Charts rarely expose every field. Instead of forking one, Helm 3 29,435 can pipe the rendered manifests through any executable, a post-renderer. Here Kustomize 547,809 adds a team label and the seccomp profile the chart lacks:
#!/bin/sh
# Helm pipes the rendered manifests in; the patched ones go out.
cd "$(dirname "$0")" && cat > all.yaml && kubectl kustomize . && rm all.yamlapiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources: [all.yaml]
labels: [{ pairs: { team: bookshop } }]
patches:
- target: { kind: Deployment }
patch: |-
- op: add
path: /spec/template/spec/securityContext
value: { seccompProfile: { type: RuntimeDefault } }chmod +x helm/post-render/kustomize.sh
helm upgrade booknest helm/booknest -n booknest-helm --reuse-values --wait \
--post-renderer helm/post-render/kustomize.sh | grep REVISION
C=NAME:.metadata.name,TEAM:.metadata.labels.team
C+=,SECCOMP:.spec.template.spec.securityContext.seccompProfile.type
kubectl get deploy -n booknest-helm -o custom-columns=$C
git add helm/post-render && git commit -qm "Add a Kustomize post-renderer for the chart"Output
REVISION: 5 NAME TEAM SECCOMP booknest-api bookshop RuntimeDefault booknest-web bookshop RuntimeDefault
An upgrade without the flag drops both changes, so keep it in the script that runs every upgrade. Helm 4.3.0 rejects the same command with plugin: {Name:helm/post-render/kustomize.sh Type:postrenderer/v1} not found: its post-renderers are plugins (helm plugin install), so wrap the script in one before moving.