---
title: Configuring custom Helm chart repositories
---

# Configuring custom Helm chart repositories {#configuring-custom-helm-chart-repositories}

You can create Helm releases on an OpenShift Container Platform cluster using the following methods:

- The CLI.
- The **Developer** perspective of the web console.

The **Developer Catalog**, in the **Developer** perspective of the web console, displays the Helm charts available in the cluster. By default, it lists the Helm charts from the Red Hat OpenShift Helm chart repository. For a list of the charts, see [the Red Hat `Helm index` file](https://charts.openshift.io/index.yaml).

As a cluster administrator, you can add multiple cluster-scoped and namespace-scoped Helm chart repositories, separate from the default cluster-scoped Helm repository, and display the Helm charts from these repositories in the **Developer Catalog**.

As a regular user or project member with the appropriate role-based access control (RBAC) permissions, you can add multiple namespace-scoped Helm chart repositories, apart from the default cluster-scoped Helm repository, and display the Helm charts from these repositories in the **Developer Catalog**.

In the **Developer** perspective of the web console, you can use the **Helm** page to:

- Create Helm Releases and Repositories using the **Create** button.
- Create, update, or delete a cluster-scoped or namespace-scoped Helm chart repository.
- View the list of the existing Helm chart repositories in the Repositories tab, which can also be easily distinguished as either cluster scoped or namespace scoped.

## Installing a Helm chart on an OpenShift Container Platform cluster {#installing-a-helm-chart-on-an-openshift-cluster_configuring-custom-helm-chart-repositories}

**Prerequisites**

- You have a running OpenShift Container Platform cluster and you have logged into it.
- You have installed Helm.

**Procedure**

1. Create a new project:

   ```terminal
   $ oc new-project vault
   ```
2. Add a repository of Helm charts to your local Helm client:

   ```terminal
   $ helm repo add openshift-helm-charts https://charts.openshift.io/
   ```

   ```terminal {title="Example output"}
   "openshift-helm-charts" has been added to your repositories
   ```
3. Update the repository:

   ```terminal
   $ helm repo update
   ```
4. Install an example HashiCorp Vault:

   ```terminal
   $ helm install example-vault openshift-helm-charts/hashicorp-vault
   ```

   ```terminal {title="Example output"}
   NAME: example-vault
   LAST DEPLOYED: Fri Mar 11 12:02:12 2022
   NAMESPACE: vault
   STATUS: deployed
   REVISION: 1
   NOTES:
   Thank you for installing HashiCorp Vault!
   ```
5. Verify that the chart has installed successfully:

   ```terminal
   $ helm list
   ```

   ```terminal {title="Example output"}
   NAME         	NAMESPACE	REVISION	UPDATED                                	STATUS  	CHART       	APP VERSION
   example-vault	vault    	1       	2022-03-11 12:02:12.296226673 +0530 IST	deployed	vault-0.19.0	1.9.2
   ```

## Creating Helm releases using the Developer perspective {#odc-creating-helm-releases-using-developer-perspective_configuring-custom-helm-chart-repositories}

You can use either the **Developer** perspective in the web console or the CLI to select and create a release from the Helm charts listed in the **Developer Catalog**. You can create Helm releases by installing Helm charts and see them in the **Developer** perspective of the web console.

**Prerequisites**

- You have logged in to the web console and have switched to [the **Developer** perspective](/openshift-docs-markdown/web_console/web-console-overview#about-developer-perspective_web-console-overview).

**Procedure**

To create Helm releases from the Helm charts provided in the **Developer Catalog**:

1. In the **Developer** perspective, navigate to the **+Add** view and select a project. Then click **Helm Chart** option to see all the Helm Charts in the **Developer Catalog**.
2. Select a chart and read the description, README, and other details about the chart.
3. Click **Create**.

   **Figure 1. Helm charts in developer catalog**

   ![odc_helm_chart_devcatalog_new](/openshift-docs-markdown/images/odc_helm_chart_devcatalog_new.png)
4. In the **Create Helm Release** page:

   1. Enter a unique name for the release in the **Release Name** field.
   2. Select the required chart version from the **Chart Version** drop-down list.
   3. Configure your Helm chart by using the **Form View** or the **YAML View**.

      > [!NOTE]
      > Where available, you can switch between the **YAML View** and **Form View**. The data is persisted when switching between the views.
   4. Click **Create** to create a Helm release. The web console displays the new release in the **Topology** view.

