<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blog on Helm</title><link>https://v3-1-0.helm.sh/blog/</link><description>Recent content in Blog on Helm</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 03 Apr 2020 00:00:00 +0000</lastBuildDate><atom:link href="https://v3-1-0.helm.sh/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>COVID-19: Extending Helm v2 Bug Fixes</title><link>https://v3-1-0.helm.sh/blog/covid-19-extending-helm-v2-bug-fixes/</link><pubDate>Fri, 03 Apr 2020 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/covid-19-extending-helm-v2-bug-fixes/</guid><description>As our world comes together to fight the global pandemic, the Helm maintainers want to ensure that we&amp;rsquo;re doing our part to help you maintain your critical systems while they are operating at peak demand in a time where normal development and operation schedules have had to be adjusted.
When Helm v3 was released in November 2019, our original commitment was that we would offer six months of Helm v2 bug fixes, which would end May 13, 2020, followed by six more months of security fixes for Helm v2.</description></item><item><title>Helm at KubeCon + CloudNativeCon NA 2019</title><link>https://v3-1-0.helm.sh/blog/2019-11-15-helm-at-cloudnativecon/</link><pubDate>Fri, 15 Nov 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/2019-11-15-helm-at-cloudnativecon/</guid><description>Next week is the annual KubeCon and CloudNativeCon in North America. The Helm project and maintainers have several things going on and we wanted to invite you to them.
Helm will have two maintainer track sessions that focus on an Introduction to Helm and a Helm 3 Deep Dive. Anyone who is new to Helm or would be interested in learning how and why they should use Helm, please consider attending the Introduction to Helm.</description></item><item><title>Helm 3.0.0 has been released!</title><link>https://v3-1-0.helm.sh/blog/helm-3-released/</link><pubDate>Wed, 13 Nov 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-released/</guid><description>The Helm Team is proud to announce the first stable release of Helm 3.
Helm 3 is the latest major release of the CLI tool. Helm 3 builds upon the success of Helm 2, continuing to meet the needs of the evolving ecosystem.
The internal implementation of Helm 3 has changed considerably from Helm 2. The most apparent change is the removal of Tiller, but it&amp;rsquo;s worth checking out the other changes by diving into the new release.</description></item><item><title>Helm Community Management</title><link>https://v3-1-0.helm.sh/blog/2019-11-11-community-management/</link><pubDate>Mon, 11 Nov 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/2019-11-11-community-management/</guid><description>Devstats and stats on GitHub are able to capture many different types of contributions to an open source project. But there is one type of contribution for which we have yet to figure out a good metric, and it has been essential for Helm&amp;rsquo;s success. That is community management.
Karen Chu has handled community management for Helm since the project was first announced at the inaugural KubeCon in San Francisco.</description></item><item><title>Helm Security Audit Results</title><link>https://v3-1-0.helm.sh/blog/2019-11-04-helm-security-audit-results/</link><pubDate>Mon, 04 Nov 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/2019-11-04-helm-security-audit-results/</guid><description>Today, the Helm Maintainers are proud to announce that we have successfully completed a 3rd party security audit for Helm 3. Helm has been recommended for public deployment.
A security audit is part of the graduation criteria for CNCF projects. Specifically, the graduation criteria says:
Have completed an independent and third party security audit with results published of similar scope and quality as the following example (including critical vulnerabilities addressed): https://github.</description></item><item><title>Helm Vulnerability: Client Loading and Packaging Chart Directory Containing Malicious Symlinked Content [CVE-2019-18658]</title><link>https://v3-1-0.helm.sh/blog/2019-10-30-helm-symlink-security-notice/</link><pubDate>Wed, 30 Oct 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/2019-10-30-helm-symlink-security-notice/</guid><description>Part of the process for Helm to become a graduated CNCF project is to complete an independent and third party security audit with the results being published. As part of the audit of Helm 3 a security issue was found that also impacts Helm v2. Cure53 performed the audit and found the issue. More about the audit will be covered in a future post.
