Helm
Helm 4 chart development and operations with security-first defaults.
What This Skill Does
Chart Development:
- Creates production charts with library pattern (reusable base + thin apps)
- Generates templates, helpers, hooks, and dependencies
- Auto-detects from Dockerfile: ports, health endpoints, resources
- Supports umbrella charts for multi-service deployments
- Adds values schema validation (JSON Schema)
Release Management:
- Install, upgrade, rollback with atomic operations
- Release history and status inspection
- Values precedence management across environments
- Hook lifecycle (pre-install, pre-upgrade, post-upgrade, test)
Registry & Distribution:
- OCI registry workflows (push, pull, digest pinning)
- Chart versioning and artifact management
- GitOps integration (ArgoCD, Flux)
Debugging:
- Template rendering and debugging workflow
- Failed release recovery (stuck states, hook failures)
- Values resolution tracing
- Policy validation (OPA/Kyverno, security scanning)
What This Skill Does NOT Do
- Generate raw Kubernetes manifests (use kubernetes skill)
- Create Kustomize-only overlays without Helm
- Deploy Operators/CRDs (chart can include, but not operator setup)
- Manage cluster infrastructure (use kubernetes skill)
- Handle non-Helm deployments
Before Implementation
| Source |
Gather |
| Codebase |
Dockerfile, existing charts, values patterns |
| Conversation |
Target environment, chart name, special requirements |
| Skill References |
Chart patterns, Helm 4 features, hooks, security |
| kubernetes skill |
Manifest patterns for templates (complementary) |
Required Clarifications
After auto-detection, confirm if ambiguous:
| Question |
When to Ask |
| Chart type |
"Creating new chart, library chart, or umbrella chart?" |
| Target registry |
"OCI registry (GHCR, ECR, Harbor) or Git repo for GitOps?" |
| Environment strategy |
"Single values file or per-environment overlays (dev/staging/prod)?" |
| Release namespace |
"Deploy to specific namespace or chart-managed?" |
Helm 4 Defaults (CRITICAL)
Helm 4 introduces breaking changes from v3:
| Feature |
Helm 4 Behavior |
Notes |
| Server-Side Apply |
Default ON |
Better conflict detection, GitOps alignment |
| kstatus watching |
Accurate health |
Replaces old --wait behavior |
| OCI-first |
Native support |
oci:// protocol, digest pinning |
| Wasm plugins |
Sandboxed |
Post-renderers require plugin format |
See references/helm4-features.md for migration guidance.
Auto-Detection Matrix
From Dockerfile
| Detect |
How |
Chart Generation |
| Port |
EXPOSE |
containerPort in deployment template |
| Health |
CMD pattern |
Liveness/readiness probe paths |
| User |
USER instruction |
securityContext.runAsUser |
| Base image |
FROM |
Resource hints (alpine=small, python=medium) |
From Code
| Detect |
How |
Chart Generation |
| Framework |
imports/deps |
Health endpoint patterns |
| GPU deps |
torch, tensorflow |
tolerations, nodeSelector, GPU resources |
| Sidecar needs |
dapr.io, istio |
Annotations for injection |
Workflow
1. PRE-FLIGHT
- Verify helm version (v4.x required)
- Check target registry/cluster access
- Identify existing charts
↓
2. ANALYZE PROJECT
- Read Dockerfile for detection
- Scan code for patterns
- Check existing values patterns
↓
3. DETERMINE CHART TYPE
- Application chart (default)
- Library chart (reusable templates)
- Umbrella chart (multi-service)
↓
4. GENERATE CHART
- Chart.yaml with dependencies
- values.yaml with schema
- Templates with helpers
- Hooks if lifecycle needs
↓
5. VALIDATE
- helm lint
- helm template --debug
- helm install --dry-run
- Policy validation (optional)
↓
6. DELIVER
- Chart in charts/ directory
- Summary of what was created
- Next steps (push to registry, GitOps setup)
Chart Structure (Library Pattern)
charts/
├── myapp-lib/ # Library chart (reusable)
│ ├── Chart.yaml # type: library
│ ├── templates/
│ │ ├── _deployment.tpl # Reusable deployment template
│ │ ├── _service.tpl # Reusable service template
│ │ ├── _helpers.tpl # Common helpers
│ │ └── _security.tpl # Security context helpers
│ └── values.yaml # Default values
│
└── myapp/ # Application chart (thin)
├── Chart.yaml # Dependencies: myapp-lib
├── templates/
│ ├── deployment.yaml # {{ include "myapp-lib.deployment" . }}
│ ├── service.yaml # {{ include "myapp-lib.service" . }}
│ └── _helpers.tpl # App-specific helpers
├── values.yaml # App defaults
├── values.schema.json # Schema validation
└── values/ # Environment overlays
├── dev.yaml
├── staging.yaml
└── prod.yaml
Core Templates
Chart.yaml (Application)
apiVersion: v2
name: myapp
version: 0.1.0 # Chart version (SemVer)
appVersion: "1.0.0" # App version
type: application # or: library
description: |
Brief description of what this chart deploys.
# Dependencies (subchart pattern)
dependencies:
- name: myapp-lib
version: ">=0.1.0"
repository: "oci://ghcr.io/myorg/charts"
- name: redis
version: "17.x.x"
repository: "oci://registry-1.docker.io/bitnamicharts"
condition: redis.enabled # Conditional dependency
# Kubernetes version constraint
kubeVersion: ">=1.25.0"
# Maintainers
maintainers:
- name: DevRaftel
email: team@devraftel.com
values.yaml (Structured)
# -- Number of replicas
replicaCount: 2
image:
# -- Container image repository
repository: myorg/myapp
# -- Image pull policy
pullPolicy: IfNotPresent
# -- Image tag (defaults to appVersion)
tag: ""
# -- Resource requests and limits
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
cpu: "500m"
memory: "512Mi"
# -- Security context (pod level)
podSecurityContext:
runAsNonRoot: true
runAsUser: 1000
fsGroup: 1000
# -- Security context (container level)
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
# -- Service configuration
service:
type: ClusterIP
port: 80
targetPort: 8080
# -- Health probes
probes:
liveness:
path: /health/live
initialDelaySeconds: 10
readiness:
path: /health/ready
initialDelaySeconds: 5
# -- Enable autoscaling
autoscaling:
enabled: false
minReplicas: 2
maxReplicas: 10
targetCPUUtilization: 80
Command Reference
Chart Development
# Create new chart
helm create myapp
# Lint chart
helm lint ./myapp
# Render templates locally
helm template myapp ./myapp -f values.yaml
# Render with debug (shows template errors)
helm template myapp ./myapp --debug 2>&1 | head -100
# Package chart
helm package ./myapp
# Update dependencies
helm dependency update ./myapp
helm dependency build ./myapp
Release Management
# Install release
helm install myapp ./myapp -n namespace --create-namespace
# Install with atomic (rollback on failure)
helm install myapp ./myapp --atomic --timeout 5m
# Upgrade release
helm upgrade myapp ./myapp --atomic
# Upgrade or install
helm upgrade --install myapp ./myapp
# Rollback to previous
helm rollback myapp 1
# Uninstall
helm uninstall myapp -n namespace
# Release status
helm status myapp
helm history myapp
OCI Registry
# Login to registry
helm registry login ghcr.io -u USERNAME
# Push chart to OCI
helm push myapp-0.1.0.tgz oci://ghcr.io/myorg/charts
# Pull from OCI
helm pull oci://ghcr.io/myorg/charts/myapp --version 0.1.0
# Install from OCI
helm install myapp oci://ghcr.io/myorg/charts/myapp --version 0.1.0
Debugging
# Get release manifest
helm get manifest myapp
# Get computed values
helm get values myapp
helm get values myapp --all # Including defaults
# Get hooks
helm get hooks myapp
# Dry-run against cluster
helm install myapp ./myapp --dry-run --debug
# Diff before upgrade (requires helm-diff plugin)
helm diff upgrade myapp ./myapp
Validation Pipeline
Before delivering charts, run:
