Kustomize with Helm

Using Kustomize as a Helm Post-Renderer

Charts rarely expose every field. Instead of forking one, Helm 3 29,435 can pipe the rendered manifests through any executable, a post-renderer. Here Kustomize 547,809 adds a team label and the seccomp profile the chart lacks:

helm/post-render/kustomize.sh: the post-rendererShell
#!/bin/sh
# Helm pipes the rendered manifests in; the patched ones go out.
cd "$(dirname "$0")" && cat > all.yaml && kubectl kustomize . && rm all.yaml
helm/post-render/kustomization.yaml: the changesYAML
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources: [all.yaml]
labels: [{ pairs: { team: bookshop } }]
patches:
- target: { kind: Deployment }
  patch: |-
    - op: add
      path: /spec/template/spec/securityContext
      value: { seccompProfile: { type: RuntimeDefault } }
Upgrading the release through the post-rendererShell
chmod +x helm/post-render/kustomize.sh
helm upgrade booknest helm/booknest -n booknest-helm --reuse-values --wait \
  --post-renderer helm/post-render/kustomize.sh | grep REVISION
C=NAME:.metadata.name,TEAM:.metadata.labels.team
C+=,SECCOMP:.spec.template.spec.securityContext.seccompProfile.type
kubectl get deploy -n booknest-helm -o custom-columns=$C
git add helm/post-render && git commit -qm "Add a Kustomize post-renderer for the chart"
Output
REVISION: 5
NAME           TEAM       SECCOMP
booknest-api   bookshop   RuntimeDefault
booknest-web   bookshop   RuntimeDefault

An upgrade without the flag drops both changes, so keep it in the script that runs every upgrade. Helm 4.3.0 rejects the same command with plugin: {Name:helm/post-render/kustomize.sh Type:postrenderer/v1} not found: its post-renderers are plugins (helm plugin install), so wrap the script in one before moving.