes compatibility This release is compatible with the following Kubernetes versions: | Kubernetes version | Minimum required | | ------------------ | ---------------- | | `v1.34` | `>= 1.34.1` | | `v1.35` | `>= 1.35.0` | | `v1.36` | `>= 1.36.0` | > \[!NOTE] > Note that the Flux project offers support only for the latest three minor versions of Kubernetes. > Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors such as > [ControlPlane](https://control-plane.io/enterprise-for-flux-cd/) that provide enterprise support for Flux. ##### OpenShift compatibility Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using [Flux Operator](https://operatorhub.io/operator/flux-operator). The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage. #### Upgrade procedure :warning: The Flux APIs `image.toolkit.fluxcd.io/v1beta2` and `notification.toolkit.fluxcd.io/v1beta2` have reached end-of-life and have been removed from the CRDs. Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from older versions of Flux to v2.9. #### Components changelog - source-controller [v1.9.1](https://github.com/fluxcd/source-controller/blob/v1.9.1/CHANGELOG.md) - kustomize-controller [v1.9.1](https://github.com/fluxcd/kustomize-controller/blob/v1.9.1/CHANGELOG.md) - notification-controller [v1.9.1](https://github.com/fluxcd/notification-controller/blob/v1.9.1/CHANGELOG.md) - helm-controller [v1.6.1](https://github.com/fluxcd/helm-controller/blob/v1.6.1/CHANGELOG.md) - image-reflector-controller [v1.2.1](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.1/CHANGELOG.md) - image-automation-controller [v1.2.1](https://github.com/fluxcd/image-automation-controller/blob/v1.2.1/CHANGELOG.md) - source-watcher [v2.2.1](https://github.com/fluxcd/source-watcher/blob/v2.2.1/CHANGELOG.md) #### CLI changelog - Add backport label for Flux 2.8 by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5732](https://github.com/fluxcd/flux2/pull/5732) - Remove no longer needed workaround for Flux 2.8 by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5733](https://github.com/fluxcd/flux2/pull/5733) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5740](https://github.com/fluxcd/flux2/pull/5740) - Add missing things to release notes template by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5743](https://github.com/fluxcd/flux2/pull/5743) - ci: add top-level permissions to upgrade-fluxcd-pkg workflow by [@&#8203;gaganhr94](https://github.com/gaganhr94) in [#&#8203;5763](https://github.com/fluxcd/flux2/pull/5763) - build(deps): bump the ci group across 1 directory with 11 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;5764](https://github.com/fluxcd/flux2/pull/5764) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5766](https://github.com/fluxcd/flux2/pull/5766) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5769](https://github.com/fluxcd/flux2/pull/5769) - Add target branch name to update branch by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5773](https://github.com/fluxcd/flux2/pull/5773) - Fix/resume exit code by [@&#8203;Aman-Cool](https://github.com/Aman-Cool) in [#&#8203;5701](https://github.com/fluxcd/flux2/pull/5701) - Mark RFC 0010, 0011 and 0012 as implemented by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5776](https://github.com/fluxcd/flux2/pull/5776) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5780](https://github.com/fluxcd/flux2/pull/5780) - Add --resolve-symlinks flag to build and push artifact commands by [@&#8203;rohansood10](https://github.com/rohansood10) in [#&#8203;5724](https://github.com/fluxcd/flux2/pull/5724) - fix: validate --source flag in create kustomization command by [@&#8203;gma1k](https://github.com/gma1k) in [#&#8203;5798](https://github.com/fluxcd/flux2/pull/5798) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5821](https://github.com/fluxcd/flux2/pull/5821) - Add `--show-source` to `flux get ks` and `flux get hr` by [@&#8203;rafaelperoco](https://github.com/rafaelperoco) in [#&#8203;5828](https://github.com/fluxcd/flux2/pull/5828) - Add `flux create secret receiver` command by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5835](https://github.com/fluxcd/flux2/pull/5835) - fix: handle multiple symlinks to same target in build artifact by [@&#8203;Iam-Karan-Suresh](https://github.com/Iam-Karan-Suresh) in [#&#8203;5833](https://github.com/fluxcd/flux2/pull/5833) - Add `--in-memory-build` to `flux build ks` and `flux diff ks` by [@&#8203;rycli](https://github.com/rycli) in [#&#8203;5794](https://github.com/fluxcd/flux2/pull/5794) - Migrate end-to-end test to latest cloud SDKs by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5840](https://github.com/fluxcd/flux2/pull/5840) - docs: Add AI Coding Assistants Guidance by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5841](https://github.com/fluxcd/flux2/pull/5841) - Add AI Agents guidance by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5847](https://github.com/fluxcd/flux2/pull/5847) - \[RFC-0013] Flux CLI Plugin System by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5795](https://github.com/fluxcd/flux2/pull/5795) - Add `--ignore-not-found` to `flux diff ks` by [@&#8203;rycli](https://github.com/rycli) in [#&#8203;5845](https://github.com/fluxcd/flux2/pull/5845) - \[RFC-0013] Implement plugin system by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5849](https://github.com/fluxcd/flux2/pull/5849) - build(deps): bump github.com/go-git/go-git/v5 from 5.17.1 to 5.18.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;5853](https://github.com/fluxcd/flux2/pull/5853) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5856](https://github.com/fluxcd/flux2/pull/5856) - Add digest pinning support to `flux plugin install` by [@&#8203;Iam-Karan-Suresh](https://github.com/Iam-Karan-Suresh) in [#&#8203;5872](https://github.com/fluxcd/flux2/pull/5872) - Add `--ns-follows-kube-context` global flag for using the kubeconfig context namespace by [@&#8203;jtyr](https://github.com/jtyr) in [#&#8203;5831](https://github.com/fluxcd/flux2/pull/5831) - include source-watcher in install.yaml manifests by [@&#8203;tmmorin](https://github.com/tmmorin) in [#&#8203;5881](https://github.com/fluxcd/flux2/pull/5881) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5890](https://github.com/fluxcd/flux2/pull/5890) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5903](https://github.com/fluxcd/flux2/pull/5903) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5907](https://github.com/fluxcd/flux2/pull/5907) - Validate Helm source URL schemes by [@&#8203;immanuwell](https://github.com/immanuwell) in [#&#8203;5909](https://github.com/fluxcd/flux2/pull/5909) - Introduce `flux trigger receiver` by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5908](https://github.com/fluxcd/flux2/pull/5908) - refactor(api): migrate MakeDependsOn to shared apis/meta func by [@&#8203;vecil](https://github.com/vecil) in [#&#8203;5912](https://github.com/fluxcd/flux2/pull/5912) - Update to Kubernetes 1.36 and Go 1.26 by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5924](https://github.com/fluxcd/flux2/pull/5924) - build(deps): bump the ci group across 1 directory with 19 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;5925](https://github.com/fluxcd/flux2/pull/5925) - Run conformance tests for Kubernetes 1.36 by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5926](https://github.com/fluxcd/flux2/pull/5926) - Add support for AWS CodeCommit to `flux bootstrap git` by [@&#8203;taraspos](https://github.com/taraspos) in [#&#8203;5868](https://github.com/fluxcd/flux2/pull/5868) - Validate plugin binary path by [@&#8203;stefanprodan](https://github.com/stefanprodan) in [#&#8203;5927](https://github.com/fluxcd/flux2/pull/5927) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5928](https://github.com/fluxcd/flux2/pull/5928) - fix: preserve invalid metadata.labels in `flux build ks` by [@&#8203;raffis](https://github.com/raffis) in [#&#8203;5906](https://github.com/fluxcd/flux2/pull/5906) - build: target host arch for local builds/envtest by [@&#8203;stealthybox](https://github.com/stealthybox) in [#&#8203;5932](https://github.com/fluxcd/flux2/pull/5932) - build(deps): bump the ci group with 6 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;5938](https://github.com/fluxcd/flux2/pull/5938) - Support specifing sparseCheckout in flux bootstrap by [@&#8203;piny940](https://github.com/piny940) in [#&#8203;5918](https://github.com/fluxcd/flux2/pull/5918) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5944](https://github.com/fluxcd/flux2/pull/5944) - Honor `ks.spec.postBuild.substituteStrategy` by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5945](https://github.com/fluxcd/flux2/pull/5945) - Add DriftIgnoreRules support to flux diff kustomization by [@&#8203;dipti-pai](https://github.com/dipti-pai) in [#&#8203;5923](https://github.com/fluxcd/flux2/pull/5923) - Allow signing commits using SSH key by [@&#8203;hiddeco](https://github.com/hiddeco) in [#&#8203;5920](https://github.com/fluxcd/flux2/pull/5920) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5950](https://github.com/fluxcd/flux2/pull/5950) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5937](https://github.com/fluxcd/flux2/pull/5937) - cmd: support `type!