Config
Non-secret configuration comes in through three values: variables for environment variables, env for explicit environment entries, and mountedFiles for configuration files on disk. Each is wired into every container automatically through the configure flags. For secret data, use Secrets instead.
Environment variables
variables declares key/value pairs that land in a ConfigMap named <fullname>-variables and are injected into every container as environment variables (via envFrom):
variables:
DATABASE_HOST: db.internal
LOG_LEVEL: infoInjection is controlled by configure.variables (on by default). This is the config counterpart of secrets, which uses the same mechanism for sensitive values.
The ConfigMap is a generated singleton with a flat data map, so it has no per-resource annotations key of its own; it receives the global annotations and labels only. See Annotations.
Explicit env
Use env when you need the full Kubernetes environment syntax, for example pulling a value from another secret or a field ref. It is a native env list, injected into every container:
env:
- name: LOGLEVEL
value: DEBUG
- name: DATABASE_PASSWORD
valueFrom:
secretKeyRef:
name: database
key: passwordenv is controlled by configure.env (on by default).
Mounted files
mountedFiles mounts configuration files into containers. A key that starts with / is an absolute path; anything else is mounted under /config:
mountedFiles:
"supervisord.conf": |
[supervisord]
nodaemon=true
"/etc/app/config.yaml": |
server:
port: 8080Store the content directly, or set it from a file at install time:
helm install myapp hosst/standard \
--set-file mountedFiles.'/etc/supervisord/supervisord\.conf'=files/supervisord.confMounting is controlled by configure.files (on by default).
Rolling on change
Changing any variables or mountedFiles value updates a checksum annotation on the deployment pod template, so the pods roll to pick up the new configuration. A chart or app version bump on its own does not roll them. See Annotations.
Opting a container out
Every configure flag can be turned off per container to stop the automatic injection:
configure:
variables: true # pod default
deployments:
app:
containers:
app:
# inherits configure.variables: true → gets the ConfigMap
sidecar:
configure:
variables: false # this container gets no variablesSee Conventions for how configure cascades from chart to pod to container.