Sign inSign up

tcwlab/helm

By tcwlab

•Updated 4 months ago

Image
0

5.0K

tcwlab/helm repository overview

⁠tcwlab/helm

Pinned Helm⁠ CLI in a hardened Alpine container for reproducible Kubernetes pipelines. Image tag = Helm version. Drop-in for Forgejo/GitHub Actions container jobs that need deterministic toolchain versions.

Docker Pulls Image Size License


⁠Quick start

docker pull tcwlab/helm:latest

# Run against the current directory
docker run --rm -v "$PWD:/workspace" tcwlab/helm:latest version

Or as a Forgejo / GitHub Actions container job:

helm-lint:
  runs-on: ubuntu-22.04
  container:
    image: tcwlab/helm:latest
  steps:
    - name: Checkout (shell-based, no Node required)
      env:
        GITHUB_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
      run: |
        git config --global init.defaultBranch main
        git init .
        git remote add origin \
          "https://oauth2:${GITHUB_TOKEN}@git.mon.k8b.co/${GITHUB_REPOSITORY}.git"
        git fetch --depth=1 origin "${GITHUB_SHA}"
        git checkout FETCH_HEAD
    - run: helm lint ./chart

Quick-start examples use :latest so you can try the image immediately. For production CI pipelines, pin a concrete tag — see Tags⁠ below.


⁠Tags

Version numbers below are illustrative. For the current set of tags, see Docker Hub tags⁠.

TagDescription
3.20.2, 3.20, 3Concrete SemVer (recommended for production pipelines)
latestRolling reference; always points at the newest release

Always pin a concrete version in production. latest is fine for local experiments, but pinning protects your pipeline from a toolchain bump that lands without a PR. The major/minor floating tags (3, 3.20) are convenient for internal use; external consumers should pin the full SemVer.

The helm image tag mirrors the Helm CLI version exactly. When Helm 3.20.2 is released, tcwlab/helm:3.20.2 contains that exact version (not a wrapper SemVer).


⁠Supported architectures

  • linux/amd64
  • linux/arm64

Every tag is a multi-arch manifest list. Docker pulls the right architecture automatically.


⁠What's included

ToolVersionPurpose
helm⁠3.20.2Kubernetes package manager
curlfrom Alpine 3.23 apkDownload support
tarfrom Alpine 3.23 apkArchive extraction
gitfrom Alpine 3.23 apkHelm chart repos via git
bashfrom Alpine 3.23 apkShell compatibility
ca-certificatesfrom Alpine 3.23 apkTLS/SSL certificate validation

Base image: alpine:3.23. Default workdir: /workspace. Default user: helmusr (non-root). Helm cache/config directories pre-created under /home/helmusr/.config/helm, /home/helmusr/.cache/helm, and /home/helmusr/.local/share/helm.


⁠Usage

⁠Lint a chart
docker run --rm -v "$PWD:/workspace" tcwlab/helm:3.20.2 lint ./chart
⁠Render templates (smoke test)
docker run --rm -v "$PWD:/workspace" tcwlab/helm:3.20.2 \
  template ./chart --debug
⁠Use against a cluster

To talk to a real cluster, mount your kubeconfig:

docker run --rm \
  -v "$PWD:/workspace" \
  -v "$HOME/.kube:/home/helmusr/.kube:ro" \
  tcwlab/helm:3.20.2 \
  list -A
⁠Forgejo workflow — full snippet
helm-lint:
  name: Helm Lint
  runs-on: ubuntu-22.04
  container:
    image: tcwlab/helm:3.20.2
  steps:
    - name: Checkout
      env:
        GITHUB_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
      run: |
        git config --global init.defaultBranch main
        git init .
        git remote add origin \
          "https://oauth2:${GITHUB_TOKEN}@git.mon.k8b.co/${GITHUB_REPOSITORY}.git"
        git fetch --depth=1 origin "${GITHUB_SHA}"
        git checkout FETCH_HEAD
    - name: helm lint
      run: helm lint ./chart
    - name: helm template (smoke test)
      run: helm template ./chart --debug | head -40

⁠Configuration

⁠Volume mount points
PathPurpose
/workspaceDefault workdir; mount your chart repo here
/home/helmusr/.kubeMount kubeconfig (read-only) to talk to a cluster
/home/helmusr/.cache/helmHelm dependency cache (mount to persist between runs)
⁠Environment variables

The image passes all environment variables directly to Helm. Common patterns:

VariableExamplePurpose
HELM_KUBECONTEXTproductionUse a specific kube context
HELM_NAMESPACEauthDefault namespace
HELM_DEBUGtrueVerbose debug output
KUBECONFIG/home/helmusr/.kube/configPath to the kubeconfig file
⁠Working directory

The image runs with WORKDIR /workspace. If your chart is in a subdirectory, use:

- run: |
    cd ./charts/my-wrapper
    helm lint .
    helm template .

⁠Why tcwlab/helm and not upstream images?

Pinning discipline. Public Helm images (Docker Hub, GHCR) often use latest or floating major versions, which means your CI toolchain can silently advance to a new Helm version without a PR. tcwlab/helm enforces the principle that every tool version is explicit — the image tag is the version, and upgrades happen via PR.

Additional benefits:

  • Deterministic builds — same tag always pulls the exact Helm version (no surprises).
  • Consistent Alpine base — all tcwlab images use Alpine 3.23, minimal and hardened identically.
  • Multi-arch by default — linux/amd64 and linux/arm64 in every release.
  • Security scanning — each build is scanned with Trivy before publication.

⁠Source, issues, contributing


⁠Build, supply chain

Every release is built and published by the repo's own .forgejo/workflows/ci.yml⁠ on a Forgejo runner:

  • Multi-arch build (linux/amd64, linux/arm64) via docker buildx with --sbom=true --provenance=mode=max.
  • Trivy vulnerability scan on HIGH/CRITICAL severity (failures show up as PR comments).
  • Self-lint via betterlint running against the Dockerfile.

The helm image version is cut by semantic-release from Conventional Commits on main. The version exactly mirrors the Helm CLI version (e.g., release of Helm 3.20.2 triggers a new tcwlab/helm:3.20.2 image).


⁠License

Apache License 2.0. See LICENSE⁠ for the full text.

Helm itself is licensed under Apache 2.0. See helm/helm⁠ for details.

Tag summary

Content type

Image

Digest

sha256:552d1b1a1…

Size

30.4 MB

Last updated

4 months ago

docker pull tcwlab/helm