Agent skill

Atmos Helm

by cloudposse in cloudposse/atmos

Native Helm components (experimental): Helm Go SDK rendering/apply/delete, components.helm, chart sources (local/repo/OCI), values, repositories, helm plugin, provision targets, and how this differs…

Apache-2.0Auto-check passedDevOps & Cloud

Install Atmos Helm

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-helm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-helm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-helm .claude/skills/atmos-helm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-helm
GitHub stars
1.4k
Token cost
~3.2k tokens
SKILL.md length
1,253 words
Files
1
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Native Helm components (experimental): Helm Go SDK rendering/apply/delete, components.helm, chart sources (local/repo/OCI), values, repositories, helm plugin, provision targets, and how this differs…

  • Tasks that involve Container orchestration
  • SKILL.md covers Related Skills, Native Helm vs. Helmfile, Component Shape and Commands, plus 4 more sections
  • Calls helm; reaches prometheus-community.github.io; needs HELM_REPO_PASSWORD

What it does

Atmos Helm is an agent skill from cloudposse/atmos. Native Helm components (experimental): Helm Go SDK rendering/apply/delete, components.helm, chart sources (local/repo/OCI), values, repositories, helm plugin, provision targets, and how this differs from Helmfile

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Helm, Git and Kubernetes. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “/atmos-helm”

What it can do on your machine

Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • prometheus-community.github.io

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HELM_REPO_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Helm loads about 3.2k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,253 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit 36726ae, republished under its Apache-2.0 licence (© cloudposse). 1,253 words, ~3,244 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-helm/SKILL.md (or your agent's skills folder).
name
atmos-helm
description
Native Helm components (experimental): Helm Go SDK rendering/apply/delete, components.helm, chart sources (local/repo/OCI), values, repositories, helm plugin, provision targets, and how this differs from Helmfile
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
orchestrators

Atmos Native Helm Components

Use this skill for the native Helm component type (components.helm). It deploys Helm charts — local, remote-repository, or OCI — through the Helm Go SDK, in-process. No helm or helmfile binary is required. This is a different component type than components.helmfile; see Native Helm vs. Helmfile below before choosing one.

This feature is experimental.

NeedLoad
Helmfile-based deployments (shells out to helmfile/helm)atmos-helmfile
Native Kubernetes manifests/Kustomize (no Helm charts)atmos-kubernetes
Component dependency ordering for --all/--affectedatmos-components
Secret values in values: (!secret)atmos-secrets
GitOps delivery targets (provision.targets, kind: git)atmos-git
EKS/cluster authenticationatmos-aws-eks, atmos-auth
Native CI job summariesatmos-ci

Native Helm vs. Helmfile

Native Helm (components.helm)Helmfile (components.helmfile)
ExecutionHelm Go SDK, in-processShells out to the helmfile and helm binaries
Binaries requiredNonehelmfile, helm (plus any declared helm plugins)
Multiple releases per componentOne chart/release per componentOne or more releases per helmfile.yaml
Diff engineEmbedded helm-diff library (no plugin install)helmfile diff (needs helm-diff plugin, installed via atmos helm plugin)
Valuesvalues:/values_files: merged through Atmos inheritanceVarfile generated from stack vars:
StatusExperimentalStable

Use native Helm for straightforward chart deployments where you want no external binaries and first-class GitOps delivery targets. Use Helmfile (atmos-helmfile) for existing helmfile.yaml projects, multi-release releases files, or helm-secrets/other Helm CLI plugins. atmos helm plugin manages plugins for Helmfile components (native Helm does not run Helm CLI subcommand plugins).

Declare Helmfile plugins in the component's stack configuration; Atmos ensures them before running Helmfile. See Helmfile plugin configuration for declarations and optional cache warming. Do not add a plugin installation prerequisite to native Helm commands.

When maintaining plugin support, extend the existing generic installer in pkg/helm/plugin. Let Helm run each plugin's installation hooks. Keep plugin requirements with the consuming component or engine; a built-in alias such as diff does not justify a separate downloader or shell wrapper.

