🎯 課程目標
了解 Helm 4 作為 Kubernetes 的套件管理器、圖表結構、如何安裝/升級/回滾、新的 Helm 4 功能(WASM、伺服器端應用)以及何時使用 Kustomize 而不是 Helm。
1.什麼是頭盔?
頭盔是 Kubernetes 的套件管理器 — 類似 Ubuntu 的 apt、macOS 的 brew。 Helm 將 Kubernetes 資源打包成可以共享、版本化和參數化的「圖表」。
好處:
- 將複雜的應用程式(許多資源)打包到 1 個單元中
- 透過values.yaml進行參數化
- 發布歷史和回滾
- 依賴管理
- 生態系:數千個社區圖表(工件中心)
2. Helm 4-2025 年 11 月(10 週年)
Helm 3 的重大變化:
- WebAssembly (WASM) 插件:插件編譯為 WASM,跨作業系統移植,沙盒執行
- 伺服器端應用程式 (SSA):使用 K8s SSA 取代客戶端合併 — 解決欄位所有權衝突
- 60% 性能提升:尤其是大型圖表(1000+ 資源)
- OCI 增強功能:多架構圖表、出處、證明
- 內建舵差速器:升級前查看差異
- Helm 3 將繼續接收安全修復,直至 2026 年 11 月
3. Helm Chart 結構
myapp/
├── Chart.yaml # chart metadata
├── values.yaml # default configuration values
├── values.schema.json # JSON Schema validation cho values (optional)
├── charts/ # chart dependencies
│ └── postgresql/ # embedded dependency
├── templates/ # Kubernetes manifest templates
│ ├── _helpers.tpl # named templates, shared logic
│ ├── deployment.yaml
│ ├── service.yaml
│ ├── ingress.yaml
│ └── NOTES.txt # hiển thị sau install
└── .helmignore # ignore files khi đóng gói
# Chart.yaml
apiVersion: v2
name: myapp
description: My Application Helm Chart
type: application
version: 0.2.0 # chart version (SemVer)
appVersion: "1.2.3" # version của app được đóng gói
dependencies:
- name: postgresql
version: "15.5.x"
repository: "https://charts.bitnami.com/bitnami"
condition: postgresql.enabled
4.values.yaml和模板
# values.yaml replicaCount: 3 image: repository: myregistry.io/myapp tag: "1.2.3" pullPolicy: Alwaysservice: type: ClusterIP port: 80
resources: requests: cpu: "100m" memory: "128Mi" limits: cpu: "500m" memory: "256Mi"
postgresql: enabled: true auth: database: myapp
# templates/deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "myapp.fullname" . }}
labels:
{{- include "myapp.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "myapp.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "myapp.selectorLabels" . | nindent 8 }}
spec:
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
resources:
{{- toYaml .Values.resources | nindent 10 }}
5. 頭盔命令
# Thêm repository helm repo add stable https://charts.helm.sh/stable helm repo add bitnami https://charts.bitnami.com/bitnami helm repo updateTìm kiếm chart
helm search repo nginx helm search hub postgresql # tìm trên Artifact Hub
Install
helm install my-nginx bitnami/nginx -n production helm install my-nginx bitnami/nginx
--namespace production
--create-namespace
--set replicaCount=3
--values custom-values.yamlXem installed releases
helm list -n production helm list --all-namespaces
Upgrade
helm upgrade my-nginx bitnami/nginx
--namespace production
--set image.tag=1.28Helm 4: xem diff trước khi upgrade (built-in)
helm diff upgrade my-nginx bitnami/nginx --set image.tag=1.28 -n production
Rollback
helm rollback my-nginx 1 -n production # rollback về revision 1 helm history my-nginx -n production # xem revision history
Uninstall
helm uninstall my-nginx -n production
Dry run
helm install my-nginx bitnami/nginx --dry-run --debug
6.OCI 註冊表
# Helm 4: OCI registry là first-class citizen # Đăng nhập registry helm registry login myregistry.io --username myuserPush chart lên OCI registry
helm package ./myapp # tạo myapp-0.2.0.tgz helm push myapp-0.2.0.tgz oci://myregistry.io/helm-charts
Pull và install từ OCI
helm install my-release oci://myregistry.io/helm-charts/myapp --version 0.2.0
Không cần helm repo add với OCI!
7. 頭盔掛鉤
# templates/db-migration.yaml
apiVersion: batch/v1
kind: Job
metadata:
name: "{{ .Release.Name }}-db-migration"
annotations:
"helm.sh/hook": pre-upgrade,pre-install # chạy TRƯỚC khi install/upgrade
"helm.sh/hook-weight": "-5" # thứ tự (nhỏ hơn chạy trước)
"helm.sh/hook-delete-policy": hook-succeeded # xóa job sau khi thành công
spec:
template:
spec:
restartPolicy: Never
containers:
- name: migration
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
command: ["python", "manage.py", "migrate"]
Helm hooks 可用於:資料庫遷移(安裝前)、冒煙測試(安裝後)、備份(刪除前)。
8. 頭盔測試
# templates/tests/test-connection.yaml
apiVersion: v1
kind: Pod
metadata:
name: "{{ .Release.Name }}-test-connection"
annotations:
"helm.sh/hook": test
spec:
restartPolicy: Never
containers:
- name: test
image: busybox:1.36
command: ['wget', '--spider', 'http://{{ include "myapp.fullname" . }}:{{ .Values.service.port }}']
helm test my-nginx -n production
# Pod "my-nginx-test-connection" created
# Pod "my-nginx-test-connection" succeeded
# Tests succeeded!
9.Helmfile-管理多個版本
# helmfile.yaml
repositories:
- name: bitnami
url: https://charts.bitnami.com/bitnami
- name: grafana
url: https://grafana.github.io/helm-charts
environments:
staging:
values:
- environments/staging.yaml
production:
values:
- environments/production.yaml
releases:
-
name: postgresql namespace: database chart: bitnami/postgresql version: "15.5.x" values:
- postgresql-values.yaml
-
name: monitoring namespace: monitoring chart: prometheus-community/kube-prometheus-stack values:
- monitoring-values.yaml
name: myapp namespace: production chart: ./myapp needs:
- database/postgresql # deploy sau postgresql values:
- myapp-values.yaml
"{{ .Environment.Name }}-values.yaml"
helmfile apply # deploy tất cả
helmfile sync -e production # sync trong environment production
helmfile diff # xem sự khác biệt
helmfile destroy # uninstall tất cả
10.Helm 與 Kustomize
- 何時使用 Helm:將圖表分發給其他用戶,需要複雜的參數化,需要依賴管理,生態系統圖表(bitnami,社群)
- 使用 Kustomize 時:簡單覆蓋(dev/staging/prod)、內建 kubectl(無需額外安裝)、GitOps 工作流程、無範本的 YAML 補丁
# Kustomize: không cần cài thêm kubectl apply -k ./overlays/productionHoặc xem output mà không apply
kubectl kustomize ./overlays/production
總結
- Helm 4(2025 年 11 月):WASM 外掛程式、SSA、60% 效能、內建 diff
- 圖表結構:Chart.yaml、values.yaml、templates/
- OCI 註冊表:一流的支持,無需額外的存儲庫
- 掛鉤:生命週期操作的安裝前/安裝後/升級/刪除
- Helmfile:編排多個 Helm 版本
- Helm 與 Kustomize:Helm 用於分發,Kustomize 用於簡單覆蓋