# 1. Lint
helm lint ./myapp --strict
# 2. Template render
helm template myapp ./myapp --debug > /dev/null
# 3. Dry-run against cluster
helm install myapp ./myapp --dry-run --debug -n test
# 4. Schema validation (if values.schema.json exists)
helm lint ./myapp # Automatically validates against schema
# 5. Policy validation (optional)
# OPA/Conftest
conftest test ./myapp/templates/
# Trivy for security scanning
trivy config ./myapp/
Output Checklist
Before delivering, verify:
Chart Structure
Security
Best Practices
Validation
GitOps Ready
Reference Files
Always Read First
| File |
Purpose |
references/chart-development.md |
CRITICAL: Template syntax, helpers, hooks |
references/values-patterns.md |
CRITICAL: Precedence, environments, schema |
references/helm4-features.md |
CRITICAL: SSA, Wasm, kstatus, OCI |
Operations
| File |
When to Read |
references/release-management.md |
Install, upgrade, rollback, atomic |
references/oci-workflows.md |
Push, pull, registry auth, digest |
references/debugging-workflow.md |
Template errors, failed releases |
references/testing-validation.md |
Lint, unittest, dry-run, integration tests |
Integration
| File |
When to Read |
references/gitops-integration.md |
ArgoCD, Flux, ApplicationSet |
references/umbrella-patterns.md |
Multi-service, subcharts, Kustomize |
references/ai-agent-patterns.md |
GPU, models, sidecars, KEDA |
Security & Compliance
| File |
When to Read |
references/security-patterns.md |
Secrets (ESO, Sealed), RBAC, policies |
references/hooks-lifecycle.md |
Hook types, weights, deletion policies |
1---2name: helm3description: Production-grade Helm 4 chart development, release management, and debugging. This skill should be used when users ask to create Helm charts, deploy with Helm, manage releases (install/upgrade/rollback), push charts to OCI registries, debug failed deployments, configure chart dependencies, create umbrella charts, set up GitOps with ArgoCD/Flux, or troubleshoot Helm issues. Auto-detects from Dockerfile/code, generates production-hardened charts with library patterns. Complements kubernetes skill.4---5
6# Helm
7
8Helm 4 chart development and operations with security-first defaults.
9
10## What This Skill Does
11
12**Chart Development:**
13- Creates production charts with library pattern (reusable base + thin apps)
14- Generates templates, helpers, hooks, and dependencies
15- Auto-detects from Dockerfile: ports, health endpoints, resources
16- Supports umbrella charts for multi-service deployments
17- Adds values schema validation (JSON Schema)
18
19**Release Management:**
20- Install, upgrade, rollback with atomic operations
21- Release history and status inspection
22- Values precedence management across environments
23- Hook lifecycle (pre-install, pre-upgrade, post-upgrade, test)
24
25**Registry & Distribution:**
26- OCI registry workflows (push, pull, digest pinning)
27- Chart versioning and artifact management
28- GitOps integration (ArgoCD, Flux)
29
30**Debugging:**
31- Template rendering and debugging workflow
32- Failed release recovery (stuck states, hook failures)
33- Values resolution tracing
34- Policy validation (OPA/Kyverno, security scanning)
35
36## What This Skill Does NOT Do
37
38- Generate raw Kubernetes manifests (use kubernetes skill)
39- Create Kustomize-only overlays without Helm
40- Deploy Operators/CRDs (chart can include, but not operator setup)
41- Manage cluster infrastructure (use kubernetes skill)
42- Handle non-Helm deployments
43
44---
45
46## Before Implementation
47
48| Source | Gather |
49|--------|--------|
50| **Codebase** | Dockerfile, existing charts, values patterns |
51| **Conversation** | Target environment, chart name, special requirements |
52| **Skill References** | Chart patterns, Helm 4 features, hooks, security |
