Neatbo.

Helm release Secret inspector

Decode a local Helm3 release Secret, preserve the exact release and manifest, and compare raw JSON field spans with decoded chart file sizes and hashes.

Browser-local processingInputHelm3 Secret JSON / encoded releaseOutputRelease JSON / manifest / inventory CSVUp to 5 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

.json · .txt

Up to 5 MiB per file · File limit: 1

    0 characters · 0 bytes
    Options

    Complete the required options first. You can keep the defaults for the rest.

    Preparing the tool…

    Before you start

    Investigate an oversized stored release from its exported Secret. See what was actually serialized, without rendering a chart or connecting to Kubernetes.

    How to use this tool

    1. Paste an exported Helm3 Secret JSON or select the explicit encoded-release mode.
    2. Compare the raw-field byte spans and decoded chart file sizes; review unreviewed fields and the encoding layer.
    3. Download the exact release, literal manifest, hook declarations and complete inventory.

    Supported inputs and limits

    One UTF-8 file or paste up to 5 MiB. Release expansion up to 8 MiB; 10,000 chart byte entries, 100,000 JSON values across envelope and release, 64 levels. Complete downloads up to 20 MiB; over-budget or invalid data rejects atomically.

    Select Secret JSON for Kubernetes kind Secret/type helm.sh/release.v1/data.release, or encoded release for the inner Helm Base64 text. Base64 is canonical and unwrapped. Gzip is streamed with CRC/truncation checks; legacy uncompressed releases are identified. YAML input is unsupported.

    release.json preserves the complete decoded UTF-8 bytes, including large number tokens. manifest.yaml preserves its literal string. hooks.json preserves hook declarations. Templates/files/schema are measured and SHA256-hashed as original decoded bytes; templates are never executed.

    Field spans are half-open byte offsets into release.json and count each original JSON value token. They are separate from decoded chart bytes and gzip payload size; sums do not predict compressed contribution or Kubernetes acceptance. Only the serialized root chart is inspected. No subchart dependency tree is reconstructed.

    Release/config/manifest can contain private values. Exports remain local. Unknown root fields are retained and labelled unreviewed. Preview is first 200 rows; cells over 2,000 characters are clipped. Above 20,000 report characters, copying gives the labelled preview; complete downloads remain available.

    Worked example

    Example input

    {"apiVersion":"v1","kind":"Secret","type":"helm.sh/release.v1","metadata":{"name":"sh.helm.release.v1.demo.v7"},"data":{"release":"SDRzSUFBQUFBQUFDRTFWUlMyN0NNQlM4U3ZUV0NNSlBLSmJZbEtvQ1JDdTFDMEEwWFpqa0JWd2NPNDFmRUJIS1hicnBNYmhOZTQvYWlVckZ3cEk5ZmpQakdaOUI4UlNCUVl5cGhsWjlNaG1QSENSMXhLWEZqcGdib1JXd1VRdUVTalN3TXhqaVZKaWFsMGxkWWd4VkM2STl6OG5kcGtnODVzVGQvbGIvcWdWK3U5djJIWXN3elNRbnRHcXYxL0VyMkxHTDJpVlAzVXNhVGNDKzJTM2tacitkTG1WVURnMWZ2OGdvZlRDemFUZTRmOVpqcU41YWtBaDVLeG5yeUhTVXRucHRPdEcvMm5EUjJ3MzVLcGpzeGczVFJIdE1hNTl5N3VQNlRzN2V0ZGoyNWgrYjFaTS9VLzdZNWVDeWNQSm5rSUl3dHowNUF6U2VOZkR3aEZGQkNKWHJSS3RFN056Z0FVczdsSWdURlRtNjRDbFhJckhwTE1venNXeWFZZDZ4RzZxRFVESHpKalgza1dlaCttdVVoY3J6WENEbXVVWkRkUVVKVDhTODc4dm56OWNsVlBhSmU2MFBOd1VZcENLREc5L0daNjYzbHVHaVc0MjgvclZDa1M1c0R6R3d3UGRIM1NEb0RRZWpnUjhFL2FyNkJmbUx6TTAxQWdBQQ=="}}
    Example options
    {"secondary":"","params":{"inputMode":"secret-json","spreadsheetSafe":true}}

    Example output

    {"format":"Helm3-local-release-inventory","summary":{"name":"demo","namespace":"local","version":"7","layers":"base64+gzip","inputMode":"secret-json","encodedPayloadBytes":381,"expandedReleaseBytes":565,"chartFiles":3,"fields":9,"hooks":1,"unreviewedFields":1,"jsonNodes":38},"fields":[{"key":"name","byteStart":8,"byteEnd":14,"jsonUtf8Bytes":6,"reviewStatus":"field-inventory"},{"key":"namespace","byteStart":27,"byteEnd":34,"jsonUtf8Bytes":7,"reviewStatus":"field-inventory"},{"key":"version","byteStart":45,"byteEnd":46,"jsonUtf8Bytes":1,"reviewStatus":"field-inventory"},{"key":"info","byteStart":54,"byteEnd":75,"jsonUtf8Bytes":21,"reviewStatus":"field-inventory"},{"key":"chart","byteStart":84,"byteEnd":351,"jsonUtf8Bytes":267,"reviewStatus":"field-inventory"},{"key":"config","byteStart":361,"byteEnd":378,"jsonUtf8Bytes":17,"reviewStatus":"field-inventory"},{"key":"manifest","byteStart":390,"byteEnd":473,"jsonUtf8Bytes":83,"reviewStatus":"field-inventory"},{"key":"hooks","byteStart":482,"byteEnd":525,"jsonUtf8Bytes":43,"reviewStatus":"field-inventory"},{"key":"extra","byteStart":534,"byteEnd":564,"jsonUtf8Bytes":30,"reviewStatus":"unreviewed-unknown-field"}],"files":[{"group":"templates","name":"templates/test.yaml","decodedBytes":23,"sha256":"17537c9c570014f30fd04fc5b54a9c17f79f0b6a2ef718767ad320f8e5543f81"},{"group":"files","name":"docs/notes.txt","decodedBytes":7,"sha256":"4e0826721642ed8e3a27e7147538ac7b7013a08fe5ae343a8ef09749b7e5790f"},{"group":"schema","name":"values.schema.json","decodedBytes":17,"sha256":"a2c799262a3ce3c19ef5cdd983bf3d12b43ab3c426227091b909dcb7054738c0"}],"scope":"Field spans refer to exact release.json UTF8 bytes and include JSON syntax of each value. Chart file sizes/hashes refer to decoded bytes. These are not additive compressed contributions or predictions of Kubernetes Secret acceptance. Only serialized root chart data is inspected; subchart dependency tree/render/install/upgrade are not reconstructed. Unknown root fields are retained in release.json and unreviewed. Outputs may contain private values."}

    When something does not work

    Check the selected mode, canonical Base64, complete gzip, UTF-8 JSON and Helm Secret shape. Re-export malformed data; reduce release size if expansion or combined downloads exceed the visible limits.

    Frequently asked questions

    Why do field sizes not add up to the gzip size?

    Each field measurement counts original decoded JSON value bytes. Compression shares patterns across the whole release, and chart bytes are separately Base64-encoded. These measurements cannot assign exact compressed contributions.

    Can this recover every original subchart?

    No. Helm serializes the root chart fields, and its internal dependency objects are not ordinary exported JSON fields. The report describes only actual serialized data.

    Does a decoded manifest run anything?

    No. YAML, hook commands and template text remain data. No Helm command, Kubernetes submission, URL request or installation occurs.

    Documentation & further reading

    Related tools