=status` in get --status-selector by [@&#8203;3uzbcqje](https://github.com/3uzbcqje) in [#&#8203;5952](https://github.com/fluxcd/flux2/pull/5952) - Fix `flux get all --status-selector` for empty results and notification resources by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5954](https://github.com/fluxcd/flux2/pull/5954) - Upgrade go-git-providers to v0.27.0 by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5956](https://github.com/fluxcd/flux2/pull/5956) - Fix using Receiver adapter for ArtifactGenerator by [@&#8203;matheuscscp](https://github.com/matheuscscp) in [#&#8203;5957](https://github.com/fluxcd/flux2/pull/5957) - feat: Install Plugins alongside Flux setup in gh actions by [@&#8203;gat786](https://github.com/gat786) in [#&#8203;5955](https://github.com/fluxcd/flux2/pull/5955) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5960](https://github.com/fluxcd/flux2/pull/5960) - Add CLI support for OCIRepository.spec.layerSelector in flux create source oci by [@&#8203;dme86](https://github.com/dme86) in [#&#8203;5892](https://github.com/fluxcd/flux2/pull/5892) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;5963](https://github.com/fluxcd/flux2/pull/5963) #### New Contributors - [@&#8203;gaganhr94](https://github.com/gaganhr94) made their first contribution in [#&#8203;5763](https://github.com/fluxcd/flux2/pull/5763) - [@&#8203;rohansood10](https://github.com/rohansood10) made their first contribution in [#&#8203;5724](https://github.com/fluxcd/flux2/pull/5724) - [@&#8203;gma1k](https://github.com/gma1k) made their first contribution in [#&#8203;5798](https://github.com/fluxcd/flux2/pull/5798) - [@&#8203;rafaelperoco](https://github.com/rafaelperoco) made their first contribution in [#&#8203;5828](https://github.com/fluxcd/flux2/pull/5828) - [@&#8203;Iam-Karan-Suresh](https://github.com/Iam-Karan-Suresh) made their first contribution in [#&#8203;5833](https://github.com/fluxcd/flux2/pull/5833) - [@&#8203;rycli](https://github.com/rycli) made their first contribution in [#&#8203;5794](https://github.com/fluxcd/flux2/pull/5794) - [@&#8203;jtyr](https://github.com/jtyr) made their first contribution in [#&#8203;5831](https://github.com/fluxcd/flux2/pull/5831) - [@&#8203;tmmorin](https://github.com/tmmorin) made their first contribution in [#&#8203;5881](https://github.com/fluxcd/flux2/pull/5881) - [@&#8203;immanuwell](https://github.com/immanuwell) made their first contribution in [#&#8203;5909](https://github.com/fluxcd/flux2/pull/5909) - [@&#8203;vecil](https://github.com/vecil) made their first contribution in [#&#8203;5912](https://github.com/fluxcd/flux2/pull/5912) - [@&#8203;taraspos](https://github.com/taraspos) made their first contribution in [#&#8203;5868](https://github.com/fluxcd/flux2/pull/5868) - [@&#8203;piny940](https://github.com/piny940) made their first contribution in [#&#8203;5918](https://github.com/fluxcd/flux2/pull/5918) - [@&#8203;3uzbcqje](https://github.com/3uzbcqje) made their first contribution in [#&#8203;5952](https://github.com/fluxcd/flux2/pull/5952) - [@&#8203;gat786](https://github.com/gat786) made their first contribution in [#&#8203;5955](https://github.com/fluxcd/flux2/pull/5955) - [@&#8203;dme86](https://github.com/dme86) made their first contribution in [#&#8203;5892](https://github.com/fluxcd/flux2/pull/5892) **Full Changelog**: <https://github.com/fluxcd/flux2/compare/v2.8.0...v2.9.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMjIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIyMi4xIiwidGFyZ2V0QnJhbmNoIjoiZnJlc2gtc3RhcnQiLCJsYWJlbHMiOltdfQ==-->
Renovate added 1 commit 2026-07-01 02:01:09 +00:00
Lumpiasty merged commit 0a9c5825db into fresh-start 2026-07-04 21:03:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Lumpiasty/klaster#348