NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3044 by repository stars
Last release 7 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
1349 releases · first in 2020
One column per quarter.
docker.io/fluxcd/kustomize-controller:v1.9.6
docker.io/fluxcd/kustomize-controller:v1.9.6ghcr.io/fluxcd/kustomize-controller:v1.9.6Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-10-01
This patch release extends the SOPS decryption error redaction to
spec.postBuild.substituteFrom values: when a substituted value is echoed back in
a Kubernetes API validation error, it is now masked out of the Kustomization status
conditions and events instead of leaking into them. It also adds the opt-in
DisableCommitStatusEvent feature gate, which lets users disable the reconciliation
success event that notification-controller turns into a Git commit status update.
Fixes:
Improvements:
docker.io/fluxcd/kustomize-controller:v1.9.5
docker.io/fluxcd/kustomize-controller:v1.9.5ghcr.io/fluxcd/kustomize-controller:v1.9.5Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-08-31
This patch release stops the controller from leaving behind the temporary
directories of a previous process that exited without running its cleanup, and
fixes a crash in post-build substitution: a substring expression with a negative
length, e.g. ${VAR:2:-1}, panicked instead of counting back from the end of
the string like Bash does. In addition, the kubeconfigs read from
.spec.kubeConfig Secrets are now required to be self-contained: credentials
and certificates must be embedded inline (token, client-certificate-data,
client-key-data, certificate-authority-data), and entries referencing files
on the local filesystem are rejected. The fluxcd/pkg updates also bring
Kubernetes to 1.36.4.
Fixes:
docker.io/fluxcd/kustomize-controller:v1.9.4
docker.io/fluxcd/kustomize-controller:v1.9.4ghcr.io/fluxcd/kustomize-controller:v1.9.4Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-23
This patch release fixes a spec.images entry that sets only some of the
image fields discarding the remaining fields already declared for the same
image in the kustomization.yaml at spec.path, e.g. overriding only
newName produced an untagged image reference.
Fixes:
docker.io/fluxcd/kustomize-controller:v1.9.3
docker.io/fluxcd/kustomize-controller:v1.9.3ghcr.io/fluxcd/kustomize-controller:v1.9.3Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-13
This patch release fixes a regression introduced in v1.9.2 where a Kustomization
with openapi.path pointing to a URL failed to reconcile with
failed to read OpenAPI schema.
Fixes:
docker.io/fluxcd/kustomize-controller:v1.9.2
docker.io/fluxcd/kustomize-controller:v1.9.2ghcr.io/fluxcd/kustomize-controller:v1.9.2Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-07
This patch release fixes three bugs. Flux variable substitution is now disabled
on the Kustomization CRD by annotating it with
kustomize.toolkit.fluxcd.io/substitute: disabled, preventing post-build
substitution from corrupting the CRD schema when it contains ${...} sequences.
The SOPS dependency was updated to fix decryption of .ini files. Finally, the
fluxcd/pkg dependencies were updated to fix a dry-run error where applying a
resource with a strategic merge patch could fail with <resource> is invalid.
Fixes:
docker.io/fluxcd/kustomize-controller:v1.9.1
docker.io/fluxcd/kustomize-controller:v1.9.1ghcr.io/fluxcd/kustomize-controller:v1.9.1Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-30
This patch release updates Kubernetes to 1.36.2 and the fluxcd/pkg dependencies, adds kubectl categories to the Kustomization CRD and documents the controller's command-line options.
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
docker.io/fluxcd/kustomize-controller:v1.9.0
docker.io/fluxcd/kustomize-controller:v1.9.0ghcr.io/fluxcd/kustomize-controller:v1.9.0Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-17
This minor release comes with new features for post-build variable substitution, drift detection, SOPS decryption and Kustomize build metadata, along with various bug fixes and dependency updates.
Post-build substitutions are now stricter by default: the controller fails the
reconciliation when a variable without a default value is referenced in the
manifests but is missing from the input vars. This behavior is controlled by the
StrictPostBuildSubstitutions feature gate, which is now enabled by default and
can be opted out of. In addition, a new .spec.postBuild.substituteStrategy: Always
option was introduced to always perform substitutions even when no variables are
defined, which is useful when the substitution expressions all carry defaults
(e.g. ${var:=default}).
Drift detection can now be fine-tuned with ignore rules. The new .spec.ignore
field accepts a list of rules selecting JSON pointer paths (optionally scoped to
specific targets) to exclude from both drift detection and the apply process.
