flux v2.9.5

HelmRepository.spec

HelmRepositorySpec specifies the required configuration to produce an Artifact for a Helm repository index YAML.

11 fields
HelmRepository.spec fields and descriptions
Field / TypeDescription
object

AccessFrom specifies an Access Control List for allowing cross-namespace references to this object. NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092

object

CertSecretRef can be given the name of a Secret containing either or both of - a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`); - a PEM-encoded CA certificate (`ca.crt`) and whichever are supplied, will be used for connecting to the registry. The client cert and key are useful if you are authenticating with a certificate; the CA cert is useful if you are using a self-signed server certificate. The Secret must be of type `Opaque` or `kubernetes.io/tls`. It takes precedence over the values specified in the Secret referred to by `.spec.secretRef`.

insecure
boolean

Insecure allows connecting to a non-TLS HTTP container registry. This field is only taken into account if the .spec.type field is set to 'oci'.

interval
string

Interval at which the HelmRepository URL is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources.

  • pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$
passCredentials
boolean

PassCredentials allows the credentials from the SecretRef to be passed on to a host that does not match the host as defined in URL. This may be required if the host of the advertised chart URLs in the index differ from the defined URL. Enabling this should be done with caution, as it can potentially result in credentials getting stolen in a MITM-attack.

provider
string

Provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. This field is optional, and only taken into account if the .spec.type field is set to 'oci'. When not specified, defaults to 'generic'.

  • enum: ["generic","aws","azure","gcp"]
  • default: "generic"
object

SecretRef specifies the Secret containing authentication credentials for the HelmRepository. For HTTP/S basic auth the secret must contain 'username' and 'password' fields. Support for TLS auth using the 'certFile' and 'keyFile', and/or 'caFile' keys is deprecated. Please use `.spec.certSecretRef` instead.

suspend
boolean

Suspend tells the controller to suspend the reconciliation of this HelmRepository.

timeout
string

Timeout is used for the index fetch operation for an HTTPS helm repository, and for remote OCI Repository operations like pulling for an OCI helm chart by the associated HelmChart. Its default value is 60s.

  • pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$
type
string

Type of the HelmRepository. When this field is set to "oci", the URL field value must be prefixed with "oci://".

  • enum: ["default","oci"]
url
string required

URL of the Helm repository, a valid URL contains at least a protocol and host.

  • pattern: ^(http|https|oci)://.*$