53| **kubernetes skill** | Manifest patterns for templates (complementary) |
54
55---
56
57## Required Clarifications
58
59After auto-detection, confirm if ambiguous:
60
61| Question | When to Ask |
62|----------|-------------|
63| Chart type | "Creating new chart, library chart, or umbrella chart?" |
64| Target registry | "OCI registry (GHCR, ECR, Harbor) or Git repo for GitOps?" |
65| Environment strategy | "Single values file or per-environment overlays (dev/staging/prod)?" |
66| Release namespace | "Deploy to specific namespace or chart-managed?" |
67
68---
69
70## Helm 4 Defaults (CRITICAL)
71
72Helm 4 introduces breaking changes from v3:
73
74| Feature | Helm 4 Behavior | Notes |
75|---------|-----------------|-------|
76| **Server-Side Apply** | Default ON | Better conflict detection, GitOps alignment |
77| **kstatus watching** | Accurate health | Replaces old `--wait` behavior |
78| **OCI-first** | Native support | `oci://` protocol, digest pinning |
79| **Wasm plugins** | Sandboxed | Post-renderers require plugin format |
80
81See `references/helm4-features.md` for migration guidance.
82
83---
84
85## Auto-Detection Matrix
86
87### From Dockerfile
88
89| Detect | How | Chart Generation |
90|--------|-----|------------------|
91| Port | EXPOSE | `containerPort` in deployment template |
92| Health | CMD pattern | Liveness/readiness probe paths |
93| User | USER instruction | `securityContext.runAsUser` |
94| Base image | FROM | Resource hints (alpine=small, python=medium) |
95
96### From Code
97
98| Detect | How | Chart Generation |
99|--------|-----|------------------|
100| Framework | imports/deps | Health endpoint patterns |
101| GPU deps | torch, tensorflow | tolerations, nodeSelector, GPU resources |
102| Sidecar needs | dapr.io, istio | Annotations for injection |
103
104---
105
106## Workflow
107
108```
1091. PRE-FLIGHT
110 - Verify helm version (v4.x required)
111 - Check target registry/cluster access
112 - Identify existing charts
113 ↓
1142. ANALYZE PROJECT
115 - Read Dockerfile for detection
116 - Scan code for patterns
117 - Check existing values patterns
118 ↓
1193. DETERMINE CHART TYPE
120 - Application chart (default)
121 - Library chart (reusable templates)
122 - Umbrella chart (multi-service)
123 ↓
1244. GENERATE CHART
125 - Chart.yaml with dependencies
126 - values.yaml with schema
127 - Templates with helpers
128 - Hooks if lifecycle needs
129 ↓
1305. VALIDATE
131 - helm lint
132 - helm template --debug
133 - helm install --dry-run
134 - Policy validation (optional)
135 ↓
1366. DELIVER
137 - Chart in charts/ directory
138 - Summary of what was created
139 - Next steps (push to registry, GitOps setup)
140```
141
142---
143
144## Chart Structure (Library Pattern)
145
146```
147charts/
148├── myapp-lib/ # Library chart (reusable)
149│ ├── Chart.yaml # type: library
150│ ├── templates/
151│ │ ├── _deployment.tpl # Reusable deployment template
152│ │ ├── _service.tpl # Reusable service template
153│ │ ├── _helpers.tpl # Common helpers
154│ │ └── _security.tpl # Security context helpers
155│ └── values.yaml # Default values
156│
157└── myapp/ # Application chart (thin)
158 ├── Chart.yaml # Dependencies: myapp-lib
159 ├── templates/
160 │ ├── deployment.yaml # {{ include "myapp-lib.deployment" . }}
161 │ ├── service.yaml # {{ include "myapp-lib.service" . }}
162 │ └── _helpers.tpl # App-specific helpers
163 ├── values.yaml # App defaults
164 ├── values.schema.json # Schema validation
165 └── values/ # Environment overlays
166 ├── dev.yaml
167 ├── staging.yaml
168 └── prod.yaml
169```
170
171---
172
173## Core Templates
174
175### Chart.yaml (Application)
176
177```yaml
178apiVersion: v2
179name: myapp
180version: 0.1.0 # Chart version (SemVer)
181appVersion: "1.0.0" # App version
182type: application # or: library
183description: |
184 Brief description of what this chart deploys.
185
186# Dependencies (subchart pattern)
187dependencies:
188 - name: myapp-lib
189 version: ">=0.1.0"
190 repository: "oci://ghcr.io/myorg/charts"
191 - name: redis
192 version: "17.x.x"
193 repository: "oci://registry-1.docker.io/bitnamicharts"
194 condition: redis.enabled # Conditional dependency
195
196# Kubernetes version constraint
197kubeVersion: ">=1.25.0"
198
199# Maintainers
200maintainers:
201 - name: DevRaftel
202 email: team@devraftel.com
203```
204
205### values.yaml (Structured)
206
207```yaml
208# -- Number of replicas
209replicaCount: 2
210
211image:
212 # -- Container image repository
213 repository: myorg/myapp
214 # -- Image pull policy
215 pullPolicy: IfNotPresent
216 # -- Image tag (defaults to appVersion)
217 tag: ""
218
219# -- Resource requests and limits
220resources:
221 requests:
222 cpu: "100m"
223 memory: "128Mi"
224 limits:
225 cpu: "500m"
226 memory: "512Mi"
227
228# -- Security context (pod level)
229podSecurityContext:
230 runAsNonRoot: true
231 runAsUser: 1000
232 fsGroup: 1000
233
234# -- Security context (container level)
235securityContext:
236 allowPrivilegeEscalation: false
237 readOnlyRootFilesystem: true
238 capabilities:
239 drop: ["ALL"]
240
241# -- Service configuration
242service:
243 type: ClusterIP
244 port: 80
245 targetPort: 8080
246
247# -- Health probes
248probes:
249 liveness:
250 path: /health/live
251 initialDelaySeconds: 10
252 readiness:
253 path: /health/ready
254 initialDelaySeconds: 5
255
256# -- Enable autoscaling
257autoscaling:
258 enabled: false
259 minReplicas: 2
260 maxReplicas: 10
261 targetCPUUtilization: 80
262```
263
264---
265
266## Command Reference
267
268### Chart Development
269
270```bash
271# Create new chart
272helm create myapp
273
274# Lint chart
275helm lint ./myapp
276
277# Render templates locally
278helm template myapp ./myapp -f values.yaml
279
280# Render with debug (shows template errors)
281helm template myapp ./myapp --debug 2>&1 | head -100
282
283# Package chart
284helm package ./myapp
285
286# Update dependencies
287helm dependency update ./myapp
288helm dependency build ./myapp
289```
290
291### Release Management
292
293```bash
294# Install release
295helm install myapp ./myapp -n namespace --create-namespace
296
297# Install with atomic (rollback on failure)
298helm install myapp ./myapp --atomic --timeout 5m
299
300# Upgrade release
301helm upgrade myapp ./myapp --atomic
302
303# Upgrade or install
304helm upgrade --install myapp ./myapp
305
306# Rollback to previous
307helm rollback myapp 1
308
309# Uninstall
310helm uninstall myapp -n namespace
311
312# Release status
313helm status myapp
314helm history myapp
315```
316
317### OCI Registry
318
319```bash
320# Login to registry
321helm registry login ghcr.io -u USERNAME
322
323# Push chart to OCI
324helm push myapp-0.1.0.tgz oci://ghcr.io/myorg/charts
325
326# Pull from OCI
327helm pull oci://ghcr.io/myorg/charts/myapp --version 0.1.0
328
329# Install from OCI
330helm install myapp oci://ghcr.io/myorg/charts/myapp --version 0.1.0
331```
332
333### Debugging
334
335```bash
336# Get release manifest
337helm get manifest myapp
338
339# Get computed values