Component Shape

Define Helm releases under components.helm in stack manifests:

yaml
components:
  helm:
    monitoring:
      chart: prometheus-community/kube-prometheus-stack
      version: "65.1.1"
      repositories:
        - name: prometheus-community
          url: https://prometheus-community.github.io/helm-charts
      namespace: monitoring
      values:
        grafana:
          adminPassword: !secret grafana_admin_password
      dependencies:
        components:
          - cert-manager
      provision:
        default: cluster
        targets:
          cluster:
            kind: kubernetes
          deployment-repo:
            kind: git
            repository: deployments
            path: "clusters/{{ .vars.stage }}/monitoring"

Helm components use the same stack sections as other component types — vars, env, auth, metadata, settings, dependencies, hooks, inheritance, and overrides — plus Helm-specific fields:

FieldPurpose
chart (required)Local path (., ./charts/app), repo/name reference, bare name with repository, or oci:// reference.
versionChart version constraint (repository/OCI charts).
repositoryExplicit HTTP chart repository URL for a bare chart name.
repositoriesList of chart repositories used to resolve repo/name references (name, url, basic auth, TLS files, pass_credentials_all, insecure_skip_tls_verify). Merges with global atmos.yaml components.helm.repositories; component-level entries with the same name win.
namespaceTarget Kubernetes namespace. Defaults to default.
create_namespaceWhether Helm creates the target namespace during install when missing. Defaults to true (existing behavior). Set false to install into a pre-existing namespace, e.g. when a platform owns the namespace or a namespace-scoped identity (CI) cannot create namespaces.
nameRelease name. Defaults to the component's last path segment.
valuesThe chart's values, merged through Atmos inheritance. This map is the values passed to the chart.
values_filesValue files layered underneath inline values (templated, in listed order).
renderDefault output for atmos helm template (output.path, output.split).
provisionDelivery targets for apply/deploy — the cluster (default) or an external target such as a Git deployment repository.
Chart sources
  • Local chart — path relative to the component directory (chart: ., chart: ./charts/app), or absolute.
  • Remote repository chart — repository: https://... + chart: <name>, or a repo/name reference resolved against merged global/component repositories:. Atmos adds/updates these repositories in Helm's local repository config before chart operations.
  • OCI chart — an oci:// reference (e.g. chart: oci://ghcr.io/acme/charts/app).
Values and secrets

The component values: map is the Helm values, merged through the normal Atmos import/inheritance chain. values_files: overlay templated value files underneath the inline values. Helm has no native secrets concept — Atmos provides it: secret values flow in through !secret and are masked automatically wherever they'd otherwise be printed (e.g. in atmos helm diff output).

Commands

CommandPurpose
atmos helm template <component> -s <stack>Render the chart to manifests via the Helm Go SDK (equivalent to helm template). No cluster or credentials needed. render is an alias.
atmos helm diff <component> -s <stack>Real unified diff (embedded helm-diff library — no plugin install) against a baseline. plan is an alias.
atmos helm values <component> -s <stack>Print the fully resolved chart values as formatted, masked YAML. Accepts the same Helm CLI value overrides as rendering operations.
atmos helm apply <component> -s <stack>Install or upgrade the release (helm upgrade --install), or deliver to a --target provision target.
atmos helm deploy <component> -s <stack>Alias for apply.
atmos helm delete <component> -s <stack>Uninstall the release (helm uninstall). No-op if the release does not exist.
atmos helm repo list [component] -s <stack>List declarative repository associations (global, component, or direct) and whether each is used by the resolved chart.
atmos helm plugin list / atmos helm plugin install <plugin>...Manage Helm CLI plugins in the Atmos-managed HELM_PLUGINS directory — for Helmfile components, not native Helm.

Render and lifecycle commands (template, diff, plan, apply, deploy, delete) accept --all, --affected (with --base/--ref/--sha/--repo-path/--clone-target-ref/--ssh-key/ --ssh-key-password), and --include-dependents, matching atmos describe affected semantics. --all/--affected are mutually exclusive with a positional component argument.

Show full SKILL.md (422 more words)Show less
diff baselines

atmos helm diff (alias plan) compares the freshly rendered chart against one baseline, selected by flag precedence --from-manifest → --against → deployed release:

BaselineFlagNotes
Deployed release (default)(none)Reads the cluster; a nonexistent release shows every object as added. Only mode needing cluster access.
Local manifest--from-manifest=<path>Fully offline.
Provision target--against=target[:<name>]The manifests currently published in a non-cluster provision target (e.g. Git deployment repo) — offline, git access only. Without :<name> uses provision.default.

--context=<n> controls unified-diff context lines (default 3).

Runtime value overrides

template/render, diff/plan, values, and apply/deploy accept repeatable Helm-compatible -f/--values, --set, --set-string, --set-file, --set-json, and --set-literal flags. They are invocation-only and override component values_files then inline values; use the same flags with values, diff, and apply to inspect, preview, and deploy identical inputs.

template output

atmos helm template writes multi-document YAML to stdout by default. Use --output <file> for a single file, or --output-dir <dir> (with optional --split for one file per object). --output/ --output-dir only work rendering a single component — configure render.output on the component for --all/--affected runs.

