==> Updating pacman database cache :: Synchronizing package databases... core downloading... extra downloading... ==> Building fluxcd -> repo: extra-staging -> arch: aarch64 -> worker: ben-1 ==> Building fluxcd for [extra-staging] (aarch64) Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. :: Synchronizing package databases... core-staging downloading... core-testing downloading... core downloading... extra-staging downloading... extra-testing downloading... aur downloading... extra downloading... :: Starting full system upgrade... there is nothing to do ==> Building in chroot for [extra-staging] (aarch64)... ==> Synchronizing chroot copy [/var/lib/archbuild/extra-staging-aarch64/root] -> [ben-1]...done ==> Making package: fluxcd 2.9.3-1 (Sat Jul 25 11:29:24 2026) ==> Retrieving sources... -> Cloning fluxcd git repo... Cloning into bare repository '/home/ben/alpb/build/fluxcd/fluxcd'... ==> Validating source files with sha512sums... fluxcd ... Passed ==> Validating source files with b2sums... fluxcd ... Passed Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. ==> Making package: fluxcd 2.9.3-1 (Sat Jul 25 18:29:33 2026) ==> Checking runtime dependencies... ==> Checking buildtime dependencies... ==> Installing missing dependencies... resolving dependencies... looking for conflicting packages... Package (7) New Version Net Change Download Size extra-testing/perl-error 0.17030-3 0.04 MiB extra-testing/perl-mailtools 2.22-3 0.10 MiB extra-testing/perl-timedate 2.35-1 0.15 MiB extra-testing/zlib-ng 2.3.3-1 0.25 MiB extra-testing/git 2.55.0-1 30.97 MiB extra-testing/go 2:1.26.5-1 210.90 MiB extra-testing/kustomize 5.8.1-1 18.81 MiB 6.94 MiB Total Download Size: 6.94 MiB Total Installed Size: 261.23 MiB :: Proceed with installation? [Y/n] :: Retrieving packages... go-2:1.26.5-1-aarch64 downloading... git-2.55.0-1-aarch64 downloading... kustomize-5.8.1-1-aarch64 downloading... zlib-ng-2.3.3-1-aarch64 downloading... checking keyring... checking package integrity... loading package files... checking for file conflicts... :: Processing package changes... installing perl-error... installing perl-timedate... installing perl-mailtools... installing zlib-ng... installing git... Optional dependencies for git git-zsh-completion: upstream zsh completion tk: gitk and git gui openssh: ssh transport and crypto man: show help with `git command --help` perl-libwww: git svn perl-term-readkey: git svn and interactive.singlekey setting perl-io-socket-ssl: git send-email TLS support perl-authen-sasl: git send-email TLS support perl-cgi: gitweb (web interface) support python: git svn & git p4 [installed] subversion: git svn org.freedesktop.secrets: keyring credential helper libsecret: libsecret credential helper [installed] less: the default pager for git installing go... installing kustomize... Optional dependencies for kustomize helm :: Running post-transaction hooks... (1/3) Creating system user accounts... Creating group 'git' with GID 969. Creating user 'git' (git daemon user) with UID 969 and GID 969. (2/3) Reloading system manager configuration... Skipped: Current root is not booted. (3/3) Arming ConditionNeedsUpdate... ==> Retrieving sources... ==> WARNING: Skipping all source file integrity checks. ==> Extracting sources... -> Creating working copy of fluxcd git repo... Cloning into 'fluxcd'... done. Switched to a new branch 'makepkg' ==> Starting prepare()... ==> Starting build()... ./manifests/scripts/bundle.sh [INFO] using kustomize 5.8.1 [INFO] building helm-controller.yaml [INFO] building image-automation-controller.yaml [INFO] building image-reflector-controller.yaml [INFO] building kustomize-controller.yaml [INFO] building notification-controller.yaml [INFO] building source-controller.yaml [INFO] building source-watcher.yaml [INFO] building rbac.yaml [INFO] building policies.yaml touch cmd/flux/.manifests.done [INFO] using kustomize 5.8.1 [INFO] building helm-controller.yaml [INFO] building image-automation-controller.yaml [INFO] building image-reflector-controller.yaml [INFO] building kustomize-controller.yaml [INFO] building notification-controller.yaml [INFO] building source-controller.yaml [INFO] building source-watcher.yaml [INFO] building rbac.yaml [INFO] building policies.yaml [INFO] archiving manifests.tar.gz internal/goarch internal/unsafeheader internal/byteorder internal/coverage/rtcov internal/godebugs internal/goos internal/goexperiment internal/cpu internal/profilerecord math/bits internal/asan internal/abi internal/runtime/syscall/linux internal/runtime/gc internal/msan internal/runtime/math internal/runtime/pprof/label internal/trace/tracev2 sync/atomic unicode internal/strconv unicode/utf8 cmp internal/bytealg internal/chacha8rand internal/runtime/atomic internal/runtime/sys crypto/internal/constanttime math internal/runtime/exithook crypto/internal/fips140deps/byteorder internal/stringslite crypto/internal/fips140deps/cpu internal/runtime/gc/scan crypto/internal/fips140/alias crypto/internal/boring/sig encoding internal/runtime/cgroup crypto/internal/fips140/subtle unicode/utf16 k8s.io/apimachinery/pkg/api/validate/constraints k8s.io/apimachinery/pkg/selection log/internal log/slog/internal internal/nettrace crypto/subtle container/list vendor/golang.org/x/crypto/cryptobyte/asn1 vendor/golang.org/x/crypto/internal/alias k8s.io/apimachinery/pkg/types google.golang.org/protobuf/internal/flags google.golang.org/protobuf/internal/set golang.org/x/text/encoding/internal/identifier golang.org/x/text/internal/utf8internal k8s.io/apimachinery/pkg/api/safe github.com/go-openapi/swag/cmdutils internal/race internal/synctest sigs.k8s.io/kustomize/kyaml/sets sigs.k8s.io/kustomize/kyaml/sliceutil sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/selection sigs.k8s.io/kustomize/kyaml/ext github.com/cyphar/filepath-securejoin/internal/consts github.com/fluxcd/pkg/apis/acl k8s.io/utils/internal/third_party/forked/golang/golang-lru github.com/tidwall/match image/color internal/runtime/maps internal/sync github.com/rivo/uniseg github.com/google/go-cmp/cmp/internal/flags github.com/aws/aws-sdk-go-v2/internal/sdkio github.com/aws/smithy-go/aws-http-auth/v4 github.com/docker/cli/cli/config/types github.com/Azure/azure-sdk-for-go/sdk/azcore/cloud github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/exported github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/internal/grant github.com/mattn/go-ciede2000 github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/version github.com/Azure/azure-sdk-for-go/sdk/azcore/to github.com/fluxcd/flux2/v2/pkg/plugin github.com/ProtonMail/go-crypto/internal/byteutil golang.org/x/crypto/cryptobyte/asn1 golang.org/x/crypto/internal/alias github.com/pjbgf/sha1cd/internal github.com/pjbgf/sha1cd/ubc github.com/go-git/go-git/v5/plumbing/color github.com/golang/groupcache/lru github.com/fluxcd/flux2/v2/pkg/log google.golang.org/grpc/serviceconfig google.golang.org/grpc/encoding/internal github.com/googleapis/gax-go/v2/internal go.opentelemetry.io/otel/trace/embedded go.opentelemetry.io/otel/metric/embedded github.com/klauspost/compress github.com/klauspost/compress/internal/le github.com/google/go-containerregistry/pkg/compression github.com/google/go-containerregistry/pkg/v1/types github.com/onsi/gomega/matchers/support/goraph/node github.com/onsi/gomega/matchers/support/goraph/util github.com/fluxcd/pkg/runtime/transform golang.org/x/net/html/atom github.com/notaryproject/notation-go/internal/container github.com/notaryproject/notation-go/internal/slices github.com/notaryproject/notation-go/internal/trustpolicy runtime internal/reflectlite iter k8s.io/klog/v2/internal/dbg weak sync runtime/metrics maps slices github.com/onsi/gomega/matchers/support/goraph/edge k8s.io/apimachinery/pkg/util/sets errors sort internal/bisect internal/testlog internal/singleflight log/slog/internal/buffer io strconv internal/oserror path syscall internal/godebug vendor/golang.org/x/net/dns/dnsmessage bytes strings hash bufio reflect hash/crc32 crypto/internal/fips140deps/godebug crypto/internal/impl math/rand crypto/internal/fips140 crypto encoding/base64 regexp/syntax encoding/base32 crypto/internal/fips140/sha256 crypto/internal/fips140/sha3 crypto/internal/fips140/sha512 github.com/x448/float16 k8s.io/klog/v2/internal/severity time internal/syscall/unix internal/syscall/execenv crypto/sha3 crypto/internal/fips140/hmac crypto/internal/fips140/check crypto/internal/fips140hash crypto/internal/fips140/nistec/fiat crypto/internal/fips140/aes crypto/fips140 regexp unique go/build/constraint k8s.io/apimachinery/pkg/api/operation math/rand/v2 crypto/internal/fips140/edwards25519/field io/fs internal/poll context crypto/internal/fips140deps/time k8s.io/klog/v2/internal/clock runtime/cgo crypto/internal/entropy/v1.0.0 net/netip crypto/internal/randutil crypto/internal/fips140/bigmod crypto/internal/fips140cache internal/filepathlite embed internal/saferio crypto/internal/fips140/nistec crypto/internal/fips140/edwards25519 crypto/internal/fips140/hkdf os crypto/internal/fips140/tls12 crypto/internal/fips140/tls13 crypto/tls/internal/fips140tls encoding/pem vendor/golang.org/x/text/transform net/http/internal/ascii golang.org/x/text/transform golang.org/x/net/internal/httpsfv hash/fnv google.golang.org/protobuf/internal/pragma google.golang.org/protobuf/internal/editiondefaults golang.org/x/text/encoding golang.org/x/text/runes k8s.io/apimachinery/pkg/version internal/fmtsort encoding/binary k8s.io/kube-openapi/pkg/util github.com/modern-go/reflect2 golang.org/x/text/encoding/internal github.com/go-openapi/swag/conv github.com/go-openapi/swag/jsonname golang.org/x/text/encoding/unicode github.com/go-openapi/swag/typeutils github.com/go-openapi/swag/stringutils k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal sigs.k8s.io/structured-merge-diff/v6/schema github.com/munnerz/goautoneg k8s.io/utils/clock k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonflags container/heap k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonopts k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonwire hash/adler32 sigs.k8s.io/kustomize/kyaml/utils sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/util/sets golang.org/x/sys/unix vendor/golang.org/x/crypto/internal/poly1305 sigs.k8s.io/randfill/bytesource sigs.k8s.io/kustomize/api/internal/image sigs.k8s.io/kustomize/api/internal/konfig/builtinpluginconsts k8s.io/cli-runtime/pkg/genericiooptions k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext github.com/liggitt/tabwriter github.com/chai2010/gettext-go/plural fmt crypto/internal/sysrand k8s.io/klog/v2/internal/buffer path/filepath crypto/internal/fips140/drbg internal/lazyregexp crypto/internal/fips140/aes/gcm crypto/internal/fips140only crypto/internal/fips140/ecdh crypto/internal/fips140/ecdsa crypto/internal/fips140/ed25519 crypto/cipher crypto/hkdf crypto/internal/fips140/mlkem crypto/md5 crypto/rc4 crypto/internal/fips140/rsa compress/flate math/big crypto/internal/boring crypto/hmac crypto/sha256 encoding/hex encoding/json database/sql/driver compress/gzip k8s.io/apimachinery/pkg/api/validate/content k8s.io/apimachinery/third_party/forked/golang/reflect k8s.io/apimachinery/pkg/fields k8s.io/apimachinery/pkg/util/errors flag k8s.io/apimachinery/pkg/conversion log go/token go/doc/comment net/url net go/internal/scannerhooks go/scanner crypto/elliptic gopkg.in/inf.v0 github.com/Masterminds/semver/v3 github.com/fxamacker/cbor/v2 sigs.k8s.io/json/internal/golang/encoding/json github.com/mattn/go-isatty golang.org/x/term k8s.io/apimachinery/pkg/util/validation/field log/slog github.com/mattn/go-colorable github.com/fatih/color github.com/briandowns/spinner go/ast k8s.io/apimachinery/pkg/conversion/queryparams os/user runtime/debug k8s.io/apimachinery/pkg/runtime/schema k8s.io/klog/v2/internal/verbosity github.com/go-logr/logr k8s.io/klog/v2/internal/sloghandler crypto/internal/rand crypto/aes k8s.io/apimachinery/pkg/util/naming crypto/des crypto/rand sigs.k8s.io/json crypto/ecdh crypto/internal/boring/bbig crypto/sha512 k8s.io/klog/v2/internal/serialize encoding/asn1 crypto/ed25519 k8s.io/apimachinery/pkg/util/json crypto/mlkem vendor/golang.org/x/crypto/chacha20 k8s.io/klog/v2 k8s.io/klog/v2/textlogger go/doc go/parser vendor/golang.org/x/crypto/chacha20poly1305 crypto/rsa k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes crypto/hpke vendor/golang.org/x/crypto/cryptobyte crypto/sha1 crypto/dsa k8s.io/apimachinery/pkg/runtime/serializer/cbor/direct crypto/x509/pkix vendor/golang.org/x/text/unicode/bidi vendor/golang.org/x/text/unicode/norm vendor/golang.org/x/net/http2/hpack mime k8s.io/apimachinery/pkg/api/resource crypto/ecdsa mime/quotedprintable net/http/internal vendor/golang.org/x/text/secure/bidirule k8s.io/utils/internal/third_party/forked/golang/net net/textproto io/ioutil k8s.io/utils/net go.yaml.in/yaml/v2 sigs.k8s.io/randfill github.com/modern-go/concurrent golang.org/x/text/unicode/bidi mime/multipart k8s.io/apimachinery/pkg/util/validation k8s.io/apimachinery/pkg/util/intstr vendor/golang.org/x/net/idna k8s.io/apimachinery/pkg/labels crypto/x509 golang.org/x/text/unicode/norm golang.org/x/net/http2/hpack github.com/json-iterator/go golang.org/x/text/secure/bidirule k8s.io/utils/ptr google.golang.org/protobuf/internal/detrand google.golang.org/protobuf/internal/version go.yaml.in/yaml/v3 google.golang.org/protobuf/internal/errors vendor/golang.org/x/net/http/httpguts vendor/golang.org/x/net/http/httpproxy google.golang.org/protobuf/encoding/protowire os/exec google.golang.org/protobuf/reflect/protoreflect golang.org/x/sync/errgroup k8s.io/apimachinery/pkg/util/framer sigs.k8s.io/yaml golang.org/x/net/idna github.com/go-openapi/swag/fileutils github.com/go-openapi/swag/jsonutils/adapters/ifaces github.com/go-openapi/swag/mangling github.com/go-openapi/swag/jsonutils/adapters/stdlib/json k8s.io/apimachinery/pkg/util/yaml golang.org/x/net/http/httpguts github.com/go-openapi/swag/netutils github.com/go-openapi/jsonreference/internal google.golang.org/protobuf/internal/encoding/messageset google.golang.org/protobuf/internal/genid google.golang.org/protobuf/internal/order google.golang.org/protobuf/internal/strs google.golang.org/protobuf/runtime/protoiface google.golang.org/protobuf/reflect/protoregistry google.golang.org/protobuf/internal/descfmt google.golang.org/protobuf/internal/descopts google.golang.org/protobuf/internal/encoding/text google.golang.org/protobuf/internal/protolazy github.com/go-openapi/swag/jsonutils/adapters crypto/tls github.com/go-openapi/swag/jsonutils k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json google.golang.org/protobuf/proto k8s.io/apimachinery/pkg/util/version google.golang.org/protobuf/internal/encoding/defval k8s.io/client-go/pkg/version k8s.io/client-go/tools/metrics k8s.io/client-go/util/connrotation golang.org/x/time/rate github.com/google/gnostic-models/jsonschema github.com/go-openapi/swag/yamlutils github.com/davecgh/go-spew/spew k8s.io/client-go/util/keyutil google.golang.org/protobuf/internal/filedesc google.golang.org/protobuf/encoding/prototext k8s.io/client-go/util/flowcontrol github.com/google/uuid k8s.io/kube-openapi/pkg/cached sigs.k8s.io/structured-merge-diff/v6/value k8s.io/utils/dump compress/zlib encoding/xml github.com/emicklei/go-restful/v3/log gopkg.in/evanphx/json-patch.v4 github.com/go-errors/errors sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/util/errors sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/util/validation/field sigs.k8s.io/kustomize/kyaml/openapi/kubernetesapi/v1_21_2 sigs.k8s.io/kustomize/kyaml/errors sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/util/validation sigs.k8s.io/kustomize/kyaml/filesys sigs.k8s.io/kustomize/kyaml/yaml/internal/k8sgen/pkg/labels sigs.k8s.io/kustomize/kyaml/openapi/kubernetesapi sigs.k8s.io/kustomize/kyaml/openapi/kustomizationapi google.golang.org/protobuf/internal/encoding/tag github.com/monochromegane/go-gitignore github.com/xlab/treeprint sigs.k8s.io/kustomize/api/internal/kusterr google.golang.org/protobuf/internal/impl github.com/blang/semver/v4 github.com/evanphx/json-patch/v5/internal/json k8s.io/apimachinery/pkg/util/mergepatch plugin sigs.k8s.io/structured-merge-diff/v6/fieldpath k8s.io/apimachinery/third_party/forked/golang/json sigs.k8s.io/kustomize/api/provenance sigs.k8s.io/controller-runtime/pkg/log encoding/csv text/template/parse github.com/spf13/pflag github.com/moby/term k8s.io/apimachinery/pkg/util/duration k8s.io/client-go/third_party/forked/golang/template sigs.k8s.io/yaml/kyaml github.com/google/btree k8s.io/client-go/util/jsonpath sigs.k8s.io/structured-merge-diff/v6/typed github.com/evanphx/json-patch/v5 github.com/peterbourgon/diskv text/template k8s.io/client-go/util/homedir net/http/httptrace k8s.io/client-go/util/cert k8s.io/component-base/version net/http/internal/httpcommon golang.org/x/net/internal/httpcommon archive/zip github.com/chai2010/gettext-go/mo net/http github.com/chai2010/gettext-go/po github.com/MakeNowJust/heredoc sigs.k8s.io/structured-merge-diff/v6/merge k8s.io/client-go/applyconfigurations/internal github.com/mitchellh/go-wordwrap html os/signal github.com/spf13/cobra github.com/russross/blackfriday/v2 k8s.io/kubectl/pkg/util/interrupt github.com/exponent-io/jsonpath k8s.io/utils/exec github.com/cyphar/filepath-securejoin github.com/fluxcd/flux2/v2/pkg/manifestgen github.com/chai2010/gettext-go github.com/fluxcd/pkg/kustomize/filesys archive/tar sigs.k8s.io/controller-runtime/pkg/config k8s.io/utils/third_party/forked/golang/btree github.com/beorn7/perks/quantile github.com/cespare/xxhash/v2 google.golang.org/protobuf/encoding/protodelim k8s.io/kubectl/pkg/util/i18n github.com/prometheus/procfs/internal/fs github.com/prometheus/procfs/internal/util k8s.io/apimachinery/pkg/util/cache github.com/pmezard/go-difflib/difflib text/tabwriter k8s.io/client-go/tools/cache/synctrack k8s.io/utils/buffer github.com/prometheus/procfs k8s.io/utils/trace k8s.io/apimachinery/pkg/util/uuid database/sql k8s.io/apimachinery/pkg/util/diff sigs.k8s.io/controller-runtime/pkg/internal/field/selector sigs.k8s.io/controller-runtime/pkg/internal/log sigs.k8s.io/controller-runtime/pkg/internal/syncs k8s.io/utils/lru internal/profile runtime/pprof runtime/trace github.com/prometheus/client_golang/prometheus/promhttp/internal github.com/fluxcd/pkg/tar github.com/fsnotify/fsnotify/internal github.com/fsnotify/fsnotify google.golang.org/protobuf/internal/filetype gomodules.xyz/jsonpatch/v2 sigs.k8s.io/controller-runtime/pkg/manager/signals github.com/tidwall/pretty hash/maphash github.com/fluxcd/pkg/version google.golang.org/protobuf/runtime/protoimpl github.com/mitchellh/go-ps github.com/lucasb-eyer/go-colorful github.com/BurntSushi/toml/internal github.com/tidwall/gjson github.com/gonvenience/term github.com/BurntSushi/toml golang.org/x/sync/syncmap google.golang.org/protobuf/types/known/anypb google.golang.org/protobuf/types/descriptorpb google.golang.org/protobuf/types/known/timestamppb github.com/google/gnostic-models/extensions github.com/tidwall/sjson github.com/gonvenience/bunt github.com/prometheus/client_model/go github.com/wI2L/jsondiff github.com/virtuald/go-ordered-json gopkg.in/yaml.v3 github.com/gonvenience/text github.com/prometheus/common/model gopkg.in/yaml.v2 github.com/mitchellh/hashstructure github.com/sergi/go-diff/diffmatchpatch github.com/texttheater/golang-levenshtein/levenshtein github.com/mattn/go-runewidth github.com/fluxcd/pkg/envsubst/parse github.com/olekukonko/tablewriter github.com/fluxcd/pkg/envsubst/path github.com/fluxcd/pkg/sourceignore/gitignore github.com/fluxcd/pkg/envsubst github.com/fluxcd/pkg/sourceignore github.com/prometheus/client_golang/prometheus/internal github.com/google/go-cmp/cmp/internal/diff github.com/google/go-cmp/cmp/internal/function github.com/google/go-cmp/cmp/internal/value internal/sysinfo github.com/aws/aws-sdk-go-v2/internal/rand github.com/aws/aws-sdk-go-v2/internal/sdk github.com/aws/aws-sdk-go-v2/internal/sync/singleflight github.com/aws/smithy-go/context testing github.com/google/go-cmp/cmp github.com/aws/smithy-go/internal/sync/singleflight github.com/aws/smithy-go/logging github.com/aws/smithy-go github.com/aws/smithy-go/time github.com/aws/smithy-go/middleware github.com/aws/smithy-go/auth github.com/aws/smithy-go/metrics github.com/aws/smithy-go/tracing github.com/aws/smithy-go/transport/http/internal/io github.com/aws/smithy-go/ptr github.com/aws/smithy-go/rand github.com/gonvenience/neat github.com/aws/aws-sdk-go-v2/internal/strings github.com/aws/aws-sdk-go-v2/config/internal/ini github.com/aws/aws-sdk-go-v2/aws/ratelimit github.com/aws/aws-sdk-go-v2/internal/timeconv github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config github.com/aws/smithy-go/io github.com/aws/aws-sdk-go-v2/internal/shareddefaults github.com/aws/aws-sdk-go-v2/internal/context github.com/aws/aws-sdk-go-v2/aws/protocol/restjson github.com/aws/smithy-go/document github.com/aws/smithy-go/encoding github.com/aws/aws-sdk-go-v2/aws/protocol/xml github.com/aws/smithy-go/encoding/json github.com/aws/aws-sdk-go-v2/internal/v4a/internal/crypto github.com/aws/aws-sdk-go-v2/service/signin/types github.com/aws/aws-sdk-go-v2/service/sso/types github.com/aws/aws-sdk-go-v2/service/ssooidc/types github.com/aws/aws-sdk-go-v2/service/sts/types github.com/aws/smithy-go/encoding/xml github.com/aws/aws-sdk-go-v2/service/ecr/types github.com/aws/smithy-go/waiter github.com/aws/aws-sdk-go-v2/service/ecrpublic/types github.com/aws/aws-sdk-go-v2/service/eks/types github.com/aws/smithy-go/aws-http-auth/credentials github.com/docker/docker-credential-helpers/credentials github.com/sirupsen/logrus github.com/opencontainers/go-digest github.com/fluxcd/go-git-providers/validation github.com/Azure/azure-sdk-for-go/sdk/internal/log github.com/docker/docker-credential-helpers/client github.com/Azure/azure-sdk-for-go/sdk/azcore/log github.com/Azure/azure-sdk-for-go/sdk/azcore/tracing github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/log github.com/google/go-containerregistry/pkg/name github.com/Azure/azure-sdk-for-go/sdk/internal/diag github.com/Azure/azure-sdk-for-go/sdk/internal/errorinfo github.com/docker/cli/cli/config/credentials github.com/Azure/azure-sdk-for-go/sdk/internal/temporal github.com/Azure/azure-sdk-for-go/sdk/internal/uuid github.com/Azure/azure-sdk-for-go/sdk/azcore/arm/internal/resource github.com/AzureAD/microsoft-authentication-library-for-go/apps/cache github.com/kylelemons/godebug/diff github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/json k8s.io/apimachinery/pkg/util/runtime golang.org/x/net/http2 github.com/google/gnostic-models/compiler github.com/go-openapi/swag/loading golang.org/x/oauth2/internal github.com/emicklei/go-restful/v3 k8s.io/apimachinery/pkg/runtime github.com/go-openapi/swag k8s.io/client-go/features golang.org/x/oauth2 k8s.io/apimachinery/pkg/util/wait github.com/google/gnostic-models/openapiv2 github.com/google/gnostic-models/openapiv3 k8s.io/client-go/util/workqueue net/http/httputil github.com/go-openapi/jsonpointer github.com/go-openapi/jsonreference k8s.io/client-go/third_party/forked/httpcache k8s.io/kube-openapi/pkg/internal github.com/hashicorp/go-cleanhttp expvar github.com/prometheus/common/expfmt net/http/pprof sigs.k8s.io/controller-runtime/pkg/healthz sigs.k8s.io/controller-runtime/pkg/internal/httpserver k8s.io/apimachinery/pkg/runtime/serializer/recognizer k8s.io/apimachinery/pkg/runtime/serializer/streaming k8s.io/client-go/tools/internal/events k8s.io/client-go/tools/clientcmd/api github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header sigs.k8s.io/controller-runtime/pkg/conversion github.com/gonvenience/ytbx github.com/gregjones/httpcache github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil github.com/aws/smithy-go/transport/http github.com/prometheus/client_golang/prometheus k8s.io/client-go/tools/clientcmd/api/v1 github.com/fluxcd/go-git-providers/gitprovider/cache github.com/fluxcd/go-git-providers/gitprovider github.com/gonvenience/idem github.com/homeport/dyff/pkg/dyff github.com/aws/smithy-go/encoding/httpbinding github.com/aws/smithy-go/auth/bearer github.com/aws/aws-sdk-go-v2/internal/auth github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/aws github.com/aws/smithy-go/endpoints github.com/aws/smithy-go/endpoints/private/rulesfn k8s.io/apimachinery/pkg/util/net github.com/aws/aws-sdk-go-v2/aws/protocol/query github.com/aws/aws-sdk-go-v2/internal/v4a/internal/v4 github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding github.com/fluxcd/flux2/v2/pkg/printers github.com/aws/smithy-go/private/requestcompression github.com/aws/smithy-go/aws-http-auth/internal/v4 github.com/docker/cli/cli/config/memorystore k8s.io/apimachinery/pkg/watch k8s.io/client-go/transport github.com/aws/aws-sdk-go-v2/aws/middleware github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4 github.com/aws/aws-sdk-go-v2/credentials github.com/aws/aws-sdk-go-v2/aws/defaults github.com/aws/aws-sdk-go-v2/internal/configsources k8s.io/kube-openapi/pkg/util/proto k8s.io/kube-openapi/pkg/validation/spec github.com/aws/aws-sdk-go-v2/internal/endpoints k8s.io/apimachinery/pkg/apis/meta/v1 github.com/aws/aws-sdk-go-v2/aws/transport/http github.com/prometheus/client_golang/prometheus/collectors github.com/prometheus/client_golang/prometheus/promhttp github.com/aws/aws-sdk-go-v2/aws/signer/v4 github.com/aws/aws-sdk-go-v2/aws/retry github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 github.com/aws/aws-sdk-go-v2/internal/auth/smithy k8s.io/kube-openapi/pkg/util/proto/validation github.com/aws/aws-sdk-go-v2/service/signin/internal/endpoints github.com/aws/aws-sdk-go-v2/credentials/processcreds github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints github.com/aws/aws-sdk-go-v2/feature/ec2/imds github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client github.com/aws/aws-sdk-go-v2/service/signin github.com/aws/aws-sdk-go-v2/service/sso k8s.io/kube-openapi/pkg/schemaconv k8s.io/kube-openapi/pkg/spec3 sigs.k8s.io/kustomize/kyaml/yaml github.com/aws/aws-sdk-go-v2/credentials/endpointcreds github.com/aws/aws-sdk-go-v2/service/ssooidc github.com/aws/aws-sdk-go-v2/internal/v4a github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds github.com/aws/aws-sdk-go-v2/service/internal/presigned-url github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints k8s.io/kube-openapi/pkg/common github.com/aws/aws-sdk-go-v2/service/ecr/internal/endpoints github.com/aws/aws-sdk-go-v2/service/sts github.com/aws/aws-sdk-go-v2/service/ecr k8s.io/kube-openapi/pkg/handler3 github.com/aws/aws-sdk-go-v2/credentials/logincreds github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints sigs.k8s.io/kustomize/api/filters/filtersutil sigs.k8s.io/kustomize/kyaml/openapi sigs.k8s.io/kustomize/kyaml/kio/kioutil sigs.k8s.io/kustomize/kyaml/order sigs.k8s.io/kustomize/kyaml/kio sigs.k8s.io/kustomize/api/hasher sigs.k8s.io/kustomize/kyaml/resid sigs.k8s.io/kustomize/kyaml/fieldmeta sigs.k8s.io/kustomize/kyaml/yaml/schema sigs.k8s.io/kustomize/api/types github.com/aws/aws-sdk-go-v2/service/ecrpublic sigs.k8s.io/kustomize/kyaml/yaml/walk github.com/aws/aws-sdk-go-v2/credentials/ssocreds sigs.k8s.io/kustomize/api/filters/patchjson6902 sigs.k8s.io/kustomize/api/filters/valueadd github.com/aws/aws-sdk-go-v2/service/eks/internal/endpoints github.com/aws/smithy-go/aws-http-auth/sigv4 sigs.k8s.io/kustomize/kyaml/yaml/merge2 k8s.io/apimachinery/pkg/apis/meta/v1/unstructured k8s.io/api/core/v1 k8s.io/api/rbac/v1 k8s.io/apimachinery/pkg/api/meta k8s.io/apimachinery/pkg/api/errors k8s.io/api/apidiscovery/v2 k8s.io/apimachinery/pkg/runtime/serializer/versioning k8s.io/apimachinery/pkg/runtime/serializer/json k8s.io/apimachinery/pkg/runtime/serializer/protobuf k8s.io/api/apidiscovery/v2beta1 k8s.io/api/admissionregistration/v1 k8s.io/apimachinery/pkg/apis/meta/v1/unstructured/unstructuredscheme k8s.io/apimachinery/pkg/runtime/serializer k8s.io/api/apiserverinternal/v1alpha1 k8s.io/api/authentication/v1 k8s.io/api/authorization/v1 k8s.io/api/certificates/v1alpha1 k8s.io/api/coordination/v1 k8s.io/api/coordination/v1alpha2 k8s.io/api/authentication/v1alpha1 k8s.io/api/authentication/v1beta1 k8s.io/api/coordination/v1beta1 k8s.io/apimachinery/pkg/api/equality k8s.io/api/authorization/v1beta1 k8s.io/apimachinery/pkg/api/validate k8s.io/api/flowcontrol/v1 k8s.io/api/flowcontrol/v1beta1 k8s.io/api/admissionregistration/v1alpha1 k8s.io/api/admissionregistration/v1beta1 k8s.io/api/flowcontrol/v1beta2 k8s.io/api/flowcontrol/v1beta3 k8s.io/api/policy/v1 k8s.io/api/policy/v1beta1 k8s.io/api/rbac/v1alpha1 k8s.io/api/rbac/v1beta1 k8s.io/api/resource/v1alpha3 k8s.io/api/scheduling/v1alpha2 k8s.io/api/storagemigration/v1beta1 k8s.io/apimachinery/pkg/apis/meta/v1/validation k8s.io/apimachinery/pkg/runtime/serializer/cbor k8s.io/apimachinery/pkg/api/validation k8s.io/client-go/pkg/apis/clientauthentication k8s.io/client-go/rest/watch k8s.io/apimachinery/pkg/util/managedfields/internal sigs.k8s.io/kustomize/api/filters/fieldspec sigs.k8s.io/kustomize/api/filters/iampolicygenerator k8s.io/client-go/pkg/apis/clientauthentication/v1 k8s.io/client-go/pkg/apis/clientauthentication/v1beta1 sigs.k8s.io/kustomize/api/filters/fsslice sigs.k8s.io/kustomize/api/konfig sigs.k8s.io/kustomize/api/filters/annotations sigs.k8s.io/kustomize/api/filters/labels sigs.k8s.io/kustomize/api/internal/utils sigs.k8s.io/kustomize/api/filters/namespace k8s.io/client-go/pkg/apis/clientauthentication/install sigs.k8s.io/kustomize/api/filters/imagetag sigs.k8s.io/kustomize/api/filters/prefix sigs.k8s.io/kustomize/api/filters/patchstrategicmerge sigs.k8s.io/kustomize/api/ifc k8s.io/client-go/plugin/pkg/client/auth/exec sigs.k8s.io/kustomize/api/internal/git sigs.k8s.io/kustomize/api/internal/generators sigs.k8s.io/kustomize/api/filters/replicacount sigs.k8s.io/kustomize/api/filters/suffix sigs.k8s.io/kustomize/kyaml/comments sigs.k8s.io/kustomize/api/filters/refvar sigs.k8s.io/kustomize/api/internal/loader sigs.k8s.io/kustomize/api/resource sigs.k8s.io/kustomize/api/kv sigs.k8s.io/kustomize/kyaml/fn/runtime/runtimeutil sigs.k8s.io/kustomize/api/internal/plugins/builtinconfig k8s.io/apimachinery/pkg/util/managedfields k8s.io/client-go/rest sigs.k8s.io/kustomize/api/internal/validate k8s.io/apimachinery/pkg/util/strategicpatch k8s.io/apimachinery/pkg/apis/meta/v1beta1 sigs.k8s.io/kustomize/kyaml/fn/runtime/exec sigs.k8s.io/kustomize/api/filters/replacement sigs.k8s.io/kustomize/api/resmap sigs.k8s.io/kustomize/kyaml/fn/runtime/container sigs.k8s.io/kustomize/api/provider k8s.io/apimachinery/pkg/apis/meta/internalversion sigs.k8s.io/kustomize/kyaml/runfn k8s.io/cli-runtime/pkg/printers sigs.k8s.io/kustomize/api/internal/builtins sigs.k8s.io/kustomize/api/internal/plugins/utils sigs.k8s.io/kustomize/api/filters/nameref sigs.k8s.io/kustomize/api/internal/plugins/execplugin