PageSourceSearch

https://docs.k3s.io/assets/js/86926d25.c22ce084.js

js k3s.io collected 2026-09-24 08:48:54 UTC 22,455 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkk_3_s_docs=self.webpackChunkk_3_s_docs||[]).push([[7697],{40387:(e,t,s)=>{s.r(t),s.d(t,{assets:()=>d,contentTitle:()=>c,default:()=>h,frontMatter:()=>a,metadata:()=>n,toc:()=>l});const n=JSON.parse('{"id":"add-ons/helm","title":"Helm","description":"Helm is the package management tool of choice for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, developers or cluster administrators can create configurable templates known as Charts, instead of just using static manifests. For more information about creating your own Chart catalog, check out the docs at https://helm.sh/docs/intro/quickstart/.","source":"@site/docs/add-ons/helm.md","sourceDirName":"add-ons","slug":"/add-ons/helm","permalink":"/add-ons/helm","draft":false,"unlisted":false,"editUrl":"https://github.com/k3s-io/docs/edit/main/docs/add-ons/helm.md","tags":[],"version":"current","lastUpdatedAt":1789781277000,"frontMatter":{"title":"Helm"},"sidebar":"mySidebar","previous":{"title":"Cluster Access","permalink":"/cluster-access"},"next":{"title":"Import Images","permalink":"/add-ons/import-images"}}');var r=s(74848),i=s(28453);const a={title:"Helm"},c=void 0,d={},l=[{value:"Using the Helm Controller",id:"using-the-helm-controller",level:2},{value:"HelmChart Field Definitions",id:"helmchart-field-definitions",level:3},{value:"Chart Values from Secrets",id:"chart-values-from-secrets",level:3},{value:"Customizing Packaged Components with HelmChartConfig",id:"customizing-packaged-components-with-helmchartconfig",level:2},{value:"HelmChartConfig Field Definitions",id:"helmchartconfig-field-definitions",level:3}];function o(e){const t={a:"a",admonition:"admonition",code:"code",h2:"h2",h3:"h3",li:"li",ol:"ol",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,i.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(t.p,{children:["Helm is the package management tool of choice for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, developers or cluster administrators can create configurable templates known as Charts, instead of just using static manifests. For more information about creating your own Chart catalog, check out the docs at ",(0,r.jsx)(t.a,{href:"https://helm.sh/docs/intro/quickstart/",children:"https://helm.sh/docs/intro/quickstart/"}),"."]}),"\n",(0,r.jsxs)(t.p,{children:["K3s does not require any special configuration to support Helm. Just be sure you have properly set the kubeconfig path as per the ",(0,r.jsx)(t.a,{href:"/cluster-access",children:"cluster access"})," documentation."]}),"\n",(0,r.jsxs)(t.p,{children:["K3s includes a ",(0,r.jsx)(t.a,{href:"https://github.com/k3s-io/helm-controller/",children:"Helm Controller"})," that manages installing, upgrading/reconfiguring, and uninstalling Helm charts using a HelmChart Custom Resource Definition (CRD). Paired with ",(0,r.jsx)(t.a,{href:"/installation/packaged-components",children:"auto-deploying AddOn manifests"}),", installing a Helm chart on your cluster can be automated by creating a single file on disk."]}),"\n",(0,r.jsx)(t.h2,{id:"using-the-helm-controller",children:"Using the Helm Controller"}),"\n",(0,r.jsxs)(t.p,{children:["The ",(0,r.jsx)(t.a,{href:"https://github.com/k3s-io/helm-controller#helm-controller",children:"HelmChart Custom Resource"})," captures most of the options you would normally pass to the ",(0,r.jsx)(t.code,{children:"helm"})," command-line tool."]}),"\n",(0,r.jsxs)(t.p,{children:["K3s also supports passing arguments directly to the ",(0,r.jsx)(t.code,{children:"helm-controller"})," process with ",(0,r.jsx)(t.code,{children:"helm-controller-arg"}),".\nThis is useful when you want to tune controller behavior globally."]}),"\n",(0,r.jsx)(t.p,{children:"For example, to customize the CPU and memory resources allocated to Helm job pods:"}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-yaml",children:'# /etc/rancher/k3s/config.yaml\nhelm-controller-arg:\n  - \'job-resources={"requests": {"cpu": "0.2", "memory": "64M"}, "limits": {"cpu": "1", "memory": "256M"}}\'\n'})}),"\n",(0,r.jsxs)(t.p,{children:["You can specify ",(0,r.jsx)(t.code,{children:"helm-controller-arg"})," multiple times in CLI form, or as a YAML list in the configuration file."]