DevOps Practitioner · Module 3: Helm and environment configuration
One Chart, Many Environments Without Copy-Paste
Environment differences are data, not forks. Layered value files express what changes per environment in lines a reviewer can read, and the merge order makes the result predictable.
10 min reading
Objectives
- Layer base values, environment files and overrides in merge order
- Diagnose a wrong-values merge from rendered output
- Keep environment differences small, named and reviewable
- Reject secret content in any values file, committed or not
Why this matters
Staging serves the old API version three weeks after production moved on, and nobody can say which value file staging actually used. The deploy job took values from a branch that was never merged, and the difference hid because nobody renders staging on purpose. Environment drift is silent until it is expensive. The cure is mechanical: every environment renders from named files in a fixed order, the order is written down, and the rendered output is checked before install.
Concepts
The layering is base values in the chart, one file per environment (values-staging.yaml), and explicit command-line overrides only for one-off previews, never for real environments. Each layer overrides the last; the full chain for staging reads base, environment file, then any release-specific set, and that chain is identical on every machine because it lives in the pipeline definition, not in tribal memory.
Diagnose merges from the rendered output, not from the files. When staging shows the wrong replica count, render with the same chain the pipeline uses and find which layer set it; the L31 lab drills exactly this. Common merge faults: a whole map replaced when only one key was meant (maps merge key by key, but a null or a type change can wipe siblings), numbers arriving as strings from command-line sets, and environment files applied in the wrong order so production values leak into staging.
Keep the difference surface tiny. If the staging file differs from base in forty lines, the environments are different systems wearing one chart; split the chart or admit the fork. Small diffs review fast and break loudly; large diffs review never and break quietly.
Secrets never ride these files. A values file with a database password commits the password to history forever, where rotation cannot reach it. Lesson 3 gives secrets their own machinery; this lesson's rule is blank: no secret content in values, examples, chat or screenshots.
Worked example
The demo chart gains a staging file that overrides replicas, host and log level. The learner renders base, staging and production, then stages a fault: an override that sets the production host inside the staging chain. The rendered output shows the leak plainly; the fix removes the stray layer rather than patching the template.
Common wrong move
Passing per-environment differences as command-line sets in the deploy job. The cluster state then depends on flags nobody versioned, and reproducing a release means reconstructing a command line from memory. Files for environments, flags only for throwaway previews.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Render the demo chart for staging with the documented layer chain, stage a leaking override, find it in the rendered output, and remove the layer.
Pass criteria
The record shows the layer chain, the leaked value in rendered output, and the corrected chain rendering clean.