Git SyncFlow

Git SyncFlow

Certified

Sync a single flow from Git

Imports one flow YAML from a Git branch into a target namespace. Flow namespace is rewritten to targetNamespace. Supports dry-run to validate without saving.

yaml
type: io.kestra.plugin.git.SyncFlow

Sync a single flow from a Git repository to a specific namespace. This can be used to deploy or update individual flows.

yaml
id: sync_single_flow_from_git
namespace: company.ops

tasks:
  - id: sync_my_flow
    type: io.kestra.plugin.git.SyncFlow
    url: https://github.com/my-org/kestra-flows
    branch: main
    username: my_git_username
    password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
    targetNamespace: dev.marketing # required
    flowPath: "flows/marketing/flow.yml" # required
    kestraUrl: "http://localhost:8080"
    auth:
      username: "{{ secret('KESTRA_USERNAME') }}"
      password: "{{ secret('KESTRA_PASSWORD') }}"
Properties

Authentication information

Definitions
apiTokenstring

API token for Bearer authentication

autobooleanstring
Defaulttrue

Automatically retrieve the URL and the credentials from Kestra's configuration if available

The default configuration can be configured globally inside the Kestra configuration file:

  • Set kestra.tasks.sdk.authentication.url to use a given API URL
  • Set kestra.tasks.sdk.authentication.api-token to use an API token
  • Set kestra.tasks.sdk.authentication.username and kestra.tasks.sdk.authentication.password for HTTP basic authentication The Enterprise edition also provides setting a default configuration at the Namespace of Tenant level by an administrator.
passwordstring

Password for HTTP Basic authentication

usernamestring

Username for HTTP Basic authentication

Flow file path

Relative path to the flow YAML inside the repository.

Target namespace

Replaces any namespace declared in the flow file.

Defaultmain

Branch to clone

Defaults to main.

Default10000

HTTP connect timeout (ms)

Default 10000 ms.

Defaultfalse

Dry run only

When true, validates and logs without importing.

Git configuration overrides

Map of git config keys and values applied after clone, e.g.:

  • core.fileMode: false (ignore permission flips)
  • core.autocrlf: false (preserve line endings)

Kestra API URL

URL of the Kestra server API. If not set, the URL of the default SDK authentication is used, set with the kestra.tasks.sdk.authentication.url configuration property, or at the namespace or the tenant level on the Enterprise Edition. It then falls back to the kestra.url configuration property, and finally to http://localhost: 8080.

Disable proxy for HTTP

When true, forces direct connections instead of using the JVM proxy settings.

Passphrase for privateKey

Password or personal access token

Supplies HTTP credentials. When a PAT is used, pushes are recorded under that PAT’s user without needing authorName and authorEmail.

**GitHub PAT permissions required: **

  • Fine-grained PAT: Contents: Read (clone/fetch) or Contents: Read and Write (push), plus Metadata: Read (mandatory base permission). Add Workflows: Read and Write when pushing .github/workflows/ files.
  • Classic PAT: repo scope covers all read/write operations; add workflow when pushing workflow files.

Reference (ref) of the pluginDefaults to apply to this task.

PEM private key

PEM-formatted private key matching a public key registered on the Git server. Generate with ssh-keygen -t ecdsa -b 256 -m PEM.

Default60000

HTTP read timeout (ms)

Default 60000 ms.

Extra trusted CA PEM path

Optional PEM-encoded CA bundle added to the JVM truststore; equivalent to git config http.sslCAInfo <path> for self-signed or internal CAs.

Repository URL

HTTP(S) or SSH URI used for clone and push operations.

Username or organization

Used for HTTP basic authentication and as a fallback commit author.

The ID of the synced flow

The namespace of the synced flow

The new revision number of the flow