// the find
databus23/helm-diff
A helm plugin that shows a diff explaining what a helm upgrade would change
A Helm plugin that renders what a `helm upgrade`, `rollback`, or revision-to-revision change would actually do, by diffing the currently deployed manifests against a freshly rendered chart. It's for anyone who deploys via Helm and is tired of finding out what changed only after it's already applied — mature, widely used (3.5k stars), and effectively the standard tool for this.
The three-way-merge mode is unusually honestly documented: the README lists four specific, named scenarios where client-side merging diverges from what the API server would actually do (dropped defaults in atomic lists, hidden drift in retainKeys structs, fields unknown to the compiled-in k8s libraries), instead of just claiming it works. Structured JSON output with JSON Pointer paths per field change makes this usable in CI pipelines, not just interactive terminals. External diff tool support (delta, difft, git diff) means you're not stuck with the built-in renderer. GPG-signed provenance artifacts for Helm 4 plugin verification shows someone's thought about supply-chain integrity, not just features.
Installation is a mess of four different paths (plugin manager, offline tarball with a magic env var, pre-2.3.0 manual unpack, from-source) that reads like a decade of accumulated compatibility hacks rather than one clean flow — expect to read carefully before it works in an air-gapped environment. The client-side three-way-merge is a structural diff of rendered YAML, not a semantic one: it has no idea whether a changed field is safe, just that it changed, so it will happily flag noise alongside real risk. Read-only RBAC for the three-way-merge still needs `get`+`list` on every kind the chart renders including ones only rendered conditionally — miss one and the diff just fails on that resource rather than degrading gracefully. It's a preview tool, not a policy tool: nothing here stops someone from ignoring the diff and applying anyway.