A new .spec.buildMetadata field allows enabling Kustomize build metadata
annotations per Kustomization, supporting the originAnnotations and
transformerAnnotations options.
The controller now keeps resources that failed to be pruned in the
.status.inventory, ensuring they remain tracked and can be retried on the next
reconciliation instead of becoming untracked orphans.
SOPS decryption now supports generic Kubernetes workload identity for the
OpenBao/Vault transit engine, allowing the controller to authenticate to OpenBao
by exchanging a Kubernetes ServiceAccount token for a short-lived OpenBao token
through a JWT-backed auth method, instead of using a static token. This is purely
additive and non-breaking: the existing sops.vault-token Secret and VAULT_TOKEN
environment variable paths are unchanged and take precedence.
Age and SOPS have also been updated to support Age hybrid post-quantum encryption.
In addition, the Kubernetes dependencies have been updated to v1.36, the controller
is now built with Go 1.26 and the source-controller API has been upgraded to v1.9.0.
The shared DependencyReference type was migrated to the apis/meta package,
preserving backward compatibility through a type alias.
Fixes:
.status.inventory
#1665Improvements:
StrictPostBuildSubstitutions by default
#1671substituteStrategy: Always
#1672.spec.buildMetadata optional field to Kustomization API
#1632DependencyReference to shared apis/meta type
#1656This patch release fixes a regression in the management of objects annotated with kustomize.toolkit.fluxcd.io/ssa: IfNotPresent where non-namespaced r
Release date: 2026-05-12
This patch release fixes a regression in the management of objects annotated
with kustomize.toolkit.fluxcd.io/ssa: IfNotPresent where non-namespaced resources were
being deleted and recreated on each reconciliation.
Fixes:
Improvements:
This patch release introduces the MigrateAPIVersion feature gate for migrating the API version of resources in managed field entries, which fixes erro
Release date: 2026-04-21
This patch release introduces the MigrateAPIVersion feature gate for
migrating the API version of resources in managed field entries, which
fixes errors like dry-run failed: .spec.accessPolicy: field not declared in schema.
Improvements:
This patch release fixes a race condition where a cancelled reconciliation could leave stale data in the cache, causing Kustomizations to get stuck.
Release date: 2026-04-07
This patch release fixes a race condition where a cancelled reconciliation could leave stale data in the cache, causing Kustomizations to get stuck.
Fixes:
This patch release fixes reconciliation queue behavior for source watch events while a Kustomization is already reconciling the watched revision.
Release date: 2026-03-12
This patch release fixes reconciliation queue behavior for source watch events while a Kustomization is already reconciling the watched revision.
Fixes:
Improvements:
This patch release fixes health check logic for StatefulSets during rolling updates when the Pods are Pending/Unschedulable.
Release date: 2026-02-27
This patch release fixes health check logic for StatefulSets during rolling updates when the Pods are Pending/Unschedulable.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated APIs in group kustomize.toolkit.fluxcd.io/v1beta2 #1584
Release date: 2026-02-17
This minor release comes with various bug fixes and improvements.
⚠️ The v1beta2 APIs were removed. Before upgrading the CRDs, Flux users
must run flux migrate to
migrate the cluster storage off v1beta2.
The controller now cancels in-progress health checks when a new reconciliation
request is received, reducing the mean time to recovery (MTTR) in case of
failed deployments. This is available through the CancelHealthCheckOnNewRevision
feature gate, that previously worked only for new source revisions but now also
works for any watch events that trigger a new reconciliation.
A custom SSA stage has been introduced, allowing Role and RoleBinding objects
to be applied in the same call even when the impersonated ServiceAccount does
not have a ClusterRoleBinding for cluster-admin. This can be specified with
the flag --custom-apply-stage-kinds=rbac.authorization.k8s.io/Role.
Health checks now handle Jobs with TTL set to zero seconds that are deleted before or during health checking.
A DirectSourceFetch feature gate has been added to bypass cache for source
objects, enabling immediate consistency for source object reads.
In addition, the Kubernetes dependencies have been updated to v1.35.0, Kustomize has been updated to v5.8.1 and the controller is now built with Go 1.26.
Fixes:
Improvements:
DirectSourceFetch feature gate to bypass cache for source objects
#1586kustomize.toolkit.fluxcd.io/v1beta2
#1584This patch release comes with a series of bug fixes, including Azure Workload Identity in Azure China Cloud. It also adds a feature gate to disable th
Release date: 2025-11-19
This patch release comes with a series of bug fixes, including
Azure Workload Identity in Azure China Cloud. It also adds a
feature gate to disable the ConfigMap and Secret watchers,
DisableConfigWatchers.
