# actions-k8s Reusable Gitea Actions for Kubernetes deployments via Flux GitOps. ## actions/flux-deploy Composite action that updates a [Flux HelmRelease](https://fluxcd.io/flux/components/helm/) image tag in a GitOps repo to trigger a Kubernetes deployment. This action clones the GitOps repo, updates the `repository` and `tag` fields in the specified release YAML, commits, and pushes. If the release already points to the requested image, the action exits cleanly (idempotent). ### Usage ```yaml jobs: deploy: runs-on: ubuntu-latest needs: [ci] if: github.event_name == 'push' && github.ref == 'refs/heads/main' steps: - name: Add SSH_KEY run: | echo "${{ secrets.SSH_KEY }}" > $HOME/.ssh/id_rsa chmod 400 $HOME/.ssh/id_rsa ssh-keyscan -H git.ericxliu.me > $HOME/.ssh/known_hosts - name: Checkout code uses: https://gitea.com/actions/checkout@v4 with: ssh-key: ${{ secrets.SSH_KEY }} - name: Build and push image id: image uses: https://git.ericxliu.me/eric/actions-docker/.gitea/actions/docker-build@main with: image-name: ${{ github.event.repository.name }} push: true - name: Deploy to K8s via Flux uses: https://git.ericxliu.me/eric/actions-k8s/.gitea/actions/flux-deploy@main with: image-repository: ${{ github.server_url }}/${{ github.repository }} image-tag: ${{ steps.image.outputs.tag }} gitops-file: apps/myapp/my-app/release.yaml deploy-key: ${{ secrets.K8S_FLUX_DEPLOY_KEY }} ``` ### Inputs | Input | Required | Default | Description | |-------|----------|---------|-------------| | `image-repository` | **Yes** | — | Full image repository (e.g. `git.ericxliu.me/eric/workout`) | | `image-tag` | **Yes** | — | Image tag to deploy (e.g. `2026-06-17-abc1234`) | | `gitops-repo` | No | `git@github.com:eric-x-liu/k8s-flux.git` | SSH URL of the GitOps repo | | `gitops-file` | **Yes** | — | Path to release YAML in the GitOps repo | | `deploy-key` | **Yes** | — | SSH private key with push access to the GitOps repo | | `git-user-name` | No | `gitops-ci` | Git commit author name | | `git-user-email` | No | `gitops-ci@users.noreply.git.ericxliu.me` | Git commit author email | | `commit-message` | No | `Update {app} image to {tag}` | Custom commit message (`{app}` and `{tag}` are replaced) | ### How It Works 1. Sets up SSH with the provided deploy key 2. Clones the GitOps repo (e.g. `k8s-flux`) 3. Updates `repository:` and `tag:` fields in the specified release YAML via regex 4. If no changes detected → exits cleanly (idempotent) 5. Commits and pushes to trigger Flux reconciliation ### Requirements - The GitOps repo must be accessible via SSH with the provided deploy key - The release YAML must contain `repository:` and `tag:` fields (standard bjw-s `app-template` chart format) - `python3` must be available on the runner (standard on `ubuntu-latest`)