The vulnerability found impacts all versions of Helm between Helm &amp;gt;=2.</description></item><item><title>Helm 2.15.0 Released</title><link>https://v3-1-0.helm.sh/blog/2019-10-22-helm-2150-released/</link><pubDate>Tue, 22 Oct 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/2019-10-22-helm-2150-released/</guid><description>Helm 2.15.0 was released last week. The 2.15.0 release of Helm introduces several improvements to helm test. Several commands - helm search, helm repo list, and helm install - received the --output flag for machine-readable output.
In addition to these new features (and many more!), many bugs and edge cases in Helm continue to fixed by members of the community. Several parts of the codebase have been refactored for easier maintainability, usability, and better testing.</description></item><item><title>How to migrate from Helm v2 to Helm v3</title><link>https://v3-1-0.helm.sh/blog/migrate-from-helm-v2-to-helm-v3/</link><pubDate>Wed, 11 Sep 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/migrate-from-helm-v2-to-helm-v3/</guid><description>One of the most important parts of upgrading to a new major release of Helm is the migration of data. This is especially true of Helm v2 to v3 considering the architectural changes between the releases. This is where the helm-2to3 plugin comes in.
It helps with this migration by supporting:
Migration of Helm v2 configuration. Migration of Helm v2 releases. Clean up Helm v2 configuration, release data and Tiller deployment.</description></item><item><title>Helm v3 Beta 1 Released</title><link>https://v3-1-0.helm.sh/blog/helm-v3-beta/</link><pubDate>Tue, 27 Aug 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-v3-beta/</guid><description>Helm v3 development has hit a new milestone with the release of the first beta. This is an especially important milestone because it is the end of the effort to refactor Helm v3. The last of the intended breaking changes has landed. From this point on, Helm v3 is focused on bug fixes, stability, and preparing it for a stable release.
If you are interested in Helm v3 now is a great time to test it out.</description></item><item><title>Announcing get.helm.sh</title><link>https://v3-1-0.helm.sh/blog/get-helm-sh/</link><pubDate>Mon, 10 Jun 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/get-helm-sh/</guid><description>The Helm Client has long been available to download from Google Cloud Storage at the bucket https://kubernetes-helm.storage.googleapis.com. This bucket in Google Cloud has been used by Helm since before Kubernetes was part of the CNCF. The first release hosted on this bucket was Helm v2.0.0-alpha.5!
Google has long been gracious in providing funding for this location. Since Helm started using it, Helm (as part of Kubernetes) moved into the CNCF, and then moved out from under the Kubernetes umbrella, becoming a sister project to Kubernetes within the CNCF.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 7: What's Next?</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt7/</link><pubDate>Mon, 13 May 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt7/</guid><description>This is the seventh and final part of our Helm 3 Preview: Charting Our Future blog series. Read our previous blog post on library charts here.
Helm 3.0.0-alpha.1 is the foundation upon which we&amp;rsquo;ll begin to build the next version of Helm. The features shared over the last few weeks were some of the big promises we made for Helm 3. Many of those features are still in their early stages and that is OK; the idea of an alpha release is to test out an idea, gather feedback from early adopters, and validate those assumptions.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 6: Introducing Library Charts</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt6/</link><pubDate>Thu, 09 May 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt6/</guid><description>This is part 6 of 7 of our Helm 3 Preview: Charting Our Future blog series on library charts. You can find our previous blog post on the Helm chart dependencies here.
Helm 3 supports a class of chart called a &amp;ldquo;library chart&amp;rdquo;. This is a chart that is shared by other charts, but does not create any release artifacts of its own. A library chart&amp;rsquo;s templates can only declare define elements.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 5: Changes to Chart Dependencies</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt5/</link><pubDate>Mon, 06 May 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt5/</guid><description>This is part 5 of 7 of our Helm 3 Preview: Charting Our Future blog series about chart dependencies and some subtle differences between Helm 2 and Helm 3. (Check out our previous blog post on release management here.)
