Skip to content

ci(helm): add Helm chart release workflow to GHCR - #864

Merged
slin1237 merged 2 commits into
mainfrom
ci/helm-release-workflow
Mar 22, 2026
Merged

slin1237 merged 2 commits into
mainfrom
ci/helm-release-workflow

Conversation

@slin1237

@slin1237 slin1237 commented Mar 22, 2026 •

Copy link
Copy Markdown
Member

Description

Problem

The Helm chart had no automated release pipeline. The chart version was stuck at 0.1.0 while the app version was 1.3.3. Users had no way to install the chart from a registry — they had to clone the repo.

Solution

Add a GitHub Actions workflow that packages and publishes the Helm chart to GitHub Container Registry (OCI) on every release, using the same version source as PyPI and Docker (bindings/python/pyproject.toml).

Changes

  • .github/workflows/release-helm.yml — New workflow:
    • Triggers on pyproject.toml changes to main (same as PyPI/Docker)
    • Reads version from pyproject.toml, syncs Chart.yaml at build time
    • Lints → packages → pushes to oci://ghcr.io/lightseekorg/charts/smg
    • Writes install instructions to GitHub Actions job summary
  • deploy/helm/smg/Chart.yaml — Chart version 0.1.0 → 1.3.3
  • scripts/check_release_versions.sh — Added helm type with getter/setter, Chart.yaml tracked in SMG_VERSION_SYNC array so version drift is caught during pre-release checks

Test Plan

  • Verified check_release_versions.sh detects helm chart version correctly:
    ✓ helm chart (deploy/helm/smg/Chart.yaml) — v1.3.3
    
  • Workflow uses azure/setup-helm@v4 and standard helm package / helm push OCI flow
  • Chart lint runs before publish to catch template errors

After merge, users can install via:

helm install smg oci://ghcr.io/lightseekorg/charts/smg --version 1.3.3
Checklist
  • CI workflow added
  • Chart version synced to SMG release version
  • Version check script updated
  • (Optional) Please join us on Slack #sig-smg to discuss, review, and merge PRs

Summary by CodeRabbit

  • New Features

    • Added an automated workflow to package and publish the Helm chart to the container registry and surface a release summary.
  • Chores

    • Bumped Helm chart version to 1.3.3.
    • Extended automated version-sync tooling to include Helm charts and enforce matching chart version/appVersion.

Add automated Helm chart packaging and publishing to GitHub Container
Registry (OCI), triggered when bindings/python/pyproject.toml changes
on main (same trigger as PyPI and Docker releases).

What changed:
- .github/workflows/release-helm.yml: new workflow that reads version
  from pyproject.toml, syncs Chart.yaml version+appVersion at build
  time, lints, packages, and pushes to oci://ghcr.io/lightseekorg/charts
- deploy/helm/smg/Chart.yaml: bump chart version from 0.1.0 to 1.3.3
  to match the current SMG release version
- scripts/check_release_versions.sh: add helm chart type with
  getter/setter functions, track Chart.yaml in SMG_VERSION_SYNC so
  future releases auto-detect version drift

Why:
The Helm chart had no release pipeline — it was committed and versioned
manually. Chart version (0.1.0) was out of sync with the app version
(1.3.3). This aligns the chart release with the existing PyPI/Docker
release pattern: version sourced from pyproject.toml, published on
push to main.

Install after publish:
  helm install smg oci://ghcr.io/lightseekorg/charts/smg --version 1.3.3

Signed-off-by: Simo Lin <linsimo.mark@gmail.com>
@github-actions github-actions Bot added the ci CI/CD configuration changes label Mar 22, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses the lack of an automated release pipeline for the Helm chart, which previously led to outdated chart versions and manual installation processes. By implementing a new GitHub Actions workflow, the Helm chart's release process is now fully automated, ensuring that it is consistently packaged and published to GHCR with synchronized versioning. This enhancement streamlines the deployment experience for users by providing an official registry for chart installation and maintaining version consistency across components.

Highlights

  • Automated Helm Chart Release Workflow: A new GitHub Actions workflow (.github/workflows/release-helm.yml) has been introduced to automate the packaging and publishing of the Helm chart to GitHub Container Registry (GHCR) upon releases. This workflow triggers on pyproject.toml changes to main, reads the version from pyproject.toml, syncs Chart.yaml at build time, lints, packages, and pushes the chart to oci://ghcr.io/lightseekorg/charts/smg.
  • Helm Chart Version Update: The deploy/helm/smg/Chart.yaml file has been updated to reflect the current application version, changing the chart version from 0.1.0 to 1.3.3.
  • Version Synchronization Script Enhancement: The scripts/check_release_versions.sh script has been extended to include support for Helm charts. It now features a helm type with dedicated getter and setter functions for Chart.yaml, ensuring that the Helm chart's version is tracked within the SMG_VERSION_SYNC array to prevent version drift during pre-release checks.
Ignored Files
  • Ignored by pattern: .github/workflows/** (1)
    • .github/workflows/release-helm.yml
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@coderabbitai

coderabbitai Bot commented Mar 22, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 050ae9ff-3354-44cd-9c47-34d76e13b358

📥 Commits

Reviewing files that changed from the base of the PR and between 63a4a26 and 11db868.

