NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2931 by repository stars
Last release 3 days ago
16 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
467 releases · first in 2020
One column per quarter.
Nothing published for this version
Nothing published for this version
:warning: Breaking change: When using SSH authentication in GitRepository, if the referenced Secret contained .data.username, it was used as the SSH u…
Release date: 2023-01-31
This prerelease comes with support for HTTPS bearer token authentication for Git
repository. The GitRepository authentication Secret is expected to contain the
bearer token in .data.bearerToken.
The caching of Secret and ConfigMap resources is disabled by
default to improve memory usage. To opt-out from this behavior, start the
controller with: --feature-gates=CacheSecretsAndConfigMaps=true.
All the Source kinds now support progressive status updates. The progress made by the controller during reconciliation of a Source is reported immediately in the status of the Source object.
In addition, the controller dependencies have been updated to Kubernetes v1.26.
:warning: Breaking change: When using SSH authentication in GitRepository,
if the referenced Secret contained .data.username, it was used as the SSH
user. With this version, SSH user will be the username in the SSH address. For
example, if the Git repository address is ssh://flux@example.com, flux will
be used as the SSH user during SSH authentication. When no username is
specified, git remains the default SSH user.
Improvements:
Nothing published for this version
For more information, refer to version 0.32.0's changelog, which started libgit2's deprecation process.
Release date: 2022-12-20
This prerelease comes with dedicated mux for the controller's fileserver. All code references to libgit2 were removed, and the spec.gitImplementation
field is no longer being honored, but rather go-git is used.
For more information, refer to version 0.32.0's changelog, which started libgit2's
deprecation process.
The controller's garbage collection now takes into consideration lock files.
The feature gate ForceGoGitImplementation was removed, users passing it as their
controller's startup args will need to remove it before upgrading.
Fixes:
Improvements:
This prerelease rectifies the v0.32.0 release by retracting the previous Go version, bumping the controller api version and the controller deployment.
Release date: 2022-11-18
This prerelease rectifies the v0.32.0 release by retracting the previous Go
version, bumping the controller api version and the controller deployment.
This version initiates the soft deprecation of the libgit2 implementation. The motivation for removing support for libgit2 being:
Release date: 2022-11-17
This prerelease comes with a major refactoring of the controller's Git operations.
The go-git implementation now supports all Git servers, including
Azure DevOps, which previously was only supported by libgit2.
This version initiates the soft deprecation of the libgit2 implementation.
The motivation for removing support for libgit2 being:
libgit2 implementation, which
is a C library called via CGO through git2go, it will never perform as well as
a pure Go implementations. At scale, memory pressure insues which then triggers
the reliability issues above.libgit2, we have to maintain an additional repository. Statically built
libgit2 libraries need to be cross-compiled for all our supported platforms.
And a lot of "unnecessary" code has to be in place to make building, testing and
fuzzing work seamlessly.As a result the field spec.gitImplementation is ignored and the
reconciliations will use go-git. To opt-out from this behaviour, start
the controller with: --feature-gates=ForceGoGitImplementation=false.
Users having any issues with go-git should report it to the Flux team,
so any issues can be resolved before support for libgit2 is completely
removed from the codebase.
Improvements:
Nothing published for this version
This prerelease comes with support for Cosign verification of Helm charts. The signatures verification can be configured by setting HelmChart.spec.ver
Release date: 2022-10-21
This prerelease comes with support for Cosign verification of Helm charts.
The signatures verification can be configured by setting HelmChart.spec.verify with
provider as cosign and a secretRef to a secret containing the public key.
Cosign keyless verification is also supported, please see the
HelmChart API documentation
for more details.
In addition, the controller dependencies have been updated to Kubernetes v1.25.3 and Helm v3.10.1.