sigs.k8s.io/kustomize/api/internal/plugins/fnplugin sigs.k8s.io/kustomize/api/internal/accumulator k8s.io/apimachinery/pkg/apis/meta/internalversion/scheme k8s.io/client-go/tools/pager k8s.io/client-go/tools/clientcmd/api/latest k8s.io/apimachinery/pkg/api/meta/testrestmapper sigs.k8s.io/kustomize/api/internal/plugins/builtinhelpers k8s.io/client-go/openapi k8s.io/client-go/util/apply k8s.io/client-go/metadata k8s.io/client-go/dynamic sigs.k8s.io/kustomize/api/internal/plugins/loader k8s.io/client-go/tools/auth k8s.io/client-go/tools/clientcmd k8s.io/client-go/testing k8s.io/api/admission/v1 sigs.k8s.io/kustomize/api/internal/target k8s.io/client-go/openapi3 k8s.io/client-go/openapi/cached k8s.io/api/admission/v1beta1 k8s.io/api/imagepolicy/v1alpha1 k8s.io/kubectl/pkg/util/term k8s.io/apiextensions-apiserver/pkg/apis/apiextensions sigs.k8s.io/kustomize/api/krusty github.com/fluxcd/flux2/v2/pkg/manifestgen/kustomization github.com/fluxcd/pkg/apis/meta k8s.io/kubectl/pkg/util/templates sigs.k8s.io/controller-runtime/pkg/scheme github.com/fluxcd/flux2/v2/pkg/manifestgen/install k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1 github.com/fluxcd/cli-utils/pkg/flowcontrol k8s.io/client-go/util/consistencydetector github.com/fluxcd/source-controller/api/v1 github.com/fluxcd/image-reflector-controller/api/v1 github.com/fluxcd/notification-controller/api/v1 k8s.io/apimachinery/pkg/apis/meta/internalversion/validation k8s.io/client-go/util/watchlist sigs.k8s.io/controller-runtime/pkg/client/config github.com/fluxcd/notification-controller/api/v1beta3 k8s.io/client-go/gentype k8s.io/client-go/tools/cache github.com/fluxcd/source-watcher/api/v2/v1beta1 github.com/aws/aws-sdk-go-v2/credentials/stscreds github.com/aws/aws-sdk-go-v2/service/eks github.com/aws/aws-sdk-go-v2/config github.com/prometheus/client_golang/prometheus/promauto github.com/fluxcd/image-automation-controller/api/v1 github.com/docker/cli/cli/config/configfile github.com/fluxcd/pkg/cache github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/shared github.com/docker/cli/cli/config github.com/Azure/azure-sdk-for-go/sdk/internal/exported github.com/google/go-containerregistry/pkg/authn github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/exported github.com/Azure/azure-sdk-for-go/sdk/internal/poller github.com/Azure/azure-sdk-for-go/sdk/azidentity/internal github.com/kylelemons/godebug/pretty github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/json/types/time github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/authority github.com/fluxcd/pkg/apis/kustomize github.com/Azure/azure-sdk-for-go/sdk/azcore/policy github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers github.com/Azure/azure-sdk-for-go/sdk/azcore/streaming github.com/AzureAD/microsoft-authentication-library-for-go/apps/errors github.com/fluxcd/helm-controller/api/v2 github.com/fluxcd/kustomize-controller/api/v1 github.com/Azure/azure-sdk-for-go/sdk/azcore/arm/policy github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers/async github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers/body github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers/fake github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers/loc github.com/Azure/azure-sdk-for-go/sdk/azcore/internal/pollers/op github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/wstrust/defs github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/shared github.com/Azure/azure-sdk-for-go/sdk/azcore/runtime github.com/golang-jwt/jwt/v5 github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/internal/comm github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/wstrust github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/options github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/local github.com/pkg/browser golang.org/x/crypto/pkcs12/internal/rc2 k8s.io/client-go/listers github.com/hashicorp/go-retryablehttp golang.org/x/crypto/pkcs12 github.com/ProtonMail/go-crypto/openpgp/errors k8s.io/client-go/listers/admissionregistration/v1 k8s.io/client-go/listers/admissionregistration/v1alpha1 k8s.io/client-go/listers/admissionregistration/v1beta1 k8s.io/client-go/listers/apiserverinternal/v1alpha1 k8s.io/client-go/listers/certificates/v1alpha1 k8s.io/client-go/listers/coordination/v1 k8s.io/client-go/listers/coordination/v1alpha2 k8s.io/client-go/listers/coordination/v1beta1 k8s.io/client-go/listers/flowcontrol/v1 k8s.io/client-go/listers/flowcontrol/v1beta1 k8s.io/client-go/listers/flowcontrol/v1beta2 k8s.io/client-go/listers/flowcontrol/v1beta3 k8s.io/client-go/listers/rbac/v1 k8s.io/client-go/listers/rbac/v1alpha1 k8s.io/client-go/listers/rbac/v1beta1 k8s.io/client-go/listers/resource/v1alpha3 k8s.io/client-go/listers/scheduling/v1alpha2 k8s.io/client-go/listers/storagemigration/v1beta1 github.com/Azure/azure-sdk-for-go/sdk/azcore github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops/accesstokens github.com/fluxcd/flux2/v2/internal/plugin github.com/ProtonMail/go-crypto/openpgp/armor github.com/ProtonMail/go-crypto/openpgp/aes/keywrap github.com/ProtonMail/go-crypto/eax github.com/ProtonMail/go-crypto/ocb golang.org/x/crypto/cast5 github.com/ProtonMail/go-crypto/bitcurves github.com/Azure/azure-sdk-for-go/sdk/azcore/arm/runtime github.com/ProtonMail/go-crypto/openpgp/internal/algorithm github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth/ops github.com/ProtonMail/go-crypto/brainpool github.com/ProtonMail/go-crypto/openpgp/internal/encoding golang.org/x/crypto/cryptobyte github.com/cloudflare/circl/math github.com/cloudflare/circl/sign github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/oauth github.com/Azure/azure-sdk-for-go/sdk/azcore/arm github.com/cloudflare/circl/internal/sha3 compress/bzip2 github.com/ProtonMail/go-crypto/openpgp/elgamal github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/base/storage golang.org/x/crypto/blake2b golang.org/x/crypto/hkdf github.com/cloudflare/circl/internal/conv github.com/cloudflare/circl/math/fp25519 github.com/cloudflare/circl/math/fp448 github.com/cloudflare/circl/math/mlsbset github.com/cloudflare/circl/dh/x25519 github.com/cloudflare/circl/sign/ed25519 github.com/cloudflare/circl/dh/x448 github.com/AzureAD/microsoft-authentication-library-for-go/apps/internal/base github.com/cloudflare/circl/ecc/goldilocks golang.org/x/crypto/argon2 github.com/ProtonMail/go-crypto/openpgp/ed25519 github.com/ProtonMail/go-crypto/openpgp/x25519 github.com/AzureAD/microsoft-authentication-library-for-go/apps/confidential github.com/AzureAD/microsoft-authentication-library-for-go/apps/managedidentity github.com/AzureAD/microsoft-authentication-library-for-go/apps/public github.com/ProtonMail/go-crypto/openpgp/s2k github.com/cloudflare/circl/sign/ed448 github.com/fluxcd/cli-utils/pkg/kstatus/status k8s.io/api/apps/v1 k8s.io/api/apps/v1beta1 k8s.io/api/apps/v1beta2 k8s.io/api/autoscaling/v1 k8s.io/api/autoscaling/v2 k8s.io/api/batch/v1 k8s.io/api/certificates/v1 k8s.io/api/batch/v1beta1 k8s.io/api/certificates/v1beta1 k8s.io/api/discovery/v1 k8s.io/api/discovery/v1beta1 k8s.io/api/events/v1 k8s.io/api/events/v1beta1 k8s.io/api/extensions/v1beta1 k8s.io/api/networking/v1beta1 k8s.io/api/networking/v1 k8s.io/api/node/v1 k8s.io/api/node/v1alpha1 k8s.io/api/node/v1beta1 k8s.io/api/resource/v1 k8s.io/api/resource/v1beta1 k8s.io/api/resource/v1beta2 k8s.io/api/scheduling/v1 k8s.io/api/scheduling/v1beta1 k8s.io/api/storage/v1 k8s.io/api/storage/v1alpha1 k8s.io/api/storage/v1beta1 k8s.io/client-go/tools/reference k8s.io/client-go/scale/scheme k8s.io/client-go/listers/apps/v1 k8s.io/client-go/scale/scheme/appsint k8s.io/client-go/scale/scheme/appsv1beta1 k8s.io/client-go/scale/scheme/appsv1beta2 k8s.io/client-go/scale/scheme/autoscalingv1 k8s.io/client-go/scale/scheme/extensionsint k8s.io/client-go/scale/scheme/extensionsv1beta1 k8s.io/client-go/listers/apps/v1beta1 k8s.io/client-go/listers/apps/v1beta2 k8s.io/client-go/listers/autoscaling/v1 k8s.io/client-go/listers/autoscaling/v2 k8s.io/client-go/listers/batch/v1 k8s.io/client-go/listers/batch/v1beta1 k8s.io/client-go/listers/certificates/v1 k8s.io/client-go/listers/certificates/v1beta1 k8s.io/client-go/listers/core/v1 k8s.io/client-go/listers/discovery/v1 k8s.io/client-go/listers/events/v1 k8s.io/client-go/listers/discovery/v1beta1 k8s.io/client-go/listers/events/v1beta1 k8s.io/client-go/listers/extensions/v1beta1 k8s.io/client-go/listers/networking/v1 k8s.io/client-go/listers/networking/v1beta1 k8s.io/client-go/listers/node/v1 k8s.io/client-go/listers/node/v1alpha1 k8s.io/client-go/listers/node/v1beta1 k8s.io/client-go/listers/policy/v1 k8s.io/client-go/listers/policy/v1beta1 k8s.io/client-go/listers/resource/v1 k8s.io/client-go/listers/resource/v1beta1 k8s.io/client-go/listers/scheduling/v1 k8s.io/client-go/kubernetes/scheme k8s.io/client-go/listers/resource/v1beta2 k8s.io/client-go/listers/scheduling/v1beta1 k8s.io/client-go/listers/storage/v1 k8s.io/client-go/listers/storage/v1alpha1 k8s.io/client-go/listers/storage/v1beta1 k8s.io/client-go/tools/record/util github.com/Azure/azure-sdk-for-go/sdk/azidentity k8s.io/client-go/discovery k8s.io/client-go/kubernetes/typed/authentication/v1 k8s.io/client-go/kubernetes/typed/authentication/v1alpha1 k8s.io/client-go/kubernetes/typed/authentication/v1beta1 k8s.io/client-go/kubernetes/typed/authorization/v1 k8s.io/client-go/kubernetes/typed/authorization/v1beta1 k8s.io/kubectl/pkg/scheme k8s.io/client-go/tools/record github.com/ProtonMail/go-crypto/openpgp/internal/ecc github.com/ProtonMail/go-crypto/openpgp/ed448 github.com/ProtonMail/go-crypto/openpgp/x448 image golang.org/x/sys/cpu golang.org/x/crypto/blake2s golang.org/x/crypto/ed25519 k8s.io/client-go/restmapper k8s.io/client-go/discovery/cached/memory k8s.io/client-go/applyconfigurations/meta/v1 k8s.io/client-go/scale k8s.io/kubectl/pkg/util/openapi github.com/ProtonMail/go-crypto/openpgp/ecdh k8s.io/client-go/discovery/cached/disk github.com/ProtonMail/go-crypto/openpgp/ecdsa sigs.k8s.io/controller-runtime/pkg/client/apiutil k8s.io/cli-runtime/pkg/resource github.com/ProtonMail/go-crypto/openpgp/eddsa image/internal/imageutil golang.org/x/crypto/sha3 golang.org/x/crypto/chacha20 image/jpeg golang.org/x/crypto/curve25519 golang.org/x/crypto/internal/poly1305 golang.org/x/crypto/blowfish k8s.io/client-go/applyconfigurations/admissionregistration/v1 k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1 k8s.io/client-go/applyconfigurations/core/v1 k8s.io/client-go/applyconfigurations/autoscaling/v1 k8s.io/client-go/applyconfigurations/autoscaling/v2 sigs.k8s.io/controller-runtime/pkg/client k8s.io/client-go/applyconfigurations/certificates/v1 k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1 k8s.io/client-go/kubernetes/typed/autoscaling/v1 k8s.io/client-go/kubernetes/typed/certificates/v1 k8s.io/client-go/kubernetes/typed/autoscaling/v2 k8s.io/client-go/applyconfigurations/certificates/v1alpha1 k8s.io/client-go/applyconfigurations/certificates/v1beta1 k8s.io/client-go/applyconfigurations/coordination/v1 k8s.io/client-go/kubernetes/typed/admissionregistration/v1 k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1 github.com/fluxcd/cli-utils/pkg/object k8s.io/cli-runtime/pkg/genericclioptions k8s.io/client-go/applyconfigurations/admissionregistration/v1beta1 k8s.io/client-go/kubernetes/typed/certificates/v1alpha1 github.com/fluxcd/cli-utils/pkg/kstatus/polling/event k8s.io/client-go/kubernetes/typed/certificates/v1beta1 github.com/fluxcd/cli-utils/pkg/kstatus/polling/engine k8s.io/client-go/kubernetes/typed/coordination/v1 k8s.io/client-go/kubernetes/typed/admissionregistration/v1alpha1 github.com/fluxcd/cli-utils/pkg/kstatus/polling/clusterreader github.com/fluxcd/cli-utils/pkg/kstatus/polling/statusreaders k8s.io/client-go/applyconfigurations/coordination/v1alpha2 k8s.io/client-go/applyconfigurations/coordination/v1beta1 k8s.io/client-go/applyconfigurations/flowcontrol/v1 k8s.io/client-go/kubernetes/typed/admissionregistration/v1beta1 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta2 k8s.io/client-go/kubernetes/typed/coordination/v1alpha2 k8s.io/client-go/kubernetes/typed/coordination/v1beta1 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3 k8s.io/client-go/kubernetes/typed/flowcontrol/v1 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta1 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2 k8s.io/client-go/applyconfigurations/policy/v1 k8s.io/client-go/applyconfigurations/apps/v1 k8s.io/client-go/applyconfigurations/apps/v1beta1 k8s.io/client-go/applyconfigurations/apps/v1beta2 k8s.io/client-go/applyconfigurations/batch/v1 k8s.io/client-go/kubernetes/typed/core/v1 k8s.io/client-go/applyconfigurations/discovery/v1 k8s.io/client-go/applyconfigurations/discovery/v1beta1 k8s.io/client-go/applyconfigurations/events/v1 k8s.io/client-go/kubernetes/typed/apps/v1beta1 k8s.io/client-go/kubernetes/typed/apps/v1 k8s.io/client-go/kubernetes/typed/discovery/v1 k8s.io/client-go/kubernetes/typed/discovery/v1beta1 k8s.io/client-go/kubernetes/typed/events/v1 k8s.io/client-go/kubernetes/typed/batch/v1 k8s.io/client-go/kubernetes/typed/apps/v1beta2 k8s.io/client-go/applyconfigurations/batch/v1beta1 k8s.io/client-go/applyconfigurations/events/v1beta1 k8s.io/client-go/applyconfigurations/extensions/v1beta1 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3 k8s.io/client-go/applyconfigurations/networking/v1 k8s.io/client-go/kubernetes/typed/events/v1beta1 k8s.io/client-go/kubernetes/typed/batch/v1beta1 k8s.io/client-go/applyconfigurations/networking/v1beta1 k8s.io/client-go/applyconfigurations/node/v1 k8s.io/client-go/applyconfigurations/node/v1alpha1 k8s.io/client-go/kubernetes/typed/networking/v1 k8s.io/client-go/applyconfigurations/node/v1beta1 k8s.io/client-go/kubernetes/typed/policy/v1 k8s.io/client-go/kubernetes/typed/extensions/v1beta1 k8s.io/client-go/kubernetes/typed/node/v1 k8s.io/client-go/kubernetes/typed/networking/v1beta1 k8s.io/client-go/kubernetes/typed/node/v1alpha1 k8s.io/client-go/applyconfigurations/policy/v1beta1 k8s.io/client-go/kubernetes/typed/node/v1beta1 k8s.io/client-go/applyconfigurations/rbac/v1 k8s.io/client-go/applyconfigurations/rbac/v1alpha1 k8s.io/client-go/applyconfigurations/rbac/v1beta1 k8s.io/client-go/kubernetes/typed/policy/v1beta1 k8s.io/client-go/applyconfigurations/resource/v1 k8s.io/client-go/applyconfigurations/resource/v1alpha3 k8s.io/client-go/applyconfigurations/resource/v1beta1 k8s.io/client-go/kubernetes/typed/rbac/v1 k8s.io/client-go/applyconfigurations/resource/v1beta2 k8s.io/client-go/kubernetes/typed/rbac/v1alpha1 k8s.io/client-go/applyconfigurations/scheduling/v1 k8s.io/client-go/kubernetes/typed/rbac/v1beta1 k8s.io/client-go/kubernetes/typed/resource/v1alpha3 k8s.io/client-go/kubernetes/typed/resource/v1 k8s.io/client-go/kubernetes/typed/scheduling/v1 k8s.io/client-go/applyconfigurations/scheduling/v1alpha2 k8s.io/client-go/kubernetes/typed/resource/v1beta1 k8s.io/client-go/applyconfigurations/scheduling/v1beta1 k8s.io/client-go/applyconfigurations/storage/v1 k8s.io/client-go/kubernetes/typed/resource/v1beta2 k8s.io/client-go/applyconfigurations/storage/v1alpha1 k8s.io/client-go/applyconfigurations/storage/v1beta1 k8s.io/client-go/kubernetes/typed/scheduling/v1alpha2 k8s.io/client-go/applyconfigurations/storagemigration/v1beta1 k8s.io/client-go/kubernetes/typed/scheduling/v1beta1 k8s.io/client-go/kubernetes/typed/storage/v1alpha1 k8s.io/kubectl/pkg/validation k8s.io/client-go/kubernetes/typed/storage/v1 github.com/fluxcd/pkg/runtime/statusreaders k8s.io/client-go/kubernetes/typed/storagemigration/v1beta1 sigs.k8s.io/controller-runtime/pkg/reconcile k8s.io/client-go/kubernetes/typed/storage/v1beta1 sigs.k8s.io/controller-runtime/pkg/cache/internal sigs.k8s.io/controller-runtime/pkg/event sigs.k8s.io/controller-runtime/pkg/controller/controllerutil github.com/fluxcd/cli-utils/pkg/kstatus/polling/aggregator github.com/fluxcd/cli-utils/pkg/kstatus/polling/collector sigs.k8s.io/controller-runtime/pkg/predicate github.com/fluxcd/pkg/ssa/utils github.com/fluxcd/pkg/kustomize github.com/fluxcd/pkg/auth github.com/ProtonMail/go-crypto/openpgp/packet sigs.k8s.io/controller-runtime/pkg/cache github.com/fluxcd/pkg/ssa/errors github.com/fluxcd/pkg/ssa/normalize github.com/fluxcd/flux2/v2/internal/tree golang.org/x/crypto/ssh/internal/bcrypt_pbkdf github.com/fluxcd/pkg/auth/aws github.com/fluxcd/pkg/auth/azure golang.org/x/crypto/ssh github.com/fluxcd/pkg/ssa/jsondiff golang.org/x/crypto/ripemd160 k8s.io/client-go/kubernetes github.com/hashicorp/go-version github.com/google/go-querystring/query github.com/go-git/go-billy/v5 github.com/google/go-github/v82/github gitlab.com/gitlab-org/api/client-go github.com/go-git/go-billy/v5/helper/polyfill dario.cat/mergo github.com/go-git/go-billy/v5/helper/chroot github.com/ProtonMail/go-crypto/openpgp github.com/go-git/go-billy/v5/util github.com/go-git/go-billy/v5/osfs github.com/go-git/go-git/v5/internal/pathutil github.com/go-git/go-git/v5/internal/url github.com/klauspost/cpuid/v2 encoding/gob github.com/go-git/gcfg/token github.com/go-git/gcfg/types github.com/go-git/gcfg/scanner gopkg.in/warnings.v0 github.com/go-git/go-git/v5/internal/path_util github.com/go-git/go-git/v5/internal/revision github.com/go-git/go-git/v5/plumbing/filemode golang.org/x/net/context github.com/go-git/go-git/v5/utils/sync github.com/jbenet/go-context/io github.com/go-git/go-git/v5/utils/ioutil github.com/emirpasic/gods/utils k8s.io/kubectl/pkg/cmd/util k8s.io/client-go/informers/internalinterfaces k8s.io/client-go/tools/leaderelection/resourcelock k8s.io/client-go/tools/events github.com/pjbgf/sha1cd github.com/42wim/httpsig k8s.io/client-go/informers/admissionregistration/v1 k8s.io/client-go/informers/admissionregistration/v1alpha1 k8s.io/client-go/informers/admissionregistration/v1beta1 k8s.io/client-go/informers/apiserverinternal/v1alpha1 k8s.io/client-go/informers/apps/v1 github.com/fluxcd/cli-utils/pkg/kstatus/polling k8s.io/client-go/informers/apps/v1beta1 k8s.io/client-go/informers/apps/v1beta2 k8s.io/client-go/informers/apiserverinternal k8s.io/client-go/informers/admissionregistration k8s.io/client-go/informers/autoscaling/v1 k8s.io/client-go/informers/autoscaling/v2 k8s.io/client-go/informers/batch/v1 k8s.io/client-go/informers/apps k8s.io/client-go/informers/batch/v1beta1 k8s.io/client-go/informers/certificates/v1 k8s.io/client-go/informers/certificates/v1alpha1 k8s.io/client-go/informers/autoscaling k8s.io/client-go/informers/certificates/v1beta1 k8s.io/client-go/informers/batch k8s.io/client-go/informers/coordination/v1 k8s.io/client-go/informers/coordination/v1alpha2 k8s.io/client-go/informers/coordination/v1beta1 k8s.io/client-go/informers/core/v1 k8s.io/client-go/informers/certificates k8s.io/client-go/informers/discovery/v1 k8s.io/client-go/informers/discovery/v1beta1 k8s.io/client-go/informers/events/v1 k8s.io/client-go/informers/coordination k8s.io/client-go/informers/events/v1beta1 k8s.io/client-go/informers/extensions/v1beta1 k8s.io/client-go/informers/discovery k8s.io/client-go/informers/flowcontrol/v1 k8s.io/client-go/informers/core k8s.io/client-go/informers/flowcontrol/v1beta1 k8s.io/client-go/informers/extensions k8s.io/client-go/informers/events k8s.io/client-go/informers/flowcontrol/v1beta2 k8s.io/client-go/informers/flowcontrol/v1beta3 k8s.io/client-go/informers/networking/v1 k8s.io/client-go/informers/networking/v1beta1 k8s.io/client-go/informers/node/v1 k8s.io/client-go/informers/node/v1alpha1 k8s.io/client-go/informers/node/v1beta1 k8s.io/client-go/informers/policy/v1 k8s.io/client-go/informers/flowcontrol k8s.io/client-go/informers/policy/v1beta1 k8s.io/client-go/informers/networking k8s.io/client-go/informers/rbac/v1 k8s.io/client-go/informers/rbac/v1alpha1 k8s.io/client-go/informers/node k8s.io/client-go/informers/rbac/v1beta1 k8s.io/client-go/informers/resource/v1 k8s.io/client-go/informers/resource/v1alpha3 k8s.io/client-go/informers/policy k8s.io/client-go/informers/resource/v1beta1 k8s.io/client-go/informers/resource/v1beta2 k8s.io/client-go/informers/scheduling/v1 k8s.io/client-go/informers/rbac k8s.io/client-go/informers/scheduling/v1alpha2 k8s.io/client-go/informers/scheduling/v1beta1 k8s.io/client-go/informers/storage/v1 k8s.io/client-go/informers/storage/v1alpha1 k8s.io/client-go/informers/storage/v1beta1 k8s.io/client-go/informers/resource k8s.io/client-go/informers/storagemigration/v1beta1 sigs.k8s.io/controller-runtime/pkg/internal/recorder sigs.k8s.io/controller-runtime/pkg/recorder sigs.k8s.io/controller-runtime/pkg/cluster sigs.k8s.io/controller-runtime/pkg/leaderelection k8s.io/client-go/informers/scheduling github.com/go-fed/httpsig github.com/fluxcd/pkg/ssa golang.org/x/crypto/ssh/agent k8s.io/client-go/informers/storagemigration github.com/fluxcd/go-git-providers/github github.com/fluxcd/go-git-providers/gitlab k8s.io/client-go/informers/storage github.com/go-git/go-git/v5/plumbing/hash github.com/go-git/go-git/v5/plumbing code.gitea.io/sdk/gitea github.com/go-git/gcfg github.com/go-git/go-git/v5/plumbing/cache github.com/go-git/go-git/v5/utils/binary github.com/emirpasic/gods/containers github.com/emirpasic/gods/lists github.com/go-git/go-git/v5/plumbing/format/idxfile github.com/go-git/go-git/v5/plumbing/format/index github.com/go-git/go-git/v5/plumbing/format/config github.com/emirpasic/gods/lists/arraylist github.com/emirpasic/gods/trees github.com/go-git/go-git/v5/plumbing/storer github.com/go-git/go-git/v5/plumbing/format/diff github.com/go-git/go-git/v5/utils/diff github.com/emirpasic/gods/trees/binaryheap github.com/go-git/go-git/v5/utils/merkletrie/noder github.com/go-git/go-git/v5/utils/trace k8s.io/client-go/informers github.com/go-git/go-git/v5/plumbing/format/packfile github.com/go-git/go-git/v5/plumbing/format/gitignore github.com/go-git/go-git/v5/utils/merkletrie/internal/frame github.com/go-git/go-git/v5/config github.com/go-git/go-git/v5/plumbing/format/pktline github.com/go-git/go-git/v5/plumbing/protocol/packp/capability github.com/go-git/go-git/v5/utils/merkletrie github.com/go-git/go-git/v5/plumbing/protocol/packp/sideband golang.org/x/sys/execabs github.com/kevinburke/ssh_config golang.org/x/crypto/ssh/knownhosts github.com/xanzy/ssh-agent golang.org/x/net/internal/socks github.com/go-git/go-git/v5/storage github.com/go-git/go-git/v5/utils/merkletrie/filesystem github.com/go-git/go-git/v5/storage/memory github.com/go-git/go-git/v5/plumbing/object golang.org/x/net/proxy github.com/skeema/knownhosts github.com/go-git/go-git/v5/utils/merkletrie/index github.com/hashicorp/errwrap github.com/fluxcd/pkg/runtime/secrets github.com/go-git/go-git/v5/plumbing/format/objfile github.com/go-git/go-git/v5/plumbing/protocol/packp github.com/fluxcd/pkg/ssh github.com/hashicorp/go-multierror github.com/hiddeco/sshsig github.com/fluxcd/flux2/v2/pkg/manifestgen/sync github.com/go-git/go-git/v5/storage/filesystem/dotgit github.com/fluxcd/source-controller/api/v1beta2 github.com/fluxcd/flux2/v2/pkg/uninstall github.com/fluxcd/flux2/v2/pkg/manifestgen/sourcesecret github.com/go-git/go-git/v5/plumbing/transport github.com/fluxcd/image-automation-controller/api/v1beta2 github.com/go-git/go-git/v5/plumbing/transport/internal/common github.com/go-git/go-git/v5/storage/filesystem github.com/go-git/go-git/v5/plumbing/transport/git github.com/go-git/go-git/v5/plumbing/revlist github.com/go-git/go-git/v5/plumbing/transport/http github.com/go-git/go-git/v5/plumbing/transport/ssh github.com/fluxcd/image-reflector-controller/api/v1beta2 github.com/fluxcd/pkg/auth/actionsoidc cloud.google.com/go/compute/metadata github.com/go-git/go-git/v5/plumbing/transport/server golang.org/x/oauth2/authhandler github.com/fluxcd/go-git-providers/gitea golang.org/x/oauth2/google/internal/impersonate golang.org/x/oauth2/google/internal/stsexchange github.com/go-git/go-git/v5/plumbing/transport/file golang.org/x/oauth2/jws github.com/googleapis/gax-go/v2/internallog/internal google.golang.org/api/internal/third_party/uritemplates golang.org/x/oauth2/google/externalaccount github.com/go-git/go-git/v5/plumbing/transport/client golang.org/x/oauth2/google/internal/externalaccountauthorizeduser google.golang.org/api/googleapi github.com/googleapis/gax-go/v2/internallog golang.org/x/oauth2/jwt github.com/go-git/go-git/v5 cloud.google.com/go/auth/internal cloud.google.com/go/auth/internal/jwt cloud.google.com/go/auth/internal/credsfile github.com/googleapis/enterprise-certificate-proxy/client/util cloud.google.com/go/auth/internal/retry html/template google.golang.org/grpc/attributes cloud.google.com/go/auth google.golang.org/grpc/grpclog/internal google.golang.org/grpc/internal/envconfig golang.org/x/oauth2/google github.com/google/s2a-go/internal/proto/common_go_proto golang.org/x/net/internal/timeseries google.golang.org/grpc/grpclog cloud.google.com/go/auth/internal/transport/headers cloud.google.com/go/auth/credentials/internal/stsexchange cloud.google.com/go/auth/credentials/internal/gdch google.golang.org/grpc/internal/credentials cloud.google.com/go/auth/credentials/internal/impersonate cloud.google.com/go/auth/credentials/internal/externalaccountuser cloud.google.com/go/auth/internal/trustboundary k8s.io/client-go/tools/leaderelection cloud.google.com/go/auth/oauth2adapt google.golang.org/grpc/credentials github.com/google/s2a-go/internal/proto/s2a_context_go_proto google.golang.org/grpc/backoff google.golang.org/grpc/connectivity google.golang.org/grpc/balancer/pickfirst/internal google.golang.org/grpc/internal google.golang.org/grpc/internal/grpclog github.com/google/s2a-go/fallback google.golang.org/protobuf/internal/encoding/json google.golang.org/protobuf/protoadapt google.golang.org/grpc/credentials/insecure net/rpc golang.org/x/net/trace google.golang.org/grpc/internal/channelz google.golang.org/grpc/metadata google.golang.org/grpc/codes google.golang.org/grpc/stats google.golang.org/protobuf/encoding/protojson google.golang.org/grpc/internal/grpcutil google.golang.org/grpc/experimental/stats google.golang.org/grpc/internal/mem google.golang.org/grpc/resolver google.golang.org/grpc/channelz google.golang.org/grpc/internal/backoff google.golang.org/grpc/internal/balancerload google.golang.org/grpc/mem google.golang.org/protobuf/types/known/durationpb github.com/fluxcd/pkg/git/signature google.golang.org/grpc/balancer github.com/fluxcd/go-git-providers/stash google.golang.org/grpc/balancer/base google.golang.org/grpc/internal/balancer/weight google.golang.org/grpc/internal/pretty github.com/googleapis/enterprise-certificate-proxy/client google.golang.org/grpc/encoding github.com/fluxcd/pkg/git google.golang.org/grpc/binarylog/grpc_binarylog_v1 google.golang.org/grpc/balancer/endpointsharding google.golang.org/grpc/balancer/pickfirst google.golang.org/grpc/encoding/proto cloud.google.com/go/auth/internal/transport/cert github.com/fluxcd/pkg/git/repository google.golang.org/grpc/internal/balancer/gracefulswitch google.golang.org/genproto/googleapis/rpc/status google.golang.org/grpc/internal/buffer google.golang.org/grpc/internal/idle cloud.google.com/go/auth/credentials/internal/externalaccount google.golang.org/grpc/internal/grpcsync google.golang.org/grpc/internal/metadata google.golang.org/grpc/internal/status google.golang.org/grpc/internal/serviceconfig google.golang.org/grpc/balancer/roundrobin google.golang.org/grpc/internal/proxyattributes google.golang.org/grpc/internal/stats google.golang.org/grpc/internal/syscall google.golang.org/grpc/internal/transport/networktype google.golang.org/grpc/status google.golang.org/grpc/internal/resolver google.golang.org/grpc/keepalive google.golang.org/grpc/peer google.golang.org/grpc/tap google.golang.org/grpc/internal/resolver/passthrough google.golang.org/grpc/internal/resolver/unix google.golang.org/grpc/balancer/grpclb/state google.golang.org/grpc/internal/resolver/dns/internal sigs.k8s.io/controller-runtime/pkg/metrics google.golang.org/grpc/internal/binarylog google.golang.org/grpc/internal/transport golang.org/x/crypto/chacha20poly1305 github.com/google/s2a-go/internal/proto/v2/common_go_proto google.golang.org/grpc/internal/resolver/dns github.com/google/s2a-go/internal/record/internal/aeadcrypter cloud.google.com/go/auth/credentials github.com/google/s2a-go/internal/record/internal/halfconn sigs.k8s.io/controller-runtime/pkg/internal/metrics sigs.k8s.io/controller-runtime/pkg/internal/controller/metrics sigs.k8s.io/controller-runtime/pkg/certwatcher/metrics sigs.k8s.io/controller-runtime/pkg/webhook/admission/metrics sigs.k8s.io/controller-runtime/pkg/webhook/internal/metrics sigs.k8s.io/controller-runtime/pkg/webhook/conversion/metrics google.golang.org/grpc/resolver/dns github.com/google/s2a-go/internal/tokenmanager github.com/google/s2a-go/internal/proto/v2/s2a_context_go_proto sigs.k8s.io/controller-runtime/pkg/certwatcher sigs.k8s.io/controller-runtime/pkg/controller/priorityqueue github.com/google/s2a-go/retry sigs.k8s.io/controller-runtime/pkg/webhook/conversion sigs.k8s.io/controller-runtime/pkg/webhook/admission google.golang.org/api/internal/cert google.golang.org/api/internal/credentialstype sigs.k8s.io/controller-runtime/pkg/handler google.golang.org/api/internal/impersonate github.com/fluxcd/flux2/v2/pkg/bootstrap/provider sigs.k8s.io/controller-runtime/pkg/metrics/server google.golang.org/genproto/googleapis/rpc/code google.golang.org/genproto/googleapis/rpc/errdetails github.com/googleapis/gax-go/v2/callctx github.com/go-logr/logr/funcr github.com/googleapis/gax-go/v2/apierror/internal/proto go.opentelemetry.io/otel/attribute/internal go.opentelemetry.io/auto/sdk/internal/telemetry sigs.k8s.io/controller-runtime/pkg/internal/source go.opentelemetry.io/otel/attribute/internal/xxhash github.com/googleapis/gax-go/v2/apierror sigs.k8s.io/controller-runtime/pkg/webhook go.opentelemetry.io/otel/attribute go.opentelemetry.io/otel/codes github.com/go-logr/stdr go.opentelemetry.io/otel/trace/internal/telemetry sigs.k8s.io/controller-runtime/pkg/source go.opentelemetry.io/otel/internal/errorhandler go.opentelemetry.io/otel/internal/baggage go.opentelemetry.io/otel/baggage sigs.k8s.io/controller-runtime/pkg/manager github.com/felixge/httpsnoop go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request google.golang.org/grpc/internal/resolver/delegatingresolver sigs.k8s.io/controller-runtime/pkg/internal/controller go.opentelemetry.io/otel/semconv/v1.37.0 go.opentelemetry.io/otel/semconv/v1.40.0 go.opentelemetry.io/otel/metric google.golang.org/api/googleapi/transport github.com/fluxcd/pkg/auth/generic google.golang.org/grpc helm.sh/helm/v4/internal/version helm.sh/helm/v4/pkg/strvals github.com/fluxcd/pkg/git/internal/build k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1beta1 go.opentelemetry.io/otel/metric/noop sigs.k8s.io/controller-runtime/pkg/controller github.com/fluxcd/pkg/ssh/knownhosts github.com/go-git/go-billy/v5/memfs