Application example

Deploy PHP Laravel to Kubernetes

Laravel fits the same image/service/probe/route contract; writable paths use emptyDir volumeMounts under a read-only root filesystem.

Chart fidelity

Examples below match Universal Helm Chart application 0.4.3 keys from values.yaml and docs/configuration.md. Replace ghcr.io/example-org/* images and hostnames with your own.

Chart 0.4.3 — args / multi-port / service.enabled

From application 0.4.3: main container args (default []); Deployment revisionHistoryLimit (default 10); multi-port via containerPorts and service.ports; optional chart-managed Service via service.enabled (default true). When service.ports is set, Ingress / simple HTTPRoute / NOTES use the first entry (templates/_helpers.tpl application.servicePort). Legacy single-port service.name / service.port / service.protocol / service.appProtocol remain supported. Set service.enabled: false when the workload does not need a chart-managed Service. Do not invent other port keys.

Install the chart once

helm repo add universal https://chaser100.github.io/u-helm-chart
helm repo update
helm search repo universal/application --versions

Package: Artifact Hub · universal-helm-chart/application.

values.yaml

Copy from the reference example, then replace the image registry and hostname. Keys below are valid chart values (see linked example page for the full file).

replicaCount: 2
image: ghcr.io/example-org/laravel
imageTag: "1.0.0"
imagePullPolicy: IfNotPresent
service:
  port: 8080
securityContext:
  runAsNonRoot: true
  runAsUser: 10001
  runAsGroup: 10001
  allowPrivilegeEscalation: false
  readOnlyRootFilesystem: true
  capabilities:
    drop: ["ALL"]
podSecurityContext:
  seccompProfile:
    type: RuntimeDefault
env:
  - name: APP_ENV
    value: production
  - name: APP_DEBUG
    value: "false"
envFrom:
  - configMapRef:
      name: laravel-config
envSecrets:
  enableEnv: true
  envs:
    - name: APP_KEY
      secretName: laravel-secrets
      secretKey: APP_KEY
    - name: DB_PASSWORD
      secretName: laravel-secrets
      secretKey: DB_PASSWORD
configMaps:
  - name: laravel-config
    data:
      LOG_CHANNEL: stderr
      SESSION_DRIVER: cookie
volumes:
  - name: laravel-storage
    emptyDir: {}
  - name: laravel-cache
    emptyDir: {}
volumeMounts:
  - name: laravel-storage
    mountPath: /var/www/html/storage
  - name: laravel-cache
    mountPath: /var/www/html/bootstrap/cache
resources:
  requests: {cpu: 100m, memory: 256Mi}
  limits: {cpu: 1000m, memory: 1Gi}
readinessProbe:
  httpGet: {path: /health, port: http}
livenessProbe:
  httpGet: {path: /health, port: http}
route:
  enabled: true
  gateway: external
  gatewayNamespace: gateway-system
  sectionName: https
  hostname: laravel.example.com

volumes / volumeMounts are first-class chart values. Pair with readOnlyRootFilesystem: true so only explicit mounts are writable.

Deploy

helm upgrade --install laravel universal/application --version 0.4.3 \
  --namespace apps --create-namespace \
  --values values.yaml

Verify

helm status laravel -n apps
kubectl get pods,svc,httproute -n apps -l app.kubernetes.io/instance=laravel
kubectl get httproute -n apps
# After DNS/Gateway attachment:
# curl -fsS https://YOUR_HOSTNAME/health

GitOps: point an Argo CD Application at chart repo https://chaser100.github.io/u-helm-chart, chart application, and this values file.

Open the full reference example → · Gateway API guide → · Getting started →