Skip to main content

Helm

Helm packages Kubernetes manifests as charts whose templates are filled from values, and installs them as named, versioned releases. The GCP Web App Blueprint ships its application as a Helm chart that ArgoCD renders, and installs every cluster add-on as a pinned Helm release; the GCP Enterprise Baseline installs its optional runner controller the same way.

What it does​

A chart is a folder with Chart.yaml, templates and a default values.yaml; extra values files override defaults in order, last one wins. A release is one installation of a chart version in a namespace, and an upgrade changes it in place. Charts come from a repository or an OCI registry. OpenTofu's helm provider manages releases as resources, so a chart version is pinned in code and changed by a pull request.

How BuiltForProd uses it​

The application chart blueprint-app (version 0.1.0) lives in acme-gcp-blueprint-webapp-gitops/blueprint-app/helm. Its templates are deployment, service, gateway, httproute, backendpolicy, hpa, pdb, networkpolicy, serviceaccount and external-secret. ArgoCD renders three values files in order:

FileWritten byHolds
helm/values.yamlPeopleDefaults: probes, hardening, network policy, spread
helm/values-<stage>.yamlPeopleStage choices: replicas, HPA, PDB, Gateway names, data subnet range
envs/<stage>/values.yamlThe code pipeline, by pull requestimage.repository and image.tag only

Stage slugs are dev, stg and prd. A deploy changes only the last file, so a release diff is one image tag; see Kubernetes for what the templates declare.

Add-on releases. The infrastructure repository installs these with the helm provider, through the cluster's DNS-based endpoint with the stage deployer's IAM token:

ReleaseChart and versionNamespace
argocdargo-cd 10.9.6argocd
cert-managercert-manager v1.21.2cert-manager
external-secretsexternal-secrets 2.11.0external-secrets
external-dns, ext-dns-intexternal-dns 1.23.0kube-system

Each sets the toleration for the tainted system pool. Chart versions are module variable defaults, changed in one place.

Runner controller (Baseline, optional). With self-hosted runners on, the github-runners unit installs gha-runner-scale-set-controller and one gha-runner-scale-set named acme-runners, both 0.15.0 from GitHub's OCI registry, on the runner cluster in acme-core-auto; see GitHub Actions.

Provider pins. hashicorp/helm ~> 3.3 and, in the web app, hashicorp/kubernetes ~> 3.2, declared in the versions.tf of each module that uses them; see OpenTofu.

Terms you will see​

TermMeaning
ChartA package of templates and default values.
ReleaseOne installation of a chart version in a namespace.
Values fileA YAML file that overrides chart defaults; later files win.
envs/<stage>The folder the code pipeline writes the image tag to.
OCI registryA container registry that also stores charts, used for the runner charts.

Where to read more​