Beside api.yaml and the hook, the chart has web.yaml, _helpers.tpl, a test (Testing Charts) and a database Secret. Generating its password with randAlphaNum alone would change it on every upgrade and lock the API out, so the template first asks the cluster for the existing Secret:
{{- $old := lookup "v1" "Secret" .Release.Namespace (include "booknest.dbSecret" .) }}
{{- $password := randAlphaNum 32 | b64enc }}
{{- if $old }}{{ $password = index $old.data "password" }}{{ end }}lookup returns nothing under helm 29,435 template, which has no cluster to ask. Install the chart as a second, independent BookNest in its own namespace, starting at API version 1.3:
helm install booknest helm/booknest -n booknest-helm --create-namespace \
--set api.image.tag=1.3 --wait --timeout 5m | grep STATUS
kubectl get pods -n booknest-helmSTATUS: deployed NAME READY STATUS RESTARTS AGE booknest-api-86794d6bbd-cpb5h 1/1 Running 0 24s booknest-api-86794d6bbd-qv7pk 1/1 Running 0 24s booknest-postgres-0 1/1 Running 0 24s booknest-web-7d8cdf7677-2lhd4 1/1 Running 0 24s booknest-web-7d8cdf7677-6zqw9 1/1 Running 0 24s
With --wait, Helm ran the migration hook once everything was ready. The init container held the API back until PostgreSQL 1,289 listened, but both replicas then run CREATE TABLE IF NOT EXISTS at once: in one install out of four here, PostgreSQL rejected one with a duplicate key in pg_type_typname_nsp_index (kubectl 5,150 logs --previous), and the restarted Pod found the table. PostgreSQL StatefulSet's db-init Job avoids that race.