Skip to content

Update Flux Operator (0.24.0) - #1167

Merged
Andrei Kvapil (kvaps) merged 2 commits into
cozystack:mainfrom
kingdonb:update-flux-operator
Jul 9, 2025
Merged

Andrei Kvapil (kvaps) merged 2 commits into
cozystack:mainfrom
kingdonb:update-flux-operator

Conversation

@kingdonb

@kingdonb Kingdon Barrett (kingdonb) commented Jul 8, 2025 •

Copy link
Copy Markdown
Member

This PR updates Flux Operator to 0.24.0 - some changes have been undertaken to make upgrading Flux on any version of the flux-operator more reliable - these are related to spec.distribution.artifact which I think you have already seen

https://fluxcd.control-plane.io/operator/fluxinstance/#distribution-artifact

May be relevant to air-gapped environments.

Summary by CodeRabbit

  • New Features

    • Added support for specifying extra pod volumes and container volume mounts via new configuration options in the Helm chart.
    • Extended CRD schemas to support additional provider types, new filtering options, and enhanced validation and authentication fields.
    • Introduced new fields for improved authentication and workload identity federation in CRDs.
  • Documentation

    • Updated README files to document new configuration options and reflect the latest chart versions.
  • Chores

    • Bumped Helm chart and app versions to 0.24.0 for both operator and instance charts.

@coderabbitai

coderabbitai Bot commented Jul 8, 2025 •

Copy link
Copy Markdown
Contributor

Walkthrough

This update increments Helm chart versions for both flux-operator and flux-instance to 0.24.0, introduces extraVolumes and extraVolumeMounts Helm values for dynamic pod customization, and significantly enhances the CRD schemas with new fields, provider types, validation rules, and documentation clarifications.

Changes

Files/Group Change Summary
.../charts/flux-operator/Chart.yaml
.../charts/flux-instance/Chart.yaml
Bumped chart and app versions from 0.23.0 to 0.24.0.
.../charts/flux-operator/README.md
.../charts/flux-instance/README.md
Updated version badges; documented new Helm values (extraVolumeMounts, extraVolumes) in flux-operator README.
.../charts/flux-operator/templates/crds.yaml Enhanced CRD schemas: new required fields, new provider types, validation rules, authentication clarifications, and filters.
.../charts/flux-operator/templates/deployment.yaml Added conditional rendering for extra volumes and volume mounts using new Helm values.
.../charts/flux-operator/values.yaml Introduced extraVolumes and extraVolumeMounts configuration arrays.

Sequence Diagram(s)

sequenceDiagram
    participant User
    participant Helm
    participant Kubernetes
    participant FluxOperator Pod

    User->>Helm: Install/upgrade flux-operator chart with extraVolumes/extraVolumeMounts values
    Helm->>Kubernetes: Rendered manifests with additional volumes/mounts
    Kubernetes->>FluxOperator Pod: Create pod with specified extra volumes/mounts
    FluxOperator Pod-->>Kubernetes: Pod runs with enhanced configuration
Loading

Possibly related PRs

  • cozystack/cozystack#1035: Previous PR updating the flux-operator Helm chart and CRD validation rules, showing a related progression of chart and schema enhancements.

Suggested labels

documentation, enhancement, size:M

Suggested reviewers

  • lllamnyp
  • klinch0
  • kvaps

Poem

In version twenty-four, we hop anew,
Extra mounts and volumes—just for you!
CRDs now smarter, with fields galore,
Helm charts polished, numbers soar.
The burrow’s schema grows robust and bright,
As rabbits code through the starry night.
🐇✨


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (5)
packages/system/fluxcd-operator/charts/flux-operator/README.md (2)

3-3: Minor spacing nitpick after badges

There are two consecutive spaces before the line break; drop one to satisfy markdown linters.

-![AppVersion: v0.24.0](https://img.shields.io/badge/AppVersion-v0.24.0-informational?style=flat-square)  
+![AppVersion: v0.24.0](https://img.shields.io/badge/AppVersion-v0.24.0-informational?style=flat-square)

41-42: Docs for new values are present – consider adding a usage example

extraVolumeMounts and extraVolumes are now documented, nice.
Including a short YAML snippet showing how to supply one volume & mount would make adoption easier.

packages/system/fluxcd-operator/charts/flux-operator/values.yaml (2)

119-121: Schema tag missing default/description details

The new extraVolumes list lacks hints for expected structure (e.g., name, emptyDir, configMap, …).
Adding an inline comment or @schema example improves IDE validation.


