* chore: bump helm release pins * chore: align helm module metadata * chore: finalize helm patch bumps * fix: add --plain-http flag for Helm 3.21+ OCI push in tests Helm 3.21.1 introduced stricter security checks that reject HTTP scheme downgrades when pushing to OCI registries, with the error: "blob upload Location downgrades scheme from https" Previously only Helm 4 required --plain-http for HTTP-only OCI registries. Now Helm 3.21+ also requires this flag. Add a new requiresPlainHTTPForOCI() helper that returns true for both Helm 4.x and Helm 3.21+, and use it in execHelmPush() instead of isHelm4(). * fix: safe fallback in requiresPlainHTTPForOCI when version detection fails Default to true (require --plain-http) when helm version detection fails, since any Helm version that supports helm push also supports the --plain-http flag. This avoids the inconsistent HELMFILE_HELM4 env var fallback which only covered Helm 4. * fix: update snapshot tests for Helm 4.2.1 OCI pull output Helm 4.2.1 now outputs additional 'Pulled:' and 'Digest: sha256:...' lines after each OCI chart pull. The SHA256 digest is non-deterministic because helm packages include build timestamps, so normalize it with a regex placeholder. - Add ociDigestRegex to normalize non-deterministic OCI digest values - Create output-helm4.yaml for 5 tests that lacked Helm 4 snapshots - Update output-helm4.yaml for oci_need and postrenderer to include the new Pulled/Digest lines from Helm dependency pull operations * fix: update ociDigestRegex to match empty digest in Helm 4.2.1 OCI pull output Helm 4.2.1 outputs "Digest: sha256:" (empty hash) when pulling OCI charts. The regex required at least one hex char ([0-9a-f]+), so it did not match and the digest was not normalized to $DIGEST in snapshot tests. Also fix the replacement string: Go regex ReplaceAllString interprets $DIGEST as a capture group reference (resolving to empty). Use $$DIGEST to produce a literal $DIGEST in the output. Signed-off-by: yxxhero <aiopsclub@163.com> --------- Signed-off-by: yxxhero <aiopsclub@163.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: yxxhero <aiopsclub@163.com>
English | 简体中文
About
Helmfile is a declarative spec for deploying helm charts. It lets you...
- Keep a directory of chart value files and maintain changes in version control.
- Apply CI/CD to configuration changes.
- Periodically sync to avoid skew in environments.
To avoid upgrades for each iteration of helm, the helmfile executable delegates to helm - as a result, the following must be installed
Highlights
Declarative: Write, version-control, apply the desired state file for visibility and reproducibility.
Modules: Modularize common patterns of your infrastructure, distribute it via Git, S3, etc. to be reused across the entire company (See #648)
Versatility: Manage your cluster consisting of charts, kustomizations, and directories of Kubernetes resources, turning everything to Helm releases (See #673)
Patch: JSON/Strategic-Merge Patch Kubernetes resources before helm-installing, without forking upstream charts (See #673)
Status
May 2025 Update
- Helmfile v1.0 and v1.1 has been released. We recommend upgrading directly to v1.1 if you are still using v0.x.
- If you haven't already upgraded, please go over this v1 proposal here to see a small list of breaking changes.
Installation
1: Binary Installation
download one of releases
2: Package Manager
- Archlinux: install via
pacman -S helmfile - openSUSE: install via
zypper in helmfileassuming you are on Tumbleweed; if you are on Leap you must add the kubic repo for your distribution version once before that command, e.g.zypper ar https://download.opensuse.org/repositories/devel:/kubic/openSUSE_Leap_\$releasever kubic - Windows (using scoop):
scoop install helmfile - macOS (using homebrew):
brew install helmfile - Linux/macOS/Windows (using mise):
mise use -g helmfile@latest
3: Container
For more details, see run as a container
Make sure to run
helmfile initonce after installation. Helmfile uses the helm-diff plugin.
4: Build from source
requirements: Go
go install github.com/helmfile/helmfile@latest
Getting Started
Let's start with a simple helmfile and gradually improve it to fit your use-case!
Generate a project scaffold with best-practice directory structure:
helmfile create my-project && cd my-project
Or create a helmfile.yaml manually. Suppose the helmfile.yaml representing the desired state of your helm releases looks like:
repositories:
- name: prometheus-community
url: https://prometheus-community.github.io/helm-charts
releases:
- name: prom-norbac-ubuntu
namespace: prometheus
chart: prometheus-community/prometheus
set:
- name: rbac.create
value: false
Sync your Kubernetes cluster state to the desired one by running:
helmfile apply
Congratulations! You now have your first Prometheus deployment running inside your cluster.
Iterate on the helmfile.yaml by referencing:
More complex examples
See: multi-env-helmfile
Docs
Please read complete documentation
Contributing
Welcome to contribute together to make helmfile better: contributing doc
Attribution
We use:
- semtag for automated semver tagging. I greatly appreciate the author(pnikosis)'s effort on creating it and their kindness to share it!
Users
Helmfile has been used by many users in production:
For more users, please see: Users