SkillByAIOpen interactive version →

Lesson 2 / 25

Charts, Releases, Repositories and Values

Use the four core Helm terms correctly and know where Helm stores state.

Four words to get right

A chart is a package: a directory (or .tgz archive) containing Chart.yaml metadata, default values.yaml and a templates/ folder. A release is one installed instance of a chart in a cluster, with a name you choose (shop-api, redis-cache); you can install the same chart many times under different release names. Each install, upgrade or rollback creates a new revision of the release. A repository is a place that serves charts, either a classic HTTP index (index.yaml) or an OCI registry. Values are the configuration that fills in the templates. Since Helm 3 there is no server-side component (the old Tiller is gone): the helm CLI talks directly to the Kubernetes API using your kubeconfig and RBAC, and stores each release revision as a Secret in the release's namespace.

Seeing where release state lives

Each revision is a Secret of type helm.sh/release.v1; never edit these by hand.

# columns: name, namespace, revision, status, chart and app version
helm list --namespace shop

# one Secret per revision, named sh.helm.release.v1.<release>.v<revision>
kubectl get secrets --namespace shop -l owner=helm

Releases are namespaced

A release lives in one namespace, and its name must be unique within that namespace. Forgetting --namespace (or -n) is the most common reason helm list looks empty: you are looking in the wrong namespace. Use helm list -A to search all namespaces.

Quick check: Where does Helm 3 store the record of each release revision by default?

  • In a Tiller pod in kube-system
  • In a local file in your home directory only
  • In the chart repository
  • As Secrets in the release's namespace
Answer

As Secrets in the release's namespace — Helm 3 removed Tiller and stores release revisions as Secrets in the namespace of the release.