fix(helm): Improve security settings and add templated image configuration#554
Merged
mbaldessari merged 6 commits intovalidatedpatterns:mainfrom Jan 19, 2026
Merged
Conversation
…alues The template hello-world-cm.yaml references .Values.global.localClusterDomain but the values file had the key named localCluster, causing the template to render with an empty value.
Setting insecureEdgeTerminationPolicy to Allow permits unencrypted HTTP traffic to the routes. Changing to Redirect forces all HTTP requests to be redirected to HTTPS, improving security. Affected routes: - hello-world - config-demo
The container already has emptyDir volumes mounted for all writable paths: - /tmp - /var/cache/httpd - /var/run/httpd - /var/www/html (via configMap) With these mounts in place, the root filesystem can safely be read-only, improving container security posture.
- Add image.repository, image.tag, image.pullPolicy to both chart values - Update deployments to use templated image values - Remove commented imagePullPolicy, now explicit in values - Allows image overrides without modifying templates Affected charts: - hello-world - config-demo
Kubernetes auto-populates creationTimestamp. Explicitly setting it to null in templates is unnecessary and may cause validation warnings.
….yaml The validated patterns operator expects 'argoProject' not 'project'. Also rename 'projects' to 'argoProjects' for consistency with values-hub.yaml.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Changes
Security Improvements
insecureEdgeTerminationPolicyfromAllowtoRedirectin both hello-world and config-demo routes (enforces HTTPS)readOnlyRootFilesystem: truein config-demo deployment with emptyDir volumes for writable pathsImage Configuration
image.repository,image.tag,image.pullPolicyto values.yaml for both charts{{ .Values.image.repository }}:{{ .Values.image.tag }}#imagePullPolicylines, now explicit in valuesConfiguration Fixes
localClustertolocalClusterDomainin hello-world values.yamlprojecttoargoProjectin values-standalone.yaml applicationsprojectstoargoProjectsin values-standalone.yamlcreationTimestamp: nullfrom pod template metadataAffected Charts
charts/all/hello-worldcharts/all/config-demovalues-standalone.yamlTest Plan
helm templateon both charts to verify valid outputFixes #531
Fixes #532
Fixes #533
Fixes #534
Fixes #535
Fixes #536
Fixes #537
Fixes #538
Fixes #539
Fixes #540
Fixes #541
Fixes #542