app-template Helm Chart

SkillCloud & infra

Deploy applications using bjw-s/app-template Helm chart - a flexible chart for helmifying container images without dedicated charts.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the app-template Helm Chart skill

What this skill tells your AI

The instructions your AI receives, as published by ionfury/homelab in .claude/skills/app-template/SKILL.md and read by ahel’s review.

The bjw-s/app-template chart deploys containerized applications without requiring a dedicated Helm chart. It provides a declarative interface for common Kubernetes resources.

Chart source: oci://ghcr.io/bjw-s-labs/helm/app-template Schema: https://raw.githubusercontent.com/bjw-s-labs/helm-charts/app-template-4.6.0/charts/other/app-template/values.schema.json

Quick Start

Minimal values.yaml for a single-container deployment:

# yaml-language-server: $schema=https://raw.githubusercontent.com/bjw-s-labs/helm-charts/app-template-4.6.0/charts/other/app-template/values.schema.json
controllers:
  main:
    containers:
      main:
        image:
          repository: nginx
          tag: latest

service:
  main:
    controller: main
    ports:
      http:
        port: 80

Security Context

Namespace Security LevelRequired
restricteddefaultPodOptions.securityContext with runAsNonRoot: true + seccompProfile: RuntimeDefault; every container needs allowPrivilegeEscalation: false, capabilities.drop: ["ALL"], readOnlyRootFilesystem: true
baselinedefaultPodOptions.securityContext with runAsUser/fsGroup recommended
privilegedNone required

task k8s:validate does NOT catch PodSecurity violations — only admission time reveals them. If an image runs as root, set runAsUser: 65534. If the app writes to the filesystem, use writable emptyDir mounts rather than disabling readOnlyRootFilesystem.

Resource Limits

Resource limits prevent runaway processes, not bin-packing. The homelab hardware is heavily over-provisioned — be generous with limits rather than running tight to avoid OOMKills and CrashLoopBackOff. Never set CPU limits unless the workload is genuinely CPU-abusive.

Workload TypeMemory RequestMemory Limit
Lightweight sidecar (gluetun, oauth2-proxy)64Mi256Mi
Web application128-256Mi512Mi-1Gi
Media application (qbittorrent, jellyfin)512Mi2-4Gi
Database (CNPG)256Mi1-2Gi

Flux HelmRelease Integration

For this homelab, app-template deploys via Flux ResourceSet. Add to kubernetes/platform/helm-charts.yaml:

- name: "my-app"
  namespace: "default"
  chart:
    name: "app-template"
    version: "4.6.0"
    url: "oci://ghcr.io/bjw-s-labs/helm"  # Note: OCI registry
  dependsOn: [cilium]

Values go in kubernetes/platform/charts/my-app.yaml.

References

  • references/values-reference.md — complete field reference with all YAML examples
  • references/patterns.md — real-world deployment examples (Vaultwarden, Home Assistant, etc.)

Signals

GitHub stars
25
Forks
3
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
app-template
Source
github.com/ionfury/homelab