Skip to content

feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.7 )#1222

Open
stimpy-bot[bot] wants to merge 1 commit into
mainfrom
renovate/fluxcd-flux2-2.x
Open

feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.7 )#1222
stimpy-bot[bot] wants to merge 1 commit into
mainfrom
renovate/fluxcd-flux2-2.x

Conversation

@stimpy-bot
Copy link
Copy Markdown
Contributor

@stimpy-bot stimpy-bot Bot commented Mar 3, 2026

This PR contains the following updates:

Package Type Update Change Pending
fluxcd/flux2 minor 2.7.52.8.7 v2.8.8
fluxcd/flux2 Kustomization minor v2.7.5v2.8.7 v2.8.8
fluxcd/flux2 action minor v2.7.5v2.8.7 v2.8.8

Release Notes

fluxcd/flux2 (fluxcd/flux2)

v2.8.7

Compare Source

Highlights

Flux v2.8.7 is a patch release that includes a bug fix in kustomize-controller, a CVE fix in source-controller and image-automation-controller via go-git v5.19.0, and dependency updates. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix management of objects annotated with kustomize.toolkit.fluxcd.io/ssa: IfNotPresent where non-namespaced resources were being deleted and recreated on each reconciliation (kustomize-controller)

Improvements:

  • Update go-git to v5.19.0 which fixes CVE-2026-45022 (source-controller, image-automation-controller)
  • Update fluxcd/pkg dependencies (source-controller, kustomize-controller, image-automation-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.6...v2.8.7

v2.8.6

Compare Source

Highlights

Flux v2.8.6 is a patch release that includes bug fixes and improvements across helm-controller, image-automation-controller, kustomize-controller, notification-controller, and source-controller. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix a post-renderer conflict between overlapping hooks and templates (helm-controller)
  • Ignore force replace when server-side apply is enabled (helm-controller)
  • Fix a regression where generic providers would not forward commit status events (notification-controller)
  • Require the audience field on the GCR Receiver secret for tighter verification — will become mandatory in Flux v2.9 (notification-controller)

Improvements:

  • Introduce the MigrateAPIVersion feature gate for migrating the API version of resources in managed field entries (kustomize-controller)
  • Update go-git to v5.18.0 bringing performance improvements for Git operations (source-controller, image-automation-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.5...v2.8.6

v2.8.5

Compare Source

Highlights

Flux v2.8.5 is a patch release that includes bug fixes and improvements across kustomize-controller, source-controller, and notification-controller. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix a race condition where a cancelled reconciliation could leave stale data in the cache, causing Kustomizations to get stuck (kustomize-controller)
  • Fix Azure Blob prefix option not being passed to the storage client (source-controller)

Improvements:

  • Improve error message for encrypted SSH keys without password (source-controller)
  • Add optional email and audience fields to the GCR Receiver for tighter verification (notification-controller)
  • Add provider manifest example for Azure Event Hub managed identity authentication (notification-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.4...v2.8.5

v2.8.4

Compare Source

Highlights

Flux v2.8.4 is a patch release that includes fixes for the Flux CLI. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix flux build ks and flux diff ks on Windows
  • Fix --source flag validation in create kustomization command
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.3...v2.8.4

v2.8.3

Compare Source

Highlights

Flux v2.8.3 is a patch release that fixes a regression in helm-controller. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix templating errors for charts that include --- in the content, e.g. YAML separators, embedded scripts, CAs inside ConfigMaps (helm-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.2...v2.8.3

v2.8.2

Compare Source

Highlights

Flux v2.8.2 is a patch release that comes with various fixes. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix enqueuing new reconciliation requests for events on source Flux objects when they are already reconciling the revision present in the watch event (kustomize-controller, helm-controller)
  • Fix the Go templates bug of YAML separator --- getting concatenated to apiVersion: by updating to Helm 4.1.3 (helm-controller)
  • Fix canceled HelmReleases getting stuck when they don't have a retry strategy configured by introducing a new feature gate DefaultToRetryOnFailure that improves the experience when the CancelHealthCheckOnNewRevision is enabled (helm-controller)
  • Fix the auth scope for Azure Container Registry to use the ACR-specific scope (source-controller, image-reflector-controller)
  • Fix potential Denial of Service (DoS) during TLS handshakes (CVE-2026-27138) by building all controllers with Go 1.26.1
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.1...v2.8.2