}),"\n",(0,r.jsx)(t.admonition,{title:"Version Gate",type:"info",children:(0,r.jsxs)(t.p,{children:["The  ",(0,r.jsx)(t.code,{children:"helm-controller-arg"})," flag is available since the K3s July 2026 releases: v1.36.3+k3s1, v1.35.7+k3s1, v1.34.10+k3s1, v1.33.13+k3s2"]})}),"\n",(0,r.jsx)(t.h3,{id:"helmchart-field-definitions",children:"HelmChart Field Definitions"}),"\n",(0,r.jsx)(t.admonition,{type:"note",children:(0,r.jsxs)(t.p,{children:["The ",(0,r.jsx)(t.code,{children:"name"})," field should follow the Helm chart naming conventions, in addition to Kubernetes rules for ",(0,r.jsx)(t.a,{href:"https://kubernetes.io/docs/concepts/
1overview/working-with-objects/names/",children:"object names and IDs"}),". Refer to the ",(0,r.jsx)(t.a,{href:"https://helm.sh/docs/chart_best_practices/conventions/#chart-names",children:"Helm Best Practices documentation"})," to learn more."]})}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Field"}),(0,r.jsx)(t.th,{children:"Default"}),(0,r.jsx)(t.th,{children:"Description"}),(0,r.jsx)(t.th,{children:"Helm Argument / Flag Equivalent"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"metadata.name"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Helm Chart name"}),(0,r.jsx)(t.td,{children:"NAME"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.chart"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Helm Chart name in repository, or complete HTTPS URL to chart archive (.tgz)"}),(0,r.jsx)(t.td,{children:"CHART"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.chartContent"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Base64-encoded chart archive .tgz - overrides spec.chart"}),(0,r.jsx)(t.td,{children:"CHART"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.targetNamespace"}),(0,r.jsx)(t.td,{children:"default"}),(0,r.jsx)(t.td,{children:"Helm Chart target namespace"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--namespace"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.createNamespace"}),(0,r.jsx)(t.td,{children:"false"}),(0,r.jsx)(t.td,{children:"Create target namespace if not present"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--create-namespace"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.version"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Helm Chart version (when installing from repository)"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--version"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.repo"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Helm Chart repository URL"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--repo"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.repoCA"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Verify certificates of HTTPS-enabled servers using this CA bundle. Should be a string containing one or more PEM-encoded CA Certificates."}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--ca-file"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.repoCAConfigMap"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Reference to a ConfigMap containing CA Certificates to be be trusted by Helm. Can be used along with or instead of ",(0,r.jsx)(t.code,{children:"repoCA"})]}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--ca-file"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.plainHTTP"}),(0,r.jsx)(t.td,{children:"false"}),(0,r.jsx)(t.td,{children:"Use insecure HTTP connections for the chart download."}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--plain-http"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.insecureSkipTLSVerify"}),(0,r.jsx)(t.td,{children:"false"}),(0,r.jsx)(t.td,{children:"Skip TLS certificate checks for the chart download."}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--insecure-skip-tls-verify"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.helmVersion"}),(0,r.jsx)(t.td,{children:"v3"}),(0,r.jsxs)(t.td,{children:["Helm version to use. Only ",(0,r.jsx)(t.code,{children:"v3"})," is currently supported."]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.bootstrap"}),(0,r.jsx)(t.td,{children:"false"}),(0,r.jsx)(t.td,{children:"Set to True if this chart is needed to bootstrap the cluster (Cloud Controller Manager, etc)"}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.jobImage"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Specify the image to use when installing the helm chart. E.g. rancher/klipper-helm",":v0",".3.0 ."]