FluxCD¶
Summary
Flux is a decentralized, pull-based GitOps toolkit for Kubernetes and a CNCF Graduated project (since 2022-11-30). It is a set of independent controllers (the GitOps Toolkit) that pull desired state from Git, OCI registries, Helm repositories or buckets and reconcile it with server-side apply, Kustomize and Helm v4. Each cluster runs its own Flux, with no central hub, API server or database. That makes it a strong fit for fleets, edge and air-gapped sites, and security-hardened platforms. The current release is v2.9.5 (2026-08-31). Flux outlived its original sponsor Weaveworks (closed February 2024) under open CNCF governance. ControlPlane now employs a third of the core maintainers and adds the Flux Operator (FluxInstance, ResourceSets, Web UI) on top.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | v2.9.5 (2026-08-31); minor 2.9.0 GA 2026-06-30 |
| Supported releases | Last three minors: 2.9, 2.8, 2.7 (2.6 is EOL) |
| Kubernetes support (2.9) | 1.34, 1.35, 1.36; OpenShift 4.21 |
| Release cadence | At least three minors a year, about two weeks after each Kubernetes minor |
| Repository | github.com/fluxcd/flux2 |
| Language | Go |
| License | Apache-2.0 (Flux Operator: AGPL-3.0) |
| Governance | CNCF Graduated (2022-11-30); 9 core maintainers from ControlPlane (3), NexHealth, SUSE, Associmates, and independents |
| Core APIs | source.toolkit.fluxcd.io/v1, kustomize.toolkit.fluxcd.io/v1, helm.toolkit.fluxcd.io/v2, image.toolkit.fluxcd.io/v1, notification.toolkit.fluxcd.io/v1beta3 (Alert/Provider) and /v1 (Receiver) |
| Ecosystem | Flux Operator v0.60.0 (2026-09-11), Flagger (progressive delivery), Flux CLI plugins (schema, mirror) |
Architecture at a Glance¶
Each cluster runs its own controllers. source-controller turns every source into an artifact, and the appliers reconcile it into the cluster.
flowchart LR
subgraph Ext["Sources"]
Git["Git"]
OCI["OCI registry"]
HelmRepo["Helm repo"]
end
subgraph Cluster["Each Kubernetes cluster (flux-system)"]
SC["source-controller"]
KC["kustomize-controller"]
HC["helm-controller"]
NC["notification-controller"]
IA["image-reflector +<br/>image-automation"]
end
API["Kubernetes API"]
Chat["Slack / Git status"]
Git --> SC
OCI --> SC
HelmRepo --> SC
SC -->|"artifacts"| KC
SC -->|"charts"| HC
KC -->|"server-side apply"| API
HC -->|"Helm v4 SSA"| API
KC -->|"events"| NC
HC -->|"events"| NC
NC --> Chat
IA -->|"commit new tags"| Git
The full component diagram, reconciliation sequence and security model are in the Explanation.
Evaluation¶
| Pros | Cons |
|---|---|
| Decentralized: no hub to lose; each cluster self-reconciles | No UI in the CNCF distribution (Flux Operator Web UI, Headlamp or Backstage plugins fill the gap) |
| Pull-based: no inbound access to clusters | Many CRDs and composition patterns, so a steeper learning curve |
| Kubernetes-native RBAC and impersonation for multi-tenancy | No first-class sync waves/hooks; ordering via dependsOn, health checks and SSA stages |
| Helm v4 (SSA, kstatus health) and Kustomize built in | Debugging is kubectl/flux CLI-centric |
| Built-in image update automation (GA since 2.7) | Smaller community than Argo CD |
| OCI artifacts with Cosign/Notation verification ("Gitless GitOps") | Richer fleet and preview features (ResourceSets) live in the separately licensed Flux Operator |
| CEL health checks and readiness expressions | Monorepos need extra design (sparse checkout, ArtifactGenerator, OCI) |
| Small footprint (64Mi memory requests); air-gapped and edge friendly |
When It Fits¶
- Good fit: many clusters or edge sites; air-gapped or regulated environments; platform teams that want Kubernetes RBAC as the only authorization model; OCI-based supply chains with signature verification; teams already on Helm and Kustomize.
- Weaker fit: organisations that need a rich multi-cluster UI with SSO-scoped RBAC out of the box; teams that depend on Argo-style sync waves and hooks; users who want Jsonnet or config-management plugins.
Recent Releases¶
| Release | Date | Headline changes |
|---|---|---|
| 2.9 | 2026-06-30 | CLI plugin system (schema, mirror); SSA field ignore rules; age post-quantum SOPS; OpenBao/Vault Workload Identity; Helm post-render strategies (default now combined); SSH commit signing/verification; OIDC Receivers; ArtifactGenerator directory discovery; removed image/v1beta2 and notification/v1beta2 |
| 2.8 | 2026-02-24 | Helm v4 (SSA + kstatus) with .status.inventory; faster recovery (cancel stale health checks); CEL readiness for HelmReleases; PR/MR comment providers; custom SSA apply stages; Cosign v3; removed v1beta2/v2beta2 source, kustomize, helm APIs |
| 2.7 | 2025-09-30 | Image automation GA (v1); ExternalArtifact + ArtifactGenerator (source-watcher); config watches; object-level Workload Identity; OpenTelemetry tracing; flux migrate |
Details and the support matrix are in Reference: Release and Support Matrix.