Provision Targets (GitOps delivery)

Like native Kubernetes components, apply/deploy can deliver rendered manifests to a provision target instead of the cluster — e.g. committing them to a Git deployment repository reconciled by Argo CD/Flux:

yaml
components:
  helm:
    monitoring:
      provision:
        default: cluster
        targets:
          cluster:
            kind: kubernetes
          deployment-repo:
            kind: git
            repository: deployments
            path: "clusters/{{ .vars.stage }}/monitoring"
shell
atmos helm deploy monitoring -s plat-ue2-dev --target deployment-repo

--target defaults to provision.default, otherwise the cluster. See atmos-git for the underlying git target mechanics (clone/fast-forward, provenance trailers, credentials from Atmos Auth).

atmos.yaml Configuration

yaml
components:
  helm:
    base_path: components/helm          # default: components/helm
    auto_generate_files: false          # render component `generate:` before operations
    repositories:                       # reusable chart repositories, referenced as repo-name/chart-name
      - name: prometheus-community
        url: https://prometheus-community.github.io/helm-charts
      - name: internal
        url: https://charts.example.com
        username: !env HELM_REPO_USERNAME
        password: !env HELM_REPO_PASSWORD
        pass_credentials_all: true

Repository fields: name/url (required), username/password (basic auth), pass_credentials_all, cert_file/key_file/ca_file (TLS), insecure_skip_tls_verify. Component-level repositories entries override global entries with the same name.

Native CI Summaries

When ci.enabled: true and CI is detected (or --ci/ATMOS_CI forces it), Helm commands write a Markdown step summary through Atmos native CI — summaries only (no $GITHUB_OUTPUT, commit statuses, PR comments, or artifacts):

CommandSummary template
template, renderci.templates.helm.template
diff, planci.templates.helm.diff
apply, deployci.templates.helm.apply
delete, destroyci.templates.helm.delete

Guidance

  • Prefer native Helm for new chart deployments that don't need Helm CLI subcommand plugins; use Helmfile for existing helmfile.yaml projects or plugin-dependent workflows (helm-secrets, etc.).
  • Use atmos helm diff before apply/deploy to review the real unified diff, not just a dry-run dump; secret values are redacted automatically.
  • Use dependencies.components so --all/--affected runs install/upgrade releases in the right order — Helm itself has no cross-release dependency ordering.
  • Use !secret for chart values that are sensitive (e.g. adminPassword) instead of plaintext in stack manifests.
  • Use provision.targets with kind: git to publish rendered manifests to a GitOps deployment repository instead of applying directly to a cluster.
  • Run atmos helm repo list to confirm which repository a component's chart resolves against before debugging chart-not-found errors.

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agent-skills/skills/atmos-helm of cloudposse/atmos.

Open the folder on GitHubat commit 36726ae

Compare with similar skills

Atmos Helm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Helm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Helm this skillcloudposse/atmos1.4k—~3.2kAutomated safety check: PassApache-2.0
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Keloskelos-dev/kelos336—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Kelos

    kelos-dev/kelos

    Install and configure Kelos; author, document, inspect, troubleshoot, and operate its Kubernetes custom resources and CRD schemas in the kelos.dev API group using manifests, kubectl, or the kelos CLI.

    336 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check passed

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Atmos Helm

What does Atmos Helm do?

Native Helm components (experimental): Helm Go SDK rendering/apply/delete, components.helm, chart sources (local/repo/OCI), values, repositories, helm plugin, provision targets, and how this differs…. Atmos Helm is an agent skill from cloudposse/atmos.

When should I use Atmos Helm?

Atmos Helm fits situations like: tasks that involve Container orchestration.

How do I install Atmos Helm in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-helm -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-helm in cloudposse/atmos) into .claude/skills/atmos-helm in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Helm in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-helm -a codex`. Or copy the skill folder (agent-skills/skills/atmos-helm in cloudposse/atmos) into .agents/skills/atmos-helm in your project. Codex loads it when a task matches its description.

Can I use Atmos Helm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-helm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-helm, .gemini/skills/atmos-helm, .github/skills/atmos-helm and .opencode/skills/atmos-helm in your project.

What does Atmos Helm need to run?

Going by SKILL.md and its folder, Atmos Helm needs the command-line tools its instructions call (helm) and credentials named HELM_REPO_PASSWORD.

Does Atmos Helm access the network?

SKILL.md names 2 domains. In commands or code: prometheus-community.github.io; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Atmos Helm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Helm use?

Atmos Helm is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Helm use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Atmos Helm?

Skills that share tags, products or a category with Atmos Helm: Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars), NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars) and Kubernetes Specialist (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Helm?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.