Previosly I used Terraform for this but am starting a new project and would like to avoid TF for management of actual k8s resources, despite it having some advantages.
Previosly I used Terraform for this but am starting a new project and would like to avoid TF for management of actual k8s resources, despite it having some advantages.
For secrets I'm a big fan of https://external-secrets.io/latest/ paired with a cloud vault, which allowed me to offload secret production/maintainance to the resource teams.
I tried using TF to manage kube manifests, I hated it all around and moved away immediately, so I agree with you.
I haven't found a good alternative to Helm. Pulumi is probably the best if you wanted to just create manifests their k8s provider is great, but we ultimately want to shift left the kubernetes manifests and helm is pretty ok for that.
It takes some "waaaaa?!" to change the mental model away from text generation and substitution, and I'll be straight that their docs could really use a LOT more CONCRETE examples, but in the end it does as advertised using only kubectl
Then, to address the stateful bit of helm (e.g. helm ls) if one is already kustomize friendly then flux is good about using CRDs to track what things have been deployed: https://github.com/fluxcd/flux2#readme (Apache 2)
Kustomize is extremely limited and opinionated, which is great if your deployments have only kustomize-approved differences between them, but it has no way to write business-aware config files and at my typical 100 deployments/chart is was becoming megaduplicated.