如何通过GitHub Actions将Helm Chart推送至ECR?
Got it, let's break down how to push your Helm Chart to Amazon ECR using GitHub Actions. I’ve set up similar workflows multiple times, so I’ll walk you through each step with concrete examples and best practices.
Prerequisites
First, make sure you have these things sorted:
- An AWS IAM user with permissions to interact with ECR: specifically
ecr:CreateRepository,ecr:GetAuthorizationToken,ecr:BatchCheckLayerAvailability,ecr:GetDownloadUrlForLayer,ecr:BatchGetImage,ecr:InitiateLayerUpload,ecr:UploadLayerPart,ecr:CompleteLayerUpload, andecr:PutImage. - Store your AWS credentials (
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY) as GitHub Secrets in your repository (go to Settings > Secrets and variables > Actions > New repository secret). - A valid Helm Chart in your repo (with a
Chart.yamlfile that defines the name and version). - Helm 3.8+ installed locally if you want to test, but the workflow will handle installing Helm for you.
Complete GitHub Actions Workflow
Here’s a ready-to-use workflow YAML file (save it as .github/workflows/push-helm-to-ecr.yml):
name: Push Helm Chart to Amazon ECR # Trigger the workflow on pushes to main or tag creation on: push: branches: [ main ] tags: [ 'v*' ] # Triggers on tags like v1.0.0 jobs: build-and-push: runs-on: ubuntu-latest steps: # Step 1: Check out your repository code - name: Checkout code uses: actions/checkout@v4 with: fetch-depth: 0 # Required to access git tags for versioning # Step 2: Configure AWS credentials for ECR access - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v4 with: aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-region: us-east-1 # Replace with your AWS region (e.g., eu-west-1) # Step 3: Log in to Amazon ECR - name: Login to Amazon ECR id: login-ecr uses: aws-actions/amazon-ecr-login@v2 # Step 4: Install Helm in the runner environment - name: Set up Helm uses: helm/setup-helm@v3 with: version: v3.12.0 # Optional: Specify your preferred Helm version (3.8+ required for OCI) # Step 5: Create ECR repository if it doesn't exist - name: Ensure ECR repository exists run: | REPO_NAME=my-helm-chart # Replace with your chart/repository name # Check if repo exists; create it if not aws ecr describe-repositories --repository-names $REPO_NAME || aws ecr create-repository --repository-name $REPO_NAME # Step 6: Package your Helm Chart into a TGZ file - name: Package Helm Chart id: package-chart run: | CHART_DIR=./charts/my-helm-chart # Replace with the path to your chart directory # Use git tag as version if available, else default to 0.1.0 VERSION=$(git describe --tags --abbrev=0 2>/dev/null || echo "0.1.0") # Package the chart with the determined version helm package $CHART_DIR --version $VERSION --app-version $VERSION # Output the path to the packaged chart for the next step echo "chart_path=$(find . -name "*.tgz")" >> $GITHUB_OUTPUT # Step 7: Push the packaged chart to ECR (using OCI format) - name: Push Helm Chart to ECR run: | REGISTRY=${{ steps.login-ecr.outputs.registry }} REPO_NAME=my-helm-chart # Match the repo name from step 5 CHART_PATH=${{ steps.package-chart.outputs.chart_path }} # Push using OCI protocol (ECR supports this natively) helm push $CHART_PATH oci://$REGISTRY/$REPO_NAME
Key Explanations & Best Practices
Let’s go through the important parts:
- OCI Format: ECR supports storing Helm Charts as OCI artifacts (this is the modern, recommended approach). Helm 3.8+ added support for pushing/pulling OCI packages, so we use
oci://in the push command. - Versioning: The workflow uses git tags as the chart version if available (e.g., a tag
v1.0.0will package the chart asmy-helm-chart-1.0.0.tgz). If no tags exist, it falls back to0.1.0. You can adjust this logic to fit your versioning strategy. - Automatic Repository Creation: The
Ensure ECR repository existsstep checks if your target repo exists in ECR; if not, it creates it. This avoids manual setup steps. - GitHub Secrets: Never hardcode AWS credentials in your workflow—always use GitHub Secrets to keep them secure.
Verifying the Push
After the workflow runs successfully:
- Go to the Amazon ECR console and navigate to your repository.
- You’ll see your Helm Chart listed under OCI artifacts.
- To test pulling the chart locally, run:
helm pull oci://<your-ecr-registry-url>/my-helm-chart --version <chart-version>
内容的提问来源于stack exchange,提问作者GuardianAngel
相关产品推荐
相关产品推荐

