CKAD — Kubernetes Application Developer
Local Helm Charts and Kustomize Overlays
Goal
Without internet access, you create a local Helm chart and render, install, and upgrade it, and you transform the same manifests per environment with a Kustomize base/overlay structure and apply them.
Why it matters
Helm and Kustomize take opposite approaches. Helm is a template. Because it produces manifests at the string level with Go templates, things like conditionals and loops come freely, but before rendering it is not valid YAML. Kustomize is a patch. Because it merges already valid YAML structurally, the result is always valid, but the range of transformations it can express is narrow.
They are alike in that both have the concept of a revision. Helm stacks release revisions as Secrets in the namespace, and for Kustomize, Git commits play that role. That is why Helm has helm rollback, while with Kustomize you do a git revert and apply again.
It is important to make helm template a habit. It is the only way to check what will be created before installing, and it is also the point where CI inspects the manifests. Questions like "check what this chart creates" also come up in the exam room.
This lab environment has no internet access. helm repo add does not work. Air-gapped environments are common in practice too, and there you bring charts in as a tgz or install them from a local path. That is exactly the approach you practice here.
Steps
- Create a chart with
helm create /root/ckad-pkg/webapp. (If needed, create the/root/ckad-pkgdirectory first.) - Edit
/root/ckad-pkg/webapp/values.yaml.replicaCount: 3,image.repository: nginx,image.tag: "1.27",service.type: NodePort,service.port: 8080. - Save the result of
helm template webapp /root/ckad-pkg/webappto/root/ckad-pkg/rendered.yaml. - Specify the local chart path as is, and install it into the namespace
ckad-pkgwith the release namewebapp. You can create the namespace in advance or create it at install time. - Use
helm upgradeto change onlyreplicaCountto 5. The release revision must become 2. - Create a Kustomize base. In
/root/ckad-pkg/kustomize/base/deployment.yaml, write a Deploymentreport(1 replica, labelapp=report, imagenginx:1.27), and register that file asresourcesin thekustomization.yamlin the same directory. - Create the overlay
/root/ckad-pkg/kustomize/overlays/prod/kustomization.yaml. Reference the base, add the prefixprod-in front of names, add the common labelenv=prod, and apply a patch that changes the replicas to 4. The result ofkubectl kustomize /root/ckad-pkg/kustomize/overlays/prodmust showprod-reportwith 4 replicas and the labelenv: prod. - Apply that overlay to the namespace
ckad-pkg(kubectl apply -k ... -n ckad-pkg). The Deploymentprod-reportmust exist with 4 replicas, the labelenv=prod, and the imagenginx:1.27.
Notes
- Check the release state and revisions with
helm list -n ckad-pkgandhelm history webapp -n ckad-pkg. kubectl kustomize <경로>only builds, whilekubectl apply -k <경로>builds and then applies (the placeholder is the path).- The safest way to patch replicas is to use
path:underpatches:to point at a patch file. You can also use the dedicatedreplicas:field. - Common mistake 1: trying
helm repo add. There is no internet, so use only local paths. - Common mistake 2: writing an absolute path in the overlay's
resources. A path relative to kustomization.yaml, such as../../base, is safe. - Common mistake 3: leaving
image.tagas1.27, like a number. YAML may parse it as a float and it can become a value other than1.27, so wrap it in quotes.
Creating a chart skeleton with helm create
Create a chart with helm create /root/ckad-pkg/webapp. (If needed, create the /root/ckad-pkg directory first.)
helm create <경로> (the placeholder is the path) creates a standard chart structure locally without internet. Check that Chart.yaml, values.yaml, and templates/ were created.
Editing values.yaml
Edit /root/ckad-pkg/webapp/values.yaml. replicaCount: 3, image.repository: nginx, image.tag: "1.27", service.type: NodePort, service.port: 8080.
Edit values.yaml directly. It is safer to keep the image tag as a string (with quotes). The service type and port are under the service block.
Checking the rendered result with helm template
Save the result of helm template webapp /root/ckad-pkg/webapp to /root/ckad-pkg/rendered.yaml.
helm template <릴리스이름> <차트경로> (the placeholders are the release name and the chart path) creates nothing in the cluster and only prints the final manifest. Save it to a file with a redirect.
helm install from a local path
Specify the local chart path as is, and install it into the namespace ckad-pkg with the release name webapp. You can create the namespace in advance or create it at install time.
Pass the chart path as is (helm install 이름 /경로, where the placeholders are the release name and the path). If the namespace does not exist, add --create-namespace. There is no internet, so you cannot use a repository name.
Building up a revision with helm upgrade
Use helm upgrade to change only replicaCount to 5. The release revision must become 2.
Override just one value with --set. When you upgrade, the release revision increases and the previous revision remains as superseded. Check with helm history.
Creating a Kustomize base
Create a Kustomize base. In /root/ckad-pkg/kustomize/base/deployment.yaml, write a Deployment report (1 replica, label app=report, image nginx:1.27), and register that file as resources in the kustomization.yaml in the same directory.
Put the manifest file and kustomization.yaml in the base directory. The resources of the kustomization is an array of paths relative to the same directory. View the build result with kubectl kustomize <경로> (the placeholder is the path).
Changing names, labels, and replicas with an overlay
Create the overlay /root/ckad-pkg/kustomize/overlays/prod/kustomization.yaml. Reference the base, add the prefix prod- in front of names, add the common label env=prod, and apply a patch that changes the replicas to 4. The result of kubectl kustomize /root/ckad-pkg/kustomize/overlays/prod must show prod-report with 4 replicas and the label env: prod.
The overlay's resources points to the base with a relative path. There are separate fields for adding a prefix in front of names and for adding a common label, and the replicas are overridden with a strategic merge patch file. Check the result in the kubectl kustomize output.
Applying the overlay to the cluster (comprehensive)
Apply that overlay to the namespace ckad-pkg (kubectl apply -k ... -n ckad-pkg). The Deployment prod-report must exist with 4 replicas, the label env=prod, and the image nginx:1.27.
kubectl apply -k <오버레이경로> (the placeholder is the overlay path) builds and applies in one go. You must specify the namespace for it to land where you want. After applying, check that the name changed along with the prefix.