rebase! chore(deps): update dependency fluxcd/flux2 to v2.9.5 #2

Closed
shark wants to merge 1 commit from renovate/fluxcd-flux2-2.x into k0s
Collaborator

This PR contains the following updates:

Package Update Change
fluxcd/flux2 patch v2.9.4 -> v2.9.5

Release Notes

fluxcd/flux2 (fluxcd/flux2)

v2.9.5

Compare Source

Highlights

Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g. ${VAR:2:-1}, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Validate kubeconfigs from .spec.kubeConfig Secrets, rejecting local file references in certificate-authority, tokenFile, client-certificate and client-key; credentials and certificates must be embedded inline (helm-controller, kustomize-controller)
  • Purge temporary directories at startup (kustomize-controller)
  • Fix panic on negative-length substring expressions in post-build substitution (kustomize-controller, flux CLI)

Improvements:

  • Move back to upstream Helm v4.2.4, dropping the Flux fork (helm-controller, source-controller)
  • Update fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4 (all controllers, flux CLI)

Components changelog

CLI changelog

Full Changelog: https://github.com/fluxcd/flux2/compare/v2.9.4...v2.9.5


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [fluxcd/flux2](https://github.com/fluxcd/flux2) | patch | `v2.9.4` -> `v2.9.5` | --- ### Release Notes <details> <summary>fluxcd/flux2 (fluxcd/flux2)</summary> ### [`v2.9.5`](https://github.com/fluxcd/flux2/releases/tag/v2.9.5) [Compare Source](https://github.com/fluxcd/flux2/compare/v2.9.4...v2.9.5) #### Highlights Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g. `${VAR:2:-1}`, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience. ℹ️ Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from Flux v2.6 to the latest version. Fixes: - Validate kubeconfigs from `.spec.kubeConfig` Secrets, rejecting local file references in `certificate-authority`, `tokenFile`, `client-certificate` and `client-key`; credentials and certificates must be embedded inline (helm-controller, kustomize-controller) - Purge temporary directories at startup (kustomize-controller) - Fix panic on negative-length substring expressions in post-build substitution (kustomize-controller, flux CLI) Improvements: - Move back to upstream Helm v4.2.4, dropping the Flux fork (helm-controller, source-controller) - Update fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4 (all controllers, flux CLI) #### Components changelog - source-controller [v1.9.5](https://github.com/fluxcd/source-controller/blob/v1.9.5/CHANGELOG.md) - source-watcher [v2.2.4](https://github.com/fluxcd/source-watcher/blob/v2.2.4/CHANGELOG.md) - kustomize-controller [v1.9.5](https://github.com/fluxcd/kustomize-controller/blob/v1.9.5/CHANGELOG.md) - helm-controller [v1.6.4](https://github.com/fluxcd/helm-controller/blob/v1.6.4/CHANGELOG.md) - notification-controller [v1.9.4](https://github.com/fluxcd/notification-controller/blob/v1.9.4/CHANGELOG.md) - image-reflector-controller [v1.2.5](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.5/CHANGELOG.md) - image-automation-controller [v1.2.5](https://github.com/fluxcd/image-automation-controller/blob/v1.2.5/CHANGELOG.md) #### CLI changelog - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6046](https://github.com/fluxcd/flux2/pull/6046) - Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6048](https://github.com/fluxcd/flux2/pull/6048) - Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6049](https://github.com/fluxcd/flux2/pull/6049) **Full Changelog**: <https://github.com/fluxcd/flux2/compare/v2.9.4...v2.9.5> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNDAuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE0MC4xIiwidGFyZ2V0QnJhbmNoIjoiazBzIiwibGFiZWxzIjpbXX0=-->
shark bot added 1 commit 2026-09-09 00:04:58 +00:00
chore(deps): update dependency fluxcd/flux2 to v2.9.5
Some checks failed
renovate/artifacts Artifact file update failure
598ec58446
Author
Collaborator

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: flux-system/gotk-components.yaml
Command failed: install-tool flux v2.9.5

### ⚠️ Artifact update problem Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens: - any of the package files in this branch needs updating, or - the branch becomes conflicted, or - you click the rebase/retry checkbox if found above, or - you rename this PR's title to start with "rebase!" to trigger it manually The artifact failure details are included below: ##### File name: flux-system/gotk-components.yaml ``` Command failed: install-tool flux v2.9.5 ```
shark bot force-pushed renovate/fluxcd-flux2-2.x from 598ec58446
Some checks failed
renovate/artifacts Artifact file update failure
to d77da611e6
Some checks failed
renovate/artifacts Artifact file update failure
2026-09-09 00:13:19 +00:00
Compare
shark bot closed this pull request 2026-09-09 00:22:36 +00:00
Author
Collaborator

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (v2.9.5). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

### Renovate Ignore Notification Because you closed this PR without merging, Renovate will ignore this update (`v2.9.5`). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the `ignoreDeps` array of your Renovate config. If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.
shark bot changed title from chore(deps): update dependency fluxcd/flux2 to v2.9.5 to rebase! chore(deps): update dependency fluxcd/flux2 to v2.9.5 2026-09-09 00:23:42 +00:00
Some checks failed
renovate/artifacts Artifact file update failure

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
valeninki/k8s!2
No description provided.