Helm Chart
| source | condition | target |
|---|---|---|
✔ | ✔ | ✔ |
Description
The helmchart resource works at two levels, and which one applies depends on the stage:
- source and condition
Talk to a chart repository. The source returns the latest version of a published chart; the condition checks that
versionexists there.- target
Works on a chart in your repository. It updates a value in the chart’s
values.yaml, then maintains the chart’s own metadata (bumpingversion, optionallyappVersion, and refreshingrequirements.lock).
That asymmetry is the thing to keep in mind: url addresses the remote repository and is read-only, while name and key address the local chart the target rewrites.
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| appversion | boolean | “appversion” defines whether the chart “appVersion” is updated. compatible:
default: false remark:
| |
| file | string | “file” defines the chart file to update. compatible:
default: values.yaml remark:
| |
| key | string | “key” defines the yamlpath query used to retrieve the value from the yaml file. compatible:
remark:
example:
| |
| name | string | “name” defines the chart name, or the chart path such as “stable/chart”. compatible:
remark:
example:
| |
| password | string | “password” defines the container registry password used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| skippackaging | boolean | “skippackaging” defines whether the chart dependencies update is skipped. compatible:
default: false | |
| token | string | “token” defines the container registry bearer token used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| url | string | “url” defines the chart repository location. compatible:
remark:
example:
| |
| username | string | “username” defines the container registry username used for authentication. default:
credentials are retrieved from the local environment, such as remark:
| |
| value | string | “value” defines the value associated with the yamlpath query. compatible:
default: the output of the associated source. | |
| version | string | “version” defines the chart version to check on the registry. compatible:
default: the output of the associated source. | |
| versionfilter | object | “versionfilter” defines the version pattern and its kind, such as “regex”, “semver” or “latest”. compatible:
default: semver | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
| |
| versionincrement | string | “versionincrement” defines how the chart version is bumped when the chart changes. compatible:
default: minor remark:
example:
|
nameThe chart, as
stable/chart. With anscm, it is the path to the chart relative to the repository root.fileDefaults to
values.yaml, resolved relative to the chart root (not to the repository root).keyTarget only. The yamlpath of the value to update, e.g.
$.image.tag.urlSource and condition only. Accepts a repository index, a git URL, or an OCI registry:
index.yaml file://./index.yaml https://github.com/updatecli/charts.git oci://ghcr.io/olblak/charts/versionCondition only.
Credentials for an OCI registry are given inline on the spec, next to the other fields, rather than under a nested key.
Version bumping
versionincrement controls what happens to the chart’s own version when a target changes something. It defaults to minor, and accepts a comma-separated list of none, major, minor, patch and auto.
Warning | The increment is applied per target. When several targets in the same pipeline update the same chart, the chart version is bumped once for each of them - three targets with the default |
appversion: true also writes the source value into the chart’s appVersion field (the usual choice when the chart ships one application whose image tag you are bumping).
skippackaging: true updates the files without packaging the chart afterwards.
Version filtering
Unlike most resources, versionfilter defaults to semver here rather than to the generic filter, since charts are required to carry semantic versions. See the "Version Filtering" page.
Example
# updatecli.yaml
name: Example of Helm Chart resources
scms:
default:
kind: github
spec:
user: "john"
email: "john@example.com"
owner: "olblak"
repository: "charts"
token: "{{ requiredEnv .github.token }}"
username: "john"
branch: "master"
sources:
lastRelease:
kind: helmchart
spec:
url: https://charts.jenkins.io
name: jenkins
conditions:
isPrometheuseHelmChartVersionAvailable:
name: "Test if the prometheus helm chart is available"
kind: helmchart
spec:
url: https://prometheus-community.github.io/helm-charts
name: prometheus
version: "11.16.5"
targets:
chartjenkins:
name: Bump Jenkins Upstream Chart Version
kind: helmchart
spec:
name: "charts/jenkins"
file: "requirements.yaml"
key: "dependencies[0].version"
versionincrement: minor
What it says:
- Source
Retrieve the version of the Jenkins chart from
https://charts.jenkins.io(2.7.1).- Condition
Check that version 11.16.5 of the prometheus chart is available from
https://prometheus-community.github.io/helm-charts. If not, the pipeline stops.- Target
Bump the upstream version into the local chart, drop
requirements.lockif present, increment the chart version, then commit and open a pull request on GitHub.