go.opentelemetry.io/otel/semconv/v1.40.0/httpconv github.com/fluxcd/pkg/oci/internal/fs github.com/google/go-containerregistry/internal/and github.com/fluxcd/pkg/git/gogit github.com/google/go-containerregistry/internal/gzip github.com/klauspost/compress/fse github.com/klauspost/compress/internal/snapref go.opentelemetry.io/otel/trace github.com/klauspost/compress/zstd/internal/xxhash github.com/klauspost/compress/huff0 github.com/google/go-containerregistry/pkg/v1 github.com/google/go-containerregistry/pkg/logs github.com/opencontainers/image-spec/specs-go github.com/google/go-containerregistry/internal/redact github.com/google/go-containerregistry/internal/retry/wait github.com/opencontainers/image-spec/specs-go/v1 github.com/google/go-containerregistry/internal/retry github.com/google/go-containerregistry/pkg/v1/remote/internal/authchallenge github.com/onsi/gomega/format github.com/klauspost/compress/zstd github.com/google/go-containerregistry/pkg/v1/match go.opentelemetry.io/otel/trace/noop go.opentelemetry.io/otel/propagation github.com/google/go-containerregistry/pkg/legacy github.com/google/go-containerregistry/pkg/v1/stream go.opentelemetry.io/auto/sdk github.com/google/go-containerregistry/internal/verify github.com/google/go-containerregistry/pkg/v1/remote/transport sigs.k8s.io/controller-runtime/pkg/builder github.com/google/go-containerregistry/pkg/v1/static github.com/onsi/gomega/types github.com/onsi/gomega/internal/gutil github.com/onsi/gomega/internal github.com/onsi/gomega/matchers/internal/miter go.opentelemetry.io/otel/internal/global github.com/onsi/gomega/matchers/support/goraph/bipartitegraph github.com/google/s2a-go/internal/proto/s2a_go_proto github.com/google/s2a-go/internal/handshaker/service github.com/google/s2a-go/internal/proto/v2/s2a_go_proto helm.sh/helm/v4/pkg/chart/common golang.org/x/net/html golang.org/x/text/encoding/charmap github.com/fluxcd/pkg/chartutil github.com/google/s2a-go/internal/authinfo github.com/google/s2a-go/internal/record go.opentelemetry.io/otel github.com/google/s2a-go/stream github.com/google/s2a-go/internal/v2/certverifier github.com/google/s2a-go/internal/v2/remotesigner github.com/googleapis/gax-go/v2 github.com/google/s2a-go/internal/handshaker go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv github.com/google/s2a-go/internal/v2/tlsconfigstore golang.org/x/text/encoding/japanese github.com/google/s2a-go/internal/v2 golang.org/x/text/encoding/korean golang.org/x/text/encoding/simplifiedchinese golang.org/x/text/encoding/traditionalchinese github.com/google/go-containerregistry/internal/zstd go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp github.com/google/go-containerregistry/internal/compression github.com/google/s2a-go sigs.k8s.io/controller-runtime github.com/google/go-containerregistry/pkg/v1/partial golang.org/x/text/internal/tag golang.org/x/text/internal/language github.com/google/go-containerregistry/pkg/v1/tarball github.com/google/go-containerregistry/pkg/v1/empty google.golang.org/api/internal cloud.google.com/go/auth/internal/transport net/http/internal/testcert net/http/httptest github.com/pkg/errors github.com/fluxcd/pkg/runtime/object github.com/chzyer/readline cloud.google.com/go/auth/httptransport github.com/manifoldco/promptui/list github.com/google/go-containerregistry/internal/windows github.com/google/go-containerregistry/pkg/legacy/tarball golang.org/x/text/internal/language/compact github.com/google/go-containerregistry/pkg/v1/mutate github.com/manifoldco/promptui/screenbuf google.golang.org/api/internal/gensupport google.golang.org/api/option github.com/notaryproject/notation-go/dir golang.org/x/text/language github.com/notaryproject/notation-go/internal/file golang.org/x/crypto/md4 github.com/go-asn1-ber/asn1-ber github.com/google/go-containerregistry/pkg/v1/layout google.golang.org/api/option/internaloption google.golang.org/api/transport/http github.com/google/go-containerregistry/pkg/v1/remote golang.org/x/text/encoding/htmlindex github.com/Azure/go-ntlmssp github.com/notaryproject/notation-core-go/internal/algorithm github.com/notaryproject/notation-core-go/internal/oid github.com/cpuguy83/go-md2man/v2/md2man github.com/notaryproject/notation-core-go/x509 golang.org/x/net/html/charset github.com/fluxcd/pkg/runtime/client google.golang.org/api/container/v1 github.com/spf13/cobra/doc github.com/notaryproject/notation-go/verifier/truststore github.com/manifoldco/promptui github.com/onsi/gomega/matchers github.com/go-ldap/ldap/v3 github.com/fluxcd/flux2/v2/pkg/status github.com/fluxcd/flux2/v2/internal/utils golang.org/x/text/internal golang.org/x/text/cases k8s.io/client-go/plugin/pkg/client/auth/azure k8s.io/client-go/plugin/pkg/client/auth/gcp k8s.io/client-go/plugin/pkg/client/auth/oidc k8s.io/client-go/tools/watch k8s.io/client-go/plugin/pkg/client/auth k8s.io/client-go/util/retry k8s.io/kubectl/pkg/util k8s.io/kubectl/pkg/util/podutils github.com/google/go-containerregistry/pkg/crane github.com/fluxcd/flux2/v2/internal/build github.com/fluxcd/flux2/v2/internal/flags github.com/fluxcd/flux2/v2/pkg/bootstrap sigs.k8s.io/yaml/goyaml.v2 github.com/onsi/gomega github.com/notaryproject/notation-go/internal/pkix github.com/notaryproject/notation-go/verifier/trustpolicy github.com/fluxcd/pkg/runtime/conditions github.com/fluxcd/pkg/oci github.com/fluxcd/pkg/runtime/patch github.com/fluxcd/pkg/auth/gcp github.com/fluxcd/pkg/auth/utils github.com/fluxcd/flux2/v2/cmd/flux ==> Starting check()... === RUN TestBootstrapValidate_signingFlags === RUN TestBootstrapValidate_signingFlags/no_signing_flags_is_valid === RUN TestBootstrapValidate_signingFlags/GPG_only_is_valid === RUN TestBootstrapValidate_signingFlags/SSH_only_is_valid === RUN TestBootstrapValidate_signingFlags/Reuse-private-key_with_private-key-file_is_valid === RUN TestBootstrapValidate_signingFlags/GPG_+_SSH_errors === RUN TestBootstrapValidate_signingFlags/GPG_+_reuse_errors === RUN TestBootstrapValidate_signingFlags/SSH_key-file_+_reuse_errors === RUN TestBootstrapValidate_signingFlags/Reuse_without_private-key-file_errors === RUN TestBootstrapValidate_signingFlags/SSH_password_without_key_errors === RUN TestBootstrapValidate_signingFlags/SSH_passphrase_alias_alone_applies === RUN TestBootstrapValidate_signingFlags/SSH_password_and_passphrase_with_same_value_passes === RUN TestBootstrapValidate_signingFlags/SSH_password_and_passphrase_with_different_values_errors === RUN TestBootstrapValidate_signingFlags/SSH_malformed_key_fails_pre-flight === RUN TestBootstrapValidate_signingFlags/SSH_encrypted_key_without_password_fails_pre-flight === RUN TestBootstrapValidate_signingFlags/GPG_with_wrong_passphrase_fails_pre-flight --- PASS: TestBootstrapValidate_signingFlags (0.56s) --- PASS: TestBootstrapValidate_signingFlags/no_signing_flags_is_valid (0.00s) --- PASS: TestBootstrapValidate_signingFlags/GPG_only_is_valid (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_only_is_valid (0.00s) --- PASS: TestBootstrapValidate_signingFlags/Reuse-private-key_with_private-key-file_is_valid (0.00s) --- PASS: TestBootstrapValidate_signingFlags/GPG_+_SSH_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/GPG_+_reuse_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_key-file_+_reuse_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/Reuse_without_private-key-file_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_password_without_key_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_passphrase_alias_alone_applies (0.21s) --- PASS: TestBootstrapValidate_signingFlags/SSH_password_and_passphrase_with_same_value_passes (0.25s) --- PASS: TestBootstrapValidate_signingFlags/SSH_password_and_passphrase_with_different_values_errors (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_malformed_key_fails_pre-flight (0.00s) --- PASS: TestBootstrapValidate_signingFlags/SSH_encrypted_key_without_password_fails_pre-flight (0.00s) --- PASS: TestBootstrapValidate_signingFlags/GPG_with_wrong_passphrase_fails_pre-flight (0.11s) === RUN TestBootstrapProviderRejectsReuseBeforeValidate === RUN TestBootstrapProviderRejectsReuseBeforeValidate/github_rejects_reuse_with_provider-specific_error === RUN TestBootstrapProviderRejectsReuseBeforeValidate/gitea_rejects_reuse_with_provider-specific_error --- PASS: TestBootstrapProviderRejectsReuseBeforeValidate (0.00s) --- PASS: TestBootstrapProviderRejectsReuseBeforeValidate/github_rejects_reuse_with_provider-specific_error (0.00s) --- PASS: TestBootstrapProviderRejectsReuseBeforeValidate/gitea_rejects_reuse_with_provider-specific_error (0.00s) === RUN Test_saveReaderToFile === RUN Test_saveReaderToFile/yaml === RUN Test_saveReaderToFile/yaml_with_carriage_return --- PASS: Test_saveReaderToFile (0.00s) --- PASS: Test_saveReaderToFile/yaml (0.00s) --- PASS: Test_saveReaderToFile/yaml_with_carriage_return (0.00s) === RUN Test_resolveSymlinks --- PASS: Test_resolveSymlinks (0.00s) === RUN Test_resolveSymlinks_singleFile --- PASS: Test_resolveSymlinks_singleFile (0.00s) === RUN Test_resolveSymlinks_cycle --- PASS: Test_resolveSymlinks_cycle (0.00s) === RUN Test_resolveSymlinks_multipleLinksSameTarget --- PASS: Test_resolveSymlinks_multipleLinksSameTarget (0.00s) === RUN Test_getFluxClusterInfo === RUN Test_getFluxClusterInfo/no_git_repository_CRD_present === RUN Test_getFluxClusterInfo/CRD_with_kustomize-controller_labels === RUN Test_getFluxClusterInfo/CRD_with_kustomize-controller_labels_and_managed-by_label === RUN Test_getFluxClusterInfo/CRD_with_only_managed-by_label === RUN Test_getFluxClusterInfo/CRD_with_no_labels === RUN Test_getFluxClusterInfo/CRD_with_only_version_label === RUN Test_getFluxClusterInfo/CRD_with_version_and_part-of_labels --- PASS: Test_getFluxClusterInfo (0.21s) --- PASS: Test_getFluxClusterInfo/no_git_repository_CRD_present (0.16s) --- PASS: Test_getFluxClusterInfo/CRD_with_kustomize-controller_labels (0.01s) --- PASS: Test_getFluxClusterInfo/CRD_with_kustomize-controller_labels_and_managed-by_label (0.00s) --- PASS: Test_getFluxClusterInfo/CRD_with_only_managed-by_label (0.01s) --- PASS: Test_getFluxClusterInfo/CRD_with_no_labels (0.01s) --- PASS: Test_getFluxClusterInfo/CRD_with_only_version_label (0.01s) --- PASS: Test_getFluxClusterInfo/CRD_with_version_and_part-of_labels (0.01s) === RUN TestCreateImageUpdate === RUN TestCreateImageUpdate/no_signing_key === RUN TestCreateImageUpdate/signing_secret_without_explicit_type_defaults_to_gpg === RUN TestCreateImageUpdate/ssh_signing_key === RUN TestCreateImageUpdate/signing-key-type_without_secret_errors === RUN TestCreateImageUpdate/invalid_signing-key-type_errors --- PASS: TestCreateImageUpdate (0.01s) --- PASS: TestCreateImageUpdate/no_signing_key (0.00s) --- PASS: TestCreateImageUpdate/signing_secret_without_explicit_type_defaults_to_gpg (0.00s) --- PASS: TestCreateImageUpdate/ssh_signing_key (0.00s) --- PASS: TestCreateImageUpdate/signing-key-type_without_secret_errors (0.00s) --- PASS: TestCreateImageUpdate/invalid_signing-key-type_errors (0.00s) === RUN TestCreateGitSecret === RUN TestCreateGitSecret/no_args === RUN TestCreateGitSecret/basic_secret === RUN TestCreateGitSecret/ssh_key === RUN TestCreateGitSecret/ssh_key_with_password === RUN TestCreateGitSecret/git_authentication_with_bearer_token === RUN TestCreateGitSecret/git_authentication_with_CA_certificate === RUN TestCreateGitSecret/git_authentication_with_basic_auth_and_bearer_token --- PASS: TestCreateGitSecret (1.13s) --- PASS: TestCreateGitSecret/no_args (0.00s) --- PASS: TestCreateGitSecret/basic_secret (0.00s) --- PASS: TestCreateGitSecret/ssh_key (0.49s) --- PASS: TestCreateGitSecret/ssh_key_with_password (0.64s) --- PASS: TestCreateGitSecret/git_authentication_with_bearer_token (0.00s) --- PASS: TestCreateGitSecret/git_authentication_with_CA_certificate (0.00s) --- PASS: TestCreateGitSecret/git_authentication_with_basic_auth_and_bearer_token (0.00s) === RUN TestCreateSecretGitHubApp === RUN TestCreateSecretGitHubApp/create_githubapp_secret_with_missing_name === RUN TestCreateSecretGitHubApp/create_githubapp_secret_with_private_key_file_that_does_not_exist === RUN TestCreateSecretGitHubApp/create_githubapp_secret_with_app_info === RUN TestCreateSecretGitHubApp/create_githubapp_secret_with_appinfo_and_base_url --- PASS: TestCreateSecretGitHubApp (0.00s) --- PASS: TestCreateSecretGitHubApp/create_githubapp_secret_with_missing_name (0.00s) --- PASS: TestCreateSecretGitHubApp/create_githubapp_secret_with_private_key_file_that_does_not_exist (0.00s) --- PASS: TestCreateSecretGitHubApp/create_githubapp_secret_with_app_info (0.00s) --- PASS: TestCreateSecretGitHubApp/create_githubapp_secret_with_appinfo_and_base_url (0.00s) === RUN TestCreateHelmSecret === RUN TestCreateHelmSecret/#00 === RUN TestCreateHelmSecret/#01 --- PASS: TestCreateHelmSecret (0.00s) --- PASS: TestCreateHelmSecret/#00 (0.00s) --- PASS: TestCreateHelmSecret/#01 (0.00s) === RUN TestCreateNotationSecret === RUN TestCreateNotationSecret/no_args === RUN TestCreateNotationSecret/no_trust_policy === RUN TestCreateNotationSecret/no_cert === RUN TestCreateNotationSecret/non_pem_and_crt_cert === RUN TestCreateNotationSecret/invalid_trust_policy === RUN TestCreateNotationSecret/invalid_trust_policy_json === RUN TestCreateNotationSecret/crt_secret === RUN TestCreateNotationSecret/pem_secret === RUN TestCreateNotationSecret/multi_secret --- PASS: TestCreateNotationSecret (0.01s) --- PASS: TestCreateNotationSecret/no_args (0.00s) --- PASS: TestCreateNotationSecret/no_trust_policy (0.00s) --- PASS: TestCreateNotationSecret/no_cert (0.00s) --- PASS: TestCreateNotationSecret/non_pem_and_crt_cert (0.00s) --- PASS: TestCreateNotationSecret/invalid_trust_policy (0.00s) --- PASS: TestCreateNotationSecret/invalid_trust_policy_json (0.00s) --- PASS: TestCreateNotationSecret/crt_secret (0.00s) --- PASS: TestCreateNotationSecret/pem_secret (0.00s) --- PASS: TestCreateNotationSecret/multi_secret (0.00s) === RUN TestCreateSecretOCI === RUN TestCreateSecretOCI/#00 === RUN TestCreateSecretOCI/#01 === RUN TestCreateSecretOCI/#02 --- PASS: TestCreateSecretOCI (0.01s) --- PASS: TestCreateSecretOCI/#00 (0.00s) --- PASS: TestCreateSecretOCI/#01 (0.00s) --- PASS: TestCreateSecretOCI/#02 (0.00s) === RUN TestCreateProxySecret === RUN TestCreateProxySecret/#00 === RUN TestCreateProxySecret/#01 --- PASS: TestCreateProxySecret (0.00s) --- PASS: TestCreateProxySecret/#00 (0.00s) --- PASS: TestCreateProxySecret/#01 (0.00s) === RUN TestCreateReceiverSecret === RUN TestCreateReceiverSecret/missing_type === RUN TestCreateReceiverSecret/invalid_type === RUN TestCreateReceiverSecret/missing_hostname === RUN TestCreateReceiverSecret/gcr_missing_email-claim === RUN TestCreateReceiverSecret/github_receiver_secret === RUN TestCreateReceiverSecret/gcr_receiver_secret === RUN TestCreateReceiverSecret/gcr_receiver_secret_with_custom_audience --- PASS: TestCreateReceiverSecret (0.00s) --- PASS: TestCreateReceiverSecret/missing_type (0.00s) --- PASS: TestCreateReceiverSecret/invalid_type (0.00s) --- PASS: TestCreateReceiverSecret/missing_hostname (0.00s) --- PASS: TestCreateReceiverSecret/gcr_missing_email-claim (0.00s) --- PASS: TestCreateReceiverSecret/github_receiver_secret (0.00s) --- PASS: TestCreateReceiverSecret/gcr_receiver_secret (0.00s) --- PASS: TestCreateReceiverSecret/gcr_receiver_secret_with_custom_audience (0.00s) === RUN TestCreateTlsSecret === RUN TestCreateTlsSecret/#00 === RUN TestCreateTlsSecret/#01 --- PASS: TestCreateTlsSecret (0.00s) --- PASS: TestCreateTlsSecret/#00 (0.00s) --- PASS: TestCreateTlsSecret/#01 (0.00s) === RUN TestCreateSourceOCI === RUN TestCreateSourceOCI/NoArgs === RUN TestCreateSourceOCI/NoURL === RUN TestCreateSourceOCI/verify_secret_specified_but_provider_missing === RUN TestCreateSourceOCI/verify_issuer_specified_but_provider_missing === RUN TestCreateSourceOCI/verify_identity_specified_but_provider_missing === RUN TestCreateSourceOCI/verify_issuer_specified_but_subject_missing === RUN TestCreateSourceOCI/all_verify_fields_set === RUN TestCreateSourceOCI/verify_subject_specified_but_issuer_missing === RUN TestCreateSourceOCI/export_manifest === RUN TestCreateSourceOCI/export_manifest_with_secret === RUN TestCreateSourceOCI/export_manifest_with_verify_secret === RUN TestCreateSourceOCI/export_manifest_with_layer_selector === RUN TestCreateSourceOCI/invalid_layer_selector_operation === RUN TestCreateSourceOCI/invalid_layer_selector_format --- PASS: TestCreateSourceOCI (0.01s) --- PASS: TestCreateSourceOCI/NoArgs (0.00s) --- PASS: TestCreateSourceOCI/NoURL (0.00s) --- PASS: TestCreateSourceOCI/verify_secret_specified_but_provider_missing (0.00s) --- PASS: TestCreateSourceOCI/verify_issuer_specified_but_provider_missing (0.00s) --- PASS: TestCreateSourceOCI/verify_identity_specified_but_provider_missing (0.00s) --- PASS: TestCreateSourceOCI/verify_issuer_specified_but_subject_missing (0.00s) --- PASS: TestCreateSourceOCI/all_verify_fields_set (0.00s) --- PASS: TestCreateSourceOCI/verify_subject_specified_but_issuer_missing (0.00s) --- PASS: TestCreateSourceOCI/export_manifest (0.00s) --- PASS: TestCreateSourceOCI/export_manifest_with_secret (0.00s) --- PASS: TestCreateSourceOCI/export_manifest_with_verify_secret (0.00s) --- PASS: TestCreateSourceOCI/export_manifest_with_layer_selector (0.00s) --- PASS: TestCreateSourceOCI/invalid_layer_selector_operation (0.00s) --- PASS: TestCreateSourceOCI/invalid_layer_selector_format (0.00s) === RUN Test_validateObjectName --- PASS: Test_validateObjectName (0.00s) === RUN TestEnvsubst --- PASS: TestEnvsubst (0.00s) === RUN TestEnvsubst_Strinct --- PASS: TestEnvsubst_Strinct (0.00s) === RUN Test_getObjectRef === RUN Test_getObjectRef/Source_Ref_for_Kustomization === RUN Test_getObjectRef/Crossnamespace_Source_Ref_for_Kustomization === RUN Test_getObjectRef/Source_Ref_for_HelmRelease === RUN Test_getObjectRef/Source_Ref_for_Alert === RUN Test_getObjectRef/Source_Ref_for_ImagePolicy === RUN Test_getObjectRef/Source_Ref_for_ImagePolicy_(lowercased) === RUN Test_getObjectRef/Empty_Ref_for_Provider === RUN Test_getObjectRef/Non_flux_resource --- PASS: Test_getObjectRef (0.01s) --- PASS: Test_getObjectRef/Source_Ref_for_Kustomization (0.00s) --- PASS: Test_getObjectRef/Crossnamespace_Source_Ref_for_Kustomization (0.00s) --- PASS: Test_getObjectRef/Source_Ref_for_HelmRelease (0.00s) --- PASS: Test_getObjectRef/Source_Ref_for_Alert (0.00s) --- PASS: Test_getObjectRef/Source_Ref_for_ImagePolicy (0.00s) --- PASS: Test_getObjectRef/Source_Ref_for_ImagePolicy_(lowercased) (0.00s) --- PASS: Test_getObjectRef/Empty_Ref_for_Provider (0.00s) --- PASS: Test_getObjectRef/Non_flux_resource (0.00s) === RUN Test_getRows === RUN Test_getRows/events_from_all_namespaces === RUN Test_getRows/events_from_default_namespaces === RUN Test_getRows/Kustomization_with_crossnamespaced_GitRepository === RUN Test_getRows/All_Kustomization_(lowercased_selector) === RUN Test_getRows/HelmRelease_with_crossnamespaced_HelmRepository === RUN Test_getRows/HelmRelease_with_crossnamespaced_HelmRepository_(lowercased) --- PASS: Test_getRows (0.01s) --- PASS: Test_getRows/events_from_all_namespaces (0.00s) --- PASS: Test_getRows/events_from_default_namespaces (0.00s) --- PASS: Test_getRows/Kustomization_with_crossnamespaced_GitRepository (0.00s) --- PASS: Test_getRows/All_Kustomization_(lowercased_selector) (0.00s) --- PASS: Test_getRows/HelmRelease_with_crossnamespaced_HelmRepository (0.00s) --- PASS: Test_getRows/HelmRelease_with_crossnamespaced_HelmRepository_(lowercased) (0.00s) === RUN Test_addEventsToList_pagination --- PASS: Test_addEventsToList_pagination (0.01s) === RUN TestInstall === RUN TestInstall/invalid_namespace === RUN TestInstall/invalid_sub-command === RUN TestInstall/missing_image_pull_secret --- PASS: TestInstall (0.00s) --- PASS: TestInstall/invalid_namespace (0.00s) --- PASS: TestInstall/invalid_sub-command (0.00s) --- PASS: TestInstall/missing_image_pull_secret (0.00s) === RUN TestInstall_ComponentsExtra --- PASS: TestInstall_ComponentsExtra (0.36s) === RUN TestGetKubeconfigContextNamespace === RUN TestGetKubeconfigContextNamespace/returns_namespace_from_current_context === RUN TestGetKubeconfigContextNamespace/returns_empty_when_context_has_no_namespace === RUN TestGetKubeconfigContextNamespace/returns_namespace_from_context_specified_via_--context_flag === RUN TestGetKubeconfigContextNamespace/returns_empty_when_context_does_not_exist --- PASS: TestGetKubeconfigContextNamespace (0.00s) --- PASS: TestGetKubeconfigContextNamespace/returns_namespace_from_current_context (0.00s) --- PASS: TestGetKubeconfigContextNamespace/returns_empty_when_context_has_no_namespace (0.00s) --- PASS: TestGetKubeconfigContextNamespace/returns_namespace_from_context_specified_via_--context_flag (0.00s) --- PASS: TestGetKubeconfigContextNamespace/returns_empty_when_context_does_not_exist (0.00s) === RUN TestContextNamespaceOptIn === RUN TestContextNamespaceOptIn/ignores_context_namespace_when_not_opted_in === RUN TestContextNamespaceOptIn/uses_context_namespace_when_opted_in_via_flag === RUN TestContextNamespaceOptIn/uses_context_namespace_when_opted_in_via_env_var === RUN TestContextNamespaceOptIn/context_namespace_takes_precedence_over_FLUX_SYSTEM_NAMESPACE_when_opted_in === RUN TestContextNamespaceOptIn/FLUX_SYSTEM_NAMESPACE_used_when_not_opted_in === RUN TestContextNamespaceOptIn/--namespace_flag_takes_precedence_over_context_namespace --- PASS: TestContextNamespaceOptIn (0.00s) --- PASS: TestContextNamespaceOptIn/ignores_context_namespace_when_not_opted_in (0.00s) --- PASS: TestContextNamespaceOptIn/uses_context_namespace_when_opted_in_via_flag (0.00s) --- PASS: TestContextNamespaceOptIn/uses_context_namespace_when_opted_in_via_env_var (0.00s) --- PASS: TestContextNamespaceOptIn/context_namespace_takes_precedence_over_FLUX_SYSTEM_NAMESPACE_when_opted_in (0.00s) --- PASS: TestContextNamespaceOptIn/FLUX_SYSTEM_NAMESPACE_used_when_not_opted_in (0.00s) --- PASS: TestContextNamespaceOptIn/--namespace_flag_takes_precedence_over_context_namespace (0.00s) === RUN TestFileSystemMigrator === RUN TestFileSystemMigrator/errors_out_for_single_file_that_is_a_symlink === RUN TestFileSystemMigrator/errors_out_for_single_file_with_wrong_extension === RUN TestFileSystemMigrator/migrate_single_file === RUN TestFileSystemMigrator/migrate_files_in_directory --- PASS: TestFileSystemMigrator (0.01s) --- PASS: TestFileSystemMigrator/errors_out_for_single_file_that_is_a_symlink (0.00s) --- PASS: TestFileSystemMigrator/errors_out_for_single_file_with_wrong_extension (0.00s) --- PASS: TestFileSystemMigrator/migrate_single_file (0.00s) --- PASS: TestFileSystemMigrator/migrate_files_in_directory (0.00s) === RUN TestPluginAppearsInHelp --- PASS: TestPluginAppearsInHelp (0.00s) === RUN TestPluginListOutput --- PASS: TestPluginListOutput (0.00s) === RUN TestPluginListWithReceipt --- PASS: TestPluginListWithReceipt (0.00s) === RUN TestPluginListEmpty --- PASS: TestPluginListEmpty (0.00s) === RUN TestNoPluginsNoRegistration --- PASS: TestNoPluginsNoRegistration (0.00s) === RUN TestPluginSkipsPersistentPreRun --- PASS: TestPluginSkipsPersistentPreRun (0.00s) === RUN TestParseNameVersion === RUN TestParseNameVersion/operator === RUN TestParseNameVersion/operator@0.45.0 === RUN TestParseNameVersion/my-tool@1.0.0 === RUN TestParseNameVersion/plugin@ === RUN TestParseNameVersion/operator@sha256:abc123 --- PASS: TestParseNameVersion (0.00s) --- PASS: TestParseNameVersion/operator (0.00s) --- PASS: TestParseNameVersion/operator@0.45.0 (0.00s) --- PASS: TestParseNameVersion/my-tool@1.0.0 (0.00s) --- PASS: TestParseNameVersion/plugin@ (0.00s) --- PASS: TestParseNameVersion/operator@sha256:abc123 (0.00s) === RUN TestIsDigestRef === RUN TestIsDigestRef/sha256:06e0a38db4fa6bc9f705a577c7e58dc020bfe2618e45488599e5ef7bb62e3a8a === RUN TestIsDigestRef/0.45.0 === RUN TestIsDigestRef/#00 === RUN TestIsDigestRef/sha256 === RUN TestIsDigestRef/SHA256:abc --- PASS: TestIsDigestRef (0.00s) --- PASS: TestIsDigestRef/sha256:06e0a38db4fa6bc9f705a577c7e58dc020bfe2618e45488599e5ef7bb62e3a8a (0.00s) --- PASS: TestIsDigestRef/0.45.0 (0.00s) --- PASS: TestIsDigestRef/#00 (0.00s) --- PASS: TestIsDigestRef/sha256 (0.00s) --- PASS: TestIsDigestRef/SHA256:abc (0.00s) === RUN TestPluginDiscoverSkipsBuiltins --- PASS: TestPluginDiscoverSkipsBuiltins (0.00s) === RUN Test_isObjectReady === RUN Test_isObjectReady/dynamic_ready === RUN Test_isObjectReady/dynamic_not_ready === RUN Test_isObjectReady/dynamic_not_reconciled === RUN Test_isObjectReady/dynamic_not_condition === RUN Test_isObjectReady/dynamic_ready_outdated === RUN Test_isObjectReady/dynamic_ready_without_per_condition_gen === RUN Test_isObjectReady/dynamic_outdated_ready_status_without_per_condition_gen === RUN Test_isObjectReady/static_empty_status === RUN Test_isObjectReady/static_no_status --- PASS: Test_isObjectReady (0.00s) --- PASS: Test_isObjectReady/dynamic_ready (0.00s) --- PASS: Test_isObjectReady/dynamic_not_ready (0.00s) --- PASS: Test_isObjectReady/dynamic_not_reconciled (0.00s) --- PASS: Test_isObjectReady/dynamic_not_condition (0.00s) --- PASS: Test_isObjectReady/dynamic_ready_outdated (0.00s) --- PASS: Test_isObjectReady/dynamic_ready_without_per_condition_gen (0.00s) --- PASS: Test_isObjectReady/dynamic_outdated_ready_status_without_per_condition_gen (0.00s) --- PASS: Test_isObjectReady/static_empty_status (0.00s) --- PASS: Test_isObjectReady/static_no_status (0.00s) === RUN TestSplitImageStr --- PASS: TestSplitImageStr (0.00s) PASS ok github.com/fluxcd/flux2/v2/cmd/flux 2.486s === RUN TestTrimSopsData === RUN TestTrimSopsData/secret_with_sops_token === RUN TestTrimSopsData/secret_with_basic_auth === RUN TestTrimSopsData/secret_sops_secret --- PASS: TestTrimSopsData (0.00s) --- PASS: TestTrimSopsData/secret_with_sops_token (0.00s) --- PASS: TestTrimSopsData/secret_with_basic_auth (0.00s) --- PASS: TestTrimSopsData/secret_sops_secret (0.00s) === RUN Test_unMarshallKustomization === RUN Test_unMarshallKustomization/valid_kustomization === RUN Test_unMarshallKustomization/Multi-doc_yaml_containing_kustomization_and_other_resources === RUN Test_unMarshallKustomization/no_namespace === RUN Test_unMarshallKustomization/kustomization_with_a_different_name === RUN Test_unMarshallKustomization/yaml_containing_other_resource_with_same_name_as_kustomization === RUN Test_unMarshallKustomization/correct_parsing_of_multiple_documents --- PASS: Test_unMarshallKustomization (0.00s) --- PASS: Test_unMarshallKustomization/valid_kustomization (0.00s) --- PASS: Test_unMarshallKustomization/Multi-doc_yaml_containing_kustomization_and_other_resources (0.00s) --- PASS: Test_unMarshallKustomization/no_namespace (0.00s) --- PASS: Test_unMarshallKustomization/kustomization_with_a_different_name (0.00s) --- PASS: Test_unMarshallKustomization/yaml_containing_other_resource_with_same_name_as_kustomization (0.00s) --- PASS: Test_unMarshallKustomization/correct_parsing_of_multiple_documents (0.00s) === RUN Test_ResolveKustomization === RUN Test_ResolveKustomization/valid_kustomization === RUN Test_ResolveKustomization/local_and_live_kustomization === RUN Test_ResolveKustomization/local_and_live_kustomization_with_dryrun === RUN Test_ResolveKustomization/live_kustomization --- PASS: Test_ResolveKustomization (0.00s) --- PASS: Test_ResolveKustomization/valid_kustomization (0.00s) --- PASS: Test_ResolveKustomization/local_and_live_kustomization (0.00s) --- PASS: Test_ResolveKustomization/local_and_live_kustomization_with_dryrun (0.00s) --- PASS: Test_ResolveKustomization/live_kustomization (0.00s) === RUN Test_isKustomization === RUN Test_isKustomization/flux_kustomization === RUN Test_isKustomization/other_kustomization === RUN Test_isKustomization/wrong_kind === RUN Test_isKustomization/wrong_object --- PASS: Test_isKustomization (0.00s) --- PASS: Test_isKustomization/flux_kustomization (0.00s) --- PASS: Test_isKustomization/other_kustomization (0.00s) --- PASS: Test_isKustomization/wrong_kind (0.00s) --- PASS: Test_isKustomization/wrong_object (0.00s) === RUN Test_kustomizationsEqual === RUN Test_kustomizationsEqual/equal === RUN Test_kustomizationsEqual/wrong_name === RUN Test_kustomizationsEqual/wrong_namespace === RUN Test_kustomizationsEqual/wrong_name_and_namespace --- PASS: Test_kustomizationsEqual (0.00s) --- PASS: Test_kustomizationsEqual/equal (0.00s) --- PASS: Test_kustomizationsEqual/wrong_name (0.00s) --- PASS: Test_kustomizationsEqual/wrong_namespace (0.00s) --- PASS: Test_kustomizationsEqual/wrong_name_and_namespace (0.00s) === RUN Test_kustomizationPath === RUN Test_kustomizationPath/full_repo === RUN Test_kustomizationPath/repo_without_namespace === RUN Test_kustomizationPath/repo_not_found --- PASS: Test_kustomizationPath (0.00s) --- PASS: Test_kustomizationPath/full_repo (0.00s) --- PASS: Test_kustomizationPath/repo_without_namespace (0.00s) --- PASS: Test_kustomizationPath/repo_not_found (0.00s) === RUN Test_inMemoryFsBackend_Generate --- PASS: Test_inMemoryFsBackend_Generate (0.00s) === RUN Test_inMemoryFsBackend_Generate_parentRef --- PASS: Test_inMemoryFsBackend_Generate_parentRef (0.09s) === RUN Test_inMemoryFsBackend_Generate_outsideCwd --- PASS: Test_inMemoryFsBackend_Generate_outsideCwd (0.08s) === RUN Test_Build_preserveAllLabels --- PASS: Test_Build_preserveAllLabels (0.09s) === RUN Test_Build_substituteStrategy === RUN Test_Build_substituteStrategy/WithVariables_skips_substitution_without_variables === RUN Test_Build_substituteStrategy/Always_substitutes_defaults_without_variables --- PASS: Test_Build_substituteStrategy (0.18s) --- PASS: Test_Build_substituteStrategy/WithVariables_skips_substitution_without_variables (0.08s) --- PASS: Test_Build_substituteStrategy/Always_substitutes_defaults_without_variables (0.10s) PASS ok github.com/fluxcd/flux2/v2/internal/build 0.535s === RUN TestCRDsPolicy_Set === RUN TestCRDsPolicy_Set/supported === RUN TestCRDsPolicy_Set/unsupported === RUN TestCRDsPolicy_Set/empty --- PASS: TestCRDsPolicy_Set (0.00s) --- PASS: TestCRDsPolicy_Set/supported (0.00s) --- PASS: TestCRDsPolicy_Set/unsupported (0.00s) --- PASS: TestCRDsPolicy_Set/empty (0.00s) === RUN TestDecryptionProvider_Set === RUN TestDecryptionProvider_Set/supported === RUN TestDecryptionProvider_Set/unsupported === RUN TestDecryptionProvider_Set/empty --- PASS: TestDecryptionProvider_Set (0.00s) --- PASS: TestDecryptionProvider_Set/supported (0.00s) --- PASS: TestDecryptionProvider_Set/unsupported (0.00s) --- PASS: TestDecryptionProvider_Set/empty (0.00s) === RUN TestECDSACurve_Set === RUN TestECDSACurve_Set/supported === RUN TestECDSACurve_Set/unsupported === RUN TestECDSACurve_Set/empty --- PASS: TestECDSACurve_Set (0.00s) --- PASS: TestECDSACurve_Set/supported (0.00s) --- PASS: TestECDSACurve_Set/unsupported (0.00s) --- PASS: TestECDSACurve_Set/empty (0.00s) === RUN TestGitLabVisibility_Set === RUN TestGitLabVisibility_Set/private === RUN TestGitLabVisibility_Set/internal === RUN TestGitLabVisibility_Set/public === RUN TestGitLabVisibility_Set/unsupported === RUN TestGitLabVisibility_Set/default --- PASS: TestGitLabVisibility_Set (0.00s) --- PASS: TestGitLabVisibility_Set/private (0.00s) --- PASS: TestGitLabVisibility_Set/internal (0.00s) --- PASS: TestGitLabVisibility_Set/public (0.00s) --- PASS: TestGitLabVisibility_Set/unsupported (0.00s) --- PASS: TestGitLabVisibility_Set/default (0.00s) === RUN TestHelmChartSource_Set === RUN TestHelmChartSource_Set/supported === RUN TestHelmChartSource_Set/lower_case_kind === RUN TestHelmChartSource_Set/unsupported === RUN TestHelmChartSource_Set/invalid_format === RUN TestHelmChartSource_Set/missing_name === RUN TestHelmChartSource_Set/empty --- PASS: TestHelmChartSource_Set (0.00s) --- PASS: TestHelmChartSource_Set/supported (0.00s) --- PASS: TestHelmChartSource_Set/lower_case_kind (0.00s) --- PASS: TestHelmChartSource_Set/unsupported (0.00s) --- PASS: TestHelmChartSource_Set/invalid_format (0.00s) --- PASS: TestHelmChartSource_Set/missing_name (0.00s) --- PASS: TestHelmChartSource_Set/empty (0.00s) === RUN TestKustomizationSource_Set === RUN TestKustomizationSource_Set/supported === RUN TestKustomizationSource_Set/default_kind === RUN TestKustomizationSource_Set/lower_case_kind === RUN TestKustomizationSource_Set/unsupported === RUN TestKustomizationSource_Set/missing_name === RUN TestKustomizationSource_Set/empty --- PASS: TestKustomizationSource_Set (0.00s) --- PASS: TestKustomizationSource_Set/supported (0.00s) --- PASS: TestKustomizationSource_Set/default_kind (0.00s) --- PASS: TestKustomizationSource_Set/lower_case_kind (0.00s) --- PASS: TestKustomizationSource_Set/unsupported (0.00s) --- PASS: TestKustomizationSource_Set/missing_name (0.00s) --- PASS: TestKustomizationSource_Set/empty (0.00s) === RUN TestLogLevel_Set === RUN TestLogLevel_Set/supported === RUN TestLogLevel_Set/unsupported === RUN TestLogLevel_Set/empty --- PASS: TestLogLevel_Set (0.00s) --- PASS: TestLogLevel_Set/supported (0.00s) --- PASS: TestLogLevel_Set/unsupported (0.00s) --- PASS: TestLogLevel_Set/empty (0.00s) === RUN TestPublicKeyAlgorithm_Set === RUN TestPublicKeyAlgorithm_Set/supported === RUN TestPublicKeyAlgorithm_Set/unsupported === RUN TestPublicKeyAlgorithm_Set/empty --- PASS: TestPublicKeyAlgorithm_Set (0.00s) --- PASS: TestPublicKeyAlgorithm_Set/supported (0.00s) --- PASS: TestPublicKeyAlgorithm_Set/unsupported (0.00s) --- PASS: TestPublicKeyAlgorithm_Set/empty (0.00s) === RUN TestRSAKeyBits_Set === RUN TestRSAKeyBits_Set/supported === RUN TestRSAKeyBits_Set/empty_(default) === RUN TestRSAKeyBits_Set/unsupported === RUN TestRSAKeyBits_Set/unsupported#01 --- PASS: TestRSAKeyBits_Set (0.00s) --- PASS: TestRSAKeyBits_Set/supported (0.00s) --- PASS: TestRSAKeyBits_Set/empty_(default) (0.00s) --- PASS: TestRSAKeyBits_Set/unsupported (0.00s) --- PASS: TestRSAKeyBits_Set/unsupported#01 (0.00s) === RUN TestRelativePath_Set === RUN TestRelativePath_Set/relative_path === RUN TestRelativePath_Set/relative_path#01 === RUN TestRelativePath_Set/traversing_relative_path === RUN TestRelativePath_Set/absolute_path === RUN TestRelativePath_Set/traversing_absolute_path === RUN TestRelativePath_Set/traversing_overflowing_absolute_path === RUN TestRelativePath_Set/empty === RUN TestRelativePath_Set/relative_empty_path === RUN TestRelativePath_Set/double_relative_empty_path === RUN TestRelativePath_Set/dot_path === RUN TestRelativePath_Set/relative_dot_path === RUN TestRelativePath_Set/current_directory === RUN TestRelativePath_Set/parent_directory === RUN TestRelativePath_Set/parent_directory_more_qualified --- PASS: TestRelativePath_Set (0.00s) --- PASS: TestRelativePath_Set/relative_path (0.00s) --- PASS: TestRelativePath_Set/relative_path#01 (0.00s) --- PASS: TestRelativePath_Set/traversing_relative_path (0.00s) --- PASS: TestRelativePath_Set/absolute_path (0.00s) --- PASS: TestRelativePath_Set/traversing_absolute_path (0.00s) --- PASS: TestRelativePath_Set/traversing_overflowing_absolute_path (0.00s) --- PASS: TestRelativePath_Set/empty (0.00s) --- PASS: TestRelativePath_Set/relative_empty_path (0.00s) --- PASS: TestRelativePath_Set/double_relative_empty_path (0.00s) --- PASS: TestRelativePath_Set/dot_path (0.00s) --- PASS: TestRelativePath_Set/relative_dot_path (0.00s) --- PASS: TestRelativePath_Set/current_directory (0.00s) --- PASS: TestRelativePath_Set/parent_directory (0.00s) --- PASS: TestRelativePath_Set/parent_directory_more_qualified (0.00s) === RUN TestSourceBucketProvider_Set === RUN TestSourceBucketProvider_Set/supported === RUN TestSourceBucketProvider_Set/unsupported === RUN TestSourceBucketProvider_Set/empty --- PASS: TestSourceBucketProvider_Set (0.00s) --- PASS: TestSourceBucketProvider_Set/supported (0.00s) --- PASS: TestSourceBucketProvider_Set/unsupported (0.00s) --- PASS: TestSourceBucketProvider_Set/empty (0.00s) === RUN TestSourceOCIVerifyProvider_Set === RUN TestSourceOCIVerifyProvider_Set/supported === RUN TestSourceOCIVerifyProvider_Set/unsupported === RUN TestSourceOCIVerifyProvider_Set/empty --- PASS: TestSourceOCIVerifyProvider_Set (0.00s) --- PASS: TestSourceOCIVerifyProvider_Set/supported (0.00s) --- PASS: TestSourceOCIVerifyProvider_Set/unsupported (0.00s) --- PASS: TestSourceOCIVerifyProvider_Set/empty (0.00s) PASS ok github.com/fluxcd/flux2/v2/internal/flags 0.087s === RUN TestFetchManifest --- PASS: TestFetchManifest (0.00s) === RUN TestFetchManifestNotFound --- PASS: TestFetchManifestNotFound (0.00s) === RUN TestFetchManifestRejectsInvalidBin === RUN TestFetchManifestRejectsInvalidBin/parent_traversal === RUN TestFetchManifestRejectsInvalidBin/nested_traversal === RUN TestFetchManifestRejectsInvalidBin/absolute_path === RUN TestFetchManifestRejectsInvalidBin/subdirectory === RUN TestFetchManifestRejectsInvalidBin/missing_prefix === RUN TestFetchManifestRejectsInvalidBin/empty --- PASS: TestFetchManifestRejectsInvalidBin (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/parent_traversal (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/nested_traversal (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/absolute_path (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/subdirectory (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/missing_prefix (0.00s) --- PASS: TestFetchManifestRejectsInvalidBin/empty (0.00s) === RUN TestFetchCatalog --- PASS: TestFetchCatalog (0.00s) === RUN TestCatalogEnvOverride --- PASS: TestCatalogEnvOverride (0.00s) === RUN TestResolveVersion === RUN TestResolveVersion/latest === RUN TestResolveVersion/specific === RUN TestResolveVersion/not_found === RUN TestResolveVersion/no_versions --- PASS: TestResolveVersion (0.00s) --- PASS: TestResolveVersion/latest (0.00s) --- PASS: TestResolveVersion/specific (0.00s) --- PASS: TestResolveVersion/not_found (0.00s) --- PASS: TestResolveVersion/no_versions (0.00s) === RUN TestResolvePlatform === RUN TestResolvePlatform/found === RUN TestResolvePlatform/not_found --- PASS: TestResolvePlatform (0.00s) --- PASS: TestResolvePlatform/found (0.00s) --- PASS: TestResolvePlatform/not_found (0.00s) === RUN TestResolveByDigest === RUN TestResolveByDigest/found_in_latest_version === RUN TestResolveByDigest/found_in_older_version === RUN TestResolveByDigest/wrong_platform === RUN TestResolveByDigest/not_found === RUN TestResolveByDigest/no_versions --- PASS: TestResolveByDigest (0.00s) --- PASS: TestResolveByDigest/found_in_latest_version (0.00s) --- PASS: TestResolveByDigest/found_in_older_version (0.00s) --- PASS: TestResolveByDigest/wrong_platform (0.00s) --- PASS: TestResolveByDigest/not_found (0.00s) --- PASS: TestResolveByDigest/no_versions (0.00s) === RUN TestParseCompletionOutput === RUN TestParseCompletionOutput/standard_output === RUN TestParseCompletionOutput/default_directive === RUN TestParseCompletionOutput/with_descriptions === RUN TestParseCompletionOutput/empty_completions === RUN TestParseCompletionOutput/empty_input --- PASS: TestParseCompletionOutput (0.00s) --- PASS: TestParseCompletionOutput/standard_output (0.00s) --- PASS: TestParseCompletionOutput/default_directive (0.00s) --- PASS: TestParseCompletionOutput/with_descriptions (0.00s) --- PASS: TestParseCompletionOutput/empty_completions (0.00s) --- PASS: TestParseCompletionOutput/empty_input (0.00s) === RUN TestDiscover --- PASS: TestDiscover (0.00s) === RUN TestDiscoverSkipsBuiltins --- PASS: TestDiscoverSkipsBuiltins (0.00s) === RUN TestDiscoverSkipsReserved --- PASS: TestDiscoverSkipsReserved (0.00s) === RUN TestDiscoverSkipsNonExecutable --- PASS: TestDiscoverSkipsNonExecutable (0.00s) === RUN TestDiscoverSkipsDirectories --- PASS: TestDiscoverSkipsDirectories (0.00s) === RUN TestDiscoverFollowsSymlinks --- PASS: TestDiscoverFollowsSymlinks (0.00s) === RUN TestDiscoverDirNotExist --- PASS: TestDiscoverDirNotExist (0.00s) === RUN TestDiscoverCustomDir --- PASS: TestDiscoverCustomDir (0.00s) === RUN TestDiscoverSkipsNonFluxPrefix --- PASS: TestDiscoverSkipsNonFluxPrefix (0.00s) === RUN TestDiscoverBrokenSymlink --- PASS: TestDiscoverBrokenSymlink (0.00s) === RUN TestPluginNameFromBinary === RUN TestPluginNameFromBinary/flux-operator === RUN TestPluginNameFromBinary/flux-my-tool === RUN TestPluginNameFromBinary/flux- === RUN TestPluginNameFromBinary/notflux-thing === RUN TestPluginNameFromBinary/flux-a --- PASS: TestPluginNameFromBinary (0.00s) --- PASS: TestPluginNameFromBinary/flux-operator (0.00s) --- PASS: TestPluginNameFromBinary/flux-my-tool (0.00s) --- PASS: TestPluginNameFromBinary/flux- (0.00s) --- PASS: TestPluginNameFromBinary/notflux-thing (0.00s) --- PASS: TestPluginNameFromBinary/flux-a (0.00s) === RUN TestPluginDir === RUN TestPluginDir/uses_env_var === RUN TestPluginDir/uses_default --- PASS: TestPluginDir (0.00s) --- PASS: TestPluginDir/uses_env_var (0.00s) --- PASS: TestPluginDir/uses_default (0.00s) === RUN TestInstall --- PASS: TestInstall (0.00s) === RUN TestInstallChecksumMismatch --- PASS: TestInstallChecksumMismatch (0.00s) === RUN TestInstallRejectsUnsafeBinName === RUN TestInstallRejectsUnsafeBinName/parent_traversal === RUN TestInstallRejectsUnsafeBinName/nested_traversal === RUN TestInstallRejectsUnsafeBinName/absolute_path === RUN TestInstallRejectsUnsafeBinName/subdirectory === RUN TestInstallRejectsUnsafeBinName/empty --- PASS: TestInstallRejectsUnsafeBinName (0.01s) --- PASS: TestInstallRejectsUnsafeBinName/parent_traversal (0.00s) --- PASS: TestInstallRejectsUnsafeBinName/nested_traversal (0.00s) --- PASS: TestInstallRejectsUnsafeBinName/absolute_path (0.00s) --- PASS: TestInstallRejectsUnsafeBinName/subdirectory (0.00s) --- PASS: TestInstallRejectsUnsafeBinName/empty (0.00s) === RUN TestInstallRejectsUnsafeBinNameRawBinary --- PASS: TestInstallRejectsUnsafeBinNameRawBinary (0.00s) === RUN TestInstallRejectsUnsafeBinNameWithExtractPath --- PASS: TestInstallRejectsUnsafeBinNameWithExtractPath (0.00s) === RUN TestInstallBinaryNotInArchive --- PASS: TestInstallBinaryNotInArchive (0.00s) === RUN TestUninstall --- PASS: TestUninstall (0.00s) === RUN TestUninstallNonExistent --- PASS: TestUninstallNonExistent (0.00s) === RUN TestUninstallSymlink --- PASS: TestUninstallSymlink (0.00s) === RUN TestUninstallManualBinary --- PASS: TestUninstallManualBinary (0.00s) === RUN TestReadReceipt === RUN TestReadReceipt/exists === RUN TestReadReceipt/not_exists --- PASS: TestReadReceipt (0.00s) --- PASS: TestReadReceipt/exists (0.00s) --- PASS: TestReadReceipt/not_exists (0.00s) === RUN TestInstallRawBinary --- PASS: TestInstallRawBinary (0.00s) === RUN TestDetectArchiveFormat === RUN TestDetectArchiveFormat/zip_extension === RUN TestDetectArchiveFormat/tar.gz_extension === RUN TestDetectArchiveFormat/tgz_extension === RUN TestDetectArchiveFormat/tar_extension === RUN TestDetectArchiveFormat/uppercase_extension === RUN TestDetectArchiveFormat/zip_magic_no_extension === RUN TestDetectArchiveFormat/gzip_magic_no_extension === RUN TestDetectArchiveFormat/tar_magic_no_extension === RUN TestDetectArchiveFormat/unknown_content === RUN TestDetectArchiveFormat/short_file === RUN TestDetectArchiveFormat/empty_file --- PASS: TestDetectArchiveFormat (0.00s) --- PASS: TestDetectArchiveFormat/zip_extension (0.00s) --- PASS: TestDetectArchiveFormat/tar.gz_extension (0.00s) --- PASS: TestDetectArchiveFormat/tgz_extension (0.00s) --- PASS: TestDetectArchiveFormat/tar_extension (0.00s) --- PASS: TestDetectArchiveFormat/uppercase_extension (0.00s) --- PASS: TestDetectArchiveFormat/zip_magic_no_extension (0.00s) --- PASS: TestDetectArchiveFormat/gzip_magic_no_extension (0.00s) --- PASS: TestDetectArchiveFormat/tar_magic_no_extension (0.00s) --- PASS: TestDetectArchiveFormat/unknown_content (0.00s) --- PASS: TestDetectArchiveFormat/short_file (0.00s) --- PASS: TestDetectArchiveFormat/empty_file (0.00s) === RUN TestExtractFromTarGz --- PASS: TestExtractFromTarGz (0.00s) === RUN TestExtractFromTarGzRejectsUnsafeEntries --- PASS: TestExtractFromTarGzRejectsUnsafeEntries (0.00s) === RUN TestExtractFromZip --- PASS: TestExtractFromZip (0.00s) === RUN TestExtractFromZipRejectsUnsafeEntries --- PASS: TestExtractFromZipRejectsUnsafeEntries (0.00s) === RUN TestInstallExtractPath --- PASS: TestInstallExtractPath (0.00s) === RUN TestInstallExtractPathZip --- PASS: TestInstallExtractPathZip (0.00s) === RUN TestMatchArchiveEntry === RUN TestMatchArchiveEntry/flux-operator_flux-operator === RUN TestMatchArchiveEntry/bin/flux-operator_flux-operator === RUN TestMatchArchiveEntry/deep/nested/flux-operator_flux-operator === RUN TestMatchArchiveEntry/other-binary_flux-operator === RUN TestMatchArchiveEntry/bin/flux-operator_bin/flux-operator === RUN TestMatchArchiveEntry/flux-operator_bin/flux-operator === RUN TestMatchArchiveEntry/other/flux-operator_bin/flux-operator --- PASS: TestMatchArchiveEntry (0.00s) --- PASS: TestMatchArchiveEntry/flux-operator_flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/bin/flux-operator_flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/deep/nested/flux-operator_flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/other-binary_flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/bin/flux-operator_bin/flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/flux-operator_bin/flux-operator (0.00s) --- PASS: TestMatchArchiveEntry/other/flux-operator_bin/flux-operator (0.00s) === RUN TestExtractFromTarGzNotFound --- PASS: TestExtractFromTarGzNotFound (0.00s) === RUN TestCheckUpdateUpToDate --- PASS: TestCheckUpdateUpToDate (0.00s) === RUN TestCheckUpdateAvailable --- PASS: TestCheckUpdateAvailable (0.00s) === RUN TestCheckUpdateManualInstall --- PASS: TestCheckUpdateManualInstall (0.00s) PASS ok github.com/fluxcd/flux2/v2/internal/plugin 0.062s ? github.com/fluxcd/flux2/v2/internal/tree [no test files] === RUN TestTruncateHex === RUN TestTruncateHex/SHA1_hash === RUN TestTruncateHex/SHA256_hash === RUN TestTruncateHex/BLAKE3_hash === RUN TestTruncateHex/SHA512_hash === RUN TestTruncateHex/part_of_digest === RUN TestTruncateHex/part_of_revision_with_digest === RUN TestTruncateHex/legacy_revision_with_hash === RUN TestTruncateHex/hex_exceeding_max_length === RUN TestTruncateHex/hex_under_min_length === RUN TestTruncateHex/within_string === RUN TestTruncateHex/within_string_(quoted) === RUN TestTruncateHex/within_string_(single_quoted) === RUN TestTruncateHex/arbitrary_string --- PASS: TestTruncateHex (0.00s) --- PASS: TestTruncateHex/SHA1_hash (0.00s) --- PASS: TestTruncateHex/SHA256_hash (0.00s) --- PASS: TestTruncateHex/BLAKE3_hash (0.00s) --- PASS: TestTruncateHex/SHA512_hash (0.00s) --- PASS: TestTruncateHex/part_of_digest (0.00s) --- PASS: TestTruncateHex/part_of_revision_with_digest (0.00s) --- PASS: TestTruncateHex/legacy_revision_with_hash (0.00s) --- PASS: TestTruncateHex/hex_exceeding_max_length (0.00s) --- PASS: TestTruncateHex/hex_under_min_length (0.00s) --- PASS: TestTruncateHex/within_string (0.00s) --- PASS: TestTruncateHex/within_string_(quoted) (0.00s) --- PASS: TestTruncateHex/within_string_(single_quoted) (0.00s) --- PASS: TestTruncateHex/arbitrary_string (0.00s) === RUN TestCompatibleVersion === RUN TestCompatibleVersion/different_major_version === RUN TestCompatibleVersion/different_minor_version === RUN TestCompatibleVersion/same_version === RUN TestCompatibleVersion/binary_patch_version_ahead === RUN TestCompatibleVersion/target_patch_version_ahead === RUN TestCompatibleVersion/prerelease_binary --- PASS: TestCompatibleVersion (0.00s) --- PASS: TestCompatibleVersion/different_major_version (0.00s) --- PASS: TestCompatibleVersion/different_minor_version (0.00s) --- PASS: TestCompatibleVersion/same_version (0.00s) --- PASS: TestCompatibleVersion/binary_patch_version_ahead (0.00s) --- PASS: TestCompatibleVersion/target_patch_version_ahead (0.00s) --- PASS: TestCompatibleVersion/prerelease_binary (0.00s) === RUN TestParseObjectKindNameNamespace === RUN TestParseObjectKindNameNamespace/with_kind_name_namespace === RUN TestParseObjectKindNameNamespace/without_namespace === RUN TestParseObjectKindNameNamespace/name_with_dots === RUN TestParseObjectKindNameNamespace/multiple_slashes --- PASS: TestParseObjectKindNameNamespace (0.00s) --- PASS: TestParseObjectKindNameNamespace/with_kind_name_namespace (0.00s) --- PASS: TestParseObjectKindNameNamespace/without_namespace (0.00s) --- PASS: TestParseObjectKindNameNamespace/name_with_dots (0.00s) --- PASS: TestParseObjectKindNameNamespace/multiple_slashes (0.00s) === RUN TestValidateComponents === RUN TestValidateComponents/default_and_extra_components === RUN TestValidateComponents/unknown_components === RUN TestValidateComponents/mix_of_default_and_unknown === RUN TestValidateComponents/empty --- PASS: TestValidateComponents (0.00s) --- PASS: TestValidateComponents/default_and_extra_components (0.00s) --- PASS: TestValidateComponents/unknown_components (0.00s) --- PASS: TestValidateComponents/mix_of_default_and_unknown (0.00s) --- PASS: TestValidateComponents/empty (0.00s) === RUN TestExtractCRDs === RUN TestExtractCRDs/with_crds === RUN TestExtractCRDs/without_crds === RUN TestExtractCRDs/non-existent_file --- PASS: TestExtractCRDs (0.00s) --- PASS: TestExtractCRDs/with_crds (0.00s) --- PASS: TestExtractCRDs/without_crds (0.00s) --- PASS: TestExtractCRDs/non-existent_file (0.00s) PASS ok github.com/fluxcd/flux2/v2/internal/utils 0.071s === RUN Test_hasRevision === RUN Test_hasRevision/Kustomization_revision === RUN Test_hasRevision/GitRepository_revision === RUN Test_hasRevision/GitRepository_revision_(wrong_revision) === RUN Test_hasRevision/Kustomization_revision_(empty_revision) === RUN Test_hasRevision/OCIRepository_revision === RUN Test_hasRevision/Alert_revision(Not_supported) --- PASS: Test_hasRevision (0.01s) --- PASS: Test_hasRevision/Kustomization_revision (0.00s) --- PASS: Test_hasRevision/GitRepository_revision (0.00s) --- PASS: Test_hasRevision/GitRepository_revision_(wrong_revision) (0.00s) --- PASS: Test_hasRevision/Kustomization_revision_(empty_revision) (0.00s) --- PASS: Test_hasRevision/OCIRepository_revision (0.00s) --- PASS: Test_hasRevision/Alert_revision(Not_supported) (0.00s) === RUN Test_objectReconciled === RUN Test_objectReconciled/GitRepository_with_no_status === RUN Test_objectReconciled/suspended_Kustomization === RUN Test_objectReconciled/Kustomization_-_status_with_old_generation === RUN Test_objectReconciled/GitRepository_-_status_with_same_generation_but_no_conditions === RUN Test_objectReconciled/GitRepository_-_status_with_conditions_but_no_ready_condition === RUN Test_objectReconciled/Kustomization_-_status_with_false_ready_condition === RUN Test_objectReconciled/Kustomization_-_status_with_true_ready_condition_but_different_revision === RUN Test_objectReconciled/GitRepository_-_status_with_true_ready_condition_but_different_revision === RUN Test_objectReconciled/GitRepository_-_ready_with_right_revision === RUN Test_objectReconciled/GitRepository_-_sequence_of_status_updates_before_ready --- PASS: Test_objectReconciled (0.13s) --- PASS: Test_objectReconciled/GitRepository_with_no_status (0.10s) --- PASS: Test_objectReconciled/suspended_Kustomization (0.00s) --- PASS: Test_objectReconciled/Kustomization_-_status_with_old_generation (0.00s) --- PASS: Test_objectReconciled/GitRepository_-_status_with_same_generation_but_no_conditions (0.00s) --- PASS: Test_objectReconciled/GitRepository_-_status_with_conditions_but_no_ready_condition (0.00s) --- PASS: Test_objectReconciled/Kustomization_-_status_with_false_ready_condition (0.00s) --- PASS: Test_objectReconciled/Kustomization_-_status_with_true_ready_condition_but_different_revision (0.00s) --- PASS: Test_objectReconciled/GitRepository_-_status_with_true_ready_condition_but_different_revision (0.00s) --- PASS: Test_objectReconciled/GitRepository_-_ready_with_right_revision (0.00s) --- PASS: Test_objectReconciled/GitRepository_-_sequence_of_status_updates_before_ready (0.00s) === RUN TestPlainGitBootstrapper_resolveSigner === RUN TestPlainGitBootstrapper_resolveSigner/no_signing_configured_returns_nil_signer === RUN TestPlainGitBootstrapper_resolveSigner/GPG_key_ring_returns_an_OpenPGP_signer === RUN TestPlainGitBootstrapper_resolveSigner/SSH_key_returns_an_SSH_signer === RUN TestPlainGitBootstrapper_resolveSigner/encrypted_SSH_key_without_password_errors === RUN TestPlainGitBootstrapper_resolveSigner/GPG_path_takes_precedence_over_SSH_path --- PASS: TestPlainGitBootstrapper_resolveSigner (0.72s) --- PASS: TestPlainGitBootstrapper_resolveSigner/no_signing_configured_returns_nil_signer (0.00s) --- PASS: TestPlainGitBootstrapper_resolveSigner/GPG_key_ring_returns_an_OpenPGP_signer (0.28s) --- PASS: TestPlainGitBootstrapper_resolveSigner/SSH_key_returns_an_SSH_signer (0.00s) --- PASS: TestPlainGitBootstrapper_resolveSigner/encrypted_SSH_key_without_password_errors (0.13s) --- PASS: TestPlainGitBootstrapper_resolveSigner/GPG_path_takes_precedence_over_SSH_path (0.30s) === RUN TestSelectOpenPGPSigningEntity === RUN TestSelectOpenPGPSigningEntity/empty_key_ring_errors === RUN TestSelectOpenPGPSigningEntity/public-only_key_ring_without_key_id_errors_instead_of_panicking === RUN TestSelectOpenPGPSigningEntity/public-only_key_ring_with_matching_key_id_errors_with_key_id_context --- PASS: TestSelectOpenPGPSigningEntity (1.50s) --- PASS: TestSelectOpenPGPSigningEntity/empty_key_ring_errors (0.00s) --- PASS: TestSelectOpenPGPSigningEntity/public-only_key_ring_without_key_id_errors_instead_of_panicking (0.53s) --- PASS: TestSelectOpenPGPSigningEntity/public-only_key_ring_with_matching_key_id_errors_with_key_id_context (0.97s) === RUN TestPlainGitBootstrapper_sshSignerProducesVerifiableCommit --- PASS: TestPlainGitBootstrapper_sshSignerProducesVerifiableCommit (0.00s) PASS ok github.com/fluxcd/flux2/v2/pkg/bootstrap 2.438s ? github.com/fluxcd/flux2/v2/pkg/bootstrap/provider [no test files] ? github.com/fluxcd/flux2/v2/pkg/log [no test files] ? github.com/fluxcd/flux2/v2/pkg/manifestgen [no test files] === RUN TestGenerate install_test.go:49: &{flux-system/gotk-components.yaml --- # This manifest was generated by flux. DO NOT EDIT. # Flux Version: latest # Components: source-controller,kustomize-controller,helm-controller,notification-controller apiVersion: v1 kind: Namespace metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest pod-security.kubernetes.io/warn: restricted pod-security.kubernetes.io/warn-version: latest name: flux-system --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: allow-egress namespace: flux-system spec: egress: - {} ingress: - from: - podSelector: {} podSelector: {} policyTypes: - Ingress - Egress --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: allow-scraping namespace: flux-system spec: ingress: - from: - namespaceSelector: {} ports: - port: 8080 protocol: TCP podSelector: {} policyTypes: - Ingress --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: allow-webhooks namespace: flux-system spec: ingress: - from: - namespaceSelector: {} podSelector: matchLabels: app: notification-controller policyTypes: - Ingress --- apiVersion: v1 kind: ResourceQuota metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: critical-pods-flux-system namespace: flux-system spec: hard: pods: "1000" scopeSelector: matchExpressions: - operator: In scopeName: PriorityClass values: - system-node-critical - system-cluster-critical --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: crd-controller-flux-system rules: - apiGroups: - source.toolkit.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - kustomize.toolkit.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - helm.toolkit.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - notification.toolkit.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - image.toolkit.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - source.extensions.fluxcd.io resources: - '*' verbs: - '*' - apiGroups: - "" resources: - namespaces - secrets - configmaps - serviceaccounts verbs: - get - list - watch - apiGroups: - "" resources: - events verbs: - create - patch - apiGroups: - "" resources: - configmaps verbs: - get - list - watch - create - update - patch - delete - apiGroups: - "" resources: - configmaps/status verbs: - get - update - patch - apiGroups: - coordination.k8s.io resources: - leases verbs: - get - list - watch - create - update - patch - delete - apiGroups: - "" resources: - serviceaccounts/token verbs: - create - nonResourceURLs: - /livez/ping verbs: - head --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" name: flux-edit-flux-system rules: - apiGroups: - notification.toolkit.fluxcd.io - source.toolkit.fluxcd.io - source.extensions.fluxcd.io - helm.toolkit.fluxcd.io - image.toolkit.fluxcd.io - kustomize.toolkit.fluxcd.io resources: - '*' verbs: - create - delete - deletecollection - patch - update --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" rbac.authorization.k8s.io/aggregate-to-view: "true" name: flux-view-flux-system rules: - apiGroups: - notification.toolkit.fluxcd.io - source.toolkit.fluxcd.io - source.extensions.fluxcd.io - helm.toolkit.fluxcd.io - image.toolkit.fluxcd.io - kustomize.toolkit.fluxcd.io resources: - '*' verbs: - get - list - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: cluster-reconciler-flux-system roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: cluster-admin subjects: - kind: ServiceAccount name: kustomize-controller namespace: flux-system - kind: ServiceAccount name: helm-controller namespace: flux-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: labels: app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: crd-controller-flux-system roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: crd-controller-flux-system subjects: - kind: ServiceAccount name: kustomize-controller namespace: flux-system - kind: ServiceAccount name: helm-controller namespace: flux-system - kind: ServiceAccount name: source-controller namespace: flux-system - kind: ServiceAccount name: notification-controller namespace: flux-system - kind: ServiceAccount name: image-reflector-controller namespace: flux-system - kind: ServiceAccount name: image-automation-controller namespace: flux-system - kind: ServiceAccount name: source-watcher namespace: flux-system --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: buckets.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: Bucket listKind: BucketList plural: buckets singular: bucket scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.endpoint name: Endpoint type: string - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: Bucket is the Schema for the buckets API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: |- BucketSpec specifies the required configuration to produce an Artifact for an object storage bucket. properties: bucketName: description: BucketName is the name of the object storage bucket. type: string certSecretRef: description: |- CertSecretRef can be given the name of a Secret containing either or both of - a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`); - a PEM-encoded CA certificate (`ca.crt`) and whichever are supplied, will be used for connecting to the bucket. The client cert and key are useful if you are authenticating with a certificate; the CA cert is useful if you are using a self-signed server certificate. The Secret must be of type `Opaque` or `kubernetes.io/tls`. This field is only supported for the `generic` provider. properties: name: description: Name of the referent. type: string required: - name type: object endpoint: description: Endpoint is the object storage address the BucketName is located at. type: string ignore: description: |- Ignore overrides the set of excluded patterns in the .sourceignore format (which is the same as .gitignore). If not provided, a default will be used, consult the documentation for your version to find out what those are. type: string insecure: description: Insecure allows connecting to a non-TLS HTTP Endpoint. type: boolean interval: description: |- Interval at which the Bucket Endpoint is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string prefix: description: Prefix to use for server-side filtering of files in the Bucket. type: string provider: default: generic description: |- Provider of the object storage bucket. Defaults to 'generic', which expects an S3 (API) compatible object storage. enum: - generic - aws - gcp - azure type: string proxySecretRef: description: |- ProxySecretRef specifies the Secret containing the proxy configuration to use while communicating with the Bucket server. properties: name: description: Name of the referent. type: string required: - name type: object region: description: Region of the Endpoint where the BucketName is located in. type: string secretRef: description: |- SecretRef specifies the Secret containing authentication credentials for the Bucket. properties: name: description: Name of the referent. type: string required: - name type: object serviceAccountName: description: |- ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate the bucket. This field is only supported for the 'gcp' and 'aws' providers. For more information about workload identity: https://fluxcd.io/flux/components/source/buckets/#workload-identity type: string sts: description: |- STS specifies the required configuration to use a Security Token Service for fetching temporary credentials to authenticate in a Bucket provider. This field is only supported for the `aws` and `generic` providers. properties: certSecretRef: description: |- CertSecretRef can be given the name of a Secret containing either or both of - a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`); - a PEM-encoded CA certificate (`ca.crt`) and whichever are supplied, will be used for connecting to the STS endpoint. The client cert and key are useful if you are authenticating with a certificate; the CA cert is useful if you are using a self-signed server certificate. The Secret must be of type `Opaque` or `kubernetes.io/tls`. This field is only supported for the `ldap` provider. properties: name: description: Name of the referent. type: string required: - name type: object endpoint: description: |- Endpoint is the HTTP/S endpoint of the Security Token Service from where temporary credentials will be fetched. pattern: ^(http|https)://.