Update dependency fluxcd/flux2 to v2.9.4 #398

Merged
Renovate merged 1 commits from renovate/fluxcd-flux2-2.x into fresh-start 2026-08-07 20:54:39 +00:00
Collaborator

This PR contains the following updates:

Package Update Change
fluxcd/flux2 patch v2.9.3v2.9.4

Release Notes

fluxcd/flux2 (fluxcd/flux2)

v2.9.4

Compare Source

Highlights

Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, Bucket error handling and GCS static authentication in source-controller. On the CLI side, flux migrate -f now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.

Note that this release contains CRD schema changes for ArtifactGenerator and ImageUpdateAutomation; both CRDs must be updated along with the controllers.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Confine tarball extraction and bound glob expansion (source-watcher)
  • Disallow force-update and deletion via refspecs (image-automation-controller)
  • Unify HTTP server request limits (notification-controller)
  • Align Helm repository index loading with upstream Helm v4 (source-controller)
  • Improve error handling in Bucket reconciliation (source-controller)
  • Pin OCI chart verification by digest (source-controller)
  • Limit GCS static authentication to service account keys (source-controller)
  • Restrict the allow-webhooks network policy to the receiver port (flux CLI)

Improvements:

  • Add support for migrating repositories to 2.9 in flux migrate -f (flux CLI)
  • Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI)
  • Update Bitbucket Cloud receiver guidance (notification-controller)

Components changelog

CLI changelog

Full Changelog: https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [fluxcd/flux2](https://github.com/fluxcd/flux2) | patch | `v2.9.3` → `v2.9.4` | --- ### Release Notes <details> <summary>fluxcd/flux2 (fluxcd/flux2)</summary> ### [`v2.9.4`](https://github.com/fluxcd/flux2/releases/tag/v2.9.4) [Compare Source](https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4) #### Highlights Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by `ImageUpdateAutomation`, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, `Bucket` error handling and GCS static authentication in source-controller. On the CLI side, `flux migrate -f` now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience. Note that this release contains CRD schema changes for `ArtifactGenerator` and `ImageUpdateAutomation`; both CRDs must be updated along with the controllers. ℹ️ Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from Flux v2.6 to the latest version. Fixes: - Confine tarball extraction and bound glob expansion (source-watcher) - Disallow force-update and deletion via refspecs (image-automation-controller) - Unify HTTP server request limits (notification-controller) - Align Helm repository index loading with upstream Helm v4 (source-controller) - Improve error handling in `Bucket` reconciliation (source-controller) - Pin OCI chart verification by digest (source-controller) - Limit GCS static authentication to service account keys (source-controller) - Restrict the `allow-webhooks` network policy to the receiver port (flux CLI) Improvements: - Add support for migrating repositories to 2.9 in `flux migrate -f` (flux CLI) - Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI) - Update Bitbucket Cloud receiver guidance (notification-controller) #### Components changelog - source-controller [v1.9.4](https://github.com/fluxcd/source-controller/blob/v1.9.4/CHANGELOG.md) - source-watcher [v2.2.3](https://github.com/fluxcd/source-watcher/blob/v2.2.3/CHANGELOG.md) - notification-controller [v1.9.3](https://github.com/fluxcd/notification-controller/blob/v1.9.3/CHANGELOG.md) - image-reflector-controller [v1.2.4](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.4/CHANGELOG.md) - image-automation-controller [v1.2.4](https://github.com/fluxcd/image-automation-controller/blob/v1.2.4/CHANGELOG.md) #### CLI changelog - \[release/v2.9.x] Add support for 2.9 in `migrate -f` by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6021](https://github.com/fluxcd/flux2/pull/6021) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6026](https://github.com/fluxcd/flux2/pull/6026) - \[release/v2.9.x] fix: restrict `allow-webhooks` netpol to receiver port by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6029](https://github.com/fluxcd/flux2/pull/6029) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6031](https://github.com/fluxcd/flux2/pull/6031) **Full Changelog**: <https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNC44IiwidXBkYXRlZEluVmVyIjoiNDQuMTQuOCIsInRhcmdldEJyYW5jaCI6ImZyZXNoLXN0YXJ0IiwibGFiZWxzIjpbXX0=-->
Renovate added 1 commit 2026-08-07 20:54:36 +00:00
Renovate scheduled this pull request to auto merge when all checks succeed 2026-08-07 20:54:36 +00:00
Renovate merged commit 304235ccd6 into fresh-start 2026-08-07 20:54:39 +00:00
Renovate deleted branch renovate/fluxcd-flux2-2.x 2026-08-07 20:54:40 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Lumpiasty/klaster#398