Manifests (Kubernetes)
Use extraManifests to render arbitrary Kubernetes resources alongside the chart's own resources. It covers anything the chart does not support natively: RBAC, ExternalSecrets, NetworkPolicies, CRDs, or one-off objects that belong with the release.
There are two modes. Pass a map to let the chart name and label each resource for you, or a list to keep full control.
Dict mode (recommended)
The key becomes the resource name, using the same naming rules as every other resource in the chart. metadata.name, metadata.namespace, and metadata.labels are injected automatically, so a resource only needs its kind and spec:
extraManifests:
allow-ingress:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
spec:
podSelector: {}
ingress:
- from:
- podSelector:
matchLabels:
app.kubernetes.io/name: frontendFor a release named test, that renders as:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: test-allow-ingress
namespace: default
labels:
app.kubernetes.io/instance: test
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: test
app.kubernetes.io/version: 4.5.6
helm.sh/chart: standard-1.2.3
spec:
podSelector: {}
ingress:
- from:
- podSelector:
matchLabels:
app.kubernetes.io/name: frontendAnything you set yourself wins. Auto-injected values only fill the gaps, so you can override the name or add labels while the chart supplies the rest:
extraManifests:
custom-config:
apiVersion: v1
kind: ConfigMap
metadata:
name: my-own-name # overrides the auto-generated name
labels:
extra-label: "true" # merged with the chart's standard labels
data:
key: valueList mode
Pass a list when you want full control and no auto-injected metadata. Each entry is rendered as-is, so you own metadata.name, the namespace, and the labels:
extraManifests:
- apiVersion: v1
kind: ServiceAccount
metadata:
name: custom-sa
namespace: kube-system
annotations:
eks.amazonaws.com/role-arn: "arn:aws:iam::123456789012:role/myapp"
- apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: pod-reader
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]Templating
Both modes run each resource through tpl, so you can reference chart values and built-ins. This is the way to tie an extra resource back to the release's generated names:
extraManifests:
- apiVersion: v1
kind: ServiceAccount
metadata:
name: "{{ include "standard.fullname" . }}-custom"
annotations:
eks.amazonaws.com/role-arn: arn:aws:iam::123456789012:role/myappSee Helpers for the template functions available inside these expressions.