Skip to main content

Helm

Helm is the package manager for Kubernetes: a chart is a set of templated manifests, and values files fill in the templates. The Azure Web App Blueprint ships its application as a Helm chart that ArgoCD renders in each cluster, and its infrastructure code installs three cluster add-ons as Helm releases.

What it does​

A chart holds templates and a default values.yaml. Rendering a chart with one or more values files, later files overriding earlier ones, produces plain Kubernetes manifests. An installed chart is a release with a name, a namespace and a chart version, upgraded in place. Charts may ship custom resource definitions (CRDs), the types that objects such as a ClusterIssuer or an ExternalSecret are instances of.

How BuiltForProd uses it​

The application chart. blueprint-app lives in acme-azure-blueprint-webapp-gitops/blueprint-app/helm (chart version 0.1.0) and ArgoCD renders it; nobody runs helm install against a cluster.

TemplateWhat it creates
deployment.yamlThe API Deployment with the pod hardening and the workload identity label
service.yamlClusterIP service on port 8080
ingress.yamlThe Ingress on nginx-internal or nginx-public, certificate from the cluster issuer
hpa.yaml, pdb.yamlAutoscaler and disruption budget, switched on per stage
networkpolicy.yamlDefault deny with the four allowed flows
serviceaccount.yamlOff by default: the app-namespace unit owns blueprint-app-sa and its identity
external-secret.yamlThe data-store host names and ports from the application vault
app-external-secret.yamlThe application secrets the Secrets Blueprint writes

ArgoCD layers three values files, in this order:

  1. values.yaml: the defaults.
  2. values-<stage>.yaml (dev, stg, prd): replicas, resources, autoscaling, ingress host and class, maintained by hand.
  3. ../envs/<stage>/values.yaml: image.repository and image.tag only, written by the deploy pull requests of the code repository. There is no latest: until the first pull request merges, no image is deployable for that stage.

The cluster add-ons. The infrastructure repository installs three releases through the hashicorp/helm ~> 3.3 provider, each on the system pool:

ReleaseChart versionNamespaceUnit
argo-cd9.5.22argocdargocd
cert-managerv1.21.2cert-managercert-manager
external-secrets2.6.0external-secretsexternal-secrets

Each chart installs its own CRDs. The objects that use them, such as the ClusterIssuers, the ClusterSecretStore and the ArgoCD Application, are written by a separate unit or resource, so a CRD and its objects never share one OpenTofu state. The NGINX controllers are not Helm releases; the application routing add-on runs them. The Container Apps runner image carries the Helm CLI v3.22.0.

Terms you will see​

TermMeaning
ChartA package of templates and default values.
Values fileYAML that fills the templates; later files override earlier ones.
ReleaseOne installed chart in a namespace, with its version history.
CRDA custom resource definition, the type behind objects such as a ClusterIssuer.
RenderingTurning templates and values into plain manifests, which ArgoCD does.

Where to read more​