# Chart CI/CD Pipelines — Helm

Source: https://www.skillbyai.com/en/helm/d-ci

> Build a pipeline that lints, tests, packages and publishes charts.

## Charts are artefacts too

Treat a chart like any other release artefact. A typical chart pipeline on every pull request runs `helm lint`, renders templates with representative values files, validates them with kubeconform, runs helm-unittest and, for larger projects, `ct install` against a kind cluster. On merge to main, it checks that the chart version was bumped, runs `helm package`, pushes the package to an OCI registry, and optionally signs it. Deployment is a separate step, either `helm upgrade --install --wait` from CD or a Git commit that a GitOps controller picks up. For application repositories, keep the chart next to the code and let the pipeline set `image.tag` to the commit or release tag it just built, so the chart and image versions are traceable.

## GitHub Actions: lint, test and publish

Publishing runs only on the main branch; the registry token comes from the workflow's built-in token.

```yaml
name: chart
on: [push, pull_request]
jobs:
  chart:
    runs-on: ubuntu-latest
    permissions: { contents: read, packages: write }
    steps:
      - uses: actions/checkout@v4
      - uses: azure/setup-helm@v4
      - run: helm dependency build charts/shop-api
      - run: helm lint charts/shop-api -f charts/shop-api/ci/prod-values.yaml
      - run: helm template t charts/shop-api -f charts/shop-api/ci/prod-values.yaml > rendered.yaml
      - run: kubeconform -strict -summary rendered.yaml   # installed in an earlier step
      - if: github.ref == 'refs/heads/main'
        run: |
          helm package charts/shop-api
          echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u ${{ github.actor }} --password-stdin
          helm push shop-api-*.tgz oci://ghcr.io/${{ github.repository_owner }}/charts
```

## Keep a ci/ folder of values

chart-testing automatically installs the chart once per file in `ci/*-values.yaml`. Keeping a minimal, a production-like and an all-features-on file there gives you a cheap test matrix.

**Quiz:** In a chart pipeline, what should happen before a new chart package is pushed?

- [ ] Nothing; push on every commit with the same version
- [ ] Delete the old chart from the registry
- [x] Lint, render and validate it, and make sure the chart version was bumped
- [ ] Run helm rollback

*Answer:* Lint, render and validate it, and make sure the chart version was bumped. Validation catches broken charts, and a version bump keeps published versions immutable.
