Skip to content

FluxCD

Summary

Flux is a decentralized, pull-based GitOps toolkit for Kubernetes and a CNCF Graduated project (since 2022-11-30). It is a set of independent controllers (the GitOps Toolkit) that pull desired state from Git, OCI registries, Helm repositories or buckets and reconcile it with server-side apply, Kustomize and Helm v4. Each cluster runs its own Flux, with no central hub, API server or database. That makes it a strong fit for fleets, edge and air-gapped sites, and security-hardened platforms. The current release is v2.9.5 (2026-08-31). Flux outlived its original sponsor Weaveworks (closed February 2024) under open CNCF governance. ControlPlane now employs a third of the core maintainers and adds the Flux Operator (FluxInstance, ResourceSets, Web UI) on top.

Key Facts

Attribute Detail
Latest Version v2.9.5 (2026-08-31); minor 2.9.0 GA 2026-06-30
Supported releases Last three minors: 2.9, 2.8, 2.7 (2.6 is EOL)
Kubernetes support (2.9) 1.34, 1.35, 1.36; OpenShift 4.21
Release cadence At least three minors a year, about two weeks after each Kubernetes minor
Repository github.com/fluxcd/flux2
Language Go
License Apache-2.0 (Flux Operator: AGPL-3.0)
Governance CNCF Graduated (2022-11-30); 9 core maintainers from ControlPlane (3), NexHealth, SUSE, Associmates, and independents
Core APIs source.toolkit.fluxcd.io/v1, kustomize.toolkit.fluxcd.io/v1, helm.toolkit.fluxcd.io/v2, image.toolkit.fluxcd.io/v1, notification.toolkit.fluxcd.io/v1beta3 (Alert/Provider) and /v1 (Receiver)
Ecosystem Flux Operator v0.60.0 (2026-09-11), Flagger (progressive delivery), Flux CLI plugins (schema, mirror)

Architecture at a Glance

Each cluster runs its own controllers. source-controller turns every source into an artifact, and the appliers reconcile it into the cluster.

flowchart LR
    subgraph Ext["Sources"]
        Git["Git"]
        OCI["OCI registry"]
        HelmRepo["Helm repo"]
    end
    subgraph Cluster["Each Kubernetes cluster (flux-system)"]
        SC["source-controller"]
        KC["kustomize-controller"]
        HC["helm-controller"]
        NC["notification-controller"]
        IA["image-reflector +<br/>image-automation"]
    end
    API["Kubernetes API"]
    Chat["Slack / Git status"]

    Git --> SC
    OCI --> SC
    HelmRepo --> SC
    SC -->|"artifacts"| KC
    SC -->|"charts"| HC
    KC -->|"server-side apply"| API
    HC -->|"Helm v4 SSA"| API
    KC -->|"events"| NC
    HC -->|"events"| NC
    NC --> Chat
    IA -->|"commit new tags"| Git

The full component diagram, reconciliation sequence and security model are in the Explanation.

Evaluation

Pros Cons
Decentralized: no hub to lose; each cluster self-reconciles No UI in the CNCF distribution (Flux Operator Web UI, Headlamp or Backstage plugins fill the gap)
Pull-based: no inbound access to clusters Many CRDs and composition patterns, so a steeper learning curve
Kubernetes-native RBAC and impersonation for multi-tenancy No first-class sync waves/hooks; ordering via dependsOn, health checks and SSA stages
Helm v4 (SSA, kstatus health) and Kustomize built in Debugging is kubectl/flux CLI-centric
Built-in image update automation (GA since 2.7) Smaller community than Argo CD
OCI artifacts with Cosign/Notation verification ("Gitless GitOps") Richer fleet and preview features (ResourceSets) live in the separately licensed Flux Operator
CEL health checks and readiness expressions Monorepos need extra design (sparse checkout, ArtifactGenerator, OCI)
Small footprint (64Mi memory requests); air-gapped and edge friendly

When It Fits

  • Good fit: many clusters or edge sites; air-gapped or regulated environments; platform teams that want Kubernetes RBAC as the only authorization model; OCI-based supply chains with signature verification; teams already on Helm and Kustomize.
  • Weaker fit: organisations that need a rich multi-cluster UI with SSO-scoped RBAC out of the box; teams that depend on Argo-style sync waves and hooks; users who want Jsonnet or config-management plugins.

