Helm V4 in Practice
Designing, Deploying, and Operating Kubernetes Applications at Scale
Available as: Online course
What You'll Learn
- Explain what Helm does during install, upgrade, rollback and uninstall
- Design charts with dependencies, subcharts, CRDs and hook lifecycle ordering
- Merge and validate configuration with values files, schemas, overrides and defaults
- Inspect what Helm installed, what it intended to install, and what is actually running
- Diagnose failed installs and broken hooks with dry runs and rendered manifests
- Sign and verify charts, and distribute them through OCI registries
- Use Helm inside GitOps workflows alongside Argo CD without the two fighting
About This Book
A guide to Helm in context rather than in isolation: the library, the ecosystem around it, and the ideas that hold everything together. It focuses on how Helm behaves in practice, not just which commands to run.
It takes you from the fundamentals to operating, debugging and designing Helm-based systems in production: how Helm models state and tracks releases, what happens during install, upgrade, rollback and uninstall, chart structure from simple charts to production charts with dependencies, subcharts, CRDs and hook ordering, values files and schemas, revision history, dry runs and rendered manifests for debugging, provenance and signing, distribution through OCI registries, and where Helm's responsibilities meet Argo CD's in a GitOps workflow.
Table of Contents
-
Preface
- Who This Guide Is For
- What You Will Learn
- About the Author
- Join the Community
- Your Feedback Matters
-
How to Use This Guide
- The Companion Kit
- Conventions Used in This Guide
-
Setting up the Environment
- The Infrastructure
- The Application
- The Container Image
- The Platform
-
Introduction to Helm
- What is Helm?
- How to Install Helm
- Charts, Releases, and Repositories
- Helm Plugins
-
Helm Repositories and OCI Registries
- Helm Chart Repositories
- Helm OCI Registries
- Chart Repositories vs. OCI Registries
-
Configuring and Customizing Helm
- Helm Environment Variables
- Repository and Registry Config Paths
- Helm Data Paths and Plugins
- Kubernetes Authentication and Connection
- The Default Namespace
- Kubernetes API Rate Limiting
- Debugging and Colored Output
- Configuration Using CLI Flags
- Summary of Helm Environment Variables
-
Chart Dependencies
- Chart Dependencies
-
Understanding Helm Chart Installation and Management
- Installing from a Specific Repository
- Using a Chart with Custom Configurations
- Using a Chart with a Custom Configuration File
- Install a Chart from a Local Tarball
- Installing a Chart from a Local Directory
- Default Helm Labels
- Understanding What's Installed and How
- Install a Chart in a Specific Namespace
- Understanding Chart Versions and Upgrading Releases
- Viewing Release
- Viewing Release History
- Uninstalling a Release
-
Creating, Developing, and Testing a Helm Chart
- Deploying a Registry
- The Starter Template
- Customizing the Chart and Pushing the Image
- Creating a Testing Pod
- Adding a Secret for Image Pulling
- Updating the Values File
- Generating a Schema for Values File
- Linting the Chart
- Dry Run Template Rendering
- Installing and Testing the Chart Locally
- Packaging and Distributing the Chart
- Installation from a Remote Registry
- Versioning and Deprecating Charts
-
Understanding Complex Helm Charts: Dependencies, CRDs, Lifecycle, Ordering, and Hooks
- Understanding Helm Dependencies
- Handling Custom Resource Definitions (CRDs) in Helm
- Helm Release Lifecycle and Hooks
- The Order of Operations
- The Overall Installation Workflow
- The Upgrade Workflow
- Helm Rollback Workflow
- Uninstall Workflow
- Helm and PVC Deletion: Direct vs. StatefulSet Behavior
-
A Practical Guide to Building Multi-Service Applications with Helm
- A Quick Recap and Moving Forward
- Creating the Helm Chart
- Building the Chart
- Deploying the Application
- Managing Dependencies
- Cleanup
-
Provenance and Integrity in Helm Charts
- What Provenance Means and Why It Matters
- How Helm Implements Provenance
- How Signing and Verification Work
- Signing Charts
- Verifying Charts Before Installation
- Publishing a Signed Chart to a Repository
- Publishing Signed Charts to an OCI Registry
-
GitOps: Cloud Native Continuous Delivery
- GitOps: Introduction and Definitions
- GitOps: Benefits and Drawbacks
- GitOps: Tools and Ecosystem
- Helm and GitOps
-
GitOps with Helm and Argo CD
- Argo CD, the Popular GitOps Tool
- Argo CD: Installation and Configuration
- Argo CD: Deploying an Application
- Argo CD: Automated Synchronization and Self-Healing
- Rollback with Argo CD
- The Declarative Way of Managing Argo CD Applications
- Argo CD: Configuration Management Using Helm
- Argo CD: Managing Different Environments
- Argo CD Application Hooks and Pitfalls to Avoid
-
Afterword
- Let's Stay Connected
- Feedback
Who This Is For
Engineers who deploy Kubernetes applications with Helm and want to reason about its behavior instead of memorizing commands.
About the Author
Aymen El Amri is a software engineer, author and founder. He runs eralabs, built FAUN.dev, and writes about cloud native systems, AI engineering and developer tooling. More about Aymen.