Git PushFlows

Git PushFlows

Certified

Push flows to Git

Exports saved flows from sourceNamespace (optionally child namespaces) into gitDirectory (default _flows) and pushes to Git. Can rewrite namespaces to targetNamespace; branch is created if missing and dry-run writes only the diff.

yaml
type: io.kestra.plugin.git.PushFlows

Automatically push all saved flows from the dev namespace and all child namespaces to a Git repository every day at 5 p.m. Before pushing to Git, the task will adjust the flow's source code to match the targetNamespace to prepare the Git branch for merging to the production namespace. Note that the automatic conversion of sourceNamespace to targetNamespace is optional and should only be considered as a helper for facilitating the Git workflow for simple use cases — only the namespace property within the flow will be adjusted and if you specify namespace names within e.g. Flow triggers, those may need to be manually adjusted. We recommend using separate Kestra instances for development and production with the same namespace names across instances.

yaml
id: push_to_git
namespace: company.ops

tasks:
  - id: commit_and_push
    type: io.kestra.plugin.git.PushFlows
    sourceNamespace: dev
    targetNamespace: prod
    flows: "*"
    includeChildNamespaces: true
    gitDirectory: _flows
    url: https://github.com/kestra-io/scripts
    username: git_username
    password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
    branch: main
    commitMessage: "add flows {{ now() }}"
    dryRun: true

triggers:
  - id: schedule_push
    type: io.kestra.plugin.core.trigger.Schedule
    cron: "0 17 * * *"

Release all flows and scripts from selected namespaces to a Git repository every Thursday at 11: 00 AM. Adjust the values list to include the namespaces for which you want to push your code to Git. This System Flow will create two commits per namespace: one for the flows and one for the scripts.

yaml
id: git_push
namespace: company.ops

tasks:
  - id: push
    type: io.kestra.plugin.core.flow.ForEach
    values: ["company", "company.team", "company.analytics"]
    tasks:
      - id: flows
        type: io.kestra.plugin.git.PushFlows
        sourceNamespace: "{{ taskrun.value }}"
        gitDirectory: "{{'flows/' ~ taskrun.value}}"
        includeChildNamespaces: false

      - id: scripts
        type: io.kestra.plugin.git.PushNamespaceFiles
        namespace: "{{ taskrun.value }}"
        gitDirectory: "{{'scripts/' ~ taskrun.value}}"

pluginDefaults:
  - type: io.kestra.plugin.git
    values:
      username: anna-geller
      url: https://github.com/anna-geller/product
      password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
      branch: main
      dryRun: false

triggers:
  - id: schedule_push_to_git
    type: io.kestra.plugin.core.trigger.Schedule
    cron: "0 11 * * 4"
Properties

Commit author email

If null, no author is set.

Commit author name

Defaults to username when empty.

Defaultmain

Branch to push flows

Defaults to main; created if absent.

Clone submodules

Default false; enable to fetch and initialize nested submodules.

DefaultAdd flows from `sourceNamespace`

Git commit message

Default10000

HTTP connect timeout (ms)

Default 10000 ms.

Defaulttrue

Delete removed resources

If true (default), removes Git files that no longer exist in Kestra.

Defaultfalse

Dry run only

When true, writes a diff file without pushing. Default false pushes immediately.

Default**

Flows to include

Glob pattern(s) against flow IDs; defaults to all (**).

Git configuration overrides

Map of git config keys and values applied after clone, e.g.:

  • core.fileMode: false (ignore permission flips)
  • core.autocrlf: false (preserve line endings)
Default_flows

Flow destination directory

Relative path inside the repo; defaults to _flows. Child namespaces are nested under this path when includeChildNamespaces is true.

Defaultfalse

Include child namespaces

When true, exports flows from child namespaces into nested directories under gitDirectory.

Disable proxy for HTTP

When true, forces direct connections instead of using the JVM proxy settings.

Passphrase for privateKey

Password or personal access token

Supplies HTTP credentials. When a PAT is used, pushes are recorded under that PAT’s user without needing authorName and authorEmail.

**GitHub PAT permissions required: **

  • Fine-grained PAT: Contents: Read (clone/fetch) or Contents: Read and Write (push), plus Metadata: Read (mandatory base permission). Add Workflows: Read and Write when pushing .github/workflows/ files.
  • Classic PAT: repo scope covers all read/write operations; add workflow when pushing workflow files.

Reference (ref) of the pluginDefaults to apply to this task.

PEM private key

PEM-formatted private key matching a public key registered on the Git server. Generate with ssh-keygen -t ecdsa -b 256 -m PEM.

Default60000

HTTP read timeout (ms)

Default 60000 ms.

Default{{ flow.namespace }}

Source namespace

Namespace to export flows from; defaults to the current flow namespace.

Target namespace override

If set, rewrites the namespace field in exported flows to this value.

Extra trusted CA PEM path

Optional PEM-encoded CA bundle added to the JVM truststore; equivalent to git config http.sslCAInfo <path> for self-signed or internal CAs.

Repository URL

HTTP(S) or SSH URI used for clone and push operations.

Username or organization

Used for HTTP basic authentication and as a fallback commit author.