Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, Bucket error handling and GCS static authentication in source-controller. On the CLI side, flux migrate -f now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.
Note that this release contains CRD schema changes for ArtifactGenerator and ImageUpdateAutomation; both CRDs must be updated along with the controllers.
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [ghcr.io/fluxcd/flux-cli](https://github.com/fluxcd/flux2) | patch | `v2.9.3` → `v2.9.4` |
---
### Release Notes
<details>
<summary>fluxcd/flux2 (ghcr.io/fluxcd/flux-cli)</summary>
### [`v2.9.4`](https://github.com/fluxcd/flux2/releases/tag/v2.9.4)
[Compare Source](https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4)
##### Highlights
Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by `ImageUpdateAutomation`, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, `Bucket` error handling and GCS static authentication in source-controller. On the CLI side, `flux migrate -f` now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.
Note that this release contains CRD schema changes for `ArtifactGenerator` and `ImageUpdateAutomation`; both CRDs must be updated along with the controllers.
ℹ️ Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
- Confine tarball extraction and bound glob expansion (source-watcher)
- Disallow force-update and deletion via refspecs (image-automation-controller)
- Unify HTTP server request limits (notification-controller)
- Align Helm repository index loading with upstream Helm v4 (source-controller)
- Improve error handling in `Bucket` reconciliation (source-controller)
- Pin OCI chart verification by digest (source-controller)
- Limit GCS static authentication to service account keys (source-controller)
- Restrict the `allow-webhooks` network policy to the receiver port (flux CLI)
Improvements:
- Add support for migrating repositories to 2.9 in `flux migrate -f` (flux CLI)
- Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI)
- Update Bitbucket Cloud receiver guidance (notification-controller)
##### Components changelog
- source-controller [v1.9.4](https://github.com/fluxcd/source-controller/blob/v1.9.4/CHANGELOG.md)
- source-watcher [v2.2.3](https://github.com/fluxcd/source-watcher/blob/v2.2.3/CHANGELOG.md)
- notification-controller [v1.9.3](https://github.com/fluxcd/notification-controller/blob/v1.9.3/CHANGELOG.md)
- image-reflector-controller [v1.2.4](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.4/CHANGELOG.md)
- image-automation-controller [v1.2.4](https://github.com/fluxcd/image-automation-controller/blob/v1.2.4/CHANGELOG.md)
##### CLI changelog
- \[release/v2.9.x] Add support for 2.9 in `migrate -f` by [@​fluxcdbot](https://github.com/fluxcdbot) in [#​6021](https://github.com/fluxcd/flux2/pull/6021)
- Update fluxcd/pkg dependencies by [@​fluxcdbot](https://github.com/fluxcdbot) in [#​6026](https://github.com/fluxcd/flux2/pull/6026)
- \[release/v2.9.x] fix: restrict `allow-webhooks` netpol to receiver port by [@​fluxcdbot](https://github.com/fluxcdbot) in [#​6029](https://github.com/fluxcd/flux2/pull/6029)
- Update toolkit components by [@​fluxcdbot](https://github.com/fluxcdbot) in [#​6031](https://github.com/fluxcd/flux2/pull/6031)
**Full Changelog**: <https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNC44IiwidXBkYXRlZEluVmVyIjoiNDQuMTQuOCIsInRhcmdldEJyYW5jaCI6ImZyZXNoLXN0YXJ0IiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v2.9.3→v2.9.4Release Notes
fluxcd/flux2 (ghcr.io/fluxcd/flux-cli)
v2.9.4Compare Source
Highlights
Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by
ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning,Bucketerror handling and GCS static authentication in source-controller. On the CLI side,flux migrate -fnow supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.Note that this release contains CRD schema changes for
ArtifactGeneratorandImageUpdateAutomation; both CRDs must be updated along with the controllers.ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
Bucketreconciliation (source-controller)allow-webhooksnetwork policy to the receiver port (flux CLI)Improvements:
flux migrate -f(flux CLI)Components changelog
CLI changelog
migrate -fby @fluxcdbot in #6021allow-webhooksnetpol to receiver port by @fluxcdbot in #6029Full Changelog: https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.