      If a Helm chart has release notes, the web console displays them.

      If a Helm chart creates workloads, the web console displays them on the **Topology** or **Helm release details** page. The workloads are `DaemonSet`, `CronJob`, `Pod`, `Deployment`, and `DeploymentConfig`.
   5. View the newly created Helm release in the **Helm Releases** page.

You can upgrade, rollback, or delete a Helm release by using the **Actions** button on the side panel or by right-clicking a Helm release.

## Using Helm in the web terminal {#_using_helm_in_the_web_terminal}

You can use Helm by [Accessing the web terminal](/openshift-docs-markdown/web_console/web_terminal/odc-using-web-terminal#odc-access-web-terminal_odc-using-web-terminal) in the **Developer** perspective of the web console.

## Creating a custom Helm chart on OpenShift Container Platform {#creating-a-custom-helm-chart-on-openshift_configuring-custom-helm-chart-repositories}

**Procedure**

1. Create a new project:

   ```terminal
   $ oc new-project nodejs-ex-k
   ```
2. Download an example Node.js chart that contains OpenShift Container Platform objects:

   ```terminal
   $ git clone https://github.com/redhat-developer/redhat-helm-charts
   ```
3. Go to the directory with the sample chart:

   ```terminal
   $ cd redhat-helm-charts/alpha/nodejs-ex-k/
   ```
4. Edit the `Chart.yaml` file  and add a description of your chart:

   ```yaml
   apiVersion: v2 (1)
   name: nodejs-ex-k (2)
   description: A Helm chart for OpenShift (3)
   icon: https://static.redhat.com/libs/redhat/brand-assets/latest/corp/logo.svg (4)
   version: 0.2.1 (5)
   ```

   1. The chart API version. It should be `v2` for Helm charts that require at least Helm 3.
   2. The name of your chart.
   3. The description of your chart.
   4. The URL to an image to be used as an icon.
   5. The Version of your chart as per the Semantic Versioning (SemVer) 2.0.0 Specification.
5. Verify that the chart is formatted properly:

   ```terminal
   $ helm lint
   ```

   ```terminal {title="Example output"}
   [INFO] Chart.yaml: icon is recommended

   1 chart(s) linted, 0 chart(s) failed
   ```
6. Navigate to the previous directory level:

   ```terminal
   $ cd ..
   ```
7. Install the chart:

   ```terminal
   $ helm install nodejs-chart nodejs-ex-k
   ```
8. Verify that the chart has installed successfully:

   ```terminal
   $ helm list
   ```

   ```terminal {title="Example output"}
   NAME NAMESPACE REVISION UPDATED STATUS CHART APP VERSION
   nodejs-chart nodejs-ex-k 1 2019-12-05 15:06:51.379134163 -0500 EST deployed nodejs-0.1.0  1.16.0
   ```

## Adding custom Helm chart repositories {#adding-helm-chart-repositories_configuring-custom-helm-chart-repositories}

As a cluster administrator, you can add custom Helm chart repositories to your cluster and enable access to the Helm charts from these repositories in the **Developer Catalog**.

**Procedure**

1. To add a new Helm Chart Repository, you must add the Helm Chart Repository custom resource (CR) to your cluster.

   ```yaml {title="Sample Helm Chart Repository CR"}
   apiVersion: helm.openshift.io/v1beta1
   kind: HelmChartRepository
   metadata:
     name: <name>
   spec:
    # optional name that might be used by console
    # name: <chart-display-name>
     connectionConfig:
       url: <helm-chart-repository-url>
   ```

   For example, to add an Azure sample chart repository, run:

   ```terminal
   $ cat <<EOF | oc apply -f -
   apiVersion: helm.openshift.io/v1beta1
   kind: HelmChartRepository
   metadata:
     name: azure-sample-repo
   spec:
     name: azure-sample-repo
     connectionConfig:
       url: https://raw.githubusercontent.com/Azure-Samples/helm-charts/master/docs
   EOF
   ```
2. Navigate to  the **Developer Catalog** in the web console to verify that the Helm charts from the chart repository are displayed.

   For example, use the **Chart repositories** filter to search for a Helm chart from the repository.

   **Figure 2. Chart repositories filter**

   ![odc_helm_chart_repo_filter](/openshift-docs-markdown/images/odc_helm_chart_repo_filter.png)

   > [!NOTE]
   > If a cluster administrator removes all of the chart repositories, then you cannot view the Helm option in the **+Add** view, **Developer Catalog**, and left navigation panel.

## Adding namespace-scoped custom Helm chart repositories {#adding-namespace-scoped-helm-chart-repositories_configuring-custom-helm-chart-repositories}

The cluster-scoped `HelmChartRepository` custom resource definition (CRD) for Helm repository provides the ability for administrators to add Helm repositories as custom resources. The namespace-scoped `ProjectHelmChartRepository` CRD allows project members with the appropriate role-based access control (RBAC) permissions to create Helm repository resources of their choice but scoped to their namespace. Such project members can see charts from both cluster-scoped and namespace-scoped Helm repository resources.

> [!NOTE]
> - Administrators can limit users from creating namespace-scoped Helm repository resources. By limiting users, administrators have the flexibility to control the RBAC through a namespace role instead of a cluster role. This avoids unnecessary permission elevation for the user and prevents access to unauthorized services or applications.
> - The addition of the namespace-scoped Helm repository does not impact the behavior of the existing cluster-scoped Helm repository.

As a regular user or project member with the appropriate RBAC permissions, you can add custom namespace-scoped Helm chart repositories to your cluster and enable access to the Helm charts from these repositories in the **Developer Catalog**.

**Procedure**

1. To add a new namespace-scoped Helm Chart Repository, you must add the Helm Chart Repository custom resource (CR) to your namespace.

   ```yaml {title="Sample Namespace-scoped Helm Chart Repository CR"}
   apiVersion: helm.openshift.io/v1beta1
   kind: ProjectHelmChartRepository
   metadata:
     name: <name>
   spec:
     url: https://my.chart-repo.org/stable

     # optional name that might be used by console
     name: <chart-repo-display-name>

     # optional and only needed for UI purposes
     description: <My private chart repo>

     # required: chart repository URL
     connectionConfig:
       url: <helm-chart-repository-url>
   ```

   For example, to add an Azure sample chart repository scoped to your `my-namespace` namespace, run:

   ```terminal
   $ cat <<EOF | oc apply --namespace my-namespace -f -
   apiVersion: helm.openshift.io/v1beta1
   kind: ProjectHelmChartRepository
   metadata:
     name: azure-sample-repo
   spec:
     name: azure-sample-repo
     connectionConfig:
       url: https://raw.githubusercontent.com/Azure-Samples/helm-charts/master/docs
   EOF
   ```

   The output verifies that the namespace-scoped Helm Chart Repository CR is created:

   ```text {title="Example output"}
   projecthelmchartrepository.helm.openshift.io/azure-sample-repo created
   ```
2. Navigate to  the **Developer Catalog** in the web console to verify that the Helm charts from the chart repository are displayed in your `my-namespace` namespace.

   For example, use the **Chart repositories** filter to search for a Helm chart from the repository.

   **Figure 3. Chart repositories filter in your namespace**

   ![odc_namespace_helm_chart_repo_filter](/openshift-docs-markdown/images/odc_namespace_helm_chart_repo_filter.png)

   Alternatively, run:

   ```terminal
   $ oc get projecthelmchartrepositories --namespace my-namespace
   ```

   ```text {title="Example output"}
   NAME                     AGE
   azure-sample-repo        1m
   ```

   > [!NOTE]
   > If a cluster administrator or a regular user with appropriate RBAC permissions removes all of the chart repositories in a specific namespace, then you cannot view the Helm option in the **+Add** view, **Developer Catalog**, and left navigation panel for that specific namespace.

## Creating credentials and CA certificates to add Helm chart repositories {#creating-credentials-and-certificates-to-add-helm-repositories_configuring-custom-helm-chart-repositories}

Some Helm chart repositories need credentials and custom certificate authority (CA) certificates to connect to it. You can use the web console as well as the CLI to add credentials and certificates.