📒 Files selected for processing (2)
  • .github/workflows/release-helm.yml
  • scripts/check_release_versions.sh

📝 Walkthrough

Walkthrough

Adds a GitHub Actions workflow to publish an OCI-packaged Helm chart (syncing version from Python pyproject), updates Chart.yaml version, and extends the release-version check script to read/update Helm chart version/appVersion.

Changes

Cohort / File(s) Summary
GitHub Actions Release Workflow
.github/workflows/release-helm.yml
New workflow: triggers on pushes to main when bindings/python/pyproject.toml changes or via manual dispatch; extracts semver from bindings/python/pyproject.toml, updates deploy/helm/smg/Chart.yaml (version & appVersion), lints, packages chart, logs into GHCR with GITHUB_TOKEN, and pushes to oci://ghcr.io/<repo_owner>/charts.
Helm Chart Metadata
deploy/helm/smg/Chart.yaml
Chart version updated from 0.1.0 → 1.3.3 (appVersion remains 1.3.3).
Version Synchronization Tooling
scripts/check_release_versions.sh
Added helm entry to sync registry; added get_helm_chart_version() and set_helm_chart_version() to read/update Chart.yaml version and appVersion; extended mismatch detection and auto-fix loop to handle Helm charts.

Sequence Diagram

sequenceDiagram
    participant GitHub as GitHub Push
    participant Actions as GitHub Actions (release-helm.yml)
    participant Repo as Repository (pyproject.toml)
    participant Helm as Chart.yaml
    participant GHCR as GHCR OCI Registry

    GitHub->>Actions: Trigger (push to main or manual)
    Actions->>Repo: Read bindings/python/pyproject.toml
    Repo-->>Actions: Return semver (e.g., 1.3.3)
    Actions->>Helm: Update Chart.yaml version & appVersion
    Helm-->>Actions: Confirm Chart.yaml updated
    Actions->>Actions: Lint and package chart (.helm-pkg/)
    Actions->>GHCR: Login with GITHUB_TOKEN
    Actions->>GHCR: Push packaged chart to OCI
    GHCR-->>Actions: Acknowledge publish
    Actions->>Actions: Append release summary to step summary
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • CatherineSue
  • key4ng
  • gongwei-130
  • XinyueZhang369

Poem

🐰 I hopped through files with nimble feet,

Chart and pyproject now perfectly meet,
A helm packaged parcel, tidy and neat,
Pushed to GHCR — a release treat! 🎉

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'ci(helm): add Helm chart release workflow to GHCR' directly and clearly describes the main change—adding a new GitHub Actions workflow for publishing Helm charts to GitHub Container Registry.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/helm-release-workflow

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a GitHub Actions workflow to automate the release of the Helm chart to GHCR. The changes include the new workflow file, updating the Helm chart version, and modifying the check_release_versions.sh script to support version synchronization for the Helm chart. The changes look good overall. I've added a couple of suggestions to improve the robustness of the shell script logic for parsing and updating the Chart.yaml file by making it more tolerant to whitespace variations, aligning with the rule to ensure accurate and robust handling of external resource versions.

Comment on lines +366 to +369
get_helm_chart_version() {
local file="$1"
grep -m1 '^version:' "$file" | sed 's/version: *//'
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The current implementation using grep and sed can be brittle. It may not correctly parse the version if there is extra whitespace after the colon, or if the version value is quoted. Using awk can make this parsing more robust.

This awk command correctly parses the version regardless of the amount of whitespace after the colon and strips optional quotes from the value. This is more robust and consistent with how other version-extraction functions in this script handle quotes.

Suggested change
get_helm_chart_version() {
local file="$1"
grep -m1 '^version:' "$file" | sed 's/version: *//'
}
get_helm_chart_version() {
local file="$1"
awk -F':[[:space:]]*' '/^version:/ {gsub(/"/, "", $2); print $2; exit}' "$file"
}
References
  1. Ensuring robust parsing and manipulation of version numbers in scripts is critical for maintaining accuracy and preventing build failures related to incorrect version identification or updates.

Comment on lines +372 to +384
set_helm_chart_version() {
local file="$1"
local old_version="$2"
local new_version="$3"
local escaped_old
escaped_old=$(escape_version "$old_version")
sed_inplace "s/^version: ${escaped_old}/version: ${new_version}/" "$file"
sed_inplace "s/^appVersion: \"${escaped_old}\"/appVersion: \"${new_version}\"/" "$file"
if ! grep -q "^version: ${new_version}" "$file"; then
echo -e " ${RED}FAILED to update $file${NC}" >&2
return 1
fi
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The sed commands and the final grep check in this function assume a specific amount of whitespace around the colon in version: and appVersion: lines. This is brittle and may fail if the file formatting changes (e.g., more spaces are added). The logic should handle any amount of whitespace to make the script more robust.

This change uses [[:space:]]* to match any amount of whitespace and uses a capture group with a back-reference to preserve the original spacing, making the update more robust. The final check is also updated to be whitespace-agnostic.

Suggested change
set_helm_chart_version() {
local file="$1"
local old_version="$2"
local new_version="$3"
local escaped_old
escaped_old=$(escape_version "$old_version")
sed_inplace "s/^version: ${escaped_old}/version: ${new_version}/" "$file"
sed_inplace "s/^appVersion: \"${escaped_old}\"/appVersion: \"${new_version}\"/" "$file"
if ! grep -q "^version: ${new_version}" "$file"; then
echo -e " ${RED}FAILED to update $file${NC}" >&2
return 1
fi
}
set_helm_chart_version() {
local file="$1"
local old_version="$2"
local new_version="$3"
local escaped_old
escaped_old=$(escape_version "$old_version")
sed_inplace "s/^\(version:[[:space:]]*\)${escaped_old}/\1${new_version}/" "$file"
sed_inplace "s/^\(appVersion:[[:space:]]*\)\"${escaped_old}\"$/\1\"${new_version}\"/" "$file"
if ! grep -q "^version:[[:space:]]*${new_version}" "$file"; then
echo -e " ${RED}FAILED to update $file${NC}" >&2
return 1
fi
}
References
  1. Ensuring robust parsing and manipulation of version numbers in scripts is critical for maintaining accuracy and preventing build failures related to incorrect version identification or updates.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release-helm.yml:
- Around line 15-23: Add a workflow-level concurrency block to the release job
(jobs.release / name: Package and push Helm chart) to prevent parallel/retried
runs from pushing the same chart; add a concurrency key (e.g. concurrency:
group: ${{ github.repository }}-helm-${{ github.ref }} cancel-in-progress: true)
so only one release for a given ref/branch runs at a time and in-progress runs
are canceled.
- Around line 26-31: The "Determine version" step extracts VERSION from
bindings/python/pyproject.toml but doesn't fail if parsing yields empty/invalid
output; change the step so after computing VERSION (the shell variable VERSION
in the Determine version step) you validate it (non-empty and optionally matches
a semver regex), and if invalid print an error to stderr and exit non-zero
(e.g., echo "Failed to parse version from pyproject.toml" >&2; exit 1), only
write "version=${VERSION}" to $GITHUB_OUTPUT and echo the Using version message
when the check passes.

In `@scripts/check_release_versions.sh`:
- Around line 379-383: The current sed_inplace call only replaces appVersion
when it exactly matches the old escaped value and the subsequent check only
verifies "version:", allowing appVersion to remain stale; change the update to
unconditionally replace the appVersion line (match appVersion: ".*") so it gets
set to "${new_version}", and adjust the verification to assert both
"^appVersion: \"${new_version}\"" and "^version: ${new_version}" are present
(i.e., add a grep check for appVersion after sed_inplace and fail if it doesn't
match) to ensure both fields are synced; refer to the existing sed_inplace
invocation and the grep check for "version:" in this block.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 462be764-5f15-4dc0-b523-85d32b323e60

📥 Commits

Reviewing files that changed from the base of the PR and between cbb01db and 63a4a26.

📒 Files selected for processing (3)
  • .github/workflows/release-helm.yml
  • deploy/helm/smg/Chart.yaml
  • scripts/check_release_versions.sh

Comment thread .github/workflows/release-helm.yml
Comment thread .github/workflows/release-helm.yml
Comment thread scripts/check_release_versions.sh Outdated
- Workflow: add concurrency group to prevent duplicate chart publish
  races from parallel/retried runs
- Workflow: validate parsed version against semver regex, fail fast
  if pyproject.toml parsing returns empty or invalid output
- Script: use awk for robust Chart.yaml version parsing, handles
  varying whitespace and optional quotes
- Script: set_helm_chart_version now unconditionally replaces
  appVersion (handles drift) and verifies both version and appVersion
  after update

Signed-off-by: Simo Lin <linsimo.mark@gmail.com>
@slin1237
slin1237 merged commit c899736 into main Mar 22, 2026
28 checks passed
@slin1237
slin1237 deleted the ci/helm-release-workflow branch March 22, 2026 06:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant