Skip to main content
Helm is the recommended method for standard Kubernetes installations of Pangolin and Newt. Use Helm when you want a chart-based workflow for installing, upgrading, rolling back, and removing releases from your cluster.

Helm repository setup

Add the Fossorial Helm chart repository:
Search for available charts:
The classic Helm repository flow is the default path for most installations:

Installation overview

A typical Helm installation flow looks like this:
1

Create namespace and labels

Create the namespace manually and apply required labels or annotations.
2

Prepare values files

Create a values.yaml file for each release (values-pangolin.yaml, values-newt.yaml).
3

Install with Helm

Install with helm upgrade --install to support first install and future updates with the same command.
4

Verify release and resources

Confirm Helm release status and Kubernetes resources after deployment.
It is recommended to create the namespace explicitly before installation. This allows you to apply Pod Security Admission labels, policy labels, annotations, or other cluster-specific metadata before the chart creates workloads.
For detailed installation steps, see:

Install command patterns

Namespace preparation

Create the namespace before installing the chart:
If your cluster uses Pod Security Admission or namespace-based policies, apply the required labels before installation. Example:
Pangolin deployments that include Gerbil require permissions that are not compatible with a restricted namespace profile, because Gerbil manages WireGuard and requires capabilities such as NET_ADMIN.
For more details, see Prerequisites.

Install with a values file

Both charts use values files for configuration. Pangolin example:
Newt example:
Using helm upgrade --install keeps the command usable for both the first installation and later configuration changes.
Do not use --create-namespace if you need custom namespace labels or annotations. Create the namespace first and then run Helm against that namespace.

Values and configuration

Keep reusable configuration in a values file:
Use --set only for small tests or temporary overrides:
Common value sources:
  • values-pangolin.yaml for Pangolin.
  • values-newt.yaml for Newt.
  • Kubernetes Secrets for credentials.
  • Existing cluster resources such as TLS secrets, StorageClasses, or ingress controllers.
Full configuration options are documented here:

Artifact Hub and chart discovery

The Fossorial charts can be installed from the Fossorial Helm repository:
Artifact Hub can also be used to discover published chart metadata, available versions, install commands, and repository information.
Always verify the chart name, chart version, and repository URL before copying install commands into production.

OCI-based charts

OCI is not a separate installation method. It only changes where Helm pulls the chart from. For Pangolin and Newt, OCI chart publishing is available in GHCR:
  • Newt: oci://ghcr.io/fosrl/helm-charts/newt
  • Pangolin: oci://ghcr.io/fosrl/helm-charts/pangolin
You still use Helm in the same way: choose a chart, select a version, provide values, and install the release.

Pull OCI charts

Newt example:
Pangolin example:

Install from OCI

Newt example:
Pangolin example:
Use the classic Helm repository when you want the normal helm repo add and helm search repo workflow. Use OCI when you want to pull charts directly from GHCR or when your deployment tooling expects OCI chart references.

Upgrade and maintenance

Update the classic Helm repository

This step is only needed when using the classic Helm repository. OCI installs pull the chart by OCI reference and version.

Upgrade Pangolin

Classic Helm repository:
OCI:

Upgrade Newt

Classic Helm repository:
OCI:

Check release status

View rendered manifests

View applied values

Roll back a release

Uninstall a release

Uninstalling a Helm release does not always remove persistent volumes, externally managed secrets, DNS records, certificates, or cloud load balancers. Review the namespace and related cluster resources before deleting data.

Troubleshooting

For component-specific troubleshooting, see: Useful Helm commands:
Useful Kubernetes commands:

Next steps

Pangolin Helm Install

Install Pangolin with the Helm chart.

Site (Newt) Helm Install

Install Site (Newt) with the Helm chart.

Pangolin Configuration

Configure Pangolin chart values for your cluster.

Newt Configuration

Configure Newt chart values and credentials.

Argo CD

Deploy the charts with Argo CD.

Flux

Deploy the charts with Flux.