Kubernetes & Helm Workflow
Apply consistent Helm patterns for test and production Kubernetes environments.
Use this skill when
- Update Helm values files
- Add or change environment variables
- Configure resources, probes, ingress, security, jobs, or cronjobs
- Work with Kubernetes secrets, namespaces, pods, and environment URLs
Follow this workflow
- Locate the target chart in
kubernetes/helm/and edit bothvalues.test.yamlandvalues.prod.yamlunless the change is environment-specific. - Add non-sensitive variables under
extraEnvVarswith directvalue; keep entries alphabetically sorted. - Add sensitive variables with
valueFrom.secretKeyRef; never inline secrets in values files. - Define hook/job secrets through the chart values key
hooks.secretName(invalues.*.yaml), then consume it in hook templates (for example migration/sync jobs). - If the repository uses local env files, mirror new variables in
.env.exampleand.envwith safe placeholder defaults. - Check chart-specific secret naming and namespace conventions before deploying.
- Use
k8s-toolfor runtime checks only after prerequisites are met:k8s-toolis a project wrapper aroundkubectlwith environment shortcuts, and requires an installed CLI plus valid kubeconfig/cluster access.
Reference material
Read concrete snippets and YAML examples in:
references/chart-structure.mdreferences/helm-examples.md
Key Rules
- Keep extraEnvVars alphabetically sorted
- Never commit secrets - use K8s secrets with
secretKeyRef - Test values are conservative - lower resources than prod
- Use appropriate probe paths -
/api/alivefor liveness,/api/healthfor readiness - CronJobs need
concurrencyPolicy: Forbidto prevent overlapping