Skip to content

Helmfile

Categories: cd, helm, kubernetes

Renovate supports updating Helmfile dependencies.

File Matching

By default, Renovate will check any files matching any of the following regular expressions:

/(^|/)helmfile\.ya?ml(?:\.gotmpl)?$/
/(^|/)helmfile\.d/.+\.ya?ml(?:\.gotmpl)?$/

For details on how to extend a manager's managerFilePatterns value, please follow this link.

Supported datasources

This manager supports extracting the following datasources: docker, helm.

Dependency types

This manager has no documented depType values.

Default config

{
  "registryAliases": {
    "stable": "https://charts.helm.sh/stable"
  },
  "commitMessageTopic": "helm chart {{depName}}",
  "managerFilePatterns": [
    "/(^|/)helmfile\\.ya?ml(?:\\.gotmpl)?$/",
    "/(^|/)helmfile\\.d/.+\\.ya?ml(?:\\.gotmpl)?$/"
  ]
}

Lock File Maintenance

This manager supports lockFileMaintenance for the following file(s):

  • helmfile.lock

Lock file maintenance is delegated to the underlying package manager, which Renovate runs as an external command.

Additional Information

Checks helmfile.yaml files and extracts dependencies for the helm datasource.

The helmfile manager defines this default registryAlias:

{
  "registryAliases": {
    "stable": "https://charts.helm.sh/stable"
  }
}

If your Helm charts make use of repository aliases then you will need to configure an registryAliases object in your config to tell Renovate where to look for them. Be aware that alias values must be properly formatted URIs.

If you need to change the versioning format, read the versioning documentation to learn more.

Private repositories and registries

To use private sources of Helm charts, you must set the password and username you use to authenticate to the private source. For this you use a custom hostRules array.

Classic repositories

Renovate passes hostRules with hostType: 'helm' to helmfile deps for classic (non-OCI) repositories. It does so through the <NAME>_USERNAME and <NAME>_PASSWORD environment variables, where <NAME> is the repository name in upper case with dashes replaced by underscores. The hostRules entry must have both a username and a password, and its matchHost must match the repository url. Helmfile uses each variable only when the repository does not set that field itself.

For example, with this helmfile.yaml:

repositories:
  - name: team-a-charts
    url: https://charts.example.com/team-a
  - name: public
    url: https://public.example.com
releases:
  - name: app
    chart: team-a-charts/app
    version: 1.0.0

and this Renovate config:

{
  hostRules: [
    {
      matchHost: 'https://charts.example.com',
      hostType: 'helm',
      username: '<some-username>',
      password: '<some-password>',
    },
  ],
}

Renovate runs helmfile deps with TEAM_A_CHARTS_USERNAME and TEAM_A_CHARTS_PASSWORD set. The public repository has no matching hostRules entry, so it gets no credentials.

OCI registries

{
  hostRules: [
    {
      // global login
      matchHost: 'ghcr.io',
      hostType: 'docker',
      username: '<some-username>',
      password: '<some-password>',
    },
    {
      // login with encrypted password
      matchHost: 'https://ghci.io',
      hostType: 'docker',
      username: '<some-username>',
      encrypted: {
        password: 'some-encrypted-password',
      },
    },
  ],
}