All skills
akin-ozer avatar

/helm-validator

@1b2342a

Validate, lint, audit, check Helm charts — Chart.yaml, templates, values.yaml, CRDs, schemas.

Use this Skill: https://skilld.dev/gh/akin-ozer/cc-devops-skills/helm-validator

This session only. Nothing lands on disk.

testtest-workload-chartREADME.md

≈930 tokens on demand. Your agent reads this file only when SKILL.md points to it.

test-workload-chart

A test Helm chart with intentional Stage 9 security violations for use with the helm-validator skill.

Purpose

This chart exists to exercise and demonstrate the mandatory Stage 9 Security Best Practices Check in the helm-validator skill workflow. It renders a valid Deployment that deliberately omits every security control the skill is expected to flag.

Do NOT deploy this chart to any environment.

Intentional Violations

Violation Location Expected Finding
:latest image tag values.yaml → image.tag Stage 9: image tag issue
Missing pod-level securityContext templates/deployment.yaml → spec.template.spec Stage 9: missing runAsNonRoot, runAsUser, fsGroup
Missing container-level securityContext templates/deployment.yaml → spec.template.spec.containers[0] Stage 9: missing allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities.drop: [ALL]
Missing resources block templates/deployment.yaml → spec.template.spec.containers[0] Stage 9: no CPU/memory limits or requests
Missing livenessProbe templates/deployment.yaml → spec.template.spec.containers[0] Stage 9: no liveness probe
Missing readinessProbe templates/deployment.yaml → spec.template.spec.containers[0] Stage 9: no readiness probe

Running the Validation

# From the helm-validator skill directory:

# Automated regression check (recommended)
bash test/test_stage9_workload.sh

# Stage 2: Structure check
bash scripts/validate_chart_structure.sh test/test-workload-chart

# Stage 3: Helm lint
helm lint test/test-workload-chart --strict

# Stage 4: Render templates
helm template test-release test/test-workload-chart --output-dir /tmp/workload-rendered

# Stage 5: YAML lint
find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) \
  -exec yamllint -c assets/.yamllint {} +

# Stage 6: CRD detection (expect: no CRDs)
find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) \
  -exec bash scripts/detect_crd_wrapper.sh {} +

# Stage 7: Schema validation
find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) -exec \
  kubeconform \
    -schema-location default \
    -summary -verbose \
    {} +

# Stage 9: Security check — all of the following should flag issues:
find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) \
  -exec grep -l "securityContext" {} +
# Expected: no output (no securityContext in any file)

find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) \
  -exec grep -l "resources:" {} +
# Expected: no output (no resources block)

find /tmp/workload-rendered -type f \( -name "*.yaml" -o -name "*.yml" \) \
  -exec grep "image:.*:latest" {} +
# Expected: matches nginx:latest in deployment.yaml

# Optional profile check: override tag and verify :latest is removed
helm template test-release test/test-workload-chart \
  -f test/test-workload-chart/values-pinned-tag.yaml \
  --output-dir /tmp/workload-rendered-pinned

Expected Stage 9 Report

| Check | Status | Detail |
|-------|--------|--------|
| Pod securityContext | ❌ Missing | runAsNonRoot, runAsUser, fsGroup absent |
| Container securityContext | ❌ Missing | allowPrivilegeEscalation, readOnlyRootFilesystem, capabilities.drop absent |
| Resource limits/requests | ❌ Missing | No cpu/memory limits or requests defined |
| Image tag | ❌ Warning | nginx:latest — pin to a specific version |
| Liveness probe | ❌ Missing | No livenessProbe defined |
| Readiness probe | ❌ Missing | No readinessProbe defined |

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    This skill provides a validation workflow for Helm charts, including structure checks, linting, and security audits. It references official installation scripts for well-known tools like Helm and cert-manager. The skill processes user-provided chart data, representing an indirect injection surface.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 1b2342a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago

README badge

README badge for akin-ozer/cc-devops-skills/helm-validator