Fixes:
Improvements:
This patch release allows running kustomize-controller on the same loopback interface as source-watcher.
Release date: 2025-10-28
This patch release allows running kustomize-controller on the same loopback interface as source-watcher.
Improvements:
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others.…
Release date: 2025-10-08
This patch release comes with various dependency updates.
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others. The full list of security fixes can be found here.
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated APIs in group kustomize.toolkit.fluxcd.io/v1beta1 #1494
Release date: 2025-09-24
This minor release comes with various bug fixes and improvements.
⚠️ The v1beta1 APIs were removed. Before upgrading the CRDs, Flux users
must run flux migrate to
migrate the cluster storage off v1beta1.
The Kustomization API now supports reconciling content from external storage systems
through the new ExternalArtifact CRD. This feature is controlled by the ExternalArtifact
feature gate and enables reconciliation of artifacts stored outside of Git repositories.
Kustomizations now track their reconciliation history in .status.history, providing
visibility into past reconciliation attempts and their outcomes.
Dependencies can now be evaluated using CEL expressions through the new readyExpr field
in dependsOn. This feature is controlled by the AdditiveCELDependencyCheck feature gate
and allows for more flexible dependency readiness checks.
The controller now supports global SOPS Age key decryption, allowing centralized management of decryption keys.
Support for workload identity authentication has been added for remote clusters.
This is support both at the controller and object levels. For object-level,
enable the feature gate ObjectLevelWorkloadIdentity.
The new .spec.ignoreMissingComponents field allows Kustomizations to continue
reconciliation even when referenced components are missing, providing more resilient
deployments.
A feature gate CancelHealthCheckOnNewRevision has been added to cancel ongoing
health checks when a new revision is detected.
In addition, the Kubernetes dependencies have been updated to v1.34, Kustomize has been updated to v5.7 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.25.
Fixes:
Improvements:
.spec.ignoreMissingComponents field to Kustomization API
#1507kustomize.toolkit.fluxcd.io/v1beta1
#1494fluxcd/gha-workflows
#1512
#1514Nothing published for this version
This patch release fixes a bug introduced in v1.6.0 that causes SOPS decryption with US Government KMS keys to fail with the error:
Release date: 2025-07-08
This patch release fixes a bug introduced in v1.6.0 that causes SOPS decryption with US Government KMS keys to fail with the error:
STS: AssumeRoleWithWebIdentity, https response error\n StatusCode: 0, RequestID: ,
request send failed, Post\n \"https://sts.arn.amazonaws.com/\": dial tcp:
lookupts.arn.amazonaws.com on 10.100.0.10:53: no such host
Fixes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This minor release comes with various bug fixes and improvements.
Release date: 2025-05-28
This minor release comes with various bug fixes and improvements.
Kustomization API now supports object-level workload identity by setting
.spec.decryption.serviceAccountName to the name of a service account
in the same namespace that has been configured with appropriate cloud
permissions. For this feature to work, the controller feature gate
ObjectLevelWorkloadIdentity must be enabled. See a complete guide
here.
Kustomization API now supports the value WaitForTermination for the
.spec.deletionPolicy field. This instructs the controller to wait for the
deletion of all resources managed by the Kustomization before allowing the
Kustomization itself to be deleted. See docs
here.
In addition, the Kubernetes dependencies have been updated to v1.33 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.24.
Fixes:
Improvements:
This patch release fixes a bug introduced in v1.5.0 that was causing spurious logging for deprecated API versions and sometimes failures on health che…
Release date: 2025-02-25
This patch release fixes a bug introduced in v1.5.0 that was causing spurious logging for deprecated API versions and sometimes failures on health checks.
In addition, all error logs resulting from SOPS decryption failures have been sanitised.
Fixes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated object metrics from controllers #1305
Release date: 2025-02-18
This minor release comes with various bug fixes and improvements.
The controller has been updated to Kustomize v5.6, please see the
kubernetes-sigs/kustomize changelog
for more details.
The Kustomization API now supports custom health checks for Custom Resources through Common Expression Language (CEL) expressions. See docs.
The controller now sends an origin revision from OCI artifact annotations to notification-controller on events, which is useful for updating commit statuses on the notification providers that support this feature. See docs.
It is now also possible to control whether or not kustomize-controller will orphan resources when a Kustomization is deleted. See docs.
In addition, the Kubernetes dependencies have been updated to v1.32.1 and various other controller dependencies have been updated to their latest version.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →