Lesson 21 / 25

Chart CI/CD Pipelines

Build a pipeline that lints, tests, packages and publishes charts.

Charts are artefacts too

Treat a chart like any other release artefact. A typical chart pipeline on every pull request runs helm lint, renders templates with representative values files, validates them with kubeconform, runs helm-unittest and, for larger projects, ct install against a kind cluster. On merge to main, it checks that the chart version was bumped, runs helm package, pushes the package to an OCI registry, and optionally signs it. Deployment is a separate step, either helm upgrade --install --wait from CD or a Git commit that a GitOps controller picks up. For application repositories, keep the chart next to the code and let the pipeline set image.tag to the commit or release tag it just built, so the chart and image versions are traceable.

GitHub Actions: lint, test and publish

Publishing runs only on the main branch; the registry token comes from the workflow's built-in token.

name: chart
on: [push, pull_request]
jobs:
  chart:
    runs-on: ubuntu-latest
    permissions: { contents: read, packages: write }
    steps:
      - uses: actions/checkout@v4
      - uses: azure/setup-helm@v4
      - run: helm dependency build charts/shop-api
      - run: helm lint charts/shop-api -f charts/shop-api/ci/prod-values.yaml
      - run: helm template t charts/shop-api -f charts/shop-api/ci/prod-values.yaml > rendered.yaml
      - run: kubeconform -strict -summary rendered.yaml   # installed in an earlier step
      - if: github.ref == 'refs/heads/main'
        run: |
          helm package charts/shop-api
          echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u ${{ github.actor }} --password-stdin
          helm push shop-api-*.tgz oci://ghcr.io/${{ github.repository_owner }}/charts

Keep a ci/ folder of values

chart-testing automatically installs the chart once per file in ci/*-values.yaml. Keeping a minimal, a production-like and an all-features-on file there gives you a cheap test matrix.

Quick check: In a chart pipeline, what should happen before a new chart package is pushed?

  • Nothing; push on every commit with the same version
  • Delete the old chart from the registry
  • Lint, render and validate it, and make sure the chart version was bumped
  • Run helm rollback
Answer

Lint, render and validate it, and make sure the chart version was bumped — Validation catches broken charts, and a version bump keeps published versions immutable.