Improvements:
Fixes:
Nothing published for this version
Nothing published for this version
This prerelease enables the use of container-level SAS tokens when using Bucket objects to access Azure Storage. The Azure SDK error message has also
Release date: 2022-10-10
This prerelease enables the use of container-level SAS tokens when using Bucket objects
to access Azure Storage. The Azure SDK error message has also been enriched to hint Flux
users the potential reasons in case of failure.
Improvements:
This prerelease adds support for Cosign verification in OCIRepository source. The signatures verification can be configured by setting OCIRepository.s
Release date: 2022-09-29
This prerelease adds support for Cosign verification in OCIRepository source.
The signatures verification can be configured by setting OCIRepository.spec.verify with
provider as cosign and a secretRef to a secret containing the public key.
Cosign keyless verification is also supported, please see the
OCIRepository API documentation
for more details.
It also comes with strict validation rules for API fields which define a
(time) duration. Effectively, this means values without a time unit (e.g. ms,
s, m, h) will now be rejected by the API server. To stimulate sane
configurations, the units ns, us and µs can no longer be configured, nor
can h be set for fields defining a timeout value.
In addition, the controller dependencies have been updated to Kubernetes controller-runtime v0.13.
:warning: Breaking changes:
.spec.interval new validation pattern is "^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$".spec.timeout new validation pattern is "^([0-9]+(\\.[0-9]+)?(ms|s|m))+$"Improvements:
Fixes:
Nothing published for this version
:warning: Breaking change: The controller logs have been aligned with the Kubernetes structured logging. For more details on the new logging structure…
Release date: 2022-09-09
This prerelease adds support for non-TLS container registries such
as Kubernetes Kind Docker Registry.
Connecting to an in-cluster registry over plain HTTP,
requires setting the OCIRepository.spec.insecure field to true.
:warning: Breaking change: The controller logs have been aligned with the Kubernetes structured logging. For more details on the new logging structure please see: fluxcd/flux2#3051.
Improvements:
Fixes:
Nothing published for this version
This prerelease adds support for contextual login to container registries when pulling Helm charts from Azure Container Registry, Amazon Elastic Conta
Release date: 2022-08-29
This prerelease adds support for contextual login to container registries when pulling
Helm charts from Azure Container Registry, Amazon Elastic Container Registry
and Google Artifact Registry. Contextual login for HelmRepository
objects can be enabled by setting the spec.provider field to azure, aws or gcp.
Selecting the OCI layer containing Kubernetes manifests is now possible
when defining OCIRepository objects by setting the spec.layerSelector.mediaType field.
In addition, the controller dependencies have been updated to Kubernetes v1.25.0 and Helm v3.9.4.
Improvements:
Nothing published for this version
Nothing published for this version
This prerelease adds support for SAS Keys when authenticating against Azure Blob Storage and improves the documentation for OCIRepository.
Release date: 2022-08-17
This prerelease adds support for SAS Keys when authenticating against Azure Blob Storage
and improves the documentation for OCIRepository.
The package sourceignore, which is used for excluding files from Flux internal artifacts,
has been moved to fluxcd/pkg/sourceignore.
Improvements:
This prerelease comes with panic recovery, to protect the controller from crashing when reconciliations lead to a crash. It also adds OCI documentatio
Release date: 2022-08-11
This prerelease comes with panic recovery, to protect the controller from crashing when reconciliations lead to a crash. It also adds OCI documentation and improvements to the controllers CI pipeline.
Improvements:
This prerelease comes with a new API kind named OCIRepository, for fetching OCI artifacts from container registries as defined in RFC-0003 Flux OCI su
Release date: 2022-08-08
This prerelease comes with a new API kind named OCIRepository,
for fetching OCI artifacts from container registries as defined in
RFC-0003 Flux OCI support for Kubernetes manifests.
Please see the
OCIRepository API documentation
for more details.
In addition, Helm charts stored in Git can now have dependencies to other charts stored as OCI artifacts in container registries.