Charts that were packaged (with helm package) for use with Helm 2 can be installed with Helm 3, but the chart development workflow received an overhaul, so some changes are necessary to continue developing charts with Helm 3.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 4: Release Management</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt4/</link><pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt4/</guid><description>This is part 4 of 7 of our Helm 3 Preview: Charting Our Future blog series on release management. (Check out our previous blog post on the Helm chart repositories here.
In Helm 3, an application&amp;rsquo;s state is tracked in-cluster by a pair of objects:
The release object: represents an instance of an application The release version secret: represents an application&amp;rsquo;s desired state at a particular instance of time (the release of a new version, for example) A helm install creates a release object and a release version secret.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 3: Chart Repositories</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt3/</link><pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt3/</guid><description>This is part 3 of 7 of our Helm 3 Preview: Charting Our Future blog series, discussing chart repositories. (Check out our previous blog post on the gentle goodbye to Tiller here.)
At a high level, a Chart Repository is a location where Charts can be stored and shared. The Helm client packs and ships Helm Charts to a Chart Repository. Simply put, a Chart Repository is a basic HTTP server that houses an index.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 2: A Gentle Farewell to Tiller</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt2/</link><pubDate>Thu, 25 Apr 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt2/</guid><description>This is part 2 of 7 of our Helm 3 Preview: Charting Our Future blog series. (Check out our previous blog post on the history of Helm here.)
During the Helm 2 development cycle, we introduced Tiller as part of our integration with Google&amp;rsquo;s Deployment Manager. Tiller played an important role for teams working on a shared cluster - it made it possible for multiple different operators to interact with the same set of releases.</description></item><item><title>Helm 3 Preview: Charting Our Future – Part 1: A History of Helm</title><link>https://v3-1-0.helm.sh/blog/helm-3-preview-pt1/</link><pubDate>Mon, 22 Apr 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-3-preview-pt1/</guid><description>On October 15th, 2015, the project now known as Helm was born. Only one year later, the Helm community joined the Kubernetes organization as Helm 2 was fast approaching. In June 2018, the Helm community joined the CNCF as an incubating project. Fast forward to today, and Helm 3 is nearing its first alpha release.
In this series of seven blog posts over the next four weeks, I&amp;rsquo;ll provide some history on Helm&amp;rsquo;s beginnings, illustrate how we got where we are today, showcase some of the new features available for the first alpha release of Helm 3, and explain how we move forward from here.</description></item><item><title>Helm Summit EU 2019</title><link>https://v3-1-0.helm.sh/blog/helm-summit-eu-2019/</link><pubDate>Thu, 18 Apr 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-summit-eu-2019/</guid><description>We&amp;rsquo;re beyond excited to share that Helm Summit EU 2019 is now official (h/t to CNCF)! Join the Helm community on September 11 - 12 in Amsterdam, The Netherlands at Pakhuis de Zwijger for our first European Helm Summit. Over the course of two days, we&amp;rsquo;ll discuss all things Helm and hold tutorials, working sessions, and small group discussions with new and exisiting users.
Interested in&amp;hellip;
Registering? Sign up here before Aug 27 for Early Bird pricing of $250.</description></item><item><title>ChartMuseum Vulnerability: Authorization Bypass [CVE-2019-1000009]</title><link>https://v3-1-0.helm.sh/blog/chartmuseum-security-notice-2019/</link><pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/chartmuseum-security-notice-2019/</guid><description>&lt;p>Security researcher Bernard Wagner of
&lt;a href="https://www.entersekt.com/" target="_blank">Entersekt&lt;/a> discovered a vulnerability in ChartMuseum, impacting &lt;strong>all versions of ChartMuseum between ChartMuseum &amp;gt;=0.1.0 and &amp;lt; 0.8.1&lt;/strong>. A specially crafted chart could be uploaded that caused the uploaded archive to be saved outside of the intended location.&lt;/p>
&lt;p>When ChartMuseum is configured for multitenancy the specially crafted chart could be uploaded to one tenant but saved in the location of another tenant. This includes overwriting a chart at a version in the other tenant.&lt;/p>
&lt;p>Additionally, if ChartMuseum is configured to use a file system the uploaded Chart archive may be uploaded to locations outside of the storage directory. It could be uploaded to any place the ChartMuseum application binary has write permission to.&lt;/p>
&lt;p>We are unaware of any public exploits caused by this issue.&lt;/p></description></item><item><title>Helm Vulnerability: Client Unpacking Chart that Contains Malicious Content [CVE-2019-1000008]</title><link>https://v3-1-0.helm.sh/blog/helm-security-notice-2019/</link><pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-security-notice-2019/</guid><description>&lt;p>Security researcher Bernard Wagner of
&lt;a href="https://www.entersekt.com/" target="_blank">Entersekt&lt;/a> discovered a vulnerability in the Helm client, impacting &lt;strong>all versions of Helm between Helm &amp;gt;=2.0.0 and &amp;lt; 2.12.2&lt;/strong>. Two Helm client commands may be coerced into unpacking unsafe content from a maliciously designed chart.&lt;/p>
&lt;p>A specially crafted chart may be able to unpack content into locations on the filesystem outside of the chart’s path, potentially overwriting existing files.&lt;/p>
&lt;p>No version of Tiller is known to be impacted. This is a client-only issue.&lt;/p>
&lt;p>The following Helm commands may unsafely unpack malformed charts onto a local folder: &lt;code>helm fetch --untar&lt;/code> and &lt;code>helm lint some.tgz&lt;/code>.&lt;/p>
&lt;p>We are unaware of any public exploits caused by this issue.&lt;/p></description></item><item><title>Introducing the Helm Hub</title><link>https://v3-1-0.helm.sh/blog/intro-helm-hub/</link><pubDate>Tue, 11 Dec 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/intro-helm-hub/</guid><description>&lt;p>Helm was designed with many distributed repositories in mind. Like Homebrew Taps and Debian APT repositories, Helm has the ability to add and work with many repositories. While the Helm
&lt;a href="https://github.com/helm/charts" target="_blank">stable and incubator repositories&lt;/a> have been front and center from the beginning it was never our intent for these to be the only public repositories.&lt;/p>
&lt;p>With this in mind, we are delighted to announce the launch of the
&lt;a href="https://hub.helm.sh" target="_blank">Helm Hub&lt;/a>. This hub provides a means for you to find charts hosted in many distributed repositories hosted by numerous people and organizations.&lt;/p></description></item><item><title>Introducing the Helm Org Maintainers</title><link>https://v3-1-0.helm.sh/blog/intro-helm-org-maintainers/</link><pubDate>Thu, 04 Oct 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/intro-helm-org-maintainers/</guid><description>&lt;p>The first major action under the
&lt;a href="https://www.helm.sh/blog/new-gov-and-elections/index.html" target="_blank">new Helm governance&lt;/a> was to elect a set of
&lt;a href="https://github.com/helm/community/blob/52161625acabf4187ae052f4e5fdd36daea91684/governance/governance.md#helm-org-maintainers" target="_blank">Helm Org Maintainers&lt;/a>. In the initial election we were looking to select 7 people to represent Helm core, charts, and other projects under the Helm umbrella. The election is now complete and I would like to introduce the first set of Org Maintainers.&lt;/p></description></item><item><title>Using the Community Chart Testing Tools Yourself</title><link>https://v3-1-0.helm.sh/blog/chart-testing-intro/</link><pubDate>Tue, 25 Sep 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/chart-testing-intro/</guid><description>&lt;p>The Helm community charts,