128-130: Mirror validation advice for extraVolumeMounts

Same comment as above – a brief schema/example (e.g., { name: foo, mountPath: /data }) would help users avoid Helm-time errors.

packages/system/fluxcd-operator/charts/flux-operator/templates/crds.yaml (1)

909-942: Filter semantics: clarify precedence between include*, exclude*, and semver.

Nice addition, but the CRD description doesn’t specify how semver interacts
with includeTag/excludeTag. Users may assume semver filtering happens
after the include/exclude regexes, but that is not obvious.

A one-line clarification in the field description will save trouble later.

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 699d38d and e70dfde.

📒 Files selected for processing (7)
  • packages/system/fluxcd-operator/charts/flux-operator/Chart.yaml (2 hunks)
  • packages/system/fluxcd-operator/charts/flux-operator/README.md (2 hunks)
  • packages/system/fluxcd-operator/charts/flux-operator/templates/crds.yaml (7 hunks)
  • packages/system/fluxcd-operator/charts/flux-operator/templates/deployment.yaml (1 hunks)
  • packages/system/fluxcd-operator/charts/flux-operator/values.yaml (1 hunks)
  • packages/system/fluxcd/charts/flux-instance/Chart.yaml (2 hunks)
  • packages/system/fluxcd/charts/flux-instance/README.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
packages/system/fluxcd/charts/flux-instance/README.md

[grammar] ~3-~3: Use proper spacing conventions.
Context: ...cation-informational?style=flat-square) AppVersion: v0.24.0 This chart is a thin wrapper around the ...

(QB_NEW_EN_OTHER_ERROR_IDS_000007)

packages/system/fluxcd-operator/charts/flux-operator/README.md

[grammar] ~3-~3: Use proper spacing conventions.
Context: ...cation-informational?style=flat-square) AppVersion: v0.24.0 The [Flux Operator](https://github.com/c...

(QB_NEW_EN_OTHER_ERROR_IDS_000007)

🔇 Additional comments (5)
packages/system/fluxcd/charts/flux-instance/README.md (1)

3-3: Version badge update looks good

Chart README is now in sync with Chart.yaml version/appVersion.
No further action needed.

packages/system/fluxcd-operator/charts/flux-operator/Chart.yaml (1)

11-11: ✅ No stale v0.23.0 references detected

Both appVersion and chart version are correctly bumped to v0.24.0, and searches across the entire flux-operator chart show no remaining v0.23.0 or 0.23.0 occurrences. Ready to merge.

packages/system/fluxcd/charts/flux-instance/Chart.yaml (1)

11-11: Chart metadata aligned with operator – good

appVersion/version bumped consistently to 0.24.0.
No issues spotted.

Also applies to: 28-28

packages/system/fluxcd-operator/charts/flux-operator/templates/crds.yaml (2)

589-592: Backwards-compat break – new required fields will reject all existing FluxReports.

platform and serverVersion are now required. Any cluster already running
FluxReport objects that omit these properties will start failing validation
once the CRD is replaced, blocking further updates.

Consider one of:

  • Make the fields optional and mark them nullable: true.
  • Provide a default via default: and drop them from required:.
  • Ship a migration Job that patches existing objects before the CRD update.

Please verify the upgrade path on live clusters.


643-659: New .spec.operator block marked required – same migration concern.

For every existing FluxReport the new operator object (with three required
scalar fields) will be missing, again causing CRD validation errors after
upgrade.

Unless you plan to recreate all FluxReport resources, treat this the same way
as the previous comment: optional/nullable or an automated data migration.

Comment on lines 100 to +110
- name: temp
mountPath: /tmp
{{- if .Values.extraVolumeMounts }}
{{- toYaml .Values.extraVolumeMounts | nindent 12 }}
{{- end }}
volumes:
- name: temp
emptyDir: {}
{{- if .Values.extraVolumes }}
{{- toYaml .Values.extraVolumes | nindent 8 }}
{{- end }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue

Empty-slice renders an invalid [] entry – guard for length, not only existence.

.Values.extraVolumeMounts and .Values.extraVolumes default to an empty list ([]).
In Go templates an empty (but non-nil) slice still evaluates to true, so the current if
block emits the YAML representation of an empty slice ([]).
Placing [] under volumeMounts:/volumes: breaks the Pod spec.

Apply a length check before rendering:

-{{- if .Values.extraVolumeMounts }}
-  {{- toYaml .Values.extraVolumeMounts | nindent 12 }}
-{{- end }}
+{{- $m := .Values.extraVolumeMounts }}
+{{- if and $m (gt (len $m) 0) }}
+  {{- toYaml $m | nindent 12 }}
+{{- end }}

and likewise for extraVolumes.

Repeatable pattern keeps the template safe even when the value is left at its
(default) empty slice.

🤖 Prompt for AI Agents
In
packages/system/fluxcd-operator/charts/flux-operator/templates/deployment.yaml
around lines 100 to 110, the template conditionals for rendering
extraVolumeMounts and extraVolumes only check for existence, causing empty
slices to render as invalid `[]` in the YAML. Update the conditionals to check
the length of .Values.extraVolumeMounts and .Values.extraVolumes instead of just
their existence, ensuring the blocks only render when the slices are non-empty.
This prevents invalid empty slice entries under volumeMounts and volumes in the
Pod spec.

Comment on lines +1038 to 1059
- message: spec.url must start with 'http://' or 'https://' when spec.type
is a Git provider
rule: '!self.type.startsWith(''Git'') || self.url.startsWith(''http'')'
- message: spec.url must start with 'http://' or 'https://' when spec.type
is a Git provider
rule: '!self.type.startsWith(''AzureDevOps'') || self.url.startsWith(''http'')'
- message: spec.url must start with 'oci://' when spec.type is an OCI
provider
rule: '!self.type.endsWith(''ArtifactTag'') || self.url.startsWith(''oci'')'
- message: cannot specify spec.serviceAccountName when spec.type is not
one of AzureDevOps* or *ArtifactTag
rule: '!has(self.serviceAccountName) || self.type.startsWith(''AzureDevOps'')
|| self.type.endsWith(''ArtifactTag'')'
- message: cannot specify spec.certSecretRef when spec.type is one of
Static, AzureDevOps*, ACRArtifactTag, ECRArtifactTag or GARArtifactTag
rule: '!has(self.certSecretRef) || !(self.url == ''Static'' || self.type.startsWith(''AzureDevOps'')
|| (self.type.endsWith(''ArtifactTag'') && self.type != ''OCIArtifactTag''))'
- message: cannot specify spec.secretRef when spec.type is one of Static,
ACRArtifactTag, ECRArtifactTag or GARArtifactTag
rule: '!has(self.secretRef) || !(self.url == ''Static'' || (self.type.endsWith(''ArtifactTag'')
&& self.type != ''OCIArtifactTag''))'
status:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue

Validation rules use self.url where they should reference self.type.

Both rules below compare the type but mistakenly reference self.url,
rendering the constraint ineffective and potentially blocking valid specs.

rule: '!has(self.certSecretRef) || !(self.url == ''Static'' || ... )'
                                             ^^^^^            ↑
rule: '!has(self.secretRef)   || !(self.url == ''Static'' || ... )'

Fix:

- !has(self.certSecretRef) || !(self.url == 'Static' || ...
+ !has(self.certSecretRef) || !(self.type == 'Static' || ...

- !has(self.secretRef) || !(self.url == 'Static' || ...
+ !has(self.secretRef) || !(self.type == 'Static' || ...

Without this change the rules silently allow forbidden combinations and fail
for the wrong reasons.

🤖 Prompt for AI Agents
In packages/system/fluxcd-operator/charts/flux-operator/templates/crds.yaml
around lines 1038 to 1059, the validation rules incorrectly use self.url when
they should reference self.type for checking specific provider types. To fix
this, replace self.url with self.type in the rules that check for 'Static' and
ArtifactTag types in the certSecretRef and secretRef validation rules, ensuring
the conditions correctly validate the resource type instead of the URL.

@kvaps Andrei Kvapil (kvaps) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you <3

@kvaps
Andrei Kvapil (kvaps) merged commit 2c12678 into cozystack:main Jul 9, 2025
@kingdonb
Kingdon Barrett (kingdonb) deleted the update-flux-operator branch July 10, 2025 13:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants