<!-- Generated by npm run confighub-example-guides. Do not edit by hand. -->

# metrics-server/metrics-server 3.13.0 - external-tls-ca

This guide explains the journey from a public Helm chart to a ConfigHub Space. Use it when you want to know why this preset exists, what problem it solves, how to repeat it, and what still needs care.

It is generated from the same records that build the package, chart page, render intent, scripts, and receipts. The proof links are lower down.

## Why this preset exists

Helm charts often expose many settings, but a values file alone does not tell the whole operations story. A team still needs to know what Kubernetes objects will be created, which Secrets or CRDs must already exist, whether hooks or setup jobs need special handling, and what evidence backs the result.

This preset is a named answer for one useful operating choice. It keeps the upstream chart, records the inputs and rendered YAML, and gives the team a repeatable starting point instead of a private values-file guess.

## What this is

This is the `external-tls-ca` preset config for `metrics-server/metrics-server@3.13.0`. The repo also calls this a base variant. Use this when TLS CA material is supplied outside the chart.

The matching catalog page is [metrics-server/metrics-server@3.13.0](https://confighub.github.io/helm-expt/site/charts/metrics-server-metrics-server-3-13-0.html).

## The chart journey

We keep the Helm chart. We lock `metrics-server/metrics-server@3.13.0`, choose the `external-tls-ca` preset config, render it with the recorded values, namespace, release name, and Kubernetes capabilities, then save the output as files.

That captured output is the render variant: [`recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml`](https://github.com/confighub/helm-expt/blob/main/recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml). It contains 9 Kubernetes object(s): ClusterRole x2, ClusterRoleBinding x2, APIService x1, Deployment x1, RoleBinding x1, Service x1, ServiceAccount x1.

The public package is `oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/metrics-server-metrics-server:3.13.0`. Users can pull it without cloning this repo. When someone runs `cub installer upload`, ConfigHub stores the rendered Kubernetes YAML in a Space so it can be searched, compared, reviewed, changed, and delivered. The example script defaults to Space `helm-metrics-server-external-tls-ca`, but users can choose another name with `CUB_SPACE=...`.

## What to check

This preset config records 1 prerequisite: 1 Secret. Follow the instructions below before you apply the rendered objects.

The catalog does not currently record a separate hook, setup job, or cleanup step for this preset.

At least one Secret must be created with your values before apply. Known limitation: existing-secret (chart ships no Secret toggle).

## Why you can trust it

- The chart version, source, namespace, release name, values, and capability profile are recorded in the render intent.
- The render variant is committed as YAML and contains 9 Kubernetes object(s).
- The installer package OCI ref points to the package users pull for this chart version.
- Render parity is recorded as passing for this preset config.
- Prerequisites are named before apply, so they are not discovered after rollout.

This is a claim about this recorded preset config. It is not a claim that every possible values file for this chart has been checked.

## Repeat it

Fast path with no ConfigHub account:

```sh
bash <(curl -fsSL https://confighub.github.io/helm-expt/site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca/try.sh)
```

Fast path with a ConfigHub account:

```sh
bash <(curl -fsSL https://confighub.github.io/helm-expt/site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca/confighub.sh)
```

The core render command is:

```sh
cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/metrics-server-metrics-server:3.13.0 --base external-tls-ca --work-dir ./metrics-server-metrics-server-3-13-0-external-tls-ca --non-interactive --namespace kube-system
```

After upload, create environment versions with `cub variant create` and move reviewed changes with `cub variant promote`. The walkthrough is [After Upload: Create A Variant And Promote Changes](../../../../docs/user/variants-after-upload.md).

## Preset details

| Item | Value |
| --- | --- |
| Chart | `metrics-server/metrics-server@3.13.0` |
| Preset config | `external-tls-ca` |
| Namespace | `kube-system` |
| Release name | `metrics-server` |
| Values | [`recipes/metrics-server/metrics-server/3.13.0/effective-values-external-tls-ca.yaml`](https://github.com/confighub/helm-expt/blob/main/recipes/metrics-server/metrics-server/3.13.0/effective-values-external-tls-ca.yaml) |
| Render intent | [`data/helm-render-intents/intents/metrics-server-metrics-server-3-13-0-external-tls-ca.yaml`](https://github.com/confighub/helm-expt/blob/main/data/helm-render-intents/intents/metrics-server-metrics-server-3-13-0-external-tls-ca.yaml) |
| Render variant | [`recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml`](https://github.com/confighub/helm-expt/blob/main/recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml) |
| Package base | [`packages/metrics-server/metrics-server/3.13.0/bases/external-tls-ca`](https://github.com/confighub/helm-expt/tree/main/packages/metrics-server/metrics-server/3.13.0/bases/external-tls-ca) |
| Scripts | [try.sh](https://confighub.github.io/helm-expt/site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca/try.sh) · [confighub.sh](https://confighub.github.io/helm-expt/site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca/confighub.sh) |

## Prerequisites and lifecycle steps

| When | What | How it is handled |
| --- | --- | --- |
| Before install | ClusterFeature: Secret kube-system/metrics-server-tls keys tls.crt,tls.key | kubectl -n kube-system create secret generic metrics-server-tls --from-literal=tls.crt=<value> --from-literal=tls.key=<value> |

## Evidence

| Check | Status |
| --- | --- |
| Render parity | `yes` |
| ConfigHub scan/upload proof | `yes` |
| Earlier local-cluster test | `yes` |
| GitOps OCI live run | `yes` |
| Live Helm vs ConfigHub comparison | `yes` |
| Lifecycle routes | `0` |

## Limits

- Known gap for this row: existing-secret (chart ships no Secret toggle).
- Production support is target-scoped. Use production support decisions before claiming production readiness.

## Source files

- Chart page: [https://confighub.github.io/helm-expt/site/charts/metrics-server-metrics-server-3-13-0.html](https://confighub.github.io/helm-expt/site/charts/metrics-server-metrics-server-3-13-0.html)
- Render intent: [`data/helm-render-intents/intents/metrics-server-metrics-server-3-13-0-external-tls-ca.yaml`](https://github.com/confighub/helm-expt/blob/main/data/helm-render-intents/intents/metrics-server-metrics-server-3-13-0-external-tls-ca.yaml)
- Rendered YAML: [`recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml`](https://github.com/confighub/helm-expt/blob/main/recipes/metrics-server/metrics-server/3.13.0/revisions/external-tls-ca/r001/rendered/release-objects.yaml)
- Package source: [`packages/metrics-server/metrics-server/3.13.0/bases/external-tls-ca`](https://github.com/confighub/helm-expt/tree/main/packages/metrics-server/metrics-server/3.13.0/bases/external-tls-ca)
- Generated scripts: [`site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca`](https://github.com/confighub/helm-expt/tree/main/site/sh/metrics-server-metrics-server-3-13-0/external-tls-ca)
- Preset doctrine: [Helm Chart Presets And Values](../../../../docs/user/helm-presets-and-values.md)
