nuc-common is the shared Helm library chart used by nxs-universal-chart and related charts.
The library exposes merged annotation helpers to keep rendered manifests deterministic and avoid duplicate YAML keys:
helpers.app.defaultHookAnnotationshelpers.app.hooksAnnotationshelpers.app.annotationshelpers.securityContexthelpers.serviceAccounts.imagePullSecretshelpers.workloads.podAnnotations
- If
generic.hookAnnotationsis not defined, the historical default hook annotations are emitted:helm.sh/hook: "pre-install,pre-upgrade"helm.sh/hook-weight: "-999"helm.sh/hook-delete-policy: before-hook-creation
- If
generic.hookAnnotationsis defined asnull, default hook annotations are disabled. - If
generic.hookAnnotationsis defined as a map, that map is rendered throughtpland used as the default hook annotation set.
helpers.app.annotations merges sources in this order, with later values overriding earlier ones:
- Default hook annotations when enabled
- Fixed annotations passed by the caller
generic.annotations- GitOps annotations
general.annotations- Resource-level
annotations - Extra annotations passed by the caller
helpers.workloads.podAnnotations applies the same no-duplicate merge model for checksum annotations and pod-level annotation maps.
helpers.securityContext renders pod/container security contexts with support for generic defaults:
generic.podSecurityContextis used for workload-level pod specs.generic.containerSecurityContextis used for containers and initContainers.- If a specific
securityContextsetsmergeWithGeneric: true, generic keys are merged first and the specific keys override them. - Otherwise, a specific
securityContextreplaces the generic default.
helpers.workloads.envsFrom renders envFrom entries from envConfigmaps, envSecrets, and raw envFrom values defined on a container or workload-family general defaults object.
- Multiple
envConfigmapsandenvSecretsentries are preserved in order. - Empty strings and
nullitems are skipped. - If no valid entries remain, the
envFromblock is omitted.
helpers.serviceAccounts.imagePullSecrets renders generated ServiceAccount.imagePullSecrets from:
serviceAccountDefaultImagePullSecretNameserviceAccountGeneral.imagePullSecretsserviceAccount.<name>.imagePullSecrets
Supported shape:
includePlatformDefault: true|falseadditional: [{name: regcred}]or["regcred"]
The helper also deduplicates repeated secret names after tpl rendering.
Typed volumes now support type: projected with a raw sources array rendered through tpl, for example:
volumes:
- name: projected-auth
type: projected
sources:
- serviceAccountToken:
path: token
- secret:
name: '{{ include "helpers.app.fullname" (dict "name" "secret-envs" "context" $) }}'