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.podSecurityContext"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Custom ",(0,r.jsx)(t.a,{href:"https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#podsecuritycontext-v1-core",children:(0,r.jsx)(t.code,{children:"v1.PodSecurityContext"})})," for the Helm job pod"]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.securityContext"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Custom ",(0,r.jsx)(t.a,{href:"https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#securitycontext-v1-core",children:(0,r.jsx)(t.code,{children:"v1.SecurityContext"})})," for the Helm job pod's containers"]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.backOffLimit"}),(0,r.jsx)(t.td,{children:"1000"}),(0,r.jsx)(t.td,{children:"Specify the number of retries before considering a job failed."}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.timeout"}),(0,r.jsx)(t.td,{children:"300s"}),(0,r.jsxs)(t.td,{children:["Timeout for Helm operations, as a ",(0,r.jsx)(t.a,{href:"https://pkg.go.dev/time#ParseDuration",children:"duration string"})," (",(0,r.jsx)(t.code,{children:"300s"}),", ",(0,r.jsx)(t.code,{children:"10m"}),", ",(0,r.jsx)(t.code,{children:"1h"}),", etc)"]}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--timeout"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.failurePolicy"}),(0,r.jsx)(t.td,{children:"reinstall"}),(0,r.jsxs)(t.td,{children:["Set to ",(0,r.jsx)(t.code,{children:"abort"})," which case the Helm operation is aborted, pending manual intervention by the operator."]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.authSecret"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Reference to Secret of type ",(0,r.jsx)(t.code,{children:"kubernetes.io/basic-auth"})," holding Basic auth credentials for the Chart repo."]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.authPassCredentials"}),(0,r.jsx)(t.td,{children:"false"}),(0,r.jsx)(t.td,{children:"Pass Basic auth credentials to all domains."}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--pass-credentials"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.dockerRegistrySecret"}),(0,r.jsx)(t.td,{}),(0,r.jsxs)(t.td,{children:["Reference to Secret of type ",(0,r.jsx)(t.code,{children:"kubernetes.io/dockerconfigjson"})," holding Docker auth credentials for the OCI-based registry acting as the Chart repo."]}),(0,r.jsx)(t.td,{})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.set"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Override simple Chart values. These take precedence over options set via valuesContent."}),(0,r.jsxs)(t.td,{children:[(0,r.jsx)(t.code,{children:"--set"})," / ",(0,r.jsx)(t.code,{children:"--set-string"})]})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.valuesContent"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Override complex Chart values via inline YAML content"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--values"})})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.valuesSecrets"}),(0,r.jsx)(t.td,{}),(0,r.jsx)(t.td,{children:"Override complex Chart values via references to external Secrets"}),(0,r.jsx)(t.td,{children:(0,r.jsx)(t.code,{children:"--values"})})]})]})]}),"\n",(0,r.jsxs)(t.p,{children:["Content placed in ",(0,r.jsx)(t.code,{children:"/var/lib/rancher/k3s/server/static/"})," can be accessed anonymously via the Kubernetes APIServer from within the cluster.\nThis URL can be templated using the special variable ",(0,r.jsx)(t.code,{children:"%{KUBERNETES_API}%"})," in the ",(0,r.jsx)(t.code,{children:"spec.chart"})," field.\nFor example, the packaged Traefik component loads its chart from ",(0,r.jsx)(t.code,{children:"https://%{KUBERNETES_API}%/static/charts/traefik-VERSION.tgz"}),"."]}),"\n",(0,r.jsx)(t.p,{children:"Chart values are used in the following order, from least to greatest precedence:"}),"\n",(0,r.jsxs)(t.ol,{children:["\n",(0,r.jsx)(t.li,{children:"Chart default values"}),"\n",(0,r.jsxs)(t.li,{children:["HelmChart ",(0,r.jsx)(t.code,{children:"spec.valuesContent"})]}),"\n",(0,r.jsxs)(t.li,{children:["HelmChart ",(0,r.jsx)(t.code,{children:"spec.valuesSecrets"})," in listed order of secret name and keys"]}),"\n",(0,r.jsxs)(t.li,{children:["HelmChartConfig ",(0,r.jsx)(t.code,{children:"spec.valuesContent"})]}),"\n",(0,r.jsxs)(t.li,{children:["HelmChartConfig ",(0,r.jsx)(t.code,{children:"spec.valuesSecrets"})," in listed order of secret name and keys"]}),"\n",(0,r.jsxs)(t.li,{children:["HelmChart ",(0,r.jsx)(t.code,{children:"spec.set"})]}),"\n"]}),"\n",(0,r.jsxs)(t.p,{children:["Here's an example of how you might deploy Apache from the Bitnami chart repository, overriding some of the default chart values. Note that the HelmChart resource itself is in the ",(0,r.jsx)(t.code,{children:"kube-system"}
