helm - The Kubernetes package manager (Helm 4)
helm COMMAND [RELEASE] [CHART] [flags]
Options you will use
install NAME CHART [-f values.yaml] [--set k=v] [-n NS] [--create-namespace] [--wait] [--rollback-on-failure] [--timeout 5m]- Render the chart and create the release (revision 1). Fails with "cannot reuse a name that is still in use" if the release exists.
upgrade NAME CHART [-i] [--reuse-values|--reset-values|--reset-then-reuse-values] [--wait] [--rollback-on-failure] [--history-max N]- New revision. Values = chart defaults + THIS command's -f/--set, unless you ask to reuse the old ones. -i installs if absent.
rollback NAME [REVISION] [--wait]- Re-apply an old revision's manifest as a NEW revision ("Rollback to N"). Without REVISION: the previous one.
uninstall NAME [--keep-history] [--cascade orphan]- Delete the release's resources (not those annotated helm.sh/resource-policy: keep) and its history.
list [-A] [-a] [--pending] [--failed] [-q] [-o json]- Releases in the namespace. Helm 4 shows every status by default.
history NAME [--max N] [-o json]- Every revision with status and description: the first place to look when a release is stuck.
status NAME [--revision N]- Status, revision, description and NOTES.
get values|manifest|notes|hooks|all NAME [--all] [--revision N]- What was actually deployed. get values = user-supplied only; --all = computed (merged) values.
template [NAME] CHART [-f] [--set] [-s templates/x.yaml] [--debug] [--output-dir DIR]- Render locally. No cluster, lookup returns {}. The fastest way to debug a chart.
lint CHART [--strict] [-f values.yaml]- Chart.yaml, values and every rendered template. [ERROR] fails, [WARNING] fails only with --strict.
create NAME / package DIR / dependency update|build|list DIR- Scaffold, archive (.tgz), and vendor subcharts into charts/ (+ Chart.lock).
repo add NAME URL / repo update / search repo KEYWORD / show values CHART / pull CHART [--untar]- Chart repositories.
registry login HOST / push CHART.tgz oci://HOST/PATH / install NAME oci://HOST/PATH/CHART --version V- OCI registries (the modern way to publish charts).
diff upgrade NAME CHART [-f] [--set] [--three-way-merge] [--detailed-exitcode] (plugin)- What an upgrade would change, per resource. --detailed-exitcode returns 2 when there are changes (CI gate).
test NAME [--logs]- Run the chart's test hooks (helm.sh/hook: test).
--dry-run=client|server / --debug- Render and validate without persisting; --debug also prints computed values.
-n, --namespace NS- Namespace scope for this request (the release lives in it). Default: the kubeconfig context's namespace.
--kube-context CONTEXT- Name of the kubeconfig context to use.
--kubeconfig FILE- Path to the kubeconfig file.
--debug- Enable verbose output (for template: print the rendered YAML even when it is invalid).
--kube-as-user USER- Username to impersonate for the operation.
--registry-config FILE- Path to the registry config file.
--repository-config FILE- Path to the file containing repository names and URLs.
--repository-cache DIR- Path to the directory containing cached repository indexes.
--burst-limit INT- Client-side default throttling limit (default 100).
--qps FLOAT- Queries per second used when communicating with the Kubernetes API, not including bursting.
Examples
$ helm template shop ./shop -f values-prod.yaml -s templates/deployment.yamlsee exactly what one template renders to
$ helm upgrade --install shop ./shop -n shop -f values.yaml --wait --timeout 3midempotent deploy that fails if pods do not become ready
$ helm history shop -n shopfind the stuck pending-upgrade revision
$ helm get values shop -n shop --allthe values that were really used
$ helm diff upgrade shop ./shop -f values.yamlreview before you upgrade
Gotchas
- Values precedence, lowest to highest: chart values.yaml < parent chart's section for a subchart < -f files in order < --set-json < --set < --set-string < --set-file < --set-literal (by kind; within a kind, left to right). null deletes a key.
- Numbers in values.yaml are float64: 1234567 renders as 1.234567e+06 unless piped through toYaml/int, and a tag like 1.10 becomes 1.1. Quote versions.
- Releases live in Secrets sh.helm.release.v1.NAME.vN in the release namespace (owner=helm). A killed helm leaves the last one pending-*: "another operation (install/upgrade/rollback) is in progress".
- Helm 4: --atomic is now --rollback-on-failure, --force is --force-replace; --wait with no value uses the kstatus watcher; new installs use server-side apply.
Try helm in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.