Git SyncApps

Git SyncApps

Certified
Enterprise Edition

Sync Apps from Git to Kestra

This task syncs apps from a given Git branch to Kestra. If the delete property is set to true, any app available in kestra but not present in the gitDirectory will be deleted, considering Git as a single source of truth. Check the Version Control with Git documentation for more details.

yaml
type: io.kestra.plugin.ee.git.SyncApps

Sync apps from a Git repository. This flow can run either on a schedule (using the Schedule trigger) or anytime you push a change to a given Git branch (using the Webhook trigger).

yaml
id: sync_apps_from_git
namespace: company.ops


tasks:
  - id: git
    type: io.kestra.plugin.ee.git.SyncApps
    delete: true # optional; by default, it's set to false to avoid destructive behavior
    url: https://github.com/kestra-io/apps # required
    branch: main
    username: git_username
    password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
    dryRun: true  # if true, the task will only log which flows from Git will be added/modified or deleted in kestra without making any changes in kestra backend yet

triggers:
  - id: every_full_hour
    type: io.kestra.plugin.core.trigger.Schedule
    cron: "0 * * * *"
Properties
Defaultmain

The branch from which apps will be synced to Kestra

Whether to clone submodules

Defaultfalse

Whether you want to delete apps present in kestra but not present in Git

It’s false by default to avoid destructive behavior. Use this property with caution because when set to true, this task will delete all apps from the targetNamespace and all its child namespaces that are not present in Git rather than only overwriting the changes.

Defaultfalse

If true, the task will only output modifications without performing any modification to Kestra. If false (default), all listed modifications will be applied

Defaulttrue

If true (default), the task will fail if the specified directory doesn't exist. If false, missing directories will be skipped

Git config applied after clone

Map of Git config keys and values, applied after clone
Few examples: 
- 'core.fileMode': false -> ignore file permission changes
- 'core.autocrlf': false -> prevent line ending conversion
Default_apps

Directory from which apps should be synced

Known hosts file content used for SSH host key verification

OpenSSH known_hosts-formatted content used to verify the remote server's SSH host key. If not set, the system/user known_hosts file is used.

The namespace to sync apps to

If set, only apps in this namespace and its child namespaces are synced, and with delete enabled only those apps are eligible for deletion. If left empty, the task operates across all namespaces (the previous behavior).

Passphrase for privateKey

Password or personal access token

When set, pushes use the identity tied to this credential, so authorName and authorEmail become optional.

Reference (ref) of the pluginDefaults to apply to this task.

SSH private key in PEM format

Use an ECDSA/PEM key whose public part is registered on Git. Example: ssh-keygen -t ecdsa -b 256 -m PEM.

Defaulttrue

Whether to verify the SSH remote server's host key

When true (default), the host key presented by the Git server is verified against knownHosts (if provided) or the system/user known_hosts file, protecting against man-in-the-middle attacks. Only disable this for trusted networks/testing.

Git repository URL

HTTPS or SSH URL used for clone/fetch/push. Supports templating.

Repository username or organization