Safe Helm Deploy
SkillCloud & infraSafe Helm deployment with image verification, cache busting, and rollback safety. Prevents deploying stale images.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Safe Helm Deploy skill
What this skill tells your AI
The instructions your AI receives, as published by thelobbi/claude in .claude/skills/helm-deploy/SKILL.md and read by ahel’s review.
Deploy via Helm with image verification: $ARGUMENTS
Pre-Deploy Checklist
-
Verify the image exists in the registry
# ACR az acr repository show-tags --name <registry> --repository <image> --orderby time_desc --top 5 # Docker Hub docker manifest inspect <registry>/<image>:<tag> -
Check what's currently running
helm list -n <namespace> kubectl get pods -n <namespace> -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.containers[*]}{.image}{"\n"}{end}{end}' -
Diff the changes before applying
helm diff upgrade <release> <chart> -n <namespace> \ --set image.tag=<new-tag> \ --set image.pullPolicy=Always \ -f values.yaml
Deploy Command Template
helm upgrade --install <release> <chart> \
--namespace <namespace> \
--set image.repository=<registry>/<image> \
--set image.tag=<specific-tag> \
--set image.pullPolicy=Always \
--atomic \
--wait \
--timeout 5m \
-f values.yaml
Post-Deploy Verification
# Verify new pods are running
kubectl rollout status deployment/<deployment> -n <namespace>
# Verify the correct image is running
kubectl get pods -n <namespace> -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.containers[*]}{.image}{"\n"}{end}{end}'
# Check pod logs for startup errors
kubectl logs -l app=<app> -n <namespace> --tail=50
Rollback (if needed)
helm rollback <release> -n <namespace>
# Or to a specific revision:
helm history <release> -n <namespace>
helm rollback <release> <revision> -n <namespace>
Critical Rules
- ALWAYS use
--set image.tag=<specific>with a unique tag (git SHA, semver) - ALWAYS use
--set image.pullPolicy=Alwaysto force fresh pulls - ALWAYS use
--atomicfor automatic rollback on failure - ALWAYS use
--waitto confirm pods are healthy - NEVER deploy with
:latestas the only tag - ALWAYS verify the image exists in registry BEFORE deploying
Signals
- GitHub stars
- 21
- Forks
- 2
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
helm-deploy- Source
- github.com/thelobbi/claude