Most CI/CD pipelines chain together separate tools: Docker build, registry push, Helm install, image cleanup. Werf integrates all of these into one tool that understands the full lifecycle from code to running deployment.
What Werf Does
Source Code ā Build Images ā Push to Registry ā Deploy (Helm) ā Cleanup Old Images
ā ā ā
All managed by werf with content-based taggingNo manual tag management. Werf generates content-based tags from your source files ā the same code always produces the same tag.
Installation
curl -sSL https://werf.io/install.sh | bashProject Configuration
# werf.yaml
project: order-api
configVersion: 1
---
image: order-api
dockerfile: Dockerfile
context: .Master this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āBuild and Deploy
# Build, push, and deploy in one command
werf converge --repo ghcr.io/myorg/order-apiwerf converge does everything:
1. Builds the Docker image
2. Pushes to the registry with a content-based tag
3. Deploys using Helm charts
4. Waits for rollout to complete
Helm Integration
Werf uses standard Helm charts with extra templating:
.helm/
āāā Chart.yaml
āāā templates/
ā āāā deployment.yaml
ā āāā service.yaml
āāā values.yaml# .helm/templates/deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Chart.Name }}
spec:
replicas: {{ .Values.replicas }}
template:
spec:
containers:
- name: app
image: {{ .Values.werf.image.order_api }}
# werf injects the correct content-based image tagNo hardcoded image tags. Werf injects the correct tag automatically.
Multi-Image Projects
# werf.yaml
project: ecommerce
configVersion: 1
---
image: frontend
dockerfile: frontend/Dockerfile
context: frontend/
---
image: order-api
dockerfile: backend/order-api/Dockerfile
context: backend/order-api/
---
image: payment-svc
dockerfile: backend/payment-svc/Dockerfile
context: backend/payment-svc/All images are built, tagged, and deployed together. If only the frontend changed, only the frontend image is rebuilt.
Content-Based Tagging
Source files hash ā Image tag
src/server.ts (changed) ā sha256:abc123 (new tag)
src/server.ts (unchanged) ā sha256:abc123 (same tag, no rebuild)Benefits: - Same code always produces the same image - No rebuilds when nothing changed