Features:
Improvements:
Fixes:
This prerelease comes with an improvement in the Helm OCI Chart to use an exact version when provided. This makes it possible to work with registries
Release date: 2022-07-27
This prerelease comes with an improvement in the Helm OCI Chart to use an exact version when provided. This makes it possible to work with registries that don't support listing tags.
Improvements:
This prerelease fixes SIGSEGV when resolving charts dependencies. It also brings CI improvements and update dependencies to patch upstream CVEs.
Release date: 2022-07-13
This prerelease fixes SIGSEGV when resolving charts dependencies. It also brings CI improvements and update dependencies to patch upstream CVEs.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This prerelease fixes an authentication issue for Helm OCI where the credentials were cached instead of being discarded after each reconciliation.
This prerelease fixes an authentication issue when using libgit2 managed transport to checkout repos on BitBucket server.
This prerelease comes with an improvement in the SSH managed transport error messages related to known hosts check and removes a deadlock in the SSH s
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This prerelease fixes an issue with leaked SSH connections on managed transport and adds some general build and libgit2 improvements.
Release date: 2022-06-14
This prerelease fixes an issue with leaked SSH connections on managed transport and adds some general build and libgit2 improvements.
Fixes:
Improvements:
Nothing published for this version
This prerelease fixes a regression for SSH host key verification and fixes semver sorting for Helm OCI charts.
Release date: 2022-06-08
This prerelease fixes a regression for SSH host key verification and fixes semver sorting for Helm OCI charts.
In addition, the controller dependencies have been updated to Kubernetes v1.24.1.
Fixes:
Improvements:
This prerelease fixes a regression when accessing Gitlab via HTTPS when the URL does not have the '.git' suffix. Plus some small documentation fixes a
Release date: 2022-06-07
This prerelease fixes a regression when accessing Gitlab via HTTPS when the URL does not have the '.git' suffix. Plus some small documentation fixes and dependency updates.
Fixes:
Improvements:
This prerelease fixes a regression in HelmRepository index caching.
Release date: 2022-06-06
This prerelease fixes a regression in HelmRepository index caching.
Fixes:
This prerelease fixes a bug which prevented the use of the OptimizedGitClones feature when using tags to checkout a Git repository, and adds docs on h
Release date: 2022-06-03
This prerelease fixes a bug which prevented the use of the OptimizedGitClones
feature when using tags to checkout a Git repository, and adds docs on how to
access Azure Blob using managed identities and aad-pod-identity.
Improvements:
Fixes:
This prerelease fixes some race conditions in the libgit2 managed ssh smart subtransport.
Release date: 2022-06-02
This prerelease fixes some race conditions in the libgit2 managed ssh smart subtransport.
Fixes:
Nothing published for this version
Nothing published for this version
This prerelease adds support for Helm OCI. Users can specify .spec.type of a HelmRepository to use an OCI repository instead of an HTTP/S Helm reposit
Release date: 2022-06-01
This prerelease adds support for Helm OCI. Users can specify .spec.type of
a HelmRepository to use an OCI repository instead of an HTTP/S Helm repository.
Please note that this currently has a couple of limitations (which will be addressed in a future release):
An example of OCI HelmRepository can be found here.
A new flag --feature-gate has been added to disable/enable new experimental
features. It works in a similar manner to Kubernetes feature gates.
The libgit2 managed transport feature has been enabled by default. Furthermore,
a few changes have been made to make the feature more stable and enable quicker
clones. Users that want to opt out and use the unmanaged transports may do so
by passing the flag --feature-gate=GitManagedTransport=false, but please note
that we encourage users not to do so.
GitRepository reconciliation has been made more efficient by adding support for
no-op clones, when checking out repositories using branches or tags.
This feature is also enabled by default, and users can opt out
by passing the flag --feature-gate=OptimizedGitClones=false.
Please note that this feature is only active when the managed transport feature
is enabled. Disabling managed transports, quietly disables optimzed Git clones.
Improvements:
Fixes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →