chore(flux): update image ghcr.io/fluxcd/flux-manifests v2.6.4 → v2.7.0 (clustertool) (#40258)
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
|
[ghcr.io/fluxcd/flux-manifests](https://redirect.github.com/fluxcd/flux2)
| minor | `v2.6.4` -> `v2.7.0` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
<details>
<summary>fluxcd/flux2 (ghcr.io/fluxcd/flux-manifests)</summary>
###
[`v2.7.0`](https://redirect.github.com/fluxcd/flux2/releases/tag/v2.7.0)
[Compare
Source](https://redirect.github.com/fluxcd/flux2/compare/v2.6.4...v2.7.0)
#### Highlights
Flux v2.7.0 is a feature release. Users are encouraged to upgrade for
the best experience.
For a compressive overview of new features and API changes included in
this release, please refer to the [Announcing Flux 2.7 GA blog
post](https://fluxcd.io/blog/2025/09/flux-v2.7.0/).
Overview of the new features:
- General availability release of the Image Automation APIs
(`ImagePolicy`, `ImageRepository`, `ImageUpdateAutomation`)
- Watch for changes in ConfigMaps and Secrets references
(`Kustomization`, `HelmRelease`)
- Support for remote cluster authentication using Workload Identity
(`Kustomization`, `HelmRelease`)
- Extend the readiness evaluation of dependencies with CEL expressions
(`Kustomization`, `HelmRelease`)
- Support for global SOPS Age decryption keys on single-tenant clusters
(`Kustomization`)
- Support for optional Kustomize components (`Kustomization`)
- Introduce `RetryOnFailure` lifecycle management strategy
(`HelmRelease`)
- Support mTLS for sending alerts to external systems (`Provider`)
- Object-level workload identity authentication (`Bucket`, `Provider`)
- Support mTLS for GitHub App transport (`GitRepository`,
`ImageUpdateAutomation`, `Provider`)
- OpenTelemetry tracing for `Kustomization` and `HelmRelease`
reconciliation (`Provider`)
- Support for 3rd-party source controllers (`ExternalArtifact`)
- Support for source composition and decomposition patterns
(`ArtifactGenerator`)
- `CancelHealthCheckOnNewRevision` feature gate (kustomize-controller)
- `GitSparseCheckout` feature gate (image-automation-controller)
❤️ Big thanks to all the Flux contributors that helped us with this
release!
##### Kubernetes compatibility
This release is compatible with the following Kubernetes versions:
| Kubernetes version | Minimum required |
| ------------------ | ---------------- |
| `v1.32` | `>= 1.32.0` |
| `v1.33` | `>= 1.33.0` |
| `v1.34` | `>= 1.34.1` |
> \[!NOTE]
> Note that the Flux project offers support only for the latest three
minor versions of Kubernetes.
> Backwards compatibility with older versions of Kubernetes and
OpenShift is offered by vendors such as
> [ControlPlane](https://control-plane.io/enterprise-for-flux-cd/) that
provide enterprise support for Flux.
##### OpenShift compatibility
Flux can be installed on Red Hat OpenShift cluster directly from
OperatorHub using [Flux
Operator](https://operatorhub.io/operator/flux-operator). The operator
allows the configuration of Flux multi-tenancy lockdown, network
policies, persistent storage, sharding, vertical scaling and the
synchronization of the cluster state from Git repositories, OCI
artifacts, and S3-compatible storage.
#### Upgrade procedure
⚠️ The Flux APIs `v1beta1` and `v2beta1` (deprecated in 2023)
have reached end-of-life and have been removed from the CRDs.
Unless you are using [Flux
Operator](https://redirect.github.com/controlplaneio-fluxcd/flux-operator)
to deploy the Flux controllers, you must run the `flux migrate` command
on clusters before upgrading.
For more details, please refer to the [Flux v2.7 upgrade
guide](https://fluxcd.io/blog/2025/09/flux-v2.7.0/#upgrade-procedure).
#### Components changelog
- source-controller
[v1.7.0](https://redirect.github.com/fluxcd/source-controller/blob/v1.7.0/CHANGELOG.md)
- kustomize-controller
[v1.7.0](https://redirect.github.com/fluxcd/kustomize-controller/blob/v1.7.0/CHANGELOG.md)
- notification-controller
[v1.7.0](https://redirect.github.com/fluxcd/notification-controller/blob/v1.7.0/CHANGELOG.md)
[v1.7.1](https://redirect.github.com/fluxcd/notification-controller/blob/v1.7.1/CHANGELOG.md)
- helm-controller
[v1.4.0](https://redirect.github.com/fluxcd/helm-controller/blob/v1.4.0/CHANGELOG.md)
- image-reflector-controller
[v1.0.0](https://redirect.github.com/fluxcd/image-reflector-controller/blob/v1.0.0/CHANGELOG.md)
[v1.0.1](https://redirect.github.com/fluxcd/image-reflector-controller/blob/v1.0.1/CHANGELOG.md)
- image-automation-controller
[v1.0.0](https://redirect.github.com/fluxcd/image-automation-controller/blob/v1.0.0/CHANGELOG.md)
[v1.0.1](https://redirect.github.com/fluxcd/image-automation-controller/blob/v1.0.1/CHANGELOG.md)
- source-watcher
[v2.0.0](https://redirect.github.com/fluxcd/source-watcher/blob/v2.0.0/CHANGELOG.md)
[v2.0.1](https://redirect.github.com/fluxcd/source-watcher/blob/v1.0.1/CHANGELOG.md)
##### New Documentation
- [ImageRepository v1
specification](https://fluxcd.io/flux/components/image/imagerepositories)
- [ImagePolicy v1
specification](https://fluxcd.io/flux/components/image/imagepolicies)
- [ImageUpdateAutomation v1
specification](https://fluxcd.io/flux/components/image/imageupdateautomations)
- [ExternalArtifact v1
specification](https://fluxcd.io/flux/components/source/externalartifacts)
- [ArtifactGenerator v1beta1
specification](https://fluxcd.io/flux/components/source/artifactgenerators)
#### CLI changelog
- Add backport label for `v2.6.x` by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5379](https://redirect.github.com/fluxcd/flux2/pull/5379)
- Update image-reflector-controller to v0.35.1 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5381](https://redirect.github.com/fluxcd/flux2/pull/5381)
- Add digest pinning to image automation testing by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5383](https://redirect.github.com/fluxcd/flux2/pull/5383)
- correct small typo by
[@​JIbald](https://redirect.github.com/JIbald) in
[#​5388](https://redirect.github.com/fluxcd/flux2/pull/5388)
- Remove credentials sync manifests by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5347](https://redirect.github.com/fluxcd/flux2/pull/5347)
- Add sparse checkout to cli by
[@​ba-work](https://redirect.github.com/ba-work) in
[#​5389](https://redirect.github.com/fluxcd/flux2/pull/5389)
- fix: Allow Azure CLI calls in `flux push artifact --provider azure` on
DevOps runners by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5390](https://redirect.github.com/fluxcd/flux2/pull/5390)
- Fix `knownhosts key mismatch` regression bug by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5404](https://redirect.github.com/fluxcd/flux2/pull/5404)
- refactor: Use `normalize.UnstructuredList` instead of
`ssa.SetNativeKindsDefaults` by
[@​cappyzawa](https://redirect.github.com/cappyzawa) in
[#​5407](https://redirect.github.com/fluxcd/flux2/pull/5407)
- Make service-account name configurable in `flux create tenant` by
[@​reiSh6phoo9o](https://redirect.github.com/reiSh6phoo9o) in
[#​5402](https://redirect.github.com/fluxcd/flux2/pull/5402)
- Update toolkit components by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5409](https://redirect.github.com/fluxcd/flux2/pull/5409)
- refactor: cleanup GetArtifactRegistryCredentials error handling by
[@​cappyzawa](https://redirect.github.com/cappyzawa) in
[#​5418](https://redirect.github.com/fluxcd/flux2/pull/5418)
- Promote image CLI commands to stable by
[@​dgunzy](https://redirect.github.com/dgunzy) in
[#​5421](https://redirect.github.com/fluxcd/flux2/pull/5421)
- Update toolkit components by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5426](https://redirect.github.com/fluxcd/flux2/pull/5426)
- Bump pkg/ssa to v0.49.0 for CABundle validation fix by
[@​dgunzy](https://redirect.github.com/dgunzy) in
[#​5431](https://redirect.github.com/fluxcd/flux2/pull/5431)
- \[RFC-0010] Add workload identity support for remote clusters by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5434](https://redirect.github.com/fluxcd/flux2/pull/5434)
- Update toolkit components by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5443](https://redirect.github.com/fluxcd/flux2/pull/5443)
- Fix `flux push artifact` for insecure registries by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5449](https://redirect.github.com/fluxcd/flux2/pull/5449)
- \[RFC-0010] Add workload identity support for remote generic clusters
by [@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5452](https://redirect.github.com/fluxcd/flux2/pull/5452)
- Fix `flux diff kustomization` ignore patterns by
[@​dgunzy](https://redirect.github.com/dgunzy) in
[#​5451](https://redirect.github.com/fluxcd/flux2/pull/5451)
- Update dependencies to Kubernetes 1.33.2 by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5453](https://redirect.github.com/fluxcd/flux2/pull/5453)
- build(deps): bump the ci group across 1 directory with 7 updates by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​5435](https://redirect.github.com/fluxcd/flux2/pull/5435)
- Upgrade fluxcd/pkg dependencies by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5455](https://redirect.github.com/fluxcd/flux2/pull/5455)
- ci: Use GITHUB\_TOKEN for API calls in update workflow by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5460](https://redirect.github.com/fluxcd/flux2/pull/5460)
- manifests: Add `app.kubernetes.io/part-of: flux` label to controller
pods by [@​pinkavaj](https://redirect.github.com/pinkavaj) in
[#​5440](https://redirect.github.com/fluxcd/flux2/pull/5440)
- Migrate sourcesecret package to runtime/secrets APIs by
[@​cappyzawa](https://redirect.github.com/cappyzawa) in
[#​5462](https://redirect.github.com/fluxcd/flux2/pull/5462)
- Implement `flux migrate` command by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5473](https://redirect.github.com/fluxcd/flux2/pull/5473)
- \[RFC-0007] Implementation history update by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5480](https://redirect.github.com/fluxcd/flux2/pull/5480)
- Run conformance tests for Kubernetes 1.34.0 by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5497](https://redirect.github.com/fluxcd/flux2/pull/5497)
- Update to Kubernetes v1.34.0 and Go 1.25.0 by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5499](https://redirect.github.com/fluxcd/flux2/pull/5499)
- build(deps): bump the ci group across 1 directory with 10 updates by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​5500](https://redirect.github.com/fluxcd/flux2/pull/5500)
- Allow the Go runtime to dynamically set `GOMAXPROCS` by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5501](https://redirect.github.com/fluxcd/flux2/pull/5501)
- fix(events): respect `--all-namespaces` flag by
[@​mohiuddin-khan-shiam](https://redirect.github.com/mohiuddin-khan-shiam)
in [#​5414](https://redirect.github.com/fluxcd/flux2/pull/5414)
- \[RFC-0011] OpenTelemetry Tracing by
[@​adri1197](https://redirect.github.com/adri1197) in
[#​5321](https://redirect.github.com/fluxcd/flux2/pull/5321)
- \[RFC-0012] External Artifact API by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5292](https://redirect.github.com/fluxcd/flux2/pull/5292)
- Add `--show-history` flag to `debug helmrelease` by
[@​hawkaii](https://redirect.github.com/hawkaii) in
[#​5505](https://redirect.github.com/fluxcd/flux2/pull/5505)
- Skip release candidates on updates by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5507](https://redirect.github.com/fluxcd/flux2/pull/5507)
- ci: Align azure e2e tests secret names with fluxcd/pkg by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5508](https://redirect.github.com/fluxcd/flux2/pull/5508)
- Update image-reflector-controller to v1.0.0 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5517](https://redirect.github.com/fluxcd/flux2/pull/5517)
- Update source-controller to v1.7.0 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5518](https://redirect.github.com/fluxcd/flux2/pull/5518)
- Add the source-watcher controller to the Flux distribution by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5519](https://redirect.github.com/fluxcd/flux2/pull/5519)
- Add read-only commands for `ArtifactGenerator` kind by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5520](https://redirect.github.com/fluxcd/flux2/pull/5520)
- ci: Add source-watcher to the update workflow by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5521](https://redirect.github.com/fluxcd/flux2/pull/5521)
- Update image-automation-controller to v1.0.0 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5522](https://redirect.github.com/fluxcd/flux2/pull/5522)
- Update image-reflector-controller to v1.0.1 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5525](https://redirect.github.com/fluxcd/flux2/pull/5525)
- Implement `flux [reconcile|suspend|resume] image policy` commands by
[@​lukas8219](https://redirect.github.com/lukas8219) in
[#​5492](https://redirect.github.com/fluxcd/flux2/pull/5492)
- Handle `force: enabled` annotation in `flux diff ks` command by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5528](https://redirect.github.com/fluxcd/flux2/pull/5528)
- ci: Refactor CI with `fluxcd/gha-workflows` by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5529](https://redirect.github.com/fluxcd/flux2/pull/5529)
- Remove `ArtifactGenerators` during uninstall by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5531](https://redirect.github.com/fluxcd/flux2/pull/5531)
- Add support for `ExternalArtifact` to `flux trace` by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5532](https://redirect.github.com/fluxcd/flux2/pull/5532)
- Set Kubernetes 1.32 as min supported version by
[@​stefanprodan](https://redirect.github.com/stefanprodan) in
[#​5533](https://redirect.github.com/fluxcd/flux2/pull/5533)
- build(deps): bump the ci group with 6 updates by
[@​dependabot](https://redirect.github.com/dependabot)\[bot] in
[#​5535](https://redirect.github.com/fluxcd/flux2/pull/5535)
- Add support for custom storage namespace in HelmRelease creation by
[@​prasad89](https://redirect.github.com/prasad89) in
[#​5534](https://redirect.github.com/fluxcd/flux2/pull/5534)
- Update toolkit components by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5537](https://redirect.github.com/fluxcd/flux2/pull/5537)
- ci: remove cron schedule from update by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5539](https://redirect.github.com/fluxcd/flux2/pull/5539)
- Update source-watcher to v2.0.1 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5540](https://redirect.github.com/fluxcd/flux2/pull/5540)
- Add `--show-history` flag to `debug kustomization` by
[@​matheuscscp](https://redirect.github.com/matheuscscp) in
[#​5541](https://redirect.github.com/fluxcd/flux2/pull/5541)
- Update image-automation-controller to v1.0.1 by
[@​fluxcdbot](https://redirect.github.com/fluxcdbot) in
[#​5542](https://redirect.github.com/fluxcd/flux2/pull/5542)
- `fluxcd/flux2/action`: Determine latest version without using GitHub
API by [@​RussellAult](https://redirect.github.com/RussellAult) in
[#​5509](https://redirect.github.com/fluxcd/flux2/pull/5509)
#### New Contributors
- [@​JIbald](https://redirect.github.com/JIbald) made their first
contribution in
[#​5388](https://redirect.github.com/fluxcd/flux2/pull/5388)
- [@​ba-work](https://redirect.github.com/ba-work) made their
first contribution in
[#​5389](https://redirect.github.com/fluxcd/flux2/pull/5389)
- [@​cappyzawa](https://redirect.github.com/cappyzawa) made their
first contribution in
[#​5407](https://redirect.github.com/fluxcd/flux2/pull/5407)
- [@​reiSh6phoo9o](https://redirect.github.com/reiSh6phoo9o) made
their first contribution in
[#​5402](https://redirect.github.com/fluxcd/flux2/pull/5402)
- [@​pinkavaj](https://redirect.github.com/pinkavaj) made their
first contribution in
[#​5440](https://redirect.github.com/fluxcd/flux2/pull/5440)
-
[@​mohiuddin-khan-shiam](https://redirect.github.com/mohiuddin-khan-shiam)
made their first contribution in
[#​5414](https://redirect.github.com/fluxcd/flux2/pull/5414)
- [@​adri1197](https://redirect.github.com/adri1197) made their
first contribution in
[#​5321](https://redirect.github.com/fluxcd/flux2/pull/5321)
- [@​hawkaii](https://redirect.github.com/hawkaii) made their
first contribution in
[#​5505](https://redirect.github.com/fluxcd/flux2/pull/5505)
- [@​lukas8219](https://redirect.github.com/lukas8219) made their
first contribution in
[#​5492](https://redirect.github.com/fluxcd/flux2/pull/5492)
- [@​prasad89](https://redirect.github.com/prasad89) made their
first contribution in
[#​5534](https://redirect.github.com/fluxcd/flux2/pull/5534)
- [@​RussellAult](https://redirect.github.com/RussellAult) made
their first contribution in
[#​5509](https://redirect.github.com/fluxcd/flux2/pull/5509)
**Full Changelog**:
<https://github.com/fluxcd/flux2/compare/v2.6.0...v2.7.0>
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS44Mi4xMCIsInVwZGF0ZWRJblZlciI6IjQxLjgyLjEwIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->