Helm
Helm is the package manager for Kubernetes: a chart is a set of templated manifests, and values files fill in the templates. The Azure Web App Blueprint ships its application as a Helm chart that ArgoCD renders in each cluster, and its infrastructure code installs three cluster add-ons as Helm releases.
What it does
A chart holds templates and a default values.yaml. Rendering a chart with one or more values files, later files overriding earlier ones, produces plain Kubernetes manifests. An installed chart is a release with a name, a namespace and a chart version, upgraded in place. Charts may ship custom resource definitions (CRDs), the types that objects such as a ClusterIssuer or an ExternalSecret are instances of.
How BuiltForProd uses it
The application chart. blueprint-app lives in acme-azure-blueprint-webapp-gitops/blueprint-app/helm (chart version 0.1.0) and ArgoCD renders it; nobody runs helm install against a cluster.
| Template | What it creates |
|---|---|
deployment.yaml | The API Deployment with the pod hardening and the workload identity label |
service.yaml | ClusterIP service on port 8080 |
ingress.yaml | The Ingress on nginx-internal or nginx-public, certificate from the cluster issuer |
hpa.yaml, pdb.yaml | Autoscaler and disruption budget, switched on per stage |
networkpolicy.yaml | Default deny with the four allowed flows |
serviceaccount.yaml | Off by default: the app-namespace unit owns blueprint-app-sa and its identity |
external-secret.yaml | The data-store host names and ports from the application vault |
app-external-secret.yaml | The application secrets the Secrets Blueprint writes |
ArgoCD layers three values files, in this order:
values.yaml: the defaults.values-<stage>.yaml(dev,stg,prd): replicas, resources, autoscaling, ingress host and class, maintained by hand.../envs/<stage>/values.yaml:image.repositoryandimage.tagonly, written by the deploy pull requests of the code repository. There is nolatest: until the first pull request merges, no image is deployable for that stage.
The cluster add-ons. The infrastructure repository installs three releases through the hashicorp/helm ~> 3.3 provider, each on the system pool:
| Release | Chart version | Namespace | Unit |
|---|---|---|---|
argo-cd | 9.5.22 | argocd | argocd |
cert-manager | v1.21.2 | cert-manager | cert-manager |
external-secrets | 2.6.0 | external-secrets | external-secrets |
Each chart installs its own CRDs. The objects that use them, such as the ClusterIssuers, the ClusterSecretStore and the ArgoCD Application, are written by a separate unit or resource, so a CRD and its objects never share one OpenTofu state. The NGINX controllers are not Helm releases; the application routing add-on runs them. The Container Apps runner image carries the Helm CLI v3.22.0.
Terms you will see
| Term | Meaning |
|---|---|
| Chart | A package of templates and default values. |
| Values file | YAML that fills the templates; later files override earlier ones. |
| Release | One installed chart in a namespace, with its version history. |
| CRD | A custom resource definition, the type behind objects such as a ClusterIssuer. |
| Rendering | Turning templates and values into plain manifests, which ArgoCD does. |
Where to read more
- Azure Web App Blueprint overview for the repositories involved.
- ArgoCD for how the chart reaches the cluster.
- GitOps for the model.