340helm get values myapp
341helm get values myapp --all # Including defaults
342
343# Get hooks
344helm get hooks myapp
345
346# Dry-run against cluster
347helm install myapp ./myapp --dry-run --debug
348
349# Diff before upgrade (requires helm-diff plugin)
350helm diff upgrade myapp ./myapp
351```
352
353---
354
355## Validation Pipeline
356
357Before delivering charts, run:
358
359```bash
360# 1. Lint
361helm lint ./myapp --strict
362
363# 2. Template render
364helm template myapp ./myapp --debug > /dev/null
365
366# 3. Dry-run against cluster
367helm install myapp ./myapp --dry-run --debug -n test
368
369# 4. Schema validation (if values.schema.json exists)
370helm lint ./myapp # Automatically validates against schema
371
372# 5. Policy validation (optional)
373# OPA/Conftest
374conftest test ./myapp/templates/
375
376# Trivy for security scanning
377trivy config ./myapp/
378```
379
380---
381
382## Output Checklist
383
384Before delivering, verify:
385
386### Chart Structure
387- [ ] Chart.yaml has apiVersion: v2, valid version, kubeVersion
388- [ ] values.yaml has comments for helm-docs
389- [ ] values.schema.json for validation
390- [ ] Templates use `_helpers.tpl` for reusable definitions
391
392### Security
393- [ ] `securityContext` in values with secure defaults
394- [ ] No secrets in values.yaml (use external secrets)
395- [ ] `runAsNonRoot: true` in pod security context
396- [ ] Resource limits defined
397
398### Best Practices
399- [ ] Labels follow `app.kubernetes.io/*` standard
400- [ ] Health probes configurable via values
401- [ ] Supports multiple environments (values overlays)
402- [ ] Hooks have deletion policies
403
404### Validation
405- [ ] `helm lint` passes without warnings
406- [ ] `helm template --debug` renders successfully
407- [ ] `helm install --dry-run` succeeds against cluster
408
409### GitOps Ready
410- [ ] Chart versioned with SemVer
411- [ ] OCI-pushable (no local dependencies)
412- [ ] ArgoCD/Flux compatible structure
413
414---
415
416## Reference Files
417
418### Always Read First
419
420| File | Purpose |
421|------|---------|
422| `references/chart-development.md` | **CRITICAL**: Template syntax, helpers, hooks |
423| `references/values-patterns.md` | **CRITICAL**: Precedence, environments, schema |
424| `references/helm4-features.md` | **CRITICAL**: SSA, Wasm, kstatus, OCI |
425
426### Operations
427
428| File | When to Read |
429|------|--------------|
430| `references/release-management.md` | Install, upgrade, rollback, atomic |
431| `references/oci-workflows.md` | Push, pull, registry auth, digest |
432| `references/debugging-workflow.md` | Template errors, failed releases |
433| `references/testing-validation.md` | Lint, unittest, dry-run, integration tests |
434
435### Integration
436
437| File | When to Read |
438|------|--------------|
439| `references/gitops-integration.md` | ArgoCD, Flux, ApplicationSet |
440| `references/umbrella-patterns.md` | Multi-service, subcharts, Kustomize |
441| `references/ai-agent-patterns.md` | GPU, models, sidecars, KEDA |
442
443### Security & Compliance
444
445| File | When to Read |
446|------|--------------|
447| `references/security-patterns.md` | Secrets (ESO, Sealed), RBAC, policies |
448| `references/hooks-lifecycle.md` | Hook types, weights, deletion policies |