v2.8.1

Compare Source

Highlights

Flux v2.8.1 is a patch release that comes with various fixes. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix Git commit status events being dropped for Kustomizations (notification-controller)
  • Fix health check for StatefulSets when the Pods are Pending/Unschedulable during rollout (helm-controller, kustomize-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.0...v2.8.1

v2.8.0

Compare Source

Highlights

Flux v2.8.0 is a feature release. Users are encouraged to upgrade for the best experience.

For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.8 GA blog post.

Overview of the new features:

  • Helm v4 support, including server-side apply and kstatus-based health checking (HelmRelease)
  • Readiness evaluation of Helm-managed objects with CEL expressions (HelmRelease)
  • Improved observability of Helm releases with inventory tracking in .status.inventory (HelmRelease)
  • Reduced the mean time to recovery of Flux-managed applications via CancelHealthCheckOnNewRevision feature gate (Kustomization, HelmRelease)
  • Support for commenting on Pull Requests directly from Flux notifications (Provider)
  • Custom SSA apply stages for ordering resource application in kustomize-controller (Kustomization)
  • Automatic GitHub App installation ID lookup from the repository owner (GitRepository, ImageUpdateAutomation, Provider)
  • Support for Cosign v3 for verifying OCI artifacts and container images (OCIRepository)
  • ArtifactGenerator support for extracting and modifying Helm charts (ArtifactGenerator)
  • Bypass cache when fetching source objects via DirectSourceFetch feature gate (Kustomization, HelmRelease, ArtifactGenerator)

❤️ Big thanks to all the Flux contributors that helped us with this release!

Kubernetes compatibility

This release is compatible with the following Kubernetes versions:

Kubernetes version Minimum required
v1.33 >= 1.32.0
v1.34 >= 1.34.1
v1.35 >= 1.35.0

[!NOTE]
Note that the Flux project offers support only for the latest three minor versions of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors such as
ControlPlane that provide enterprise support for Flux.

OpenShift compatibility

Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.

Upgrade procedure

⚠️ The Flux APIs v1beta2 and v2beta2 (deprecated in 2024) have reached end-of-life and have been removed from the CRDs.

Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.8.

Components changelog
CLI changelog
New Contributors

Full Changelog: fluxcd/flux2@v2.7.0...v2.8.0


Configuration

📅 Schedule: (in timezone America/Chicago)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 6 times, most recently from ba9850c to b43a0c7 Compare March 6, 2026 13:26
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.0 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.1 ) Mar 6, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 2 times, most recently from 1c587b4 to d9a99eb Compare March 9, 2026 23:10
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 2 times, most recently from 00c8c97 to a56d9e1 Compare March 19, 2026 15:20
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.1 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.2 ) Mar 19, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 2 times, most recently from 0539170 to a78c93f Compare March 23, 2026 14:29
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.2 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.3 ) Mar 23, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 2 times, most recently from 3137be4 to 64e7c93 Compare March 28, 2026 19:15
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 7 times, most recently from 760e231 to cf2ba6e Compare April 7, 2026 15:34
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.3 ) feat(github-release): update fluxcd/flux2 Apr 7, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 3 times, most recently from 78596a5 to 067ebdf Compare April 14, 2026 15:30
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.4 ) Apr 14, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch from 067ebdf to c3b2dad Compare April 14, 2026 18:30
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.4 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.5 ) Apr 14, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch 6 times, most recently from 2f8c4d3 to cd3e9f7 Compare April 25, 2026 13:59
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch from cd3e9f7 to 4e8b444 Compare April 28, 2026 12:42
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.5 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.6 ) Apr 28, 2026
@stimpy-bot stimpy-bot Bot force-pushed the renovate/fluxcd-flux2-2.x branch from 4e8b444 to f48da5b Compare May 19, 2026 13:13
@stimpy-bot stimpy-bot Bot changed the title feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.6 ) feat(github-release): update fluxcd/flux2 ( v2.7.5 → v2.8.7 ) May 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants