awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
fluxcd avatar

fluxcd/flux2

0
View on GitHub↗
7,888 stars·716 forks·Go·apache-2.0·44 viewsfluxcd.io↗

Flux2

Flux is a Kubernetes GitOps delivery tool used to automate application deployments by synchronizing cluster state with configurations stored in Git, OCI, or Helm repositories. It functions as a set of controllers that monitor desired state in external sources and continuously reconcile the live cluster to match those definitions.

The system distinguishes itself through a multi-cluster management plane that coordinates application delivery across fleets of remote clusters from a central hub. It provides a dedicated mechanism for automated image updates, which scans container registries for new tags and automatically commits updated references back to the configuration repository. Additionally, it includes a secret decryption pipeline that secures sensitive data in version control using PGP, Age, or cloud KMS providers.

The project covers a broad range of delivery capabilities, including declarative Helm release management, Kustomize-based rendering, and infrastructure bootstrapping. It also provides integrated support for workload identity federation, artifact-based configuration, and event-driven synchronization via webhooks.

Users can manage the delivery pipelines and cluster resources through a dedicated command line interface.

Features

  • Cluster Bootstrapping - Performs the initial setup and configuration of a cluster, including the creation of a GitOps source repository.
  • Cluster State Reconciliation - Automates resource deployment by reconciling cluster state with configuration stored in repositories.
  • GitOps State Synchronization - Mirrors configuration from repositories and applies it via automatic reconciliation to synchronize cluster state.
  • Multi-Cluster Deployment Managers - Provides a centralized control plane to coordinate application delivery and authentication across fleets of remote Kubernetes clusters.
  • Kubernetes Manifest Management - Fetches, decrypts, and applies Kubernetes manifests and overlays to a cluster based on a pipeline.
  • Reconciliation Loops - Implements continuous control loops that synchronize the live cluster state with the desired state defined in repositories.
  • Configuration Syncing - Monitors repositories, registries, or buckets for changes and produces artifacts to synchronize cluster state.
  • Source Map Composers - Combines multiple configuration sources into one artifact or decomposes large monorepos into independent, triggerable pieces.
  • Artifact Distribution - Uses OCI-compliant container registries as the primary source of truth for distributing versioned configuration artifacts.
  • Configuration Source Management - Fetches configuration and manifests from Git, OCI registries, and cloud buckets to synchronize the cluster state.
  • Automated Container Updaters - Scans registries for new tags and automatically commits updated image references back to the configuration repository.
  • Secrets Deployment Pipelines - Decrypts secrets during the reconciliation process before they are applied to the cluster.
  • CI/CD and Pipeline Management - Assembles and configures continuous delivery pipelines on clusters via a command line interface.
  • CD Resource Orchestration - Creates the necessary configuration objects for sources, releases, and automation policies to orchestrate continuous delivery.
  • GitOps Tools - Provides a version-controlled deployment process to install the essential GitOps tooling on a cluster.
  • Git-Based Bootstrapping - Installs the toolkit and configures a remote Git repository as the primary source of truth for the cluster.
  • GitOps Bootstrapping - Creates a configuration repository and configures a cluster to synchronize with the source to initialize GitOps.
  • Chart Composition - Retrieves specific charts and merges value files to create deployable artifacts.
  • Configuration Source Management - Provides utilities to manage and synchronize connections to external configuration sources including Git, OCI, and cloud buckets.
  • Container Registry Scanning - Monitors registries for new image tags and digests using configurable intervals and filters.
  • GitOps Automation - Automates infrastructure updates and synchronization by connecting delivery controllers to Gitea repositories.
  • GitOps Controllers - Implements a reconciliation loop that allows the GitOps controllers to manage their own version updates.
  • GitOps Source Synchronization - Fetches specific branches, tags, or commits from Git to produce compressed configuration archives for deployment.
  • GitOps Workflows - Implements automated pipelines that synchronize cluster infrastructure state with version control repositories.
  • GitOps Dependency Synchronizers - Automates resource delivery by synchronizing cluster state with configurations stored in repositories or OCI artifacts.
  • Helm Chart Management - Manages the full lifecycle of Helm chart releases using declarative custom resources.
  • Chart Repositories - Tracks remote Helm chart repositories and their indices to resolve specific chart versions.
  • Helm Chart Deployment - Installs and updates application charts using declarative configurations to align cluster state with defined versions.
  • Drift Detection - Automates the identification of discrepancies between defined configuration and the actual live cluster state.
  • Kubernetes Drift Detectors - Specializes in identifying configuration drift specifically within Kubernetes cluster resources.
  • Multi-Cluster Orchestrators - Provides a management plane that coordinates the deployment and lifecycle of applications across multiple remote Kubernetes clusters.
  • Kubernetes Application Deployments - Automates the application of Kubernetes manifests to a cluster by continuously tracking a specific configuration source.
  • Manifest Rendering - Generates final Kubernetes manifests by applying overlays and strategic patches to base configurations via Kustomize.
  • Kustomize Deployment - Applies Kustomize manifests and overlays to the cluster, supporting strategic patches and image overrides.
  • Release Lifecycle Management - Manages the full lifecycle of Helm releases through declarative manifests for automated installation and upgrades.
  • Remote Cluster Access - Coordinates and applies configuration updates to remote Kubernetes clusters using secure authentication and impersonation.
  • Artifact Hosting - Retrieves configuration data from OCI repositories using tags, versions, or digests to maintain the cluster state.
  • Repository Synchronization - Automates manifest deployment by synchronizing the live cluster state with configurations stored in Git repositories.
  • Source Configurators - Connects the cluster to external Git repositories, OCI registries, buckets, or Helm charts to synchronize desired state.
  • Latest Version Identification - Evaluates image tags against a policy to identify the most recent version for automated updates.
  • Configuration Artifacts - Retrieves versioned configuration archives from multiple sources using secure authentication and PGP validation.
  • Image Tag Selection Policies - Selects the most recent image tag using semantic, alphabetical, or numerical rules.
  • Access Authentication - Connects to Git servers using SSH keys, agents, basic authentication, or bearer tokens.
  • AWS Authentication Strategies - Provides identity management for AWS services using Pod Identity, OIDC, or access keys.
  • Secret-less Identities - Uses short-lived tokens and workload identity to access cloud resources without static secrets.
  • Registry Access Controls - Connects to image repositories using secrets, pull secrets, or workload identities.
  • Access Control - Integrates with role-based access control and impersonation to restrict resource modification across the cluster.
  • Version-Controlled Secret Encryption - Decrypts secrets stored in version control using PGP, Age, or cloud KMS providers during deployment.
  • Workload Identity Federation - Implements workload identity federation to exchange short-lived Kubernetes tokens for cloud provider credentials.
  • Resource State Synchronization - Applies manifests from overlays to a cluster to ensure the live state matches the desired configuration.
  • Source Configurators - Splits large configuration sources into distinct artifacts so that updates only trigger the affected components.
  • Artifact Composition - Combines manifests and files from multiple external sources into single virtual artifacts for streamlined deployment.
  • Source Change Monitors - Tracks updates to Git and OCI repositories to trigger immediate synchronization of the cluster state.
  • State Syncing Reactivity - Fetches manifests and artifacts from remote sources to ensure the cluster reflects the desired state.
  • Rollout Health Monitoring - Monitors the rollout status of resources to determine if a deployment successfully reached a healthy state.
  • Access Control and RBAC - Implements role-based access control and impersonation to strictly limit resource modification.
  • Azure Blob Manifest Synchronization - Pulls manifests from Azure blob storage containers and packages them as artifacts.
  • Object Storage Integration - Retrieves objects from cloud storage and packages them into compressed archives for use in the delivery pipeline.
  • Resource Scaling Strategies - Adjusts processing limits and distributes tasks across instances to maintain system stability.
  • Bucket Sources - Creates resources to download and track configuration artifacts from cloud storage buckets.
  • Registry Authentication - Configures pull secrets and pods to access private registries using provided credentials.
  • Remote Resource Management Tools - Uses cloud identity principals to authenticate and manipulate resources in remote clusters via cloud APIs.
  • Cross-Repository Artifact Sharing - Maps the contents of one repository artifact into another to allow shared dependencies across different sources.
  • Webhook Notifications - Handles incoming webhooks and alerts from external providers to trigger immediate GitOps reconciliation.
  • Infrastructure Reconciliation Triggers - Forces instant synchronization of cluster resources upon receiving webhooks from version control or registries.
  • Artifact Packaging Tools - Provides an SDK to develop controllers that package, store, and serve configuration artifacts via a standardized API.
  • OCI Source Synchronization - Defines an OCI artifact registry as a source of truth to automate delivery.
  • OCI Artifact Retrieval - Retrieves OCI artifacts, tags, and digests from cloud registries to synchronize cluster state.
  • Artifact Signature Verifications - Validates the authenticity of fetched OCI artifacts using trusted public keys.
  • Webhook Triggers - Provides HTTP endpoints that trigger immediate reconciliation and release upgrades when external repositories push new versions.
  • Resource State Monitoring - Tracks the readiness and suspension status of Kubernetes resources to verify their operational state.
  • Manifest Fetching - Fetches configuration manifests from cloud buckets and packages them as artifacts.
  • S3 Manifest Integration - Retrieves configuration manifests from Amazon S3 buckets and packages them as artifacts.
  • Cluster Administrative Provisioning - Uses a high-privilege service account to provision namespaces and RBAC for individual tenants.
  • Cluster Resource Pruning - Removes objects from the cluster that are no longer present in the current configuration source revision.
  • Cluster Upgrades - Detects existing installations on a cluster and applies updates to keep the tooling current.
  • Concurrency Controllers - Limits the number of simultaneous reconciliation tasks to prevent cluster resource contention.
  • Configuration Artifact Packaging - Creates compressed archives containing manifests from directories or files for distribution and deployment.
  • Image Update Policies - Implements automated policies to calculate the latest image version from a repository for automated updates.
  • Container Image Versioning - Enables rolling back deployments to previous image versions by updating policies or tags.
  • Image Overrides - Updates the name, tag, or digest of container images without modifying the manifests.
  • Container Image Versioning - Defines and tracks container image repositories to enable automated scanning for new versions and tags.
  • Policy-Based Image Promotion - Automatically deploys specific container image versions to environments using configurable versioning rules.
  • Azure Registry Manifest Synchronization - Pulls OCI artifacts and reflects tags and digests from Azure container registries.
  • Controller Deployments - Allows modification of controller configurations using strategic merge or JSON patches during setup.
  • Deployment Dependency Management - Enforces the specific order of infrastructure rollouts to ensure required resources are ready for applications.
  • Deployment Environment Management - Organizes and isolates configurations across different deployment environments using monorepos or specific repository structures.
  • Deployment Sequencing - Ensures specific configurations are only applied after their designated dependencies have reached a ready state.
  • Deployment Orchestration - Orchestrates the sequence of delivery pipelines by defining dependencies between workloads.
  • Deployment Workflow Renderers - Separates the rendering of manifests from the application phase to support version control and complex environments.
  • Custom Artifact Generators - Creates custom artifact resources using an SDK for consumption by deployment controllers.
  • Progressive Delivery Strategies - Supports advanced deployment methodologies such as canary releases and A/B testing to reduce release risk.
  • Direct Cluster Deployment - Provides the capability to apply generated manifests from Helm or Kustomize directly to the cluster via API.
  • Event-Driven Synchronization - Uses webhooks to trigger immediate reconciliation of resources upon detecting changes in external sources.
  • Event Receiver Management - Manages endpoints that receive and process external events from version control to trigger synchronization updates.
  • Automated Chart Upgrades - Monitors repositories for new Helm chart versions and applies upgrades based on semantic versioning ranges.
  • Chart Signature Verifications - Validates the authenticity of Helm charts from OCI registries using trusted public keys.
  • Multi-Cluster Distribution - Propagates Helm chart definitions and releases from a central management plane to multiple remote clusters.
  • Multi-Source Chart Synchronization - Retrieves Helm chart artifacts from various sources using defined checkout strategies and intervals.
  • Post-Rendering Patches - Applies strategic merge or image patches to Helm charts using a post-renderer.
  • Release Dependency Management - Sequences Helm releases by requiring specific dependencies to be verified before starting the next installation step.
  • Load Sharding - Distributes resource synchronization across multiple instances using unique label selectors.
  • Leader Election - Uses leader election to ensure a single active controller manager for high availability.
  • Horizontal Scaling Tools - Distributes controller workloads across multiple instances using sharding to handle high traffic.
  • Air-Gapped Deployments - Configures controllers to operate in isolated networks without internet connectivity.
  • Kubernetes Job Execution - Executes lifecycle tasks as isolated Kubernetes jobs to handle migrations or health checks during deployment.
  • Git-Based Multi-Cluster Routing - Assigns unique directory paths within a single repository to different clusters for independent state synchronization.
  • Resource Validators - Evaluates the readiness of custom resources during a release using health check expressions.
  • Manifest Assembly and Validation - Assembles and validates configuration artifacts and kustomizations to prepare them for deployment.
  • Kustomize Scaffolding - Applies transformations to local directories to generate the final rendered YAML output for Kustomize deployments.
  • Manifest Delivery Automation - Writes generated manifests into a target branch to trigger automated deployment via reconciliation.
  • Object Storage Source Synchronization - Tracks files in cloud storage buckets and fetches updates based on defined intervals and filters.
  • Automated Release Remediation - Triggers automated rollbacks or uninstalls when a release fails using configurable retry logic.
  • Configuration-Driven Release Triggers - Forces a release upgrade immediately when referenced secrets or configurations are modified.
  • Release Remediation - Triggers automatic rollbacks, retries, or uninstalls when releases fail to reach a healthy state.
  • Manifest Patching - Modifies rendered manifests using directives for patches and image overrides before application.
  • Cloud Registry Synchronization - Retrieves OCI artifacts and digests specifically from Amazon ECR for cluster synchronization.
  • Automated - Automatically updates Helm releases when new chart versions are published based on semantic versioning ranges.
  • Webhook Triggers - Provides webhook endpoints to trigger immediate synchronization and release upgrades upon repository changes.
  • YAML Patching Engines - Modifies Kubernetes resources using strategic merge or JSON patches defined inline.
  • Webhook Notifications - Validates external webhook event payloads to trigger the reconciliation of specific Kubernetes cluster resources.
  • Workspace Access Restrictions - Locks down configurations to ensure teams only manage their designated namespaces.
  • Repository Content Filters - Excludes specific paths from repository ingestion using ignore patterns to restrict manifest synchronization.
  • Cloud Authentication Providers - Establishes secure authentication and identity permissions between the cluster and cloud-based resources.
  • Cloud Service Authentication - Provides mechanisms for authenticating with cloud provider services to access storage without static secrets.
  • Decryption Utilities - Provides a pipeline to decrypt secrets using PGP or cloud KMS providers immediately before cluster application.
  • Encrypted Secret Management - Uses decrypted values from encrypted secrets to configure application releases via secret generation.
  • Cloud KMS Integrations - Integrates with cloud-based key management services to decrypt encrypted secrets before application.
  • Resource-Level Access Controls - Grants or denies tenant access to custom resources based on administrative levels.
  • Orchestration Admission Controllers - Integrates with admission controllers to ensure manifests meet compliance standards.
  • Object-Level Token Permissions - Grants controllers permissions to create service account tokens for object-level identity.
  • Per-Object Identities - Assigns unique identities to individual resources to enforce the principle of least privilege.
  • RBAC Impersonation - Impersonates specific service accounts to apply manifests with restricted permissions.
  • Control Plane Isolation - Provides the ability to segment control plane access by namespace and RBAC to prevent cross-tenant interference.
  • Reconciler Scope Isolation - Generates namespaces and role bindings to restrict reconcilers to specific environments.
  • Policy Validators - Integrates with admission controllers to ensure configurations adhere to security and operational policies.
  • Secret Encryption - Protects sensitive data in Git using external encryption tools and key management services.
  • Secret Vault Integrations - Uses Azure Key Vault integrations to decrypt encrypted secrets before applying manifests.
  • Webhook Security - Validates incoming webhook requests using HMAC signatures, ID tokens, or secret headers to ensure authenticity.
  • Chart Instance Configurations - Customizes chart deployments using inline YAML or external resources to separate configuration from the chart.
  • Immutable Image Pinning - Ensures deployment immutability by tracking and updating unique container image digests for specific tags.
  • Controller Lifecycle Management - Manages the installation and version upgrades of Kubernetes controllers through a declarative API.
  • Manifest Transformations - Applies custom overlays and transformations to rendered Helm chart output before deploying resources.
  • Service Account Permissions - Enforces the use of specific service accounts to ensure workloads have defined permissions.
  • Reconciliation Account Scoping - Runs the reconciliation process under a specific service account to limit modifications.
  • Release Scope Restrictions - Impersonates a service account to limit a release's ability to modify specific namespaces.
  • Logic And Infrastructure Decoupling - Separates core application manifests from infrastructure logic by referencing external repositories to avoid duplication.
  • Alert Notification Systems - Dispatches real-time operational alerts to chat platforms when system events or failures occur.
  • Alerting Systems - Retrieves and displays the status of resource alerts to diagnose synchronization issues.
  • Cluster Health Monitoring - Performs health assessments on clusters and workloads to ensure the success of application deployments.
  • Cluster State Comparison - Performs a dry-run on resources to print the difference between current and target configurations.
  • Deployment Failure Diagnostics - Inspects failing release reconciliations to identify and resolve deployment errors.
  • Event Monitoring Systems - Tracks and broadcasts deployment status and controller events to external notification systems in real-time.
  • External Process Triggers - Triggers immediate resource synchronization upon receiving webhooks from external systems.
  • Instance Health Monitors - Checks the status of reconciled resources using specific health assessments and timeouts.
  • Metrics Exporters - Exposes operational data via compatible endpoints to monitor reconciliation and system usage.
  • Operational Health and Alerting - Implements operational health alerting to monitor delivery pipeline health and notify operators of failures.
  • Event Monitoring Systems - Monitors system-level events to track the progress and success of GitOps synchronization tasks.
  • Application Health Monitors - Provides customizable health monitoring logic to determine the readiness or failure states of resources.
  • Reconciliation Troubleshooting - Analyzes failing Kustomization reconciliations to identify why configuration changes are not being applied.
  • Performance Metrics Exporters - Provides interfaces that expose system health and operational performance data for visualization.
  • Repository Inspection - Provides diagnostic tools to verify the synchronization state of image repositories and update policies.
  • GitOps Resource Pruning - Controls the garbage collection of managed resources through automated pruning and configurable deletion policies.
  • Deployment Status Monitors - Tracks the synchronization and readiness state of deployed Helm releases.
  • Resource Change Monitors - Monitors and displays events associated with controllers to diagnose deployment issues and track changes.
  • System Health Dashboards - Displays controller statistics and reconciliation states through pre-configured operational dashboards.
  • Webhook Listeners - Implements webhook listeners that receive events from repositories or registries to trigger immediate cluster synchronization.
  • Deployment Rollbacks - Reverts applications to previous stable revisions using force replacement or server-side apply when upgrades fail.
  • Automation and CI/CD - GitOps tool integrated with the Kubernetes API system.
  • Core Tools - Extensible continuous delivery solution powered by the GitOps toolkit.

