Helm
Helm packages Kubernetes manifests as charts whose templates are filled from values, and installs them as named, versioned releases. The GCP Web App Blueprint ships its application as a Helm chart that ArgoCD renders, and installs every cluster add-on as a pinned Helm release; the GCP Enterprise Baseline installs its optional runner controller the same way.
What it does
A chart is a folder with Chart.yaml, templates and a default values.yaml; extra values files override defaults in order, last one wins. A release is one installation of a chart version in a namespace, and an upgrade changes it in place. Charts come from a repository or an OCI registry. OpenTofu's helm provider manages releases as resources, so a chart version is pinned in code and changed by a pull request.
How BuiltForProd uses it
The application chart blueprint-app (version 0.1.0) lives in acme-gcp-blueprint-webapp-gitops/blueprint-app/helm. Its templates are deployment, service, gateway, httproute, backendpolicy, hpa, pdb, networkpolicy, serviceaccount and external-secret. ArgoCD renders three values files in order:
| File | Written by | Holds |
|---|---|---|
helm/values.yaml | People | Defaults: probes, hardening, network policy, spread |
helm/values-<stage>.yaml | People | Stage choices: replicas, HPA, PDB, Gateway names, data subnet range |
envs/<stage>/values.yaml | The code pipeline, by pull request | image.repository and image.tag only |
Stage slugs are dev, stg and prd. A deploy changes only the last file, so a release diff is one image tag; see Kubernetes for what the templates declare.
Add-on releases. The infrastructure repository installs these with the helm provider, through the cluster's DNS-based endpoint with the stage deployer's IAM token:
| Release | Chart and version | Namespace |
|---|---|---|
argocd | argo-cd 10.9.6 | argocd |
cert-manager | cert-manager v1.21.2 | cert-manager |
external-secrets | external-secrets 2.11.0 | external-secrets |
external-dns, ext-dns-int | external-dns 1.23.0 | kube-system |
Each sets the toleration for the tainted system pool. Chart versions are module variable defaults, changed in one place.
Runner controller (Baseline, optional). With self-hosted runners on, the github-runners unit installs gha-runner-scale-set-controller and one gha-runner-scale-set named acme-runners, both 0.15.0 from GitHub's OCI registry, on the runner cluster in acme-core-auto; see GitHub Actions.
Provider pins. hashicorp/helm ~> 3.3 and, in the web app, hashicorp/kubernetes ~> 3.2, declared in the versions.tf of each module that uses them; see OpenTofu.
Terms you will see
| Term | Meaning |
|---|---|
| Chart | A package of templates and default values. |
| Release | One installation of a chart version in a namespace. |
| Values file | A YAML file that overrides chart defaults; later files win. |
envs/<stage> | The folder the code pipeline writes the image tag to. |
| OCI registry | A container registry that also stores charts, used for the runner charts. |
Where to read more
- GCP Web App Blueprint overview for the repositories.
- ArgoCD for how the chart reaches each cluster.
- GitOps for the delivery model.