Ecosystem and Governance¶
- Flux Operator (ControlPlane, AGPL-3.0):
FluxInstancefor declarative install and upgrades,ResourceSetfor templated app bundles and PR preview environments,FluxReport, the Flux Web UI and an MCP server. See Explanation: Flux Operator and ResourceSets. - Weaveworks aftermath: Weaveworks (creator of Flux and coiner of "GitOps") shut down in February 2024. Flux continued because the CNCF owns it. Weave GitOps, the old UI, is now a community-driven project with little release activity (its latest line is 0.39.0-rc as of 2026-09). The Flux Operator Web UI has become the UI the maintainers promote.
- Commercial support: ControlPlane (enterprise distribution, extended Kubernetes/OpenShift compatibility) and cloud vendors (Azure's Flux-based GitOps extension) ship or support Flux (Flux releases).
- Companions: Flagger (canary/blue-green),
fluxcd/agent-skillsfor coding agents, Terraform provider for bootstrap.
Alternatives, Migration and Lock-in¶
- Argo CD is the main alternative: centralized hub, rich UI, sync waves, ApplicationSets. See GitOps Comparison: ArgoCD vs FluxCD and Argo CD.
- Lock-in is low. Flux consumes plain Kubernetes YAML, Kustomize overlays and Helm charts. Only the thin layer of Flux CRDs (GitRepository, Kustomization, HelmRelease) is Flux-specific. Moving to Argo CD mostly means rewriting those objects as Applications.
- Within Flux, the main migrations are API upgrades (
flux migrate) and moving fromflux bootstrapto the Flux Operator.
Topic Map¶
- How-to Guides: install, bootstrap (CLI or Operator), upgrade, Git/OCI delivery, Helm, image automation, SOPS, multi-tenancy, ResourceSets, monorepos, webhooks, plugins, troubleshooting.
- Reference: release/support matrix, component versions, CRD API versions, ports and resources, lockdown flags, auth and notification options, feature gates, hardening checklist, scaling data.
- Explanation: architecture, reconciliation model, artifacts and OCI, ArtifactGenerator, SSA and drift, Helm v4, image automation, topologies, security model, Flux Operator, history and governance.
Related Topics¶
- Argo CD: the other CNCF Graduated GitOps engine
- CI/CD domain overview
- SOPS: secret encryption decrypted natively by kustomize-controller
- External Secrets Operator: alternative to secrets-in-Git
- Kubernetes: the platform Flux reconciles into
Sources¶
- Flux documentation
- flux2 repository and releases
- Flux releases and support policy
- Announcing Flux 2.9 GA
- Announcing Flux 2.8 GA
- Announcing Flux 2.7 GA
- GitOps Toolkit components
- Flux FAQ
- Flux is a CNCF Graduated project
- CNCF project page
- Flux turns 10
- Flux core maintainers
- Flux Project Roadmap for 2026 (discussion)
- Flux Operator and docs
Questions¶
Open¶
- When will
ArtifactGenerator(source.extensions.fluxcd.io/v1beta1) reach GA? The provisional v2.10 milestone in the Flux roadmap does not list it (checked 2026-09-27); see also the 2026 roadmap discussion. - Will
CancelHealthCheckOnNewRevisionbecome default-on? The 2.8 announcement says it will once stable across both controllers. See Reference: Feature Gates of Note.
Answered¶
- Q: When will
AlertandProviderreach GA? The provisional v2.10 milestone ("mid Q4 2026") plans to promote theEvent,AlertandProviderAPIs tov1and to deprecatenotification.toolkit.fluxcd.io/v1beta3(Flux roadmap, checked 2026-09-27). - Q: Which APIs will Flux 2.10 remove? None are listed. The provisional milestone only deprecates
notification.toolkit.fluxcd.io/v1beta3and ends support for Flux 2.7.x and Kubernetes 1.34.x (Flux roadmap, checked 2026-09-27). - Q: How does Flux handle large monorepos (10,000+ files)? — source-controller packages the whole checkout as one artifact, so very large repos are slow. Use, in rising order of effect:
spec.ignore(smaller artifact, full fetch),spec.sparseCheckout(fetch only listed directories), a deploy branch, several narrowGitRepositoryobjects,ArtifactGeneratordecomposition (per-app artifacts, 2.7+, directory discovery in 2.9), or OCI artifacts built in CI (most scalable). See How-to Guides: Handle a Monorepo. Reference: Flux FAQ. - Q: Does Flux have a UI? — Not in the CNCF distribution. The maintained option is the Flux Operator's Flux Web UI (dashboards, workload view and pod logs since the 2.9 era, OIDC SSO, RBAC-scoped actions). Weave GitOps is community-driven with little activity. Headlamp and Backstage plugins are alternatives.
- Q: Is Flux still safe to adopt after Weaveworks closed? — Yes. It is CNCF Graduated with open governance, ships three minors a year (2.7 → 2.9 in nine months), and its maintainers work at several companies (CORE-MAINTAINERS).