&lt;a href="https://github.com/helm/charts" target="_blank">available as the stable and incubator repositories&lt;/a>, have long had testing. That testing has grown and improved a significant amount in the past year; from Helm linting and testing if an application runs in a cluster to now include YAML linting, some validation on maintainers, &lt;code>Chart.yaml&lt;/code> schema validation, tests on chart version increments, and more.&lt;/p></description></item><item><title>New Governance And Elections</title><link>https://v3-1-0.helm.sh/blog/new-gov-and-elections/</link><pubDate>Fri, 07 Sep 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/new-gov-and-elections/</guid><description>&lt;p>Being a top level incubating CNCF project requires having a governance structure to ensure that there is a publicly documented process for making decisions regarding the project and the community. While Helm was under Kubernetes, we relied on Kubernetes governance. As part of the transition to CNCF, the Helm project is required to have its own governance structure. To handle this we set up a
&lt;a href="https://github.com/helm/community/blob/aa0586011786dfbc3993e7edd959a841241c96e3/governance/provisional-governance.md" target="_blank">provisional governance&lt;/a> with a goal of creating a long term one. After a few months we are happy to announce that the new governance structure has been written and approved.&lt;/p></description></item><item><title>Helm Moves To DCO</title><link>https://v3-1-0.helm.sh/blog/helm-dco/</link><pubDate>Mon, 27 Aug 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-dco/</guid><description>&lt;p>When Helm was part of the Kubernetes project it, like the rest of Kubernetes, used the
&lt;a href="https://github.com/cncf/cla" target="_blank">CNCF Contributor License Agreement (CLA)&lt;/a>. This served Helm well for years. But, most of the CNCF projects use a
&lt;a href="https://developercertificate.org/" target="_blank">Developers Certificate of Origin (DCO)&lt;/a> instead of a CLA. The exceptions are Kubernetes and gRPC. Upon Helm becoming a CNCF project itself we were asked if we wanted to move Helm to a DCO. After some careful consideration and a little research, the Helm maintainers voted to move to a DCO.&lt;/p></description></item><item><title>Helm Emeritus Maintainer Rimas Mocevicius</title><link>https://v3-1-0.helm.sh/blog/helm-emeritus-maintainer-rimas-mocevicius/</link><pubDate>Tue, 24 Jul 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-emeritus-maintainer-rimas-mocevicius/</guid><description>Rimas Mocevicius ( rimusz) has become the fourth Helm Emeritus Maintainer. Rimas is one of the three original founders of Helm. Author of CoreOS Essentials (Packt, 2016) and creator of Kube Solo, Rimas is a long-time member of the Kubernetes ecosystem. Rimas was an active contributor on Helm Classic, and has been a leading voice in the community ever since.
Check out Rimas&amp;rsquo; latest blog post on Tillerless Helm.</description></item><item><title>Bringing Helm Home</title><link>https://v3-1-0.helm.sh/blog/bringing-helm-home/</link><pubDate>Mon, 23 Jul 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/bringing-helm-home/</guid><description>&lt;p>Earlier this summer, we announced that
&lt;a href="https://www.cncf.io/blog/2018/06/01/cncf-to-host-helm/" target="_blank">Helm joined the CNCF&lt;/a> as an official incubating project. Part of that transition involves moving the Helm project out of the Kubernetes GitHub org and into its org. We’re excited to announce that we’ve completed that process. As of last week, we have moved the Helm code repository to
&lt;a href="https://github.com/helm/helm" target="_blank">https://github.com/helm/helm&lt;/a>.&lt;/p></description></item><item><title>Helm Enters the CNCF</title><link>https://v3-1-0.helm.sh/blog/helm-enters-the-cncf/</link><pubDate>Fri, 01 Jun 2018 00:00:00 +0000</pubDate><guid>https://v3-1-0.helm.sh/blog/helm-enters-the-cncf/</guid><description>&lt;p>Today we are happy to announce that Helm has become an official top-level
&lt;a href="https://www.cncf.io/" target="_blank">CNCF&lt;/a> project, joining the ranks of Prometheus, Linkerd, OpenTracing, and others. Helm will enter the CNCF as an incubating project as we continue to work on the next-generation Helm 3 cloud-native package manager.&lt;/p></description></item></channel></rss>