
Git SyncFlows
CertifiedSync flows from Git
Git SyncFlows
Sync flows from Git
Imports flows from a Git branch into targetNamespace, optionally traversing child namespaces. Can rewrite namespaces to targetNamespace, delete missing flows when delete is true, and emit a diff on dry-run.
type: io.kestra.plugin.git.SyncFlowsExamples
id: sync_flows_from_git
namespace: company.ops
tasks:
- id: git
type: io.kestra.plugin.git.SyncFlows
gitDirectory: flows
targetNamespace: git
includeChildNamespaces: true
delete: true
url: https://github.com/kestra-io/flows
branch: main
username: git_username
password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
dryRun: true
triggers:
- id: every_full_hour
type: io.kestra.plugin.core.trigger.Schedule
cron: "0 * * * *"
Sync all flows and scripts for selected namespaces from Git to Kestra every full hour. Note that this is a System Flow, so make sure to adjust the Scope to SYSTEM in the UI filter to see this flow or its executions.
id: git_sync
namespace: company.ops
tasks:
- id: sync
type: io.kestra.plugin.core.flow.ForEach
values: ["company", "company.team", "company.analytics"]
tasks:
- id: flows
type: io.kestra.plugin.git.SyncFlows
targetNamespace: "{{ taskrun.value }}"
gitDirectory: "{{'flows/' ~ taskrun.value}}"
includeChildNamespaces: false
- id: scripts
type: io.kestra.plugin.git.SyncNamespaceFiles
namespace: "{{ taskrun.value }}"
gitDirectory: "{{'scripts/' ~ taskrun.value}}"
pluginDefaults:
- type: io.kestra.plugin.git
values:
username: anna-geller
url: https://github.com/anna-geller/product
password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
branch: main
dryRun: false
triggers:
- id: every_full_hour
type: io.kestra.plugin.core.trigger.Schedule
cron: "0 * * * *"
Properties
targetNamespace *Requiredstring
Target namespace
Flows are rewritten to this namespace (and nested namespaces when applicable).
branch string
mainBranch to sync
Defaults to main.
cloneSubmodules booleanstring
Clone submodules
Default false; enable to fetch and initialize nested submodules.
connectTimeout integerstring
10000HTTP connect timeout (ms)
Default 10000 ms.
delete booleanstring
falseDelete flows missing in Git
Default false to avoid destructive syncs. When true (and especially with includeChildNamespaces), removes flows not present in Git.
dryRun booleanstring
falseDry run only
When true, writes a diff without applying changes to Kestra.
failOnMissingDirectory booleanstring
trueFail if git directory missing
Default true. If false, skips when the rendered gitDirectory path does not exist.
gitConfig object
Git configuration overrides
Map of git config keys and values applied after clone, e.g.:
- core.fileMode: false (ignore permission flips)
- core.autocrlf: false (preserve line endings)
gitDirectory string
_flowsGit directory for flows
Relative path containing flow YAML; defaults to _flows. Subdirectories map to child namespaces when includeChildNamespaces is true.
ignoreInvalidFlows booleanstring
falseIgnore invalid flows
If true, skips flows that fail validation instead of failing the task.
includeChildNamespaces booleanstring
falseInclude child namespaces
Default false. When true, subdirectories under gitDirectory are synced to corresponding child namespaces.
noProxy booleanstring
Disable proxy for HTTP
When true, forces direct connections instead of using the JVM proxy settings.
passphrase string
Passphrase for privateKey
password string
Password or personal access token
Supplies HTTP credentials. When a PAT is used, pushes are recorded under that PAT’s user without needing authorName and authorEmail.
**GitHub PAT permissions required: **
- Fine-grained PAT:
Contents: Read(clone/fetch) orContents: Read and Write(push), plusMetadata: Read(mandatory base permission). AddWorkflows: Read and Writewhen pushing.github/workflows/files. - Classic PAT:
reposcope covers all read/write operations; addworkflowwhen pushing workflow files.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
privateKey string
PEM private key
PEM-formatted private key matching a public key registered on the Git server. Generate with ssh-keygen -t ecdsa -b 256 -m PEM.
readTimeout integerstring
60000HTTP read timeout (ms)
Default 60000 ms.
trustedCaPemPath string
Extra trusted CA PEM path
Optional PEM-encoded CA bundle added to the JVM truststore; equivalent to git config http.sslCAInfo <path> for self-signed or internal CAs.
url string
Repository URL
HTTP(S) or SSH URI used for clone and push operations.
username string
Username or organization
Used for HTTP basic authentication and as a fallback commit author.