NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2801 by repository stars
Last release 7 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
910 releases · first in 2020
One column per quarter.
docker.io/fluxcd/helm-controller:v1.6.5
docker.io/fluxcd/helm-controller:v1.6.5ghcr.io/fluxcd/helm-controller:v1.6.5Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-10-01
This patch release stops chart CRDs from being reapplied on every upgrade when
server-side apply is enabled (the default): the default Create policy is meant to
leave existing CRDs alone, but SSA's upsert semantics were updating them anyway, and
they are now skipped as with client-side apply. It also recovers HelmReleases
stranded with a drifted Ready=Unknown condition after a failed status patch, keeps
HelmChart cleanup from getting stuck when the chart is already gone, and corrects the
documented default CRD upgrade policy (.spec.upgrade.crds defaults to Create,
not Skip).
Fixes:
docker.io/fluxcd/helm-controller:v1.6.4
docker.io/fluxcd/helm-controller:v1.6.4ghcr.io/fluxcd/helm-controller:v1.6.4Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-08-31
This patch release hardens the handling of HelmRelease kubeconfig Secrets: kubeconfigs referencing local files are now rejected, credentials and certificates must be embedded inline. It also moves the controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork, and updates Kubernetes to 1.36.4.
Fixes:
Improvements:
docker.io/fluxcd/helm-controller:v1.6.3
docker.io/fluxcd/helm-controller:v1.6.3ghcr.io/fluxcd/helm-controller:v1.6.3Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-23
This patch release fixes empty lines vanishing from rendered chart manifests, and releases being marked as tested when their Helm test hooks never ran.
Fixes:
Improvements:
docker.io/fluxcd/helm-controller:v1.6.2
docker.io/fluxcd/helm-controller:v1.6.2ghcr.io/fluxcd/helm-controller:v1.6.2Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-07
This patch release disables Flux variable substitution on the HelmRelease CRD.
The CRD is now annotated with kustomize.toolkit.fluxcd.io/substitute: disabled
so that Kustomizations with post-build substitution enabled no longer corrupt
the CRD schema when it contains ${...} sequences.
Fixes:
docker.io/fluxcd/helm-controller:v1.6.1
docker.io/fluxcd/helm-controller:v1.6.1ghcr.io/fluxcd/helm-controller:v1.6.1Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-30
This patch release updates Kubernetes to 1.36.2, Helm to v4.2.2 and the fluxcd/pkg dependencies. It also adds kubectl categories to the HelmRelease CRD and documents the controller's command-line options.
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
docker.io/fluxcd/helm-controller:v1.6.0
docker.io/fluxcd/helm-controller:v1.6.0ghcr.io/fluxcd/helm-controller:v1.6.0Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-17
This minor release continues aligning Flux with Helm v4, adding support for Helm's post-render strategies along with several new HelmRelease configuration options and improved drift observability.
⚠️ Breaking change: the default post-render strategy is now combined, to
stay aligned with Helm v4.2's default for sending hooks to post-renderers.
Users relying on the previous Helm v3 behavior can either enable the
UseHelm3Defaults feature gate (which switches the default back to nohooks)
or pin the behavior per HelmRelease via .spec.postRenderStrategy.
Helm's post-render strategies are now supported through the new
.spec.postRenderStrategy field, which controls how hooks are passed to
post-renderers. The accepted values are nohooks, combined and separate.
The default is combined to stay aligned with Helm v4.2, switching to nohooks
when the UseHelm3Defaults feature gate is enabled.
A new .spec.upgrade.chartNameChangeStrategy field controls what happens when a
HelmRelease's chart name changes. The default Reinstall keeps the current
behavior of uninstalling and reinstalling the release, while InPlaceUpdate
performs an in-place Helm upgrade instead, re-introducing on an opt-in basis the
behavior present before Flux 2.2.
valuesFrom entries now accept a literal field. When set to true, the
referenced value is used verbatim instead of being parsed with Helm's --set
syntax, allowing arbitrary file content (JSON blobs, multi-line YAML, HOCON,
etc.) that would otherwise be misinterpreted by the strvals parser.
A new Drifted condition is now set on the HelmRelease to improve the
observability of drift detection.