Star history

Star history chart for fluxcd/flux2Star history chart for fluxcd/flux2

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does fluxcd/flux2 do?

Flux is a Kubernetes GitOps delivery tool used to automate application deployments by synchronizing cluster state with configurations stored in Git, OCI, or Helm repositories. It functions as a set of controllers that monitor desired state in external sources and continuously reconcile the live cluster to match those definitions.

What are the main features of fluxcd/flux2?

The main features of fluxcd/flux2 are: Cluster Bootstrapping, Cluster State Reconciliation, GitOps State Synchronization, Multi-Cluster Deployment Managers, Kubernetes Manifest Management, Reconciliation Loops, Configuration Syncing, Source Map Composers.

Which projects share features with fluxcd/flux2?

Projects with overlapping indexed features include: devtron-labs/devtron — Devtron is a Kubernetes management platform and CI/CD orchestrator designed to unify application lifecycles and… jenkins-x/jx — jx is a GitOps delivery platform and Kubernetes CI/CD orchestrator designed to automate the building and deployment of… fluxcd/helm-controller — The project is a declarative GitOps controller and package manager designed to automate the deployment and lifecycle… komodorio/helm-dashboard — Helm Dashboard is a web-based interface for managing and monitoring Helm releases in Kubernetes clusters. It provides… operator-framework/operator-sdk — The Operator SDK is a framework for building, packaging, and managing custom controllers that extend the Kubernetes… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and…

Projects sharing features with Flux2

These projects share indexed features with Flux2. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • devtron-labs/devtrondevtron-labs avatar

    devtron-labs/devtron

    5,518View on GitHub↗

    Devtron is a Kubernetes management platform and CI/CD orchestrator designed to unify application lifecycles and infrastructure operations across multiple clusters from a single interface. It serves as a centralized dashboard for orchestrating workloads, managing security, and providing observability for Kubernetes environments. The platform distinguishes itself with a no-code workflow engine for automating container builds and software delivery pipelines, alongside a visual GitOps deployment tool for managing declarative applications and reconciling configuration drift. Its capability surfac

    Go
    View on GitHub↗5,518
  • jenkins-x/jxjenkins-x avatar

    jenkins-x/jx

    4,691View on GitHub↗

    jx is a GitOps delivery platform and Kubernetes CI/CD orchestrator designed to automate the building and deployment of applications. It functions as a cloud native pipeline manager that executes container-based build and deployment sequences using a catalog of reusable tasks. The project distinguishes itself through the automated orchestration of preview environments, which are created and destroyed based on pull request activity to enable validation before merging. It employs a GitOps-based state synchronization model to maintain the desired state of clusters by polling git repositories and

    Goacceleratorcicdcontinuous-delivery
    View on GitHub↗4,691
  • fluxcd/helm-controllerfluxcd avatar

    fluxcd/helm-controller

    500View on GitHub↗

    The project is a declarative GitOps controller and package manager designed to automate the deployment and lifecycle management of Helm charts within a cluster. It continuously watches custom resources and external artifact sources, comparing the actual cluster state against desired declarations to drive reconciliation. Artifacts and manifests are retrieved from standard package repositories, Git sources, OCI registries, and object storage buckets. The system handles complex application delivery through dependency sequencing, automated failure remediation, and drift detection. It supports cro

    Gogitops-toolkit
    View on GitHub↗500
  • komodorio/helm-dashboardkomodorio avatar

    komodorio/helm-dashboard

    5,625View on GitHub↗

    Helm Dashboard is a web-based interface for managing and monitoring Helm releases in Kubernetes clusters. It provides a graphical alternative to the command line for viewing deployed releases, inspecting installed charts, and performing the full lifecycle of Helm operations including installation, upgrades, rollbacks, and uninstalls. The dashboard enables users to browse releases with filtering by namespace or name, view revision history and deployment details, and compare manifest or values differences between revisions before applying changes. It supports deploying charts from repositories,

    TypeScriptguihelmhelm-plugin
    View on GitHub↗5,625
Compare all 30 related projects→