Phase 3 — Helm Chart
Dependencies: S03E04 (#37) must be merged (single-container image must exist). S03E05 (#38) should be merged or near-complete (Terraform outputs define the values.yaml shape).
Parent plan: Pivot Plan v3
Context
The Helm chart is the primary distribution unit for Kubernetes adopters. It deploys a single Comet container (the unified Go+React image from S03E04) configured to point at the adopter's existing Boundary cluster (provisioned by the Terraform module from S03E05 or manually via WebUI).
Scope
Step 3.1 — Scaffold charts/comet-boundary/
| File |
Content |
Chart.yaml |
name: comet-boundary, version: 0.1.0, appVersion: "0.1.0", description: "Browser-based SSH access for HashiCorp Boundary" |
values.yaml |
image.repository, image.tag, boundary.address, boundary.authMethodId, boundary.ldapAuthMethodId, replicaCount, resources, ingress config |
.helmignore |
Standard ignores |
Step 3.2 — Templates
templates/deployment.yaml:
- Single container from
{{ .Values.image.repository }}:{{ .Values.image.tag }}
- Env vars from values:
BOUNDARY_ADDR, BOUNDARY_AUTH_METHOD_ID, BOUNDARY_LDAP_AUTH_METHOD_ID, PORT
- Resource limits (defaults: 256Mi memory request, 512Mi limit; 250m CPU request, 500m limit)
- Liveness probe:
httpGet path / on container port
- Readiness probe: same
templates/service.yaml:
- ClusterIP, port 8080 -> container port
templates/ingress.yaml:
- Conditional on
{{ .Values.ingress.enabled }}
- Standard K8s Ingress spec
- HTTP only (TLS termination is the adopter's responsibility)
Step 3.3 — Helm lint + template validation
helm lint charts/comet-boundary/
helm template comet charts/comet-boundary/ --set boundary.address=http://example.com --set boundary.authMethodId=ampw_test
Add helm lint charts/comet-boundary/ to Tier 1 CI (ci.yml) as a new job. This requires Helm to be installed on the runner (azure/setup-helm@v4).
Step 3.4 — (Optional) Local Kind validation
If time permits:
kind create cluster
kind load docker-image comet-boundary:local
helm install comet charts/comet-boundary/ --set boundary.address=http://host.docker.internal:9200 --set boundary.authMethodId=...
kubectl port-forward svc/comet-comet-boundary 8080:8080
- Confirm login + SSH works
Acceptance Criteria
Phase 3 — Helm Chart
Dependencies: S03E04 (#37) must be merged (single-container image must exist). S03E05 (#38) should be merged or near-complete (Terraform outputs define the
values.yamlshape).Parent plan: Pivot Plan v3
Context
The Helm chart is the primary distribution unit for Kubernetes adopters. It deploys a single Comet container (the unified Go+React image from S03E04) configured to point at the adopter's existing Boundary cluster (provisioned by the Terraform module from S03E05 or manually via WebUI).
Scope
Step 3.1 — Scaffold
charts/comet-boundary/Chart.yamlname: comet-boundary,version: 0.1.0,appVersion: "0.1.0",description: "Browser-based SSH access for HashiCorp Boundary"values.yamlimage.repository,image.tag,boundary.address,boundary.authMethodId,boundary.ldapAuthMethodId,replicaCount,resources,ingressconfig.helmignoreStep 3.2 — Templates
templates/deployment.yaml:{{ .Values.image.repository }}:{{ .Values.image.tag }}BOUNDARY_ADDR,BOUNDARY_AUTH_METHOD_ID,BOUNDARY_LDAP_AUTH_METHOD_ID,PORThttpGetpath/on container porttemplates/service.yaml:templates/ingress.yaml:{{ .Values.ingress.enabled }}Step 3.3 — Helm lint + template validation
Add
helm lint charts/comet-boundary/to Tier 1 CI (ci.yml) as a new job. This requires Helm to be installed on the runner (azure/setup-helm@v4).Step 3.4 — (Optional) Local Kind validation
If time permits:
kind create clusterkind load docker-image comet-boundary:localhelm install comet charts/comet-boundary/ --set boundary.address=http://host.docker.internal:9200 --set boundary.authMethodId=...kubectl port-forward svc/comet-comet-boundary 8080:8080Acceptance Criteria
helm lintpasses:helm lint charts/comet-boundary/reports no errors or warningshelm templaterenders valid YAML:helm template comet charts/comet-boundary/ --set boundary.address=http://example.com --set boundary.authMethodId=testproduces valid Kubernetes manifests (Deployment, Service, no Ingress by default)BOUNDARY_ADDR,BOUNDARY_AUTH_METHOD_ID,BOUNDARY_LDAP_AUTH_METHOD_ID), liveness/readiness probes, and resource limitsingress.enabled=false(default); renders valid Ingress wheningress.enabled=truevalues.yamlis fully documented: every value has a comment explaining its purpose0.1.0, appVersion"0.1.0", description presenthelm lintruns as part of CI (new job or added to existing job)