Recent Releases

Release Date Headline changes
2.9 2026-06-30 CLI plugin system (schema, mirror); SSA field ignore rules; age post-quantum SOPS; OpenBao/Vault Workload Identity; Helm post-render strategies (default now combined); SSH commit signing/verification; OIDC Receivers; ArtifactGenerator directory discovery; removed image/v1beta2 and notification/v1beta2
2.8 2026-02-24 Helm v4 (SSA + kstatus) with .status.inventory; faster recovery (cancel stale health checks); CEL readiness for HelmReleases; PR/MR comment providers; custom SSA apply stages; Cosign v3; removed v1beta2/v2beta2 source, kustomize, helm APIs
2.7 2025-09-30 Image automation GA (v1); ExternalArtifact + ArtifactGenerator (source-watcher); config watches; object-level Workload Identity; OpenTelemetry tracing; flux migrate

Details and the support matrix are in Reference: Release and Support Matrix.

Ecosystem and Governance

  • Flux Operator (ControlPlane, AGPL-3.0): FluxInstance for declarative install and upgrades, ResourceSet for templated app bundles and PR preview environments, FluxReport, the Flux Web UI and an MCP server. See Explanation: Flux Operator and ResourceSets.
  • Weaveworks aftermath: Weaveworks (creator of Flux and coiner of "GitOps") shut down in February 2024. Flux continued because the CNCF owns it. Weave GitOps, the old UI, is now a community-driven project with little release activity (its latest line is 0.39.0-rc as of 2026-09). The Flux Operator Web UI has become the UI the maintainers promote.
  • Commercial support: ControlPlane (enterprise distribution, extended Kubernetes/OpenShift compatibility) and cloud vendors (Azure's Flux-based GitOps extension) ship or support Flux (Flux releases).
  • Companions: Flagger (canary/blue-green), fluxcd/agent-skills for coding agents, Terraform provider for bootstrap.

Alternatives, Migration and Lock-in

  • Argo CD is the main alternative: centralized hub, rich UI, sync waves, ApplicationSets. See GitOps Comparison: ArgoCD vs FluxCD and Argo CD.
  • Lock-in is low. Flux consumes plain Kubernetes YAML, Kustomize overlays and Helm charts. Only the thin layer of Flux CRDs (GitRepository, Kustomization, HelmRelease) is Flux-specific. Moving to Argo CD mostly means rewriting those objects as Applications.
  • Within Flux, the main migrations are API upgrades (flux migrate) and moving from flux bootstrap to the Flux Operator.

Topic Map

  • How-to Guides: install, bootstrap (CLI or Operator), upgrade, Git/OCI delivery, Helm, image automation, SOPS, multi-tenancy, ResourceSets, monorepos, webhooks, plugins, troubleshooting.
  • Reference: release/support matrix, component versions, CRD API versions, ports and resources, lockdown flags, auth and notification options, feature gates, hardening checklist, scaling data.
  • Explanation: architecture, reconciliation model, artifacts and OCI, ArtifactGenerator, SSA and drift, Helm v4, image automation, topologies, security model, Flux Operator, history and governance.

Sources

Questions

Open

  • When will ArtifactGenerator (source.extensions.fluxcd.io/v1beta1) reach GA? The provisional v2.10 milestone in the Flux roadmap does not list it (checked 2026-09-27); see also the 2026 roadmap discussion.
  • Will CancelHealthCheckOnNewRevision become default-on? The 2.8 announcement says it will once stable across both controllers. See Reference: Feature Gates of Note.

Answered

  • Q: When will Alert and Provider reach GA? The provisional v2.10 milestone ("mid Q4 2026") plans to promote the Event, Alert and Provider APIs to v1 and to deprecate notification.toolkit.fluxcd.io/v1beta3 (Flux roadmap, checked 2026-09-27).
  • Q: Which APIs will Flux 2.10 remove? None are listed. The provisional milestone only deprecates notification.toolkit.fluxcd.io/v1beta3 and ends support for Flux 2.7.x and Kubernetes 1.34.x (Flux roadmap, checked 2026-09-27).
  • Q: How does Flux handle large monorepos (10,000+ files)? — source-controller packages the whole checkout as one artifact, so very large repos are slow. Use, in rising order of effect: spec.ignore (smaller artifact, full fetch), spec.sparseCheckout (fetch only listed directories), a deploy branch, several narrow GitRepository objects, ArtifactGenerator decomposition (per-app artifacts, 2.7+, directory discovery in 2.9), or OCI artifacts built in CI (most scalable). See How-to Guides: Handle a Monorepo. Reference: Flux FAQ.
  • Q: Does Flux have a UI? — Not in the CNCF distribution. The maintained option is the Flux Operator's Flux Web UI (dashboards, workload view and pod logs since the 2.9 era, OIDC SSO, RBAC-scoped actions). Weave GitOps is community-driven with little activity. Headlamp and Backstage plugins are alternatives.
  • Q: Is Flux still safe to adopt after Weaveworks closed? — Yes. It is CNCF Graduated with open governance, ships three minors a year (2.7 → 2.9 in nine months), and its maintainers work at several companies (CORE-MAINTAINERS).