1)," namespace, but the chart's resources will be deployed to the ",(0,r.jsx)(t.code,{children:"web"})," namespace, which is created in the same manifest. This can be useful if you want to keep your HelmChart resources separated from the resources they deploy."]}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-yaml",children:"apiVersion: v1\nkind: Namespace\nmetadata:\n  name: web\n---\napiVersion: helm.cattle.io/v1\nkind: HelmChart\nmetadata:\n  name: apache\n  namespace: kube-system\nspec:\n  repo: https://charts.bitnami.com/bitnami\n  chart: apache\n  targetNamespace: web\n  valuesContent: |-\n    service:\n      type: ClusterIP\n    ingress:\n      enabled: true\n      hostname: www.example.com\n    metrics:\n      enabled: true\n"})}),"\n",(0,r.jsx)(t.p,{children:"An example of deploying a helm chart from a private repo with authentication:"}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-yaml",children:"apiVersion: helm.cattle.io/v1\nkind: HelmChart\nmetadata:\n  namespace: kube-system\n  name: example-app\nspec:\n  targetNamespace: example-namespace\n  createNamespace: true\n  version: v1.2.3\n  chart: example-app\n  repo: https://secure-repo.example.com\n  authSecret:\n    name: example-repo-auth\n  repoCAConfigMap:\n    name: example-repo-ca\n  valuesContent: |-\n    image:\n      tag: v1.2.2\n---\napiVersion: v1\nkind: Secret\nmetadata:\n  namespace: kube-system\n  name: example-repo-auth\ntype: kubernetes.io/basic-auth\nstringData:\n  username: user\n  password: pass\n---\napiVersion: v1\nkind: ConfigMap\nmetadata:\n  namespace: kube-system\n  name: example-repo-ca\ndata:\n  ca.crt: |-\n    -----BEGIN CERTIFICATE-----\n    <YOUR CERTIFICATE>\n    -----END CERTIFICATE-----\n"})}),"\n",(0,r.jsx)(t.h3,{id:"chart-values-from-secrets",children:"Chart Values from Secrets"}),"\n",(0,r.jsxs)(t.p,{children:["Chart values can be read from externally-managed Secrets, instead of storing the values in the ",(0,r.jsx)(t.code,{children:"spec.set"})," or ",(0,r.jsx)(t.code,{children:"spec.valuesContent"})," fields.\nThis should be done when passing confidential information such as credentials in to Charts that do not support referring to existing Secrets via the ",(0,r.jsx)(t.code,{children:"existingSecret"})," pattern."]}),"\n",(0,r.jsxs)(t.p,{children:["As with other Secrets (",(0,r.jsx)(t.code,{children:"spec.authSecret"})," and ",(0,r.jsx)(t.code,{children:"spec.dockerRegistrySecret"}),"), Secrets referenced in ",(0,r.jsx)(t.code,{children:"spec.valuesSecrets"})," must be in the same namespace as the HelmChart."]}),"\n",(0,r.jsxs)(t.p,{children:["Each listed ",(0,r.jsx)(t.code,{children:"valuesSecrets"})," entry has the following fields:"]}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Field"}),(0,r.jsx)(t.th,{children:"Description"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"name"}),(0,r.jsx)(t.td,{children:"The name of the Secret. Required."})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"keys"}),(0,r.jsx)(t.td,{children:"List of keys to read values from, values are used in the listed order. Required."})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"ignoreUpdates"}),(0,r.jsxs)(t.td,{children:["Mark this Secret as optional, and do not update the chart if the Secret changes. Optional, defaults to ",(0,r.jsx)(t.code,{children:"false"}),"."]})]})]})]}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsxs)(t.li,{children:["If ",(0,r.jsx)(t.code,{children:"ignoreUpdates"})," is set to ",(0,r.jsx)(t.code,{children:"false"})," or unspecified, the Secret and all listed keys must exist. Any change to a referenced values Secret will cause the chart to be updated with new values."]