Improvements:
literal field to valuesFrom
#1503Drifted condition to HelmRelease
#1367DependencyReference to shared apis/meta type
#1502docker.io/fluxcd/helm-controller:v1.5.5
docker.io/fluxcd/helm-controller:v1.5.5ghcr.io/fluxcd/helm-controller:v1.5.5Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-05-20
This patch release fixes several reliability issues. HTTP artifact fetches
could block indefinitely and stall reconciliations, the Kubernetes client
transport accumulated a new retry wrapper on every reconcile causing
unbounded memory growth, non-CRD objects placed under a chart's crds/
directory were force-applied, and the Helm test action failed to find
releases with names longer than 53 characters. It also moves Helm back to
upstream v4.2.0 (off the Flux fork) and updates Kubernetes and fluxcd/pkg
dependencies.
Fixes:
Improvements:
This patch release fixes a post-renderer conflict between overlapping hooks and templates, and preserves line endings in SplitManifests for downstream
Release date: 2026-04-21
This patch release fixes a post-renderer conflict between overlapping hooks
and templates, and preserves line endings in SplitManifests for downstream
YAML parsers. It also ensures force-replace is ignored when server-side apply
is enabled.
Fixes:
This patch release fixes templating errors for charts that include --- in the content, e.g. YAML separators, embedded scripts, CAs inside ConfigMaps,
Release date: 2026-03-16
This patch release fixes templating errors for charts that include
--- in the content, e.g. YAML separators, embedded scripts, CAs
inside ConfigMaps, etc. Some of the errors that could be encountered
due to this issue are:
invalid document separator: ---apiVersion: v1wrong node kindFixes:
--- for post renderers
#1442This patch release fixes reconciliation queue behavior for source watch events while a HelmRelease is already reconciling the watched revision. It als
Release date: 2026-03-12
This patch release fixes reconciliation queue behavior for source watch events
while a HelmRelease is already reconciling the watched revision. It also comes
with Helm 4.1.3, which fixes a Go templates bug where the YAML document separator
--- could be concatenated to apiVersion as ---apiVersion, and introduces
the DefaultToRetryOnFailure feature gate to improve the experience when
CancelHealthCheckOnNewRevision is enabled by ensuring canceled HelmReleases
do not get stuck when no retry strategy is configured.
Fixes:
Improvements:
This patch release fixes health check logic for StatefulSets during rolling updates when the Pods are Pending/Unschedulable.
Release date: 2026-02-27
This patch release fixes health check logic for StatefulSets during rolling updates when the Pods are Pending/Unschedulable.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The controller now uses Helm v4, and, with this change, new default behaviors are being introduced (breaking changes) to keep Flux and Helm aligned:
Release date: 2026-02-20
This minor release comes with Helm v4 support, server-side apply for Helm releases, and various bug fixes and improvements.
⚠️ The v2beta2 APIs were removed. Before upgrading the CRDs, Flux users
must run flux migrate to
migrate the cluster storage off v2beta2.
The controller now uses Helm v4, and, with this change, new default behaviors are being introduced (breaking changes) to keep Flux and Helm aligned:
Those defaults can be changed back to Helm v3's defaults by setting the
feature gate UseHelm3Defaults. Alternatively, fine-tuning the apply
and health check methods is also possible on a per-HelmRelease basis by
using the following fields:
.spec.install.serverSideApply (boolean, default defined by UseHelm3Defaults).spec.upgrade.serverSideApply (enabled, disabled or auto, defaults to auto).spec.rollback.serverSideApply (enabled, disabled or auto, defaults to auto).spec.waitStrategy.name (poller or legacy, default defined by UseHelm3Defaults)Note that Helm persists the apply method in the release storage, hence
why the auto value is an option for upgrade and rollback actions. When
set to auto, the controller will reuse the apply method used in the last
successful release revision as recorded in the Helm storage, defaulting
to client-side apply. This means that existing HelmReleases will continue
to use client-side apply until their .spec is updated with
.spec.{upgrade|rollback}.serverSideApply: enabled.
The poller health check strategy uses kstatus to check the status
of applied resources, while the legacy strategy uses Helm v3's
built-in health checking behavior.
The controller now can be configured to cancel in-progress health checks when a new
reconciliation request is received, reducing the mean time to recovery (MTTR) in case
of failed deployments. This feature is enabled by the CancelHealthCheckOnNewRevision
feature gate. Note that enabling this feature gate will not cancel apply operations,
and will only cancel health checks for managed resources. Waiting for Helm hooks and
tests will not be cancelled. Note also that this feature is only available with the
poller health check strategy.
Still on the health check subject, custom health checks via CEL expressions
are now supported for HelmRelease via the .spec.healthCheckExprs field,
similar to the Kustomization API. Please see the
CEL cheatsheet
for more information.
The --override-manager=<manager> flag has been added for server-side apply drift
detection and correction. This flag can be passed multiple times. Note that drift
detection and correction in helm-controller is completely unrelated to Helm v4's
server-side apply support, and was implemented long before Helm v4 was released.
The DirectSourceFetch feature gate has been introduced for bypassing the cache
when fetching source objects on reconciliations.
For improved observability, inventory tracking has been added via
.status.inventory. Hooks and tests are not tracked in this field.
Only resources present in the Helm storage and CRDs are tracked.
Also for improved observability, the controller now tracks the action (install,
upgrade, rollback, uninstall, uninstall-remediation) in snapshots:
.status.history[].action.
In addition, the Kubernetes dependencies have been updated to v1.35.0, Kustomize has been updated to v5.8.1 and the controller is now built with Go 1.26.
Fixes:
Improvements:
.status.inventory to track managed objects
#1385--override-manager flag for server-side apply drift detection
#1365DirectSourceFetch feature gate to bypass cache for source objects
#1407helm.toolkit.fluxcd.io/v2beta2
#1404This patch release fixes the HelmRelease .status.history filling up etcd when the RetryOnFailure strategy is used.
Release date: 2025-11-27
This patch release fixes the HelmRelease .status.history
filling up etcd when the RetryOnFailure strategy is used.
Fixes:
This patch release fixes the error no URLLoader registered and Azure Workload Identity in Azure China Cloud. It also adds a feature gate to disable th
Release date: 2025-11-19
This patch release fixes the error no URLLoader registered and
Azure Workload Identity in Azure China Cloud. It also adds a
feature gate to disable the ConfigMap and Secret watchers,
DisableConfigWatchers.
Improvements:
This patch release comes with various fixes and improvements.
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others.…
Release date: 2025-10-08
This patch release comes with various dependency updates.
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others. The full list of security fixes can be found here.
Improvements:
This patch release fixes the controller setting the Ready condition to Unknown redundantly during reconciliation.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated helm.toolkit.fluxcd.io/v2beta1 API group #1280
Release date: 2025-09-25
This minor release comes with various bug fixes and improvements.
⚠️ The v2beta1 APIs were removed. Before upgrading the CRDs, Flux users
must run flux migrate to
migrate the cluster storage off v2beta1.
The controller now supports ExternalArtifact Helm chart sources
under the feature gate ExternalArtifact.
A new RetryOnFailure strategy has been added for automatic
retries on Helm release failures.
Dependencies can now be evaluated using CEL expressions via the new
readyExpr field, providing more flexible and powerful dependency
readiness checks.
Support for workload identity authentication has been added for remote clusters.
This is supported both at the controller and object levels. For object-level,
enable the feature gate ObjectLevelWorkloadIdentity.
In addition, the Kubernetes dependencies have been updated to v1.34, Helm has been updated to v3.19 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.25.
Fixes:
Improvements:
helm.toolkit.fluxcd.io/v2beta1 API group
#1280readyExpr field
#1271Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This minor release comes with various bug fixes and improvements.
Release date: 2025-05-28
This minor release comes with various bug fixes and improvements.
The controller now supports the DisableChartDigestTracking feature gate,
which allows disabling appending the digest of OCI Helm charts to the
chart version. This is useful for charts that do not follow Helm's
recommendation of using the app version instead of the chart version
as a label in the manifests.
In addition, the Kubernetes dependencies have been updated to v1.33, Helm has been updated to v3.17.3 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.24.
Fixes:
Improvements:
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →