Helm 3 vs Helm 2: No More Tiller
What changed and why Helm 3 is client-only and safer.
Helm 3 vs Helm 2: No More Tiller is a free Helm Academy lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Helm Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Helm Has a History
Today you use Helm 3, but Helm 2 came first and worked very differently. Knowing the shift helps you read older guides correctly. 📜
Helm 2 Had Two Parts
Helm 2 split into a client and a cluster-side component called Tiller. The CLI talked to Tiller, and Tiller talked to Kubernetes.
What Tiller Did
Tiller ran as a Pod inside the cluster. It received your commands and applied the actual resources on your behalf.
The Security Problem
Tiller often ran with broad cluster-admin rights. Anyone who reached it could effectively do anything, which was a real risk. 🔓
Helm 3 Removed Tiller
The headline change in Helm 3 is simple: Tiller is gone. The CLI now talks directly to the Kubernetes API, just like kubectl. 🎉
Client-Only Helm
Helm 3 is purely a client. It uses your kubeconfig and your own permissions, so there is no extra server component to secure.
Your Permissions Apply
Because Helm 3 uses your credentials, you can only do what your Kubernetes role allows. Access control becomes simple and standard.
Release Data Moved
Helm 3 stores each release's state as a Kubernetes Secret in the release's namespace, rather than in Tiller's old storage.
Namespace-Scoped Releases
In Helm 3, release names are unique per namespace, not cluster-wide. The same name can exist safely in two different namespaces.
Other Helm 3 Upgrades
Helm 3 also added optional values schema validation and native OCI registry support, on top of dropping Tiller entirely.
Why It Matters to You
If a tutorial mentions Tiller or helm init, it is for Helm 2. Modern Helm needs no init step, so you can safely skip that. 👍
Quick Check
What was the biggest architectural change in Helm 3?
Recap
Helm 3 removed Tiller, became client-only, uses your own permissions, and stores releases as namespaced Secrets. Safer and simpler. ✅
Frequently asked questions
Is the “Helm 3 vs Helm 2: No More Tiller” lesson free?
Yes — the full text of “Helm 3 vs Helm 2: No More Tiller” is free to read here on the web, and the Helm Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Helm Academy course, upgrade to CoddyKit PRO.
What will I learn in “Helm 3 vs Helm 2: No More Tiller”?
What changed and why Helm 3 is client-only and safer. You practise Helm Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Helm Academy?
No prior experience is required. Helm Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Helm 3 vs Helm 2: No More Tiller” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Helm Academy lesson?
Yes. Every Helm Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- The Pain of Raw kubectl apply
- Helm as apt/yum for Kubernetes
- Charts, Releases, and Repositories at a Glance
- Helm 3 vs Helm 2: No More Tiller