}),"\n",(0,r.jsxs)(t.li,{children:["If ",(0,r.jsx)(t.code,{children:"ignoreUpdates"})," is set to ",(0,r.jsx)(t.code,{children:"true"}),", the Secret is used if it exists when the Chart is created, or updated due to any other change to related resources. Changes to the Secret will not cause the chart to be updated."]}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"An example of deploying a helm chart using an existing Secret with two keys:"}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-yaml",children:"apiVersion: helm.cattle.io/v1\nkind: HelmChart\nmetadata:\n  namespace: kube-system\n  name: example-app\nspec:\n  targetNamespace: example-namespace\n  createNamespace: true\n  version: v1.2.3\n  chart: example-app\n  repo: https://repo.example.com\n  valuesContent: |-\n    image:\n      tag: v1.2.2\n  valuesSecrets:\n    - name: example-app-custom-values\n      ignoreUpdates: false\n      keys:\n        - someValues\n        - moreValues\n---\napiVersion: v1\nkind: Secret\nmetadata:\n  namespace: kube-system\n  name: example-app-custom-values\nstringData:\n  moreValues: |-\n    database:\n      address: db.example.com\n      username: user\n      password: pass\n  someValues: |-\n    adminUser:\n      create: true\n      username: admin\n      password: secret\n"})}),"\n",(0,r.jsx)(t.h2,{id:"customizing-packaged-components-with-helmchartconfig",children:"Customizing Packaged Components with HelmChartConfig"}),"\n",(0,r.jsxs)(t.p,{children:["To allow overriding values for packaged components that are deployed as HelmCharts (such as Traefik), K3s supports customizing deployments via a HelmChartConfig resources. The HelmChartConfig resource must match the name and namespace of its corresponding HelmChart, and it supports providing additional ",(0,r.jsx)(t.code,{children:"valuesContent"}),", which is passed to the ",(0,r.jsx)(t.code,{children:"helm"})," command as an additional value file."]}),"\n",(0,r.jsx)(t.h3,{id:"helmchartconfig-field-definitions",children:"HelmChartConfig Field Definitions"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Field"}),(0,r.jsx)(t.th,{children:"Description"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"metadata.name"}),(0,r.jsx)(t.td,{children:"Helm Chart name - must match the HelmChart resource name."})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.valuesContent"}),(0,r.jsx)(t.td,{children:"Override complex default Chart values via YAML file content."})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.valuesSecrets"}),(0,r.jsx)(t.td,{children:"Override complect default Chart values via external Secrets."})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"spec.failurePolicy"}),(0,r.jsxs)(t.td,{children:["Set to ",(0,r.jsx)(t.code,{children:"abort"})," which case the Helm operation is aborted, pending manual intervention by the operator."]})]})]})]}),"\n",(0,r.jsx)(t.admonition,{type:"note",children:(0,r.jsxs)(t.p,{children:["HelmChart ",(0,r.jsx)(t.code,{children:"spec.set"})," values override HelmChart and HelmChartConfig ",(0,r.jsx)(t.code,{children:"spec.valuesContent"})," and ",(0,r.jsx)(t.code,{children:"spec.valuesSecrets"}
1)," settings, as described above."]})}),"\n",(0,r.jsxs)(t.p,{children:["For example, to customize the packaged Traefik ingress configuration, you can create a file named ",(0,r.jsx)(t.code,{children:"/var/lib/rancher/k3s/server/manifests/traefik-config.yaml"})," and populate it with the following content:"]}),"\n",(0,r.jsx)(t.pre,{children:(0,r.jsx)(t.code,{className:"language-yaml",children:"apiVersion: helm.cattle.io/v1\nkind: HelmChartConfig\nmetadata:\n  name: traefik\n  namespace: kube-system\nspec:\n  valuesContent: |-\n    image:\n      repository: docker.io/library/traefik\n      tag: 3.3.5\n    ports:\n      web:\n        forwardedHeaders:\n          trustedIPs:\n            - 10.0.0.0/8\n"})})]})}function h(e={}){const{wrapper:t}={...(0,i.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(o,{...e})}):o(e)}},28453:(e,t,s)=>{s.d(t,{R:()=>a,x:()=>c});var n=s(96540);const r={},i=n.createContext(r);function a(e){const t=n.useContext(i);return n.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function c(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:a(e.components),n.createElement(i.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.