Learning · Kubernetes

Packaging and Helm

Charts, Kustomize, and GitOps packaging — reusable templates without snowflake YAML per environment.

Raw manifests do not scale across environments. Packaging is how you keep one workload definition parameterized safely.

Helm

Charts template Kubernetes YAML with values. Useful for dependencies and standard apps. Pin chart versions; review rendered output (helm template) in PRs. Values files per env beat copy-paste charts.

Watch for:

  • templates that hide critical probes/resources
  • wild defaults (latest, open RBAC)
  • hooks that surprise during upgrade/rollback

Kustomize

Overlays patch a base without a templating language. Good for small env diffs (replicas, ingress host). Painful for heavy branching logic — do not rebuild Helm inside Kustomize patches.

GitOps rendering

Argo CD / Flux apply rendered or chart-sourced desired state. The repo is the source of truth; cluster drift is detected, not celebrated. Secrets still need sealing/external stores.

Version everything

Chart version, app version, and git SHA should be traceable on the running workload (labels/annotations). “Whatever was in main last Tuesday” is not a release identifier.

Smell test

If every environment needs a hand-edited live object after install, packaging failed — fix values and templates, not the cluster.

← Kubernetes