Add and Verify the Helm Repository
Helm is a tool for packaging and deploying Kubernetes applications. Kron PAM Secrets Management Agent components are installed from a Helm chart repository that Kron Technologies publishes. In this step, we register that repository with Helm.
Helm Repository Commands | |
|---|---|
Command | What it does |
helm repo list | Lists registered repositories |
helm repo add <name> <url> | Adds a new chart repository |
helm repo update | Refreshes the chart list/versions in the repo (metadata only, not the container image) |
helm list -A | Lists installed releases across all namespaces in the cluster |
Kron PAM Secrets Management Agent charts are published in a single public Helm repository. Register it as follows:
helm repo list
helm repo add kron-pam https://krontechnology.github.io/kron-pam-aapm-helmcharts/
helm repo update
helm list -AThe repository must be registered under the name kron-pam. All helm install commands in this guide reference charts as kron-pam/<chart-name>. If you choose a different local repository name, you must change the chart reference in every subsequent command accordingly.
If the repository is already registered and you want to overwrite it (because the URL has changed):
helm repo add kron-pam https://krontechnology.github.io/kron-pam-aapm-helmcharts/ --force-update
helm repo updateVerify that the repository is reachable and that the charts are visible:
helm repo list
helm search repo kron-pamExpected result: helm list -A should return empty (on a clean environment). If it isn't empty, don't proceed without cleaning prior to installations—there is a risk of conflict. See the section “Uninstalling and Cleaning Up".
helm repo update refreshes chart metadata only (the repository index.yaml). It doesn't update container images. If an image was rebuilt and pushed to the registry under the same tag, no Helm operation will pull it, because the default imagePullPolicy is IfNotPresent and the old image is already cached on the node. In that case the cached image must be removed from the node and the workload restarted — see the Troubleshooting section.
Chart Inventory
All three components are published under the same kron-pam repository.
Charts in the kron-pam Repository | |||
|---|---|---|---|
Chart | Release name used in this guide | Namespace | Container image(s) pulled |
kron-pam/kron-aapm-agent | kron-aapm-agent | ns-agent | krontechnology/aapm-agent |
kron-pam/aapm-service | aapm-service | kron-pam-aapm | krontechnology/aapm-service |
kron-pam/kron-aapm-sidecar | kron-aapm-sidecar | ns-sidecar | krontechnology/aapm-sidecar-injector (the injector itself) and krontechnology/aapm-client (the container injected into target pods) |
aapm-client isn't installed as a separate Helm release. It is injected into target pods by the kron-aapm-sidecar chart, and its image is controlled by the sidecarImage.* values of that chart.
kron-aapm-sidecar registers cluster-scoped resources (ClusterRole, ClusterRoleBinding, MutatingWebhookConfiguration). Therefore only one instance of this chart can run per cluster. A second installation will fail or silently conflict on identically named cluster-scoped objects.
Inspecting Chart Versions and Default Values
Before installing, list the available chart versions and review the chart defaults.
Chart Inspection Commands | |
|---|---|
Command | What it does |
helm search repo kron-pam --versions | Lists every available version of every chart in the repository, together with its APP VERSION |
helm show chart kron-pam/<chart> | Displays chart metadata, including appVersion, which supplies the default image tag |
helm show values kron-pam/<chart> | Prints the chart's complete default values.yaml — use this to discover every configurable parameter |
helm show values kron-pam/<chart> > values-default.yaml | Saves the defaults to a file so they can be edited and reused |
helm search repo kron-pam --versions
helm show chart kron-pam/kron-aapm-sidecar
helm show values kron-pam/kron-aapm-sidecarTo install a specific, pinned chart version rather than the latest one, add --version to the install command:
helm install kron-aapm-agent kron-pam/kron-aapm-agent --version <CHART_VERSION> ...Pin the chart version with --version in production environments. Without it, a later helm repo update followed by a reinstall may silently pull a newer chart with different defaults.
By default, the image tag of each chart is derived from the chart's appVersion. This is why sidecarImage.tag may need to be overridden explicitly, as described in the injector installation and Troubleshooting section.