*$ type: string provider: description: Provider of the Security Token Service. enum: - aws - ldap type: string secretRef: description: |- SecretRef specifies the Secret containing authentication credentials for the STS endpoint. This Secret must contain the fields `username` and `password` and is supported only for the `ldap` provider. properties: name: description: Name of the referent. type: string required: - name type: object required: - endpoint - provider type: object suspend: description: |- Suspend tells the controller to suspend the reconciliation of this Bucket. type: boolean timeout: default: 60s description: Timeout for fetch operations, defaults to 60s. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ type: string required: - bucketName - endpoint - interval type: object x-kubernetes-validations: - message: STS configuration is only supported for the 'aws' and 'generic' Bucket providers rule: self.provider == 'aws' || self.provider == 'generic' || !has(self.sts) - message: '''aws'' is the only supported STS provider for the ''aws'' Bucket provider' rule: self.provider != 'aws' || !has(self.sts) || self.sts.provider == 'aws' - message: '''ldap'' is the only supported STS provider for the ''generic'' Bucket provider' rule: self.provider != 'generic' || !has(self.sts) || self.sts.provider == 'ldap' - message: spec.sts.secretRef is not required for the 'aws' STS provider rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.secretRef)' - message: spec.sts.certSecretRef is not required for the 'aws' STS provider rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.certSecretRef)' - message: ServiceAccountName is not supported for the 'generic' Bucket provider rule: self.provider != 'generic' || !has(self.serviceAccountName) - message: cannot set both .spec.secretRef and .spec.serviceAccountName rule: '!has(self.secretRef) || !has(self.serviceAccountName)' status: default: observedGeneration: -1 description: BucketStatus records the observed state of a Bucket. properties: artifact: description: Artifact represents the last successful Bucket reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the Bucket. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: ObservedGeneration is the last observed generation of the Bucket object. format: int64 type: integer observedIgnore: description: |- ObservedIgnore is the observed exclusion patterns used for constructing the source artifact. type: string url: description: |- URL is the dynamic fetch link for the latest Artifact. It is provided on a "best effort" basis, and using the precise BucketStatus.Artifact data is recommended. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: externalartifacts.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: ExternalArtifact listKind: ExternalArtifactList plural: externalartifacts shortNames: - ea singular: externalartifact scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string - jsonPath: .spec.sourceRef.name name: Source type: string name: v1 schema: openAPIV3Schema: description: ExternalArtifact is the Schema for the external artifacts API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: ExternalArtifactSpec defines the desired state of ExternalArtifact properties: sourceRef: description: |- SourceRef points to the Kubernetes custom resource for which the artifact is generated. properties: apiVersion: description: API version of the referent, if not specified the Kubernetes preferred version will be used. type: string kind: description: Kind of the referent. type: string name: description: Name of the referent. type: string namespace: description: Namespace of the referent, when not specified it acts as LocalObjectReference. type: string required: - kind - name type: object type: object status: description: ExternalArtifactStatus defines the observed state of ExternalArtifact properties: artifact: description: Artifact represents the output of an ExternalArtifact reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the ExternalArtifact. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array type: object type: object served: true storage: true subresources: status: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: gitrepositories.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: GitRepository listKind: GitRepositoryList plural: gitrepositories shortNames: - gitrepo singular: gitrepository scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.url name: URL type: string - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: GitRepository is the Schema for the gitrepositories API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: |- GitRepositorySpec specifies the required configuration to produce an Artifact for a Git repository. properties: ignore: description: |- Ignore overrides the set of excluded patterns in the .sourceignore format (which is the same as .gitignore). If not provided, a default will be used, consult the documentation for your version to find out what those are. type: string include: description: |- Include specifies a list of GitRepository resources which Artifacts should be included in the Artifact produced for this GitRepository. items: description: |- GitRepositoryInclude specifies a local reference to a GitRepository which Artifact (sub-)contents must be included, and where they should be placed. properties: fromPath: description: |- FromPath specifies the path to copy contents from, defaults to the root of the Artifact. type: string repository: description: |- GitRepositoryRef specifies the GitRepository which Artifact contents must be included. properties: name: description: Name of the referent. type: string required: - name type: object toPath: description: |- ToPath specifies the path to copy contents to, defaults to the name of the GitRepositoryRef. type: string required: - repository type: object type: array interval: description: |- Interval at which the GitRepository URL is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string provider: description: |- Provider used for authentication, can be 'aws', 'azure', 'github', 'generic'. When not specified, defaults to 'generic'. enum: - generic - aws - azure - github type: string proxySecretRef: description: |- ProxySecretRef specifies the Secret containing the proxy configuration to use while communicating with the Git server. properties: name: description: Name of the referent. type: string required: - name type: object recurseSubmodules: description: |- RecurseSubmodules enables the initialization of all submodules within the GitRepository as cloned from the URL, using their default settings. type: boolean ref: description: |- Reference specifies the Git reference to resolve and monitor for changes, defaults to the 'master' branch. properties: branch: description: Branch to check out, defaults to 'master' if no other field is defined. type: string commit: description: |- Commit SHA to check out, takes precedence over all reference fields. This can be combined with Branch to shallow clone the branch, in which the commit is expected to exist. type: string name: description: |- Name of the reference to check out; takes precedence over Branch, Tag and SemVer. It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head" type: string semver: description: SemVer tag expression to check out, takes precedence over Tag. type: string tag: description: Tag to check out, takes precedence over Branch. type: string type: object secretRef: description: |- SecretRef specifies the Secret containing authentication credentials for the GitRepository. For HTTPS repositories the Secret must contain 'username' and 'password' fields for basic auth or 'bearerToken' field for token auth. For SSH repositories the Secret must contain 'identity' and 'known_hosts' fields. properties: name: description: Name of the referent. type: string required: - name type: object serviceAccountName: description: |- ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate to the GitRepository. This field is only supported for 'azure' and 'aws' providers. type: string sparseCheckout: description: |- SparseCheckout specifies a list of directories to checkout when cloning the repository. If specified, only these directories are included in the Artifact produced for this GitRepository. items: type: string type: array suspend: description: |- Suspend tells the controller to suspend the reconciliation of this GitRepository. type: boolean timeout: default: 60s description: Timeout for Git operations like cloning, defaults to 60s. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ type: string url: description: URL specifies the Git repository URL, it can be an HTTP/S or SSH address. pattern: ^(http|https|ssh)://.*$ type: string verify: description: |- Verification specifies the configuration to verify the Git commit signature(s). properties: mode: default: HEAD description: |- Mode specifies which Git object(s) should be verified. The variants "head" and "HEAD" both imply the same thing, i.e. verify the commit that the HEAD of the Git repository points to. The variant "head" solely exists to ensure backwards compatibility. enum: - head - HEAD - Tag - TagAndHEAD type: string secretRef: description: |- SecretRef specifies the Secret containing the public keys of trusted Git authors. PGP public keys must be stored under keys with the .asc suffix, and SSH public keys must be stored under keys with the .sshpub suffix. properties: name: description: Name of the referent. type: string required: - name type: object required: - secretRef type: object required: - interval - url type: object x-kubernetes-validations: - message: serviceAccountName can only be set when provider is 'azure' or 'aws' rule: '!has(self.serviceAccountName) || (has(self.provider) && (self.provider == ''azure'' || self.provider == ''aws''))' status: default: observedGeneration: -1 description: GitRepositoryStatus records the observed state of a Git repository. properties: artifact: description: Artifact represents the last successful GitRepository reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the GitRepository. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array includedArtifacts: description: |- IncludedArtifacts contains a list of the last successfully included Artifacts as instructed by GitRepositorySpec.Include. items: description: Artifact represents the output of a Source reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: |- ObservedGeneration is the last observed generation of the GitRepository object. format: int64 type: integer observedIgnore: description: |- ObservedIgnore is the observed exclusion patterns used for constructing the source artifact. type: string observedInclude: description: |- ObservedInclude is the observed list of GitRepository resources used to produce the current Artifact. items: description: |- GitRepositoryInclude specifies a local reference to a GitRepository which Artifact (sub-)contents must be included, and where they should be placed. properties: fromPath: description: |- FromPath specifies the path to copy contents from, defaults to the root of the Artifact. type: string repository: description: |- GitRepositoryRef specifies the GitRepository which Artifact contents must be included. properties: name: description: Name of the referent. type: string required: - name type: object toPath: description: |- ToPath specifies the path to copy contents to, defaults to the name of the GitRepositoryRef. type: string required: - repository type: object type: array observedRecurseSubmodules: description: |- ObservedRecurseSubmodules is the observed resource submodules configuration used to produce the current Artifact. type: boolean observedSparseCheckout: description: |- ObservedSparseCheckout is the observed list of directories used to produce the current Artifact. items: type: string type: array sourceVerificationMode: description: |- SourceVerificationMode is the last used verification mode indicating which Git object(s) have been verified. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: helmcharts.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: HelmChart listKind: HelmChartList plural: helmcharts shortNames: - hc singular: helmchart scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.chart name: Chart type: string - jsonPath: .spec.version name: Version type: string - jsonPath: .spec.sourceRef.kind name: Source Kind type: string - jsonPath: .spec.sourceRef.name name: Source Name type: string - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: HelmChart is the Schema for the helmcharts API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: HelmChartSpec specifies the desired state of a Helm chart. properties: chart: description: |- Chart is the name or path the Helm chart is available at in the SourceRef. type: string ignoreMissingValuesFiles: description: |- IgnoreMissingValuesFiles controls whether to silently ignore missing values files rather than failing. type: boolean interval: description: |- Interval at which the HelmChart SourceRef is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string reconcileStrategy: default: ChartVersion description: |- ReconcileStrategy determines what enables the creation of a new artifact. Valid values are ('ChartVersion', 'Revision'). See the documentation of the values for an explanation on their behavior. Defaults to ChartVersion when omitted. enum: - ChartVersion - Revision type: string sourceRef: description: SourceRef is the reference to the Source the chart is available at. properties: apiVersion: description: APIVersion of the referent. type: string kind: description: |- Kind of the referent, valid values are ('HelmRepository', 'GitRepository', 'Bucket'). enum: - HelmRepository - GitRepository - Bucket type: string name: description: Name of the referent. type: string required: - kind - name type: object suspend: description: |- Suspend tells the controller to suspend the reconciliation of this source. type: boolean valuesFiles: description: |- ValuesFiles is an alternative list of values files to use as the chart values (values.yaml is not included by default), expected to be a relative path in the SourceRef. Values files are merged in the order of this list with the last file overriding the first. Ignored when omitted. items: type: string type: array verify: description: |- Verify contains the secret name containing the trusted public keys used to verify the signature and specifies which provider to use to check whether OCI image is authentic. This field is only supported when using HelmRepository source with spec.type 'oci'. Chart dependencies, which are not bundled in the umbrella chart artifact, are not verified. properties: matchOIDCIdentity: description: |- MatchOIDCIdentity specifies the identity matching criteria to use while verifying an OCI artifact which was signed using Cosign keyless signing. The artifact's identity is deemed to be verified if any of the specified matchers match against the identity. items: description: |- OIDCIdentityMatch specifies options for verifying the certificate identity, i.e. the issuer and the subject of the certificate. properties: issuer: description: |- Issuer specifies the regex pattern to match against to verify the OIDC issuer in the Fulcio certificate. The pattern must be a valid Go regular expression. type: string subject: description: |- Subject specifies the regex pattern to match against to verify the identity subject in the Fulcio certificate. The pattern must be a valid Go regular expression. type: string required: - issuer - subject type: object type: array provider: default: cosign description: Provider specifies the technology used to sign the OCI Artifact. enum: - cosign - notation type: string secretRef: description: |- SecretRef specifies the Kubernetes Secret containing the trusted public keys. properties: name: description: Name of the referent. type: string required: - name type: object required: - provider type: object version: default: '*' description: |- Version is the chart version semver expression, ignored for charts from GitRepository and Bucket sources. Defaults to latest when omitted. type: string required: - chart - interval - sourceRef type: object x-kubernetes-validations: - message: spec.verify is only supported when spec.sourceRef.kind is 'HelmRepository' rule: '!has(self.verify) || self.sourceRef.kind == ''HelmRepository''' status: default: observedGeneration: -1 description: HelmChartStatus records the observed state of the HelmChart. properties: artifact: description: Artifact represents the output of the last successful reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the HelmChart. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedChartName: description: |- ObservedChartName is the last observed chart name as specified by the resolved chart reference. type: string observedGeneration: description: |- ObservedGeneration is the last observed generation of the HelmChart object. format: int64 type: integer observedSourceArtifactRevision: description: |- ObservedSourceArtifactRevision is the last observed Artifact.Revision of the HelmChartSpec.SourceRef. type: string observedValuesFiles: description: |- ObservedValuesFiles are the observed value files of the last successful reconciliation. It matches the chart in the last successfully reconciled artifact. items: type: string type: array url: description: |- URL is the dynamic fetch link for the latest Artifact. It is provided on a "best effort" basis, and using the precise HelmChartStatus.Artifact data is recommended. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: helmrepositories.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: HelmRepository listKind: HelmRepositoryList plural: helmrepositories shortNames: - helmrepo singular: helmrepository scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.url name: URL type: string - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: HelmRepository is the Schema for the helmrepositories API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: |- HelmRepositorySpec specifies the required configuration to produce an Artifact for a Helm repository index YAML. properties: accessFrom: description: |- AccessFrom specifies an Access Control List for allowing cross-namespace references to this object. NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 properties: namespaceSelectors: description: |- NamespaceSelectors is the list of namespace selectors to which this ACL applies. Items in this list are evaluated using a logical OR operation. items: description: |- NamespaceSelector selects the namespaces to which this ACL applies. An empty map of MatchLabels matches all namespaces in a cluster. properties: matchLabels: additionalProperties: type: string description: |- MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed. type: object type: object type: array required: - namespaceSelectors type: object certSecretRef: description: |- CertSecretRef can be given the name of a Secret containing either or both of - a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`); - a PEM-encoded CA certificate (`ca.crt`) and whichever are supplied, will be used for connecting to the registry. The client cert and key are useful if you are authenticating with a certificate; the CA cert is useful if you are using a self-signed server certificate. The Secret must be of type `Opaque` or `kubernetes.io/tls`. It takes precedence over the values specified in the Secret referred to by `.spec.secretRef`. properties: name: description: Name of the referent. type: string required: - name type: object insecure: description: |- Insecure allows connecting to a non-TLS HTTP container registry. This field is only taken into account if the .spec.type field is set to 'oci'. type: boolean interval: description: |- Interval at which the HelmRepository URL is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string passCredentials: description: |- PassCredentials allows the credentials from the SecretRef to be passed on to a host that does not match the host as defined in URL. This may be required if the host of the advertised chart URLs in the index differ from the defined URL. Enabling this should be done with caution, as it can potentially result in credentials getting stolen in a MITM-attack. type: boolean provider: default: generic description: |- Provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. This field is optional, and only taken into account if the .spec.type field is set to 'oci'. When not specified, defaults to 'generic'. enum: - generic - aws - azure - gcp type: string secretRef: description: |- SecretRef specifies the Secret containing authentication credentials for the HelmRepository. For HTTP/S basic auth the secret must contain 'username' and 'password' fields. Support for TLS auth using the 'certFile' and 'keyFile', and/or 'caFile' keys is deprecated. Please use `.spec.certSecretRef` instead. properties: name: description: Name of the referent. type: string required: - name type: object suspend: description: |- Suspend tells the controller to suspend the reconciliation of this HelmRepository. type: boolean timeout: description: |- Timeout is used for the index fetch operation for an HTTPS helm repository, and for remote OCI Repository operations like pulling for an OCI helm chart by the associated HelmChart. Its default value is 60s. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ type: string type: description: |- Type of the HelmRepository. When this field is set to "oci", the URL field value must be prefixed with "oci://". enum: - default - oci type: string url: description: |- URL of the Helm repository, a valid URL contains at least a protocol and host. pattern: ^(http|https|oci)://.*$ type: string required: - url type: object status: default: observedGeneration: -1 description: HelmRepositoryStatus records the observed state of the HelmRepository. properties: artifact: description: Artifact represents the last successful HelmRepository reconciliation. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the HelmRepository. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: |- ObservedGeneration is the last observed generation of the HelmRepository object. format: int64 type: integer url: description: |- URL is the dynamic fetch link for the latest Artifact. It is provided on a "best effort" basis, and using the precise HelmRepositoryStatus.Artifact data is recommended. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: ocirepositories.source.toolkit.fluxcd.io spec: group: source.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-sources kind: OCIRepository listKind: OCIRepositoryList plural: ocirepositories shortNames: - ocirepo singular: ocirepository scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.url name: URL type: string - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1 schema: openAPIV3Schema: description: OCIRepository is the Schema for the ocirepositories API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: OCIRepositorySpec defines the desired state of OCIRepository properties: certSecretRef: description: |- CertSecretRef can be given the name of a Secret containing either or both of - a PEM-encoded client certificate (`tls.crt`) and private key (`tls.key`); - a PEM-encoded CA certificate (`ca.crt`) and whichever are supplied, will be used for connecting to the registry. The client cert and key are useful if you are authenticating with a certificate; the CA cert is useful if you are using a self-signed server certificate. The Secret must be of type `Opaque` or `kubernetes.io/tls`. properties: name: description: Name of the referent. type: string required: - name type: object ignore: description: |- Ignore overrides the set of excluded patterns in the .sourceignore format (which is the same as .gitignore). If not provided, a default will be used, consult the documentation for your version to find out what those are. type: string insecure: description: Insecure allows connecting to a non-TLS HTTP container registry. type: boolean interval: description: |- Interval at which the OCIRepository URL is checked for updates. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string layerSelector: description: |- LayerSelector specifies which layer should be extracted from the OCI artifact. When not specified, the first layer found in the artifact is selected. properties: mediaType: description: |- MediaType specifies the OCI media type of the layer which should be extracted from the OCI Artifact. The first layer matching this type is selected. type: string operation: description: |- Operation specifies how the selected layer should be processed. By default, the layer compressed content is extracted to storage. When the operation is set to 'copy', the layer compressed content is persisted to storage as it is. enum: - extract - copy type: string type: object provider: default: generic description: |- The provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. When not specified, defaults to 'generic'. enum: - generic - aws - azure - gcp type: string proxySecretRef: description: |- ProxySecretRef specifies the Secret containing the proxy configuration to use while communicating with the container registry. properties: name: description: Name of the referent. type: string required: - name type: object ref: description: |- The OCI reference to pull and monitor for changes, defaults to the latest tag. properties: digest: description: |- Digest is the image digest to pull, takes precedence over SemVer. The value should be in the format 'sha256:'. type: string semver: description: |- SemVer is the range of tags to pull selecting the latest within the range, takes precedence over Tag. type: string semverFilter: description: SemverFilter is a regex pattern to filter the tags within the SemVer range. type: string tag: description: Tag is the image tag to pull, defaults to latest. type: string type: object secretRef: description: |- SecretRef contains the secret name containing the registry login credentials to resolve image metadata. The secret must be of type kubernetes.io/dockerconfigjson. properties: name: description: Name of the referent. type: string required: - name type: object serviceAccountName: description: |- ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate the image pull if the service account has attached pull secrets. For more information: https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account type: string suspend: description: This flag tells the controller to suspend the reconciliation of this source. type: boolean timeout: default: 60s description: The timeout for remote OCI Repository operations like pulling, defaults to 60s. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ type: string url: description: |- URL is a reference to an OCI artifact repository hosted on a remote container registry. pattern: ^oci://.*$ type: string verify: description: |- Verify contains the secret name containing the trusted public keys used to verify the signature and specifies which provider to use to check whether OCI image is authentic. properties: matchOIDCIdentity: description: |- MatchOIDCIdentity specifies the identity matching criteria to use while verifying an OCI artifact which was signed using Cosign keyless signing. The artifact's identity is deemed to be verified if any of the specified matchers match against the identity. items: description: |- OIDCIdentityMatch specifies options for verifying the certificate identity, i.e. the issuer and the subject of the certificate. properties: issuer: description: |- Issuer specifies the regex pattern to match against to verify the OIDC issuer in the Fulcio certificate. The pattern must be a valid Go regular expression. type: string subject: description: |- Subject specifies the regex pattern to match against to verify the identity subject in the Fulcio certificate. The pattern must be a valid Go regular expression. type: string required: - issuer - subject type: object type: array provider: default: cosign description: Provider specifies the technology used to sign the OCI Artifact. enum: - cosign - notation type: string secretRef: description: |- SecretRef specifies the Kubernetes Secret containing the trusted public keys. properties: name: description: Name of the referent. type: string required: - name type: object trustedRootSecretRef: description: |- TrustedRootSecretRef specifies the Kubernetes Secret containing a Sigstore trusted_root.json file. This enables verification against self-hosted Sigstore infrastructure (custom Fulcio CA, self-hosted Rekor instance). The Secret must contain a key named "trusted_root.json". properties: name: description: Name of the referent. type: string required: - name type: object required: - provider type: object required: - interval - url type: object status: default: observedGeneration: -1 description: OCIRepositoryStatus defines the observed state of OCIRepository properties: artifact: description: Artifact represents the output of the last successful OCI Repository sync. properties: digest: description: Digest is the digest of the file in the form of ':'. pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ type: string lastUpdateTime: description: |- LastUpdateTime is the timestamp corresponding to the last update of the Artifact. format: date-time type: string metadata: additionalProperties: type: string description: Metadata holds upstream information such as OCI annotations. type: object path: description: |- Path is the relative file path of the Artifact. It can be used to locate the file in the root of the Artifact storage on the local file system of the controller managing the Source. type: string revision: description: |- Revision is a human-readable identifier traceable in the origin source system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. type: string size: description: Size is the number of bytes in the file. format: int64 type: integer url: description: |- URL is the HTTP address of the Artifact as exposed by the controller managing the Source. It can be used to retrieve the Artifact for consumption, e.g. by another controller applying the Artifact contents. type: string required: - digest - lastUpdateTime - path - revision - url type: object conditions: description: Conditions holds the conditions for the OCIRepository. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: ObservedGeneration is the last observed generation. format: int64 type: integer observedIgnore: description: |- ObservedIgnore is the observed exclusion patterns used for constructing the source artifact. type: string observedLayerSelector: description: |- ObservedLayerSelector is the observed layer selector used for constructing the source artifact. properties: mediaType: description: |- MediaType specifies the OCI media type of the layer which should be extracted from the OCI Artifact. The first layer matching this type is selected. type: string operation: description: |- Operation specifies how the selected layer should be processed. By default, the layer compressed content is extracted to storage. When the operation is set to 'copy', the layer compressed content is persisted to storage as it is. enum: - extract - copy type: string type: object url: description: URL is the download link for the artifact output of the last OCI Repository sync. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: v1 kind: ServiceAccount metadata: labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: source-controller namespace: flux-system --- apiVersion: v1 kind: Service metadata: labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: source-controller namespace: flux-system spec: ports: - name: http port: 80 protocol: TCP targetPort: http selector: app: source-controller type: ClusterIP --- apiVersion: apps/v1 kind: Deployment metadata: labels: app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: source-controller namespace: flux-system spec: replicas: 1 selector: matchLabels: app: source-controller strategy: type: Recreate template: metadata: annotations: prometheus.io/port: "8080" prometheus.io/scrape: "true" labels: app: source-controller app.kubernetes.io/component: source-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest spec: containers: - args: - --events-addr=http://notification-controller.$(RUNTIME_NAMESPACE).svc.cluster.local./ - --watch-all-namespaces=true - --log-level=info - --log-encoding=json - --enable-leader-election - --storage-path=/data - --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local. env: - name: RUNTIME_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: TUF_ROOT value: /tmp/.sigstore - name: GOMEMLIMIT valueFrom: resourceFieldRef: containerName: manager resource: limits.memory image: ghcr.io/fluxcd/source-controller:v1.9.3 imagePullPolicy: IfNotPresent livenessProbe: httpGet: path: /healthz port: healthz name: manager ports: - containerPort: 9090 name: http protocol: TCP - containerPort: 8080 name: http-prom protocol: TCP - containerPort: 9440 name: healthz protocol: TCP readinessProbe: httpGet: path: / port: http resources: limits: cpu: 1000m memory: 1Gi requests: cpu: 50m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /data name: data - mountPath: /tmp name: tmp nodeSelector: kubernetes.io/os: linux priorityClassName: system-cluster-critical securityContext: fsGroup: 1337 serviceAccountName: source-controller terminationGracePeriodSeconds: 10 tolerations: - key: node.kubernetes.io/controllers operator: Exists volumes: - emptyDir: {} name: data - emptyDir: {} name: tmp --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: kustomize-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: kustomizations.kustomize.toolkit.fluxcd.io spec: group: kustomize.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-appliers kind: Kustomization listKind: KustomizationList plural: kustomizations shortNames: - ks singular: kustomization scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: Kustomization is the Schema for the kustomizations API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: |- KustomizationSpec defines the configuration to calculate the desired state from a Source using Kustomize. properties: buildMetadata: description: |- BuildMetadata specifies which kustomize build metadata should be added to the built resources. The allowed values are 'originAnnotations' to annotate resources with their source origin, and 'transformerAnnotations' to annotate resources with the transformers that produced them. items: description: BuildMetadataOption defines the supported buildMetadata options. enum: - originAnnotations - transformerAnnotations type: string type: array commonMetadata: description: |- CommonMetadata specifies the common labels and annotations that are applied to all resources. Any existing label or annotation will be overridden if its key matches a common one. properties: annotations: additionalProperties: type: string description: Annotations to be added to the object's metadata. type: object labels: additionalProperties: type: string description: Labels to be added to the object's metadata. type: object type: object components: description: Components specifies relative paths to kustomize Components. items: type: string type: array decryption: description: Decrypt Kubernetes secrets before applying them on the cluster. properties: provider: description: Provider is the name of the decryption engine. enum: - sops type: string secretRef: description: |- The secret name containing the private OpenPGP keys used for decryption. A static credential for a cloud provider defined inside the Secret takes priority to secret-less authentication with the ServiceAccountName field. properties: name: description: Name of the referent. type: string required: - name type: object serviceAccountName: description: |- ServiceAccountName is the name of the service account used to authenticate with KMS services from cloud providers. If a static credential for a given cloud provider is defined inside the Secret referenced by SecretRef, that static credential takes priority. type: string required: - provider type: object deletionPolicy: description: |- DeletionPolicy can be used to control garbage collection when this Kustomization is deleted. Valid values are ('MirrorPrune', 'Delete', 'WaitForTermination', 'Orphan'). 'MirrorPrune' mirrors the Prune field (orphan if false, delete if true). Defaults to 'MirrorPrune'. enum: - MirrorPrune - Delete - WaitForTermination - Orphan type: string dependsOn: description: |- DependsOn may contain a DependencyReference slice with references to Kustomization resources that must be ready before this Kustomization can be reconciled. items: description: |- DependencyReference contains enough information to locate the referenced Kubernetes resource object and optional CEL expression to assess its readiness. properties: name: description: Name of the referent. type: string namespace: description: |- Namespace of the referent, defaults to the namespace of the resource object that contains the reference. type: string readyExpr: description: |- ReadyExpr is a CEL expression that can be used to assess the readiness of a dependency. When specified, the built-in readiness check is replaced by the logic defined in the CEL expression. To make the CEL expression additive to the built-in readiness check, the feature gate `AdditiveCELDependencyCheck` must be set to `true`. type: string required: - name type: object type: array force: default: false description: |- Force instructs the controller to recreate resources when patching fails due to an immutable field change. type: boolean healthCheckExprs: description: |- HealthCheckExprs is a list of healthcheck expressions for evaluating the health of custom resources using Common Expression Language (CEL). The expressions are evaluated only when Wait or HealthChecks are specified. items: description: CustomHealthCheck defines the health check for custom resources. properties: apiVersion: description: APIVersion of the custom resource under evaluation. type: string current: description: |- Current is the CEL expression that determines if the status of the custom resource has reached the desired state. type: string failed: description: |- Failed is the CEL expression that determines if the status of the custom resource has failed to reach the desired state. type: string inProgress: description: |- InProgress is the CEL expression that determines if the status of the custom resource has not yet reached the desired state. type: string kind: description: Kind of the custom resource under evaluation. type: string required: - apiVersion - current type: object type: array healthChecks: description: A list of resources to be included in the health assessment. items: description: |- NamespacedObjectKindReference contains enough information to locate the typed referenced Kubernetes resource object in any namespace. properties: apiVersion: description: API version of the referent, if not specified the Kubernetes preferred version will be used. type: string kind: description: Kind of the referent. type: string name: description: Name of the referent. type: string namespace: description: Namespace of the referent, when not specified it acts as LocalObjectReference. type: string required: - kind - name type: object type: array ignore: description: |- Ignore is a list of rules for specifying which changes to ignore during drift detection. These rules are applied to the resources managed by the Kustomization and are used to exclude specific JSON pointer paths from the drift detection and apply process. items: description: |- IgnoreRule defines a rule to selectively disregard specific changes during the drift detection process. properties: paths: description: |- Paths is a list of JSON Pointer (RFC 6901) paths to be excluded from consideration in a Kubernetes object. items: type: string type: array target: description: |- Target is a selector for specifying Kubernetes objects to which this rule applies. If Target is not set, the Paths will be ignored for all Kubernetes objects within the manifest of the Kustomization. properties: annotationSelector: description: |- AnnotationSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource annotations. type: string group: description: |- Group is the API group to select resources from. Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string kind: description: |- Kind of the API Group to select resources from. Together with Group and Version it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string labelSelector: description: |- LabelSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource labels. type: string name: description: Name to match resources with. type: string namespace: description: Namespace to select resources from. type: string version: description: |- Version of the API Group to select resources from. Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string type: object required: - paths type: object type: array ignoreMissingComponents: description: |- IgnoreMissingComponents instructs the controller to ignore Components paths not found in source by removing them from the generated kustomization.yaml before running kustomize build. type: boolean images: description: |- Images is a list of (image name, new name, new tag or digest) for changing image names, tags or digests. This can also be achieved with a patch, but this operator is simpler to specify. items: description: Image contains an image name, a new name, a new tag or digest, which will replace the original name and tag. properties: digest: description: |- Digest is the value used to replace the original image tag. If digest is present NewTag value is ignored. type: string name: description: Name is a tag-less image name. type: string newName: description: NewName is the value used to replace the original name. type: string newTag: description: NewTag is the value used to replace the original tag. type: string required: - name type: object type: array interval: description: |- The interval at which to reconcile the Kustomization. This interval is approximate and may be subject to jitter to ensure efficient use of resources. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string kubeConfig: description: |- The KubeConfig for reconciling the Kustomization on a remote cluster. When used in combination with KustomizationSpec.ServiceAccountName, forces the controller to act on behalf of that Service Account at the target cluster. If the --default-service-account flag is set, its value will be used as a controller level fallback for when KustomizationSpec.ServiceAccountName is empty. properties: configMapRef: description: |- ConfigMapRef holds an optional name of a ConfigMap that contains the following keys: - `provider`: the provider to use. One of `aws`, `azure`, `gcp`, or `generic`. Required. - `cluster`: the fully qualified resource name of the Kubernetes cluster in the cloud provider API. Not used by the `generic` provider. Required when one of `address` or `ca.crt` is not set. - `address`: the address of the Kubernetes API server. Required for `generic`. For the other providers, if not specified, the first address in the cluster resource will be used, and if specified, it must match one of the addresses in the cluster resource. If audiences is not set, will be used as the audience for the `generic` provider. - `ca.crt`: the optional PEM-encoded CA certificate for the Kubernetes API server. If not set, the controller will use the CA certificate from the cluster resource. - `audiences`: the optional audiences as a list of line-break-separated strings for the Kubernetes ServiceAccount token. Defaults to the `address` for the `generic` provider, or to specific values for the other providers depending on the provider. - `serviceAccountName`: the optional name of the Kubernetes ServiceAccount in the same namespace that should be used for authentication. If not specified, the controller ServiceAccount will be used. Mutually exclusive with SecretRef. properties: name: description: Name of the referent. type: string required: - name type: object secretRef: description: |- SecretRef holds an optional name of a secret that contains a key with the kubeconfig file as the value. If no key is set, the key will default to 'value'. Mutually exclusive with ConfigMapRef. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling Kubernetes resources. Supported only for the generic provider. properties: key: description: Key in the Secret, when not specified an implementation-specific default key is used. type: string name: description: Name of the Secret. type: string required: - name type: object type: object x-kubernetes-validations: - message: exactly one of spec.kubeConfig.configMapRef or spec.kubeConfig.secretRef must be specified rule: has(self.configMapRef) || has(self.secretRef) - message: exactly one of spec.kubeConfig.configMapRef or spec.kubeConfig.secretRef must be specified rule: '!has(self.configMapRef) || !has(self.secretRef)' namePrefix: description: NamePrefix will prefix the names of all managed resources. maxLength: 200 minLength: 1 type: string nameSuffix: description: NameSuffix will suffix the names of all managed resources. maxLength: 200 minLength: 1 type: string patches: description: |- Strategic merge and JSON patches, defined as inline YAML objects, capable of targeting objects based on kind, label and annotation selectors. items: description: |- Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should be applied to. properties: patch: description: |- Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with an array of operation objects. type: string target: description: Target points to the resources that the patch document should be applied to. properties: annotationSelector: description: |- AnnotationSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource annotations. type: string group: description: |- Group is the API group to select resources from. Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string kind: description: |- Kind of the API Group to select resources from. Together with Group and Version it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string labelSelector: description: |- LabelSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource labels. type: string name: description: Name to match resources with. type: string namespace: description: Namespace to select resources from. type: string version: description: |- Version of the API Group to select resources from. Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string type: object required: - patch type: object type: array path: description: |- Path to the directory containing the kustomization.yaml file, or the set of plain YAMLs a kustomization.yaml should be generated for. Defaults to 'None', which translates to the root path of the SourceRef. type: string postBuild: description: |- PostBuild describes which actions to perform on the YAML manifest generated by building the kustomize overlay. properties: substitute: additionalProperties: type: string description: |- Substitute holds a map of key/value pairs. The variables defined in your YAML manifests that match any of the keys defined in the map will be substituted with the set value. Includes support for bash string replacement functions e.g. ${var:=default}, ${var:position} and ${var/substring/replacement}. type: object substituteFrom: description: |- SubstituteFrom holds references to ConfigMaps and Secrets containing the variables and their values to be substituted in the YAML manifests. The ConfigMap and the Secret data keys represent the var names, and they must match the vars declared in the manifests for the substitution to happen. items: description: |- SubstituteReference contains a reference to a resource containing the variables name and value. properties: kind: description: Kind of the values referent, valid values are ('Secret', 'ConfigMap'). enum: - Secret - ConfigMap type: string name: description: |- Name of the values referent. Should reside in the same namespace as the referring resource. maxLength: 253 minLength: 1 type: string optional: default: false description: |- Optional indicates whether the referenced resource must exist, or whether to tolerate its absence. If true and the referenced resource is absent, proceed as if the resource was present but empty, without any variables defined. type: boolean required: - kind - name type: object type: array substituteStrategy: description: |- SubstituteStrategy defines the strategy for substituting variables in the YAML manifests. Valid values are: - WithVariables (the default): require at least one variable to be defined, either through the inline map or through the resolved references to ConfigMaps and Secrets. - Always: perform the substitution even if no variables are defined. enum: - WithVariables - Always type: string type: object prune: description: Prune enables garbage collection. type: boolean retryInterval: description: |- The interval at which to retry a previously failed reconciliation. When not specified, the controller uses the KustomizationSpec.Interval value to retry failures. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string serviceAccountName: description: |- The name of the Kubernetes service account to impersonate when reconciling this Kustomization. type: string sourceRef: description: Reference of the source where the kustomization file is. properties: apiVersion: description: API version of the referent. type: string kind: description: Kind of the referent. enum: - OCIRepository - GitRepository - Bucket - ExternalArtifact type: string name: description: Name of the referent. type: string namespace: description: |- Namespace of the referent, defaults to the namespace of the Kubernetes resource object that contains the reference. type: string required: - kind - name type: object suspend: description: |- This flag tells the controller to suspend subsequent kustomize executions, it does not apply to already started executions. Defaults to false. type: boolean targetNamespace: description: |- TargetNamespace sets or overrides the namespace in the kustomization.yaml file. maxLength: 63 minLength: 1 type: string timeout: description: |- Timeout for validation, apply and health checking operations. Defaults to 'Interval' duration. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string wait: description: |- Wait instructs the controller to check the health of all the reconciled resources. When enabled, the HealthChecks are ignored. Defaults to false. type: boolean required: - interval - prune - sourceRef type: object status: default: observedGeneration: -1 description: KustomizationStatus defines the observed state of a kustomization. properties: conditions: items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array history: description: |- History contains a set of snapshots of the last reconciliation attempts tracking the revision, the state and the duration of each attempt. items: description: |- Snapshot represents a point-in-time record of a group of resources reconciliation, including timing information, status, and a unique digest identifier. properties: digest: description: Digest is the checksum in the format `:` of the resources in this snapshot. type: string firstReconciled: description: FirstReconciled is the time when this revision was first reconciled to the cluster. format: date-time type: string lastReconciled: description: LastReconciled is the time when this revision was last reconciled to the cluster. format: date-time type: string lastReconciledDuration: description: LastReconciledDuration is time it took to reconcile the resources in this revision. type: string lastReconciledStatus: description: LastReconciledStatus is the status of the last reconciliation. type: string metadata: additionalProperties: type: string description: Metadata contains additional information about the snapshot. type: object totalReconciliations: description: TotalReconciliations is the total number of reconciliations that have occurred for this snapshot. format: int64 type: integer required: - digest - firstReconciled - lastReconciled - lastReconciledDuration - lastReconciledStatus - totalReconciliations type: object type: array inventory: description: |- Inventory contains the list of Kubernetes resource object references that have been successfully applied. properties: entries: description: Entries of Kubernetes resource object references. items: description: ResourceRef contains the information necessary to locate a resource within a cluster. properties: id: description: |- ID is the string representation of the Kubernetes resource object's metadata, in the format '___'. type: string v: description: Version is the API version of the Kubernetes resource object's kind. type: string required: - id - v type: object type: array required: - entries type: object lastAppliedOriginRevision: description: |- The last successfully applied origin revision. Equals the origin revision of the applied Artifact from the referenced Source. Usually present on the Metadata of the applied Artifact and depends on the Source type, e.g. for OCI it's the value associated with the key "org.opencontainers.image.revision". type: string lastAppliedRevision: description: |- The last successfully applied revision. Equals the Revision of the applied Artifact from the referenced Source. type: string lastAttemptedRevision: description: LastAttemptedRevision is the revision of the last reconciliation attempt. type: string lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: ObservedGeneration is the last reconciled generation. format: int64 type: integer type: object type: object served: true storage: true subresources: status: {} --- apiVersion: v1 kind: ServiceAccount metadata: labels: app.kubernetes.io/component: kustomize-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: kustomize-controller namespace: flux-system --- apiVersion: apps/v1 kind: Deployment metadata: labels: app.kubernetes.io/component: kustomize-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: kustomize-controller namespace: flux-system spec: replicas: 1 selector: matchLabels: app: kustomize-controller template: metadata: annotations: prometheus.io/port: "8080" prometheus.io/scrape: "true" labels: app: kustomize-controller app.kubernetes.io/component: kustomize-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest spec: containers: - args: - --events-addr=http://notification-controller.$(RUNTIME_NAMESPACE).svc.cluster.local./ - --watch-all-namespaces=true - --log-level=info - --log-encoding=json - --enable-leader-election env: - name: RUNTIME_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: GOMEMLIMIT valueFrom: resourceFieldRef: containerName: manager resource: limits.memory image: ghcr.io/fluxcd/kustomize-controller:v1.9.4 imagePullPolicy: IfNotPresent livenessProbe: httpGet: path: /healthz port: healthz name: manager ports: - containerPort: 8080 name: http-prom protocol: TCP - containerPort: 9440 name: healthz protocol: TCP readinessProbe: httpGet: path: /readyz port: healthz resources: limits: cpu: 1000m memory: 1Gi requests: cpu: 100m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /tmp name: temp nodeSelector: kubernetes.io/os: linux priorityClassName: system-cluster-critical securityContext: fsGroup: 1337 serviceAccountName: kustomize-controller terminationGracePeriodSeconds: 60 tolerations: - key: node.kubernetes.io/controllers operator: Exists volumes: - emptyDir: {} name: temp --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: helm-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: helmreleases.helm.toolkit.fluxcd.io spec: group: helm.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-appliers kind: HelmRelease listKind: HelmReleaseList plural: helmreleases shortNames: - hr singular: helmrelease scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v2 schema: openAPIV3Schema: description: HelmRelease is the Schema for the helmreleases API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: HelmReleaseSpec defines the desired state of a Helm release. properties: chart: description: |- Chart defines the template of the v1.HelmChart that should be created for this HelmRelease. properties: metadata: description: ObjectMeta holds the template for metadata like labels and annotations. properties: annotations: additionalProperties: type: string description: |- Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ type: object labels: additionalProperties: type: string description: |- Map of string keys and values that can be used to organize and categorize (scope and select) objects. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ type: object type: object spec: description: Spec holds the template for the v1.HelmChartSpec for this HelmRelease. properties: chart: description: The name or path the Helm chart is available at in the SourceRef. maxLength: 2048 minLength: 1 type: string ignoreMissingValuesFiles: description: IgnoreMissingValuesFiles controls whether to silently ignore missing values files rather than failing. type: boolean interval: description: |- Interval at which to check the v1.Source for updates. Defaults to 'HelmReleaseSpec.Interval'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string reconcileStrategy: default: ChartVersion description: |- Determines what enables the creation of a new artifact. Valid values are ('ChartVersion', 'Revision'). See the documentation of the values for an explanation on their behavior. Defaults to ChartVersion when omitted. enum: - ChartVersion - Revision type: string sourceRef: description: The name and namespace of the v1.Source the chart is available at. properties: apiVersion: description: APIVersion of the referent. type: string kind: description: Kind of the referent. enum: - HelmRepository - GitRepository - Bucket type: string name: description: Name of the referent. maxLength: 253 minLength: 1 type: string namespace: description: Namespace of the referent. maxLength: 63 minLength: 1 type: string required: - kind - name type: object valuesFiles: description: |- Alternative list of values files to use as the chart values (values.yaml is not included by default), expected to be a relative path in the SourceRef. Values files are merged in the order of this list with the last file overriding the first. Ignored when omitted. items: type: string type: array verify: description: |- Verify contains the secret name containing the trusted public keys used to verify the signature and specifies which provider to use to check whether OCI image is authentic. This field is only supported for OCI sources. Chart dependencies, which are not bundled in the umbrella chart artifact, are not verified. properties: provider: default: cosign description: Provider specifies the technology used to sign the OCI Helm chart. enum: - cosign - notation type: string secretRef: description: |- SecretRef specifies the Kubernetes Secret containing the trusted public keys. properties: name: description: Name of the referent. type: string required: - name type: object required: - provider type: object version: default: '*' description: |- Version semver expression, ignored for charts from v1.GitRepository and v1beta2.Bucket sources. Defaults to latest when omitted. type: string required: - chart - sourceRef type: object required: - spec type: object chartRef: description: |- ChartRef holds a reference to a source controller resource containing the Helm chart artifact. properties: apiVersion: description: APIVersion of the referent. type: string kind: description: Kind of the referent. enum: - OCIRepository - HelmChart - ExternalArtifact type: string name: description: Name of the referent. maxLength: 253 minLength: 1 type: string namespace: description: |- Namespace of the referent, defaults to the namespace of the Kubernetes resource object that contains the reference. maxLength: 63 minLength: 1 type: string required: - kind - name type: object commonMetadata: description: |- CommonMetadata specifies the common labels and annotations that are applied to all resources. Any existing label or annotation will be overridden if its key matches a common one. properties: annotations: additionalProperties: type: string description: Annotations to be added to the object's metadata. type: object labels: additionalProperties: type: string description: Labels to be added to the object's metadata. type: object type: object dependsOn: description: |- DependsOn may contain a DependencyReference slice with references to HelmRelease resources that must be ready before this HelmRelease can be reconciled. items: description: |- DependencyReference contains enough information to locate the referenced Kubernetes resource object and optional CEL expression to assess its readiness. properties: name: description: Name of the referent. type: string namespace: description: |- Namespace of the referent, defaults to the namespace of the resource object that contains the reference. type: string readyExpr: description: |- ReadyExpr is a CEL expression that can be used to assess the readiness of a dependency. When specified, the built-in readiness check is replaced by the logic defined in the CEL expression. To make the CEL expression additive to the built-in readiness check, the feature gate `AdditiveCELDependencyCheck` must be set to `true`. type: string required: - name type: object type: array driftDetection: description: |- DriftDetection holds the configuration for detecting and handling differences between the manifest in the Helm storage and the resources currently existing in the cluster. properties: ignore: description: |- Ignore contains a list of rules for specifying which changes to ignore during diffing. items: description: |- IgnoreRule defines a rule to selectively disregard specific changes during the drift detection process. properties: paths: description: |- Paths is a list of JSON Pointer (RFC 6901) paths to be excluded from consideration in a Kubernetes object. items: type: string type: array target: description: |- Target is a selector for specifying Kubernetes objects to which this rule applies. If Target is not set, the Paths will be ignored for all Kubernetes objects within the manifest of the Helm release. properties: annotationSelector: description: |- AnnotationSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource annotations. type: string group: description: |- Group is the API group to select resources from. Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string kind: description: |- Kind of the API Group to select resources from. Together with Group and Version it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string labelSelector: description: |- LabelSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource labels. type: string name: description: Name to match resources with. type: string namespace: description: Namespace to select resources from. type: string version: description: |- Version of the API Group to select resources from. Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string type: object required: - paths type: object type: array mode: description: |- Mode defines how differences should be handled between the Helm manifest and the manifest currently applied to the cluster. If not explicitly set, it defaults to DiffModeDisabled. enum: - enabled - warn - disabled type: string type: object healthCheckExprs: description: |- HealthCheckExprs is a list of healthcheck expressions for evaluating the health of custom resources using Common Expression Language (CEL). The expressions are evaluated only when the specific Helm action taking place has wait enabled, i.e. DisableWait is false, and the 'poller' WaitStrategy is used. items: description: CustomHealthCheck defines the health check for custom resources. properties: apiVersion: description: APIVersion of the custom resource under evaluation. type: string current: description: |- Current is the CEL expression that determines if the status of the custom resource has reached the desired state. type: string failed: description: |- Failed is the CEL expression that determines if the status of the custom resource has failed to reach the desired state. type: string inProgress: description: |- InProgress is the CEL expression that determines if the status of the custom resource has not yet reached the desired state. type: string kind: description: Kind of the custom resource under evaluation. type: string required: - apiVersion - current type: object type: array install: description: Install holds the configuration for Helm install actions for this HelmRelease. properties: crds: description: |- CRDs upgrade CRDs from the Helm Chart's crds directory according to the CRD upgrade policy provided here. Valid values are `Skip`, `Create` or `CreateReplace`. Default is `Create` and if omitted CRDs are installed but not updated. Skip: do neither install nor replace (update) any CRDs. Create: new CRDs are created, existing CRDs are neither updated nor deleted. CreateReplace: new CRDs are created, existing CRDs are updated (replaced) but not deleted. By default, CRDs are applied (installed) during Helm install action. With this option users can opt in to CRD replace existing CRDs on Helm install actions, which is not (yet) natively supported by Helm. https://helm.sh/docs/chart_best_practices/custom_resource_definitions. enum: - Skip - Create - CreateReplace type: string createNamespace: description: |- CreateNamespace tells the Helm install action to create the HelmReleaseSpec.TargetNamespace if it does not exist yet. On uninstall, the namespace will not be garbage collected. type: boolean disableHooks: description: DisableHooks prevents hooks from running during the Helm install action. type: boolean disableOpenAPIValidation: description: |- DisableOpenAPIValidation prevents the Helm install action from validating rendered templates against the Kubernetes OpenAPI Schema. type: boolean disableSchemaValidation: description: |- DisableSchemaValidation prevents the Helm install action from validating the values against the JSON Schema. type: boolean disableTakeOwnership: description: |- DisableTakeOwnership disables taking ownership of existing resources during the Helm install action. Defaults to false. type: boolean disableWait: description: |- DisableWait disables the waiting for resources to be ready after a Helm install has been performed. type: boolean disableWaitForJobs: description: |- DisableWaitForJobs disables waiting for jobs to complete after a Helm install has been performed. type: boolean remediation: description: |- Remediation holds the remediation configuration for when the Helm install action for the HelmRelease fails. The default is to not perform any action. properties: ignoreTestFailures: description: |- IgnoreTestFailures tells the controller to skip remediation when the Helm tests are run after an install action but fail. Defaults to 'Test.IgnoreFailures'. type: boolean remediateLastFailure: description: |- RemediateLastFailure tells the controller to remediate the last failure, when no retries remain. Defaults to 'false'. type: boolean retries: description: |- Retries is the number of retries that should be attempted on failures before bailing. Remediation, using an uninstall, is performed between each attempt. Defaults to '0', a negative integer equals to unlimited retries. type: integer type: object replace: description: |- Replace tells the Helm install action to re-use the 'ReleaseName', but only if that name is a deleted release which remains in the history. type: boolean serverSideApply: description: |- ServerSideApply enables server-side apply for resources during install. Defaults to true (or false when UseHelm3Defaults feature gate is enabled). type: boolean skipCRDs: description: |- SkipCRDs tells the Helm install action to not install any CRDs. By default, CRDs are installed if not already present. Deprecated use CRD policy (`crds`) attribute with value `Skip` instead. type: boolean strategy: description: |- Strategy defines the install strategy to use for this HelmRelease. Defaults to 'RemediateOnFailure', or 'RetryOnFailure' when the DefaultToRetryOnFailure feature gate is enabled. properties: name: description: Name of the install strategy. enum: - RemediateOnFailure - RetryOnFailure type: string retryInterval: description: |- RetryInterval is the interval at which to retry a failed install. Can be used only when Name is set to RetryOnFailure. Defaults to '5m'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string required: - name type: object x-kubernetes-validations: - message: .retryInterval cannot be set when .name is 'RemediateOnFailure' rule: '!has(self.retryInterval) || self.name != ''RemediateOnFailure''' timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation (like Jobs for hooks) during the performance of a Helm install action. Defaults to 'HelmReleaseSpec.Timeout'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string type: object interval: description: Interval at which to reconcile the Helm release. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string kubeConfig: description: |- KubeConfig for reconciling the HelmRelease on a remote cluster. When used in combination with HelmReleaseSpec.ServiceAccountName, forces the controller to act on behalf of that Service Account at the target cluster. If the --default-service-account flag is set, its value will be used as a controller level fallback for when HelmReleaseSpec.ServiceAccountName is empty. properties: configMapRef: description: |- ConfigMapRef holds an optional name of a ConfigMap that contains the following keys: - `provider`: the provider to use. One of `aws`, `azure`, `gcp`, or `generic`. Required. - `cluster`: the fully qualified resource name of the Kubernetes cluster in the cloud provider API. Not used by the `generic` provider. Required when one of `address` or `ca.crt` is not set. - `address`: the address of the Kubernetes API server. Required for `generic`. For the other providers, if not specified, the first address in the cluster resource will be used, and if specified, it must match one of the addresses in the cluster resource. If audiences is not set, will be used as the audience for the `generic` provider. - `ca.crt`: the optional PEM-encoded CA certificate for the Kubernetes API server. If not set, the controller will use the CA certificate from the cluster resource. - `audiences`: the optional audiences as a list of line-break-separated strings for the Kubernetes ServiceAccount token. Defaults to the `address` for the `generic` provider, or to specific values for the other providers depending on the provider. - `serviceAccountName`: the optional name of the Kubernetes ServiceAccount in the same namespace that should be used for authentication. If not specified, the controller ServiceAccount will be used. Mutually exclusive with SecretRef. properties: name: description: Name of the referent. type: string required: - name type: object secretRef: description: |- SecretRef holds an optional name of a secret that contains a key with the kubeconfig file as the value. If no key is set, the key will default to 'value'. Mutually exclusive with ConfigMapRef. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling Kubernetes resources. Supported only for the generic provider. properties: key: description: Key in the Secret, when not specified an implementation-specific default key is used. type: string name: description: Name of the Secret. type: string required: - name type: object type: object x-kubernetes-validations: - message: exactly one of spec.kubeConfig.configMapRef or spec.kubeConfig.secretRef must be specified rule: has(self.configMapRef) || has(self.secretRef) - message: exactly one of spec.kubeConfig.configMapRef or spec.kubeConfig.secretRef must be specified rule: '!has(self.configMapRef) || !has(self.secretRef)' maxHistory: description: |- MaxHistory is the number of revisions saved by Helm for this HelmRelease. Use '0' for an unlimited number of revisions; defaults to '5'. type: integer persistentClient: description: |- PersistentClient tells the controller to use a persistent Kubernetes client for this release. When enabled, the client will be reused for the duration of the reconciliation, instead of being created and destroyed for each (step of a) Helm action. This can improve performance, but may cause issues with some Helm charts that for example do create Custom Resource Definitions during installation outside Helm's CRD lifecycle hooks, which are then not observed to be available by e.g. post-install hooks. If not set, it defaults to true. type: boolean postRenderStrategy: description: |- PostRenderStrategy defines the strategy for sending hooks to post-renderers. Valid values are 'nohooks' (hooks not sent to post-renderers, Helm 3 behavior), 'combined' (hooks and templates sent together, Helm 4 default), and 'separate' (hooks and templates sent in separate streams, Helm 4.2 opt-in). Defaults to 'combined', or 'nohooks' when the UseHelm3Defaults feature gate is enabled. enum: - nohooks - combined - separate type: string postRenderers: description: |- PostRenderers holds an array of Helm PostRenderers, which will be applied in order of their definition. items: description: PostRenderer contains a Helm PostRenderer specification. properties: kustomize: description: Kustomization to apply as PostRenderer. properties: images: description: |- Images is a list of (image name, new name, new tag or digest) for changing image names, tags or digests. This can also be achieved with a patch, but this operator is simpler to specify. items: description: Image contains an image name, a new name, a new tag or digest, which will replace the original name and tag. properties: digest: description: |- Digest is the value used to replace the original image tag. If digest is present NewTag value is ignored. type: string name: description: Name is a tag-less image name. type: string newName: description: NewName is the value used to replace the original name. type: string newTag: description: NewTag is the value used to replace the original tag. type: string required: - name type: object type: array patches: description: |- Strategic merge and JSON patches, defined as inline YAML objects, capable of targeting objects based on kind, label and annotation selectors. items: description: |- Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should be applied to. properties: patch: description: |- Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with an array of operation objects. type: string target: description: Target points to the resources that the patch document should be applied to. properties: annotationSelector: description: |- AnnotationSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource annotations. type: string group: description: |- Group is the API group to select resources from. Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string kind: description: |- Kind of the API Group to select resources from. Together with Group and Version it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string labelSelector: description: |- LabelSelector is a string that follows the label selection expression https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api It matches with the resource labels. type: string name: description: Name to match resources with. type: string namespace: description: Namespace to select resources from. type: string version: description: |- Version of the API Group to select resources from. Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md type: string type: object required: - patch type: object type: array type: object type: object type: array releaseName: description: |- ReleaseName used for the Helm release. Defaults to a composition of '[TargetNamespace-]Name'. maxLength: 53 minLength: 1 type: string rollback: description: Rollback holds the configuration for Helm rollback actions for this HelmRelease. properties: cleanupOnFail: description: |- CleanupOnFail allows deletion of new resources created during the Helm rollback action when it fails. type: boolean disableHooks: description: DisableHooks prevents hooks from running during the Helm rollback action. type: boolean disableWait: description: |- DisableWait disables the waiting for resources to be ready after a Helm rollback has been performed. type: boolean disableWaitForJobs: description: |- DisableWaitForJobs disables waiting for jobs to complete after a Helm rollback has been performed. type: boolean force: description: |- Force forces resource updates through a replacement strategy that avoids 3-way merge conflicts on client-side apply. This field is ignored for server-side apply (which always forces conflicts with other field managers). type: boolean recreate: description: |- Recreate performs pod restarts for any managed workloads. Deprecated: This behavior was deprecated in Helm 3: - Deprecation: https://github.com/helm/helm/pull/6463 - Removal: https://github.com/helm/helm/pull/31023 After helm-controller was upgraded to the Helm 4 SDK, this field is no longer functional and will print a warning if set to true. It will also be removed in a future release. type: boolean serverSideApply: description: |- ServerSideApply enables server-side apply for resources during rollback. Can be "enabled", "disabled", or "auto". When "auto", server-side apply usage will be based on the release's previous usage. Defaults to "auto". enum: - enabled - disabled - auto type: string timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation (like Jobs for hooks) during the performance of a Helm rollback action. Defaults to 'HelmReleaseSpec.Timeout'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string type: object serviceAccountName: description: |- The name of the Kubernetes service account to impersonate when reconciling this HelmRelease. maxLength: 253 minLength: 1 type: string storageNamespace: description: |- StorageNamespace used for the Helm storage. Defaults to the namespace of the HelmRelease. maxLength: 63 minLength: 1 type: string suspend: description: |- Suspend tells the controller to suspend reconciliation for this HelmRelease, it does not apply to already started reconciliations. Defaults to false. type: boolean targetNamespace: description: |- TargetNamespace to target when performing operations for the HelmRelease. Defaults to the namespace of the HelmRelease. maxLength: 63 minLength: 1 type: string test: description: Test holds the configuration for Helm test actions for this HelmRelease. properties: enable: description: |- Enable enables Helm test actions for this HelmRelease after an Helm install or upgrade action has been performed. type: boolean filters: description: Filters is a list of tests to run or exclude from running. items: description: Filter holds the configuration for individual Helm test filters. properties: exclude: description: Exclude specifies whether the named test should be excluded. type: boolean name: description: Name is the name of the test. maxLength: 253 minLength: 1 type: string required: - name type: object type: array ignoreFailures: description: |- IgnoreFailures tells the controller to skip remediation when the Helm tests are run but fail. Can be overwritten for tests run after install or upgrade actions in 'Install.IgnoreTestFailures' and 'Upgrade.IgnoreTestFailures'. type: boolean timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation during the performance of a Helm test action. Defaults to 'HelmReleaseSpec.Timeout'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string type: object timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation (like Jobs for hooks) during the performance of a Helm action. Defaults to '5m0s'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string uninstall: description: Uninstall holds the configuration for Helm uninstall actions for this HelmRelease. properties: deletionPropagation: default: background description: |- DeletionPropagation specifies the deletion propagation policy when a Helm uninstall is performed. enum: - background - foreground - orphan type: string disableHooks: description: DisableHooks prevents hooks from running during the Helm rollback action. type: boolean disableWait: description: |- DisableWait disables waiting for all the resources to be deleted after a Helm uninstall is performed. type: boolean keepHistory: description: |- KeepHistory tells Helm to remove all associated resources and mark the release as deleted, but retain the release history. type: boolean timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation (like Jobs for hooks) during the performance of a Helm uninstall action. Defaults to 'HelmReleaseSpec.Timeout'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string type: object upgrade: description: Upgrade holds the configuration for Helm upgrade actions for this HelmRelease. properties: chartNameChangeStrategy: description: |- ChartNameChangeStrategy defines the strategy to use when a Helm chart name changes. Valid values are 'Reinstall' or 'InPlaceUpdate'. Defaults to 'Reinstall' if omitted. Reinstall: Reinstall the Helm release, uninstalling the existing Helm release. InPlaceUpdate: Update the Helm release in place. enum: - InPlaceUpdate - Reinstall type: string cleanupOnFail: description: |- CleanupOnFail allows deletion of new resources created during the Helm upgrade action when it fails. type: boolean crds: description: |- CRDs upgrade CRDs from the Helm Chart's crds directory according to the CRD upgrade policy provided here. Valid values are `Skip`, `Create` or `CreateReplace`. Default is `Skip` and if omitted CRDs are neither installed nor upgraded. Skip: do neither install nor replace (update) any CRDs. Create: new CRDs are created, existing CRDs are neither updated nor deleted. CreateReplace: new CRDs are created, existing CRDs are updated (replaced) but not deleted. By default, CRDs are not applied during Helm upgrade action. With this option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm. https://helm.sh/docs/chart_best_practices/custom_resource_definitions. enum: - Skip - Create - CreateReplace type: string disableHooks: description: DisableHooks prevents hooks from running during the Helm upgrade action. type: boolean disableOpenAPIValidation: description: |- DisableOpenAPIValidation prevents the Helm upgrade action from validating rendered templates against the Kubernetes OpenAPI Schema. type: boolean disableSchemaValidation: description: |- DisableSchemaValidation prevents the Helm upgrade action from validating the values against the JSON Schema. type: boolean disableTakeOwnership: description: |- DisableTakeOwnership disables taking ownership of existing resources during the Helm upgrade action. Defaults to false. type: boolean disableWait: description: |- DisableWait disables the waiting for resources to be ready after a Helm upgrade has been performed. type: boolean disableWaitForJobs: description: |- DisableWaitForJobs disables waiting for jobs to complete after a Helm upgrade has been performed. type: boolean force: description: |- Force forces resource updates through a replacement strategy that avoids 3-way merge conflicts on client-side apply. This field is ignored for server-side apply (which always forces conflicts with other field managers). type: boolean preserveValues: description: |- PreserveValues will make Helm reuse the last release's values and merge in overrides from 'Values'. Setting this flag makes the HelmRelease non-declarative. type: boolean remediation: description: |- Remediation holds the remediation configuration for when the Helm upgrade action for the HelmRelease fails. The default is to not perform any action. properties: ignoreTestFailures: description: |- IgnoreTestFailures tells the controller to skip remediation when the Helm tests are run after an upgrade action but fail. Defaults to 'Test.IgnoreFailures'. type: boolean remediateLastFailure: description: |- RemediateLastFailure tells the controller to remediate the last failure, when no retries remain. Defaults to 'false' unless 'Retries' is greater than 0. type: boolean retries: description: |- Retries is the number of retries that should be attempted on failures before bailing. Remediation, using 'Strategy', is performed between each attempt. Defaults to '0', a negative integer equals to unlimited retries. type: integer strategy: description: Strategy to use for failure remediation. Defaults to 'rollback'. enum: - rollback - uninstall type: string type: object serverSideApply: description: |- ServerSideApply enables server-side apply for resources during upgrade. Can be "enabled", "disabled", or "auto". When "auto", server-side apply usage will be based on the release's previous usage. Defaults to "auto". enum: - enabled - disabled - auto type: string strategy: description: |- Strategy defines the upgrade strategy to use for this HelmRelease. Defaults to 'RemediateOnFailure', or 'RetryOnFailure' when the DefaultToRetryOnFailure feature gate is enabled. properties: name: description: Name of the upgrade strategy. enum: - RemediateOnFailure - RetryOnFailure type: string retryInterval: description: |- RetryInterval is the interval at which to retry a failed upgrade. Can be used only when Name is set to RetryOnFailure. Defaults to '5m'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string required: - name type: object x-kubernetes-validations: - message: .retryInterval can only be set when .name is 'RetryOnFailure' rule: '!has(self.retryInterval) || self.name == ''RetryOnFailure''' timeout: description: |- Timeout is the time to wait for any individual Kubernetes operation (like Jobs for hooks) during the performance of a Helm upgrade action. Defaults to 'HelmReleaseSpec.Timeout'. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string type: object values: description: Values holds the values for this Helm release. x-kubernetes-preserve-unknown-fields: true valuesFrom: description: |- ValuesFrom holds references to resources containing Helm values for this HelmRelease, and information about how they should be merged. items: description: |- ValuesReference contains a reference to a resource containing Helm values, and optionally the key they can be found at. properties: kind: description: Kind of the values referent, valid values are ('Secret', 'ConfigMap'). enum: - Secret - ConfigMap type: string literal: description: |- Literal marks this ValuesReference as a literal value. When set in combination with TargetPath, the referenced value is merged at the target path without interpreting Helm's `--set` syntax (commas, brackets, dots, equal signs, etc.), mirroring the behavior of `helm --set-literal`. This is the only safe way to inject arbitrary file content (config files, JSON blobs, multi-line strings containing special characters) through `valuesFrom`. Has no effect when TargetPath is empty: in that mode the referenced value is always YAML-merged at the root. type: boolean name: description: |- Name of the values referent. Should reside in the same namespace as the referring resource. maxLength: 253 minLength: 1 type: string optional: description: |- Optional marks this ValuesReference as optional. When set, a not found error for the values reference is ignored, but any ValuesKey, TargetPath or transient error will still result in a reconciliation failure. type: boolean targetPath: description: |- TargetPath is the YAML dot notation path the value should be merged at. When set, the ValuesKey is expected to be a single flat value. Defaults to 'None', which results in the values getting merged at the root. maxLength: 250 pattern: ^([a-zA-Z0-9_\-.\\\/]|\[[0-9]{1,5}\])+$ type: string valuesKey: description: |- ValuesKey is the data key where the values.yaml or a specific value can be found at. Defaults to 'values.yaml'. maxLength: 253 pattern: ^[\-._a-zA-Z0-9]+$ type: string required: - kind - name type: object type: array waitStrategy: description: |- WaitStrategy defines Helm's wait strategy for waiting for applied resources to become ready. properties: name: description: |- Name is Helm's wait strategy for waiting for applied resources to become ready. One of 'poller' or 'legacy'. The 'poller' strategy uses kstatus to poll resource statuses, while the 'legacy' strategy uses Helm v3's waiting logic. Defaults to 'poller', or to 'legacy' when UseHelm3Defaults feature gate is enabled. enum: - poller - legacy type: string required: - name type: object required: - interval type: object x-kubernetes-validations: - message: either chart or chartRef must be set rule: (has(self.chart) && !has(self.chartRef)) || (!has(self.chart) && has(self.chartRef)) status: default: observedGeneration: -1 description: HelmReleaseStatus defines the observed state of a HelmRelease. properties: conditions: description: Conditions holds the conditions for the HelmRelease. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array failures: description: |- Failures is the reconciliation failure count against the latest desired state. It is reset after a successful reconciliation. format: int64 type: integer helmChart: description: |- HelmChart is the namespaced name of the HelmChart resource created by the controller for the HelmRelease. type: string history: description: |- History holds the history of Helm releases performed for this HelmRelease up to the last successfully completed release. items: description: |- Snapshot captures a point-in-time copy of the status information for a Helm release, as managed by the controller. properties: action: description: Action is the action that resulted in this snapshot being created. type: string apiVersion: description: |- APIVersion is the API version of the Snapshot. When the calculation method of the Digest field is changed, this field will be used to distinguish between the old and new methods. type: string appVersion: description: AppVersion is the chart app version of the release object in storage. type: string chartName: description: ChartName is the chart name of the release object in storage. type: string chartVersion: description: |- ChartVersion is the chart version of the release object in storage. type: string configDigest: description: |- ConfigDigest is the checksum of the config (better known as "values") of the release object in storage. It has the format of `:`. type: string deleted: description: Deleted is when the release was deleted. format: date-time type: string digest: description: |- Digest is the checksum of the release object in storage. It has the format of `:`. type: string firstDeployed: description: FirstDeployed is when the release was first deployed. format: date-time type: string lastDeployed: description: LastDeployed is when the release was last deployed. format: date-time type: string name: description: Name is the name of the release. type: string namespace: description: Namespace is the namespace the release is deployed to. type: string ociDigest: description: OCIDigest is the digest of the OCI artifact associated with the release. type: string status: description: Status is the current state of the release. type: string testHooks: additionalProperties: description: |- TestHookStatus holds the status information for a test hook as observed to be run by the controller. properties: lastCompleted: description: LastCompleted is the time the test hook last completed. format: date-time type: string lastStarted: description: LastStarted is the time the test hook was last started. format: date-time type: string phase: description: Phase the test hook was observed to be in. type: string type: object description: |- TestHooks is the list of test hooks for the release as observed to be run by the controller. type: object version: description: Version is the version of the release object in storage. type: integer required: - chartName - chartVersion - configDigest - digest - firstDeployed - lastDeployed - name - namespace - status - version type: object type: array installFailures: description: |- InstallFailures is the install failure count against the latest desired state. It is reset after a successful reconciliation. format: int64 type: integer inventory: description: |- Inventory contains the list of Kubernetes resource object references that have been applied for this release. properties: entries: description: Entries of Kubernetes resource object references. items: description: ResourceRef contains the information necessary to locate a resource within a cluster. properties: id: description: |- ID is the string representation of the Kubernetes resource object's metadata, in the format '___'. type: string v: description: Version is the API version of the Kubernetes resource object's kind. type: string required: - id - v type: object type: array required: - entries type: object lastAttemptedConfigDigest: description: |- LastAttemptedConfigDigest is the digest for the config (better known as "values") of the last reconciliation attempt. type: string lastAttemptedGeneration: description: |- LastAttemptedGeneration is the last generation the controller attempted to reconcile. format: int64 type: integer lastAttemptedReleaseAction: description: |- LastAttemptedReleaseAction is the last release action performed for this HelmRelease. It is used to determine the active retry or remediation strategy. enum: - install - upgrade type: string lastAttemptedReleaseActionDuration: description: |- LastAttemptedReleaseActionDuration is the duration of the last release action performed for this HelmRelease. type: string lastAttemptedRevision: description: |- LastAttemptedRevision is the Source revision of the last reconciliation attempt. For OCIRepository sources, the 12 first characters of the digest are appended to the chart version e.g. "1.2.3+1234567890ab". type: string lastAttemptedRevisionDigest: description: |- LastAttemptedRevisionDigest is the digest of the last reconciliation attempt. This is only set for OCIRepository sources. type: string lastAttemptedValuesChecksum: description: |- LastAttemptedValuesChecksum is the SHA1 checksum for the values of the last reconciliation attempt. Deprecated: Use LastAttemptedConfigDigest instead. type: string lastHandledForceAt: description: |- LastHandledForceAt holds the value of the most recent force request value, so a change of the annotation value can be detected. type: string lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string lastHandledResetAt: description: |- LastHandledResetAt holds the value of the most recent reset request value, so a change of the annotation value can be detected. type: string lastReleaseRevision: description: |- LastReleaseRevision is the revision of the last successful Helm release. Deprecated: Use History instead. type: integer observedCommonMetadataDigest: description: |- ObservedCommonMetadataDigest is the digest for the common metadata of the last successful reconciliation attempt. type: string observedGeneration: description: ObservedGeneration is the last observed generation. format: int64 type: integer observedPostRenderersDigest: description: |- ObservedPostRenderersDigest is the digest for the post-renderers of the last successful reconciliation attempt. type: string storageNamespace: description: |- StorageNamespace is the namespace of the Helm release storage for the current release. maxLength: 63 minLength: 1 type: string upgradeFailures: description: |- UpgradeFailures is the upgrade failure count against the latest desired state. It is reset after a successful reconciliation. format: int64 type: integer type: object type: object served: true storage: true subresources: status: {} --- apiVersion: v1 kind: ServiceAccount metadata: labels: app.kubernetes.io/component: helm-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: helm-controller namespace: flux-system --- apiVersion: apps/v1 kind: Deployment metadata: labels: app.kubernetes.io/component: helm-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: helm-controller namespace: flux-system spec: replicas: 1 selector: matchLabels: app: helm-controller template: metadata: annotations: prometheus.io/port: "8080" prometheus.io/scrape: "true" labels: app: helm-controller app.kubernetes.io/component: helm-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest spec: containers: - args: - --events-addr=http://notification-controller.$(RUNTIME_NAMESPACE).svc.cluster.local./ - --watch-all-namespaces=true - --log-level=info - --log-encoding=json - --enable-leader-election env: - name: RUNTIME_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: GOMEMLIMIT valueFrom: resourceFieldRef: containerName: manager resource: limits.memory image: ghcr.io/fluxcd/helm-controller:v1.6.3 imagePullPolicy: IfNotPresent livenessProbe: httpGet: path: /healthz port: healthz name: manager ports: - containerPort: 8080 name: http-prom protocol: TCP - containerPort: 9440 name: healthz protocol: TCP readinessProbe: httpGet: path: /readyz port: healthz resources: limits: cpu: 1000m memory: 1Gi requests: cpu: 100m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /tmp name: temp nodeSelector: kubernetes.io/os: linux priorityClassName: system-cluster-critical securityContext: fsGroup: 1337 serviceAccountName: helm-controller terminationGracePeriodSeconds: 600 tolerations: - key: node.kubernetes.io/controllers operator: Exists volumes: - emptyDir: {} name: temp --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: alerts.notification.toolkit.fluxcd.io spec: group: notification.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-notifications kind: Alert listKind: AlertList plural: alerts singular: alert scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1beta3 schema: openAPIV3Schema: description: Alert is the Schema for the alerts API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: AlertSpec defines an alerting rule for events involving a list of objects. properties: eventMetadata: additionalProperties: type: string description: |- EventMetadata is an optional field for adding metadata to events dispatched by the controller. This can be used for enhancing the context of the event. If a field would override one already present on the original event as generated by the emitter, then the override doesn't happen, i.e. the original value is preserved, and an info log is printed. type: object eventSeverity: default: info description: |- EventSeverity specifies how to filter events based on severity. If set to 'info' no events will be filtered. enum: - info - error type: string eventSources: description: |- EventSources specifies how to filter events based on the involved object kind, name and namespace. items: description: |- CrossNamespaceObjectReference contains enough information to let you locate the typed referenced object at cluster level properties: apiVersion: description: API version of the referent type: string kind: description: Kind of the referent enum: - Bucket - GitRepository - Kustomization - HelmRelease - HelmChart - HelmRepository - ImageRepository - ImagePolicy - ImageUpdateAutomation - OCIRepository - ArtifactGenerator - ExternalArtifact type: string matchLabels: additionalProperties: type: string description: |- MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed. MatchLabels requires the name to be set to `*`. type: object name: description: |- Name of the referent If multiple resources are targeted `*` may be set. maxLength: 253 minLength: 1 type: string namespace: description: Namespace of the referent maxLength: 253 minLength: 1 type: string required: - kind - name type: object type: array exclusionList: description: |- ExclusionList specifies a list of Golang regular expressions to be used for excluding messages. items: type: string type: array inclusionList: description: |- InclusionList specifies a list of Golang regular expressions to be used for including messages. items: type: string type: array providerRef: description: ProviderRef specifies which Provider this Alert should use. properties: name: description: Name of the referent. type: string required: - name type: object summary: description: |- Summary holds a short description of the impact and affected cluster. Deprecated: Use EventMetadata instead. maxLength: 255 type: string suspend: description: |- Suspend tells the controller to suspend subsequent events handling for this Alert. type: boolean required: - eventSources - providerRef type: object type: object served: true storage: true subresources: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: providers.notification.toolkit.fluxcd.io spec: group: notification.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-notifications kind: Provider listKind: ProviderList plural: providers singular: provider scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1beta3 schema: openAPIV3Schema: description: Provider is the Schema for the providers API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: ProviderSpec defines the desired state of the Provider. properties: address: description: |- Address specifies the endpoint, in a generic sense, to where alerts are sent. What kind of endpoint depends on the specific Provider type being used. For the generic Provider, for example, this is an HTTP/S address. For other Provider types this could be a project ID or a namespace. maxLength: 2048 type: string certSecretRef: description: |- CertSecretRef specifies the Secret containing TLS certificates for secure communication. Supported configurations: - CA-only: Server authentication (provide ca.crt only) - mTLS: Mutual authentication (provide ca.crt + tls.crt + tls.key) - Client-only: Client authentication with system CA (provide tls.crt + tls.key only) Legacy keys "caFile", "certFile", "keyFile" are supported but deprecated. Use "ca.crt", "tls.crt", "tls.key" instead. properties: name: description: Name of the referent. type: string required: - name type: object channel: description: Channel specifies the destination channel where events should be posted. maxLength: 2048 type: string commitStatusExpr: description: |- CommitStatusExpr is a CEL expression that evaluates to a string value that can be used to generate a custom commit status message for use with eligible Provider types (github, gitlab, gitea, bitbucketserver, bitbucket, azuredevops). Supported variables are: event, provider, and alert. type: string interval: description: |- Interval at which to reconcile the Provider with its Secret references. Deprecated and not used in v1beta3. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string proxy: description: |- Proxy the HTTP/S address of the proxy server. Deprecated: Use ProxySecretRef instead. Will be removed in v1. maxLength: 2048 pattern: ^(http|https)://.*$ type: string proxySecretRef: description: |- ProxySecretRef specifies the Secret containing the proxy configuration for this Provider. The Secret should contain an 'address' key with the HTTP/S address of the proxy server. Optional 'username' and 'password' keys can be provided for proxy authentication. properties: name: description: Name of the referent. type: string required: - name type: object secretRef: description: |- SecretRef specifies the Secret containing the authentication credentials for this Provider. properties: name: description: Name of the referent. type: string required: - name type: object serviceAccountName: description: |- ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate with cloud provider services through workload identity. This enables multi-tenant authentication without storing static credentials. Supported provider types: azureeventhub, azuredevops, googlepubsub When specified, the controller will: 1. Create an OIDC token for the specified ServiceAccount 2. Exchange it for cloud provider credentials via STS 3. Use the obtained credentials for API authentication When unspecified, controller-level authentication is used (single-tenant). An error is thrown if static credentials are also defined in SecretRef. This field requires the ObjectLevelWorkloadIdentity feature gate to be enabled. type: string suspend: description: |- Suspend tells the controller to suspend subsequent events handling for this Provider. type: boolean timeout: description: Timeout for sending alerts to the Provider. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ type: string type: description: Type specifies which Provider implementation to use. enum: - slack - discord - msteams - rocket - generic - generic-hmac - github - gitlab - gitea - giteapullrequestcomment - bitbucketserver - bitbucket - azuredevops - googlechat - googlepubsub - webex - sentry - azureeventhub - telegram - lark - matrix - opsgenie - alertmanager - grafana - githubdispatch - githubpullrequestcomment - gitlabmergerequestcomment - pagerduty - datadog - nats - zulip - otel type: string username: description: Username specifies the name under which events are posted. maxLength: 2048 type: string required: - type type: object x-kubernetes-validations: - message: spec.commitStatusExpr is only supported for the 'github', 'gitlab', 'gitea', 'bitbucketserver', 'bitbucket', 'azuredevops' provider types rule: self.type == 'github' || self.type == 'gitlab' || self.type == 'gitea' || self.type == 'bitbucketserver' || self.type == 'bitbucket' || self.type == 'azuredevops' || !has(self.commitStatusExpr) type: object served: true storage: true subresources: {} --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 kustomize.toolkit.fluxcd.io/substitute: disabled labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: receivers.notification.toolkit.fluxcd.io spec: group: notification.toolkit.fluxcd.io names: categories: - all - fluxcd - fluxcd-notifications kind: Receiver listKind: ReceiverList plural: receivers singular: receiver scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .status.conditions[?(@.type=="Ready")].message name: Status type: string name: v1 schema: openAPIV3Schema: description: Receiver is the Schema for the receivers API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: ReceiverSpec defines the desired state of the Receiver. properties: events: description: |- Events specifies the list of event types to handle, e.g. 'push' for GitHub or 'Push Hook' for GitLab. items: type: string type: array interval: default: 10m description: Interval at which to reconcile the Receiver with its Secret references. pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string oidcProviders: description: |- OIDCProviders specifies the OIDC providers used to authenticate incoming requests when Type is 'generic-oidc'. The provider whose IssuerURL matches the token's 'iss' claim is used to verify the token signature, expiration and audience, and to evaluate the configured CEL validations against the token claims. items: description: |- OIDCProvider configures an OIDC issuer used to authenticate requests for a 'generic-oidc' Receiver. properties: audience: description: |- Audience is the expected audience ('aud' claim) for tokens issued by this provider. Defaults to 'notification-controller'. type: string issuerURL: description: |- IssuerURL is the OIDC issuer URL used for provider discovery. It must match the 'iss' claim of tokens issued by this provider. pattern: ^https?:// type: string validations: description: |- Validations is the list of CEL boolean expressions evaluated against the token claims and the variables. The request is accepted only if all of them evaluate to true; the message of each failing expression is returned to the caller. At least one validation is required. A valid signature alone does not authorize a request: public issuers issue tokens to any caller on the platform, so the validations must constrain the caller's identity claims (e.g. 'repository_owner' for GitHub Actions). items: description: |- OIDCValidation is a CEL boolean expression evaluated against the OIDC token claims and variables of a 'generic-oidc' Receiver. properties: expression: description: Expression is the CEL boolean expression to evaluate. type: string message: description: Message is returned to the caller when the expression evaluates to false. type: string required: - expression - message type: object minItems: 1 type: array variables: description: |- Variables is an optional list of named CEL expressions, evaluated in order and exposed as 'vars.'. Each expression can read the token claims via 'claims' and any variable defined before it. Use it to share sub-expressions across validations. items: description: |- OIDCVariable is a named CEL expression evaluated against the OIDC token claims of a 'generic-oidc' Receiver. properties: expression: description: Expression is the CEL expression that defines the variable value. type: string name: description: Name is the variable name; it must be a valid CEL identifier. type: string required: - expression - name type: object type: array required: - issuerURL - validations type: object type: array x-kubernetes-list-map-keys: - issuerURL x-kubernetes-list-type: map resourceFilter: description: |- ResourceFilter is a CEL expression expected to return a boolean that is evaluated for each resource referenced in the Resources field when a webhook is received. If the expression returns false then the controller will not request a reconciliation for the resource. The expression can read the resource metadata via 'res' and the webhook request body via 'req'. For generic-oidc receivers, the verified OIDC token claims are also available via 'claims'. When the expression is specified the controller will parse it and mark the object as terminally failed if the expression is invalid or does not return a boolean. type: string resources: description: A list of resources to be notified about changes. items: description: |- ReceiverResource references a resource to be notified about changes, with an optional per-resource CEL filter. properties: apiVersion: description: API version of the referent type: string filter: description: |- Filter is a CEL expression expected to return a boolean that is evaluated for each resource matched by this reference when a webhook is received, in addition to the top-level resourceFilter. A reconciliation is requested only when both expressions (when set) return true. The expression can read the resource metadata via 'res' and the webhook request body via 'req'. For generic-oidc receivers, the verified OIDC token claims are also available via 'claims'. When the expression is specified the controller will parse it and mark the object as terminally failed if the expression is invalid or does not return a boolean. type: string kind: description: Kind of the referent enum: - Bucket - GitRepository - Kustomization - HelmRelease - HelmChart - HelmRepository - ImageRepository - ImagePolicy - ImageUpdateAutomation - OCIRepository - ArtifactGenerator - ExternalArtifact type: string matchLabels: additionalProperties: type: string description: |- MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed. MatchLabels requires the name to be set to `*`. type: object name: description: |- Name of the referent If multiple resources are targeted `*` may be set. maxLength: 253 minLength: 1 type: string namespace: description: Namespace of the referent maxLength: 253 minLength: 1 type: string required: - kind - name type: object type: array secretRef: description: |- SecretRef specifies the Secret containing the token used to validate the payload authenticity. The Secret must contain a 'token' key. For GCR receivers, the Secret must also contain an 'email' key with the IAM service account email configured on the Pub/Sub push subscription, and an 'audience' key with the expected OIDC token audience. Required for all receiver types except 'generic-oidc', which authenticates requests using the OIDC token instead and must not set this field. properties: name: description: Name of the referent. type: string required: - name type: object suspend: description: |- Suspend tells the controller to suspend subsequent events handling for this receiver. type: boolean type: description: |- Type of webhook sender, used to determine the validation procedure and payload deserialization. enum: - generic - generic-hmac - generic-oidc - github - gitlab - bitbucket - harbor - dockerhub - quay - gcr - nexus - acr - cdevents type: string required: - resources - type type: object x-kubernetes-validations: - message: generic-oidc receivers must define at least one oidcProvider rule: self.type != 'generic-oidc' || (has(self.oidcProviders) && size(self.oidcProviders) > 0) - message: oidcProviders can only be set when type is generic-oidc rule: self.type == 'generic-oidc' || !has(self.oidcProviders) || size(self.oidcProviders) == 0 - message: secretRef cannot be set when type is generic-oidc rule: self.type != 'generic-oidc' || !has(self.secretRef) - message: secretRef is required when type is not generic-oidc rule: self.type == 'generic-oidc' || has(self.secretRef) status: default: observedGeneration: -1 description: ReceiverStatus defines the observed state of the Receiver. properties: conditions: description: Conditions holds the conditions for the Receiver. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array lastHandledReconcileAt: description: |- LastHandledReconcileAt holds the value of the most recent reconcile request value, so a change of the annotation value can be detected. type: string observedGeneration: description: ObservedGeneration is the last observed generation of the Receiver object. format: int64 type: integer webhookPath: description: |- WebhookPath is the generated incoming webhook address in the format of '/hook/sha256sum(token+name+namespace)'. type: string type: object type: object served: true storage: true subresources: status: {} --- apiVersion: v1 kind: ServiceAccount metadata: labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest name: notification-controller namespace: flux-system --- apiVersion: v1 kind: Service metadata: labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: notification-controller namespace: flux-system spec: ports: - name: http port: 80 protocol: TCP targetPort: http selector: app: notification-controller type: ClusterIP --- apiVersion: v1 kind: Service metadata: labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: webhook-receiver namespace: flux-system spec: ports: - name: http port: 80 protocol: TCP targetPort: http-webhook selector: app: notification-controller type: ClusterIP --- apiVersion: apps/v1 kind: Deployment metadata: labels: app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest control-plane: controller name: notification-controller namespace: flux-system spec: replicas: 1 selector: matchLabels: app: notification-controller template: metadata: annotations: prometheus.io/port: "8080" prometheus.io/scrape: "true" labels: app: notification-controller app.kubernetes.io/component: notification-controller app.kubernetes.io/instance: flux-system app.kubernetes.io/part-of: flux app.kubernetes.io/version: latest spec: containers: - args: - --watch-all-namespaces=true - --log-level=info - --log-encoding=json - --enable-leader-election env: - name: RUNTIME_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: GOMEMLIMIT valueFrom: resourceFieldRef: containerName: manager resource: limits.memory image: ghcr.io/fluxcd/notification-controller:v1.9.2 imagePullPolicy: IfNotPresent livenessProbe: httpGet: path: /healthz port: healthz name: manager ports: - containerPort: 9090 name: http protocol: TCP - containerPort: 9292 name: http-webhook protocol: TCP - containerPort: 8080 name: http-prom protocol: TCP - containerPort: 9440 name: healthz protocol: TCP readinessProbe: httpGet: path: /readyz port: healthz resources: limits: cpu: 1000m memory: 1Gi requests: cpu: 100m memory: 64Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true runAsNonRoot: true seccompProfile: type: RuntimeDefault volumeMounts: - mountPath: /tmp name: temp nodeSelector: kubernetes.io/os: linux securityContext: fsGroup: 1337 serviceAccountName: notification-controller terminationGracePeriodSeconds: 10 tolerations: - key: node.kubernetes.io/controllers operator: Exists volumes: - emptyDir: {} name: temp } --- PASS: TestGenerate (0.83s) PASS ok github.com/fluxcd/flux2/v2/pkg/manifestgen/install 0.871s ? github.com/fluxcd/flux2/v2/pkg/manifestgen/kustomization [no test files] === RUN Test_passwordLoadKeyPair === RUN Test_passwordLoadKeyPair/private_key_pair_with_password --- PASS: Test_passwordLoadKeyPair (0.14s) --- PASS: Test_passwordLoadKeyPair/private_key_pair_with_password (0.14s) === RUN Test_PasswordlessLoadKeyPair === RUN Test_PasswordlessLoadKeyPair/rsa-openssh-format === RUN Test_PasswordlessLoadKeyPair/p384-openssh-format === RUN Test_PasswordlessLoadKeyPair/p521-openssh-format === RUN Test_PasswordlessLoadKeyPair/user === RUN Test_PasswordlessLoadKeyPair/ecdsa === RUN Test_PasswordlessLoadKeyPair/ecdsap384 === RUN Test_PasswordlessLoadKeyPair/rsa === RUN Test_PasswordlessLoadKeyPair/pkcs8 === RUN Test_PasswordlessLoadKeyPair/p256-openssh-format === RUN Test_PasswordlessLoadKeyPair/ca === RUN Test_PasswordlessLoadKeyPair/dsa === RUN Test_PasswordlessLoadKeyPair/ecdsap256 === RUN Test_PasswordlessLoadKeyPair/ecdsap521 === RUN Test_PasswordlessLoadKeyPair/ed25519 --- PASS: Test_PasswordlessLoadKeyPair (0.02s) --- PASS: Test_PasswordlessLoadKeyPair/rsa-openssh-format (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/p384-openssh-format (0.01s) --- PASS: Test_PasswordlessLoadKeyPair/p521-openssh-format (0.01s) --- PASS: Test_PasswordlessLoadKeyPair/user (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ecdsa (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ecdsap384 (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/rsa (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/pkcs8 (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/p256-openssh-format (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ca (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/dsa (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ecdsap256 (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ecdsap521 (0.00s) --- PASS: Test_PasswordlessLoadKeyPair/ed25519 (0.00s) PASS ok github.com/fluxcd/flux2/v2/pkg/manifestgen/sourcesecret 0.207s === RUN TestGenerate # This manifest was generated by flux. DO NOT EDIT. --- apiVersion: source.toolkit.fluxcd.io/v1 kind: GitRepository metadata: name: flux-system namespace: flux-system spec: interval: 1m0s ref: branch: main secretRef: name: flux-system url: "" --- apiVersion: kustomize.toolkit.fluxcd.io/v1 kind: Kustomization metadata: name: flux-system namespace: flux-system spec: interval: 10m0s path: ./ prune: true sourceRef: kind: GitRepository name: flux-system --- PASS: TestGenerate (0.00s) PASS ok github.com/fluxcd/flux2/v2/pkg/manifestgen/sync 0.023s ? github.com/fluxcd/flux2/v2/pkg/plugin [no test files] ? github.com/fluxcd/flux2/v2/pkg/printers [no test files] ? github.com/fluxcd/flux2/v2/pkg/status [no test files] ? github.com/fluxcd/flux2/v2/pkg/uninstall [no test files] ? github.com/fluxcd/flux2/v2/tests/bootstrap [no test files] ? github.com/fluxcd/flux2/v2/tests/image-automation [no test files] ==> Entering fakeroot environment... ==> Starting package()... install: creating directory '/build/fluxcd/pkg/fluxcd/usr' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/bin' 'flux' -> '/build/fluxcd/pkg/fluxcd/usr/bin/flux' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/bash-completion' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/bash-completion/completions' 'completion.bash' -> '/build/fluxcd/pkg/fluxcd/usr/share/bash-completion/completions/flux' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/fish' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/fish/vendor_completions.d' 'completion.fish' -> '/build/fluxcd/pkg/fluxcd/usr/share/fish/vendor_completions.d/flux.fish' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/zsh' install: creating directory '/build/fluxcd/pkg/fluxcd/usr/share/zsh/site-functions' 'completion.zsh' -> '/build/fluxcd/pkg/fluxcd/usr/share/zsh/site-functions/_flux' ==> Tidying install... -> Removing libtool files... -> Removing static library files... -> Purging unwanted files... -> Stripping unneeded symbols from binaries and libraries... -> Compressing man and info pages... ==> Checking for packaging issues... ==> WARNING: Package contains reference to $srcdir usr/bin/flux ==> Creating package "fluxcd"... -> Generating .PKGINFO file... -> Generating .BUILDINFO file... -> Generating .MTREE file... -> Compressing package... ==> Leaving fakeroot environment. ==> Finished making: fluxcd 2.9.3-1 (Sat Jul 25 18:33:08 2026) ==> Installing package fluxcd with pacman -U... loading packages... resolving dependencies... looking for conflicting packages... Package (1) New Version Net Change fluxcd 2.9.3-1 105.45 MiB Total Installed Size: 105.45 MiB :: Proceed with installation? [Y/n] checking keyring... checking package integrity... loading package files... checking for file conflicts... :: Processing package changes... installing fluxcd... :: Running post-transaction hooks... (1/1) Arming ConditionNeedsUpdate... resolving dependencies... looking for conflicting packages... Package (6) New Version Net Change core/licenses 20240728-1 1.54 MiB extra-testing/pyalpm 0.11.1-1 0.25 MiB extra-testing/python-boolean.py 5.0-2 0.36 MiB extra-testing/python-license-expression 30.4.4-2 1.24 MiB extra-testing/python-pyelftools 0.33-1 2.57 MiB extra-testing/namcap 3.6.0-3 1.00 MiB Total Installed Size: 6.96 MiB :: Proceed with installation? [Y/n] :: Retrieving packages... pyalpm-0.11.1-1-aarch64 downloading... checking keyring... checking package integrity... loading package files... checking for file conflicts... :: Processing package changes... installing licenses... installing pyalpm... installing python-boolean.py... installing python-license-expression... installing python-pyelftools... installing namcap... :: Running post-transaction hooks... (1/1) Arming ConditionNeedsUpdate... Checking PKGBUILD Checking fluxcd-2.9.3-1-aarch64.pkg.tar.zst fluxcd W: Referenced library 'libresolv.so.2' is an uninstalled dependency (needed in files ['usr/bin/flux']) fluxcd W: Referenced library 'libc.so.6' is an uninstalled dependency (needed in files ['usr/bin/flux']) fluxcd W: Unused shared library '/usr/lib/libresolv.so.2' by file ('usr/bin/flux') fluxcd W: Dependency included, but may not be needed ('glibc') ==> Running checkpkg -> Downloading current versions Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. Package (1) Old Version New Version Net Change Download Size extra-testing/fluxcd 2.9.3-1 2.9.2-1 0.00 MiB 23.34 MiB Total Download Size: 23.34 MiB :: Proceed with download? [Y/n] :: Retrieving packages... fluxcd-2.9.2-1-aarch64 downloading... checking keyring... checking package integrity... -> Checking packages ==> No soname differences for fluxcd. [?25h==> Generating .SRCINFO...done ==> Finished building fluxcd 2.9.3-1 [?25h