Lesson 6 / 25
Repositories and OCI Registries
Pull and push charts from classic repositories and OCI registries.
Two ways to distribute charts
A classic chart repository is any HTTP server hosting an index.yaml plus chart archives; you use it with helm repo add and refer to charts as repo/chart. Modern Helm also stores charts in OCI registries, the same registries that hold container images (GitHub Container Registry, Docker Hub, Amazon ECR, Google Artifact Registry, Azure Container Registry, Harbor). With OCI there is no repo add step: you log in with helm registry login and refer to charts by URL, oci://registry/path/chart, with --version. OCI is now the common choice for internal charts because you reuse existing registry authentication, access control, replication and scanning. Artifact Hub is a search index for public charts, not a repository itself.
Packaging and pushing to an OCI registry
The chart name and version come from Chart.yaml; the push target is the parent path.
helm package ./charts/shop-api # creates shop-api-1.4.0.tgz
helm registry login ghcr.io -u my-user # token from stdin or prompt
helm push shop-api-1.4.0.tgz oci://ghcr.io/acme/charts
# consumers
helm show chart oci://ghcr.io/acme/charts/shop-api --version 1.4.0
helm upgrade --install shop-api oci://ghcr.io/acme/charts/shop-api \
--version 1.4.0 -n shop -f values-prod.yamlTreat chart versions as immutable
Never push different content under an existing chart version. Clusters and caches may already hold the old artefact, and two environments would silently run different charts with the same number. Bump the version for every change.
Quick check: How do you install a chart from an OCI registry?
- helm install NAME oci://registry/path/chart --version X
- helm repo add, then helm install repo/chart
- kubectl apply -f oci://...
- helm pull is required before any install
Answer
helm install NAME oci://registry/path/chart --version X — OCI charts are referenced directly by an oci:// URL; no repo add step is needed.