**Procedure**

To configure the credentials and certificates, and then add a Helm chart repository using the CLI:

1. In the `openshift-config` namespace, create a `ConfigMap` object with a custom CA certificate in PEM encoded format, and store it under the `ca-bundle.crt` key within the config map:

   ```terminal
   $ oc create configmap helm-ca-cert \
   --from-file=ca-bundle.crt=/path/to/certs/ca.crt \
   -n openshift-config
   ```
2. In the `openshift-config` namespace, create a `Secret` object to add the client TLS configurations:

   ```terminal
   $ oc create secret tls helm-tls-configs \
   --cert=/path/to/certs/client.crt \
   --key=/path/to/certs/client.key \
   -n openshift-config
   ```

   Note that the client certificate and key must be in PEM encoded format and stored under the keys `tls.crt` and `tls.key`, respectively.
3. Add the Helm repository as follows:

   ```terminal
   $ cat <<EOF | oc apply -f -
   apiVersion: helm.openshift.io/v1beta1
   kind: HelmChartRepository
   metadata:
     name: <helm-repository>
   spec:
     name: <helm-repository>
     connectionConfig:
       url: <URL for the Helm repository>
       tlsConfig:
           name: helm-tls-configs
       ca:
   	name: helm-ca-cert
   EOF
   ```

   The `ConfigMap` and `Secret` are consumed in the HelmChartRepository CR using the `tlsConfig` and `ca` fields. These certificates are used to connect to the Helm repository URL.
4. By default, all authenticated users have access to all configured charts. However, for chart repositories where certificates are needed, you must provide users with read access to the `helm-ca-cert` config map and `helm-tls-configs` secret in the `openshift-config` namespace, as follows:

   ```terminal
   $ cat <<EOF | kubectl apply -f -
   apiVersion: rbac.authorization.k8s.io/v1
   kind: Role
   metadata:
     namespace: openshift-config
     name: helm-chartrepos-tls-conf-viewer
   rules:
   - apiGroups: [""]
     resources: ["configmaps"]
     resourceNames: ["helm-ca-cert"]
     verbs: ["get"]
   - apiGroups: [""]
     resources: ["secrets"]
     resourceNames: ["helm-tls-configs"]
     verbs: ["get"]
   ---
   kind: RoleBinding
   apiVersion: rbac.authorization.k8s.io/v1
   metadata:
     namespace: openshift-config
     name: helm-chartrepos-tls-conf-viewer
   subjects:
     - kind: Group
       apiGroup: rbac.authorization.k8s.io
       name: 'system:authenticated'
   roleRef:
     apiGroup: rbac.authorization.k8s.io
     kind: Role
     name: helm-chartrepos-tls-conf-viewer
   EOF
   ```

## Filtering Helm Charts by their certification level {#filtering-helm-charts-by-certification-level_configuring-custom-helm-chart-repositories}

You can filter Helm charts based on their certification level in the **Developer Catalog**.

**Procedure**

1. In the **Developer** perspective, navigate to the **+Add** view and select a project.
2. From the **Developer Catalog** tile, select the **Helm Chart** option to see all the Helm charts in the **Developer Catalog**.
3. Use the filters to the left of the list of Helm charts to filter the required charts:

   - Use the **Chart Repositories** filter to filter charts provided by **Red Hat Certification Charts** or **OpenShift Helm Charts**.
   - Use the **Source** filter to filter charts sourced from **Partners**, **Community**, or **Red Hat**. Certified charts are indicated with the (![odc_verified_icon](/openshift-docs-markdown/images/odc_verified_icon.png "Certified icon")) icon.

   > [!NOTE]
   > The **Source** filter will not be visible when there is only one provider type.

You can now select the required chart and install it.

## Disabling Helm Chart repositories {#helm-disabling-helm-chart-repositories_configuring-custom-helm-chart-repositories}

You can disable Helm Charts from a particular Helm Chart Repository in the catalog by setting the `disabled` property in the `HelmChartRepository` custom resource to `true`.

**Procedure**

- To disable a Helm Chart repository by using CLI, add the `disabled: true` flag to the custom resource. For example, to remove an Azure sample chart repository, run:

  ```
  $ cat <<EOF | oc apply -f -
  apiVersion: helm.openshift.io/v1beta1
  kind: HelmChartRepository
  metadata:
    name: azure-sample-repo
  spec:
    connectionConfig:
     url:https://raw.githubusercontent.com/Azure-Samples/helm-charts/master/docs
    disabled: true
  EOF
  ```
- To disable a recently added Helm Chart repository by using Web Console:

  1. Go to **Custom Resource Definitions** and search for the `HelmChartRepository` custom resource.
  2. Go to **Instances**, find the repository you want to disable, and click its name.
  3. Go to the **YAML** tab, add the `disabled: true` flag in the `spec` section, and click `Save`.

     ```text {title="Example"}
     spec:
       connectionConfig:
         url: <url-of-the-repositoru-to-be-disabled>
       disabled: true
     ```

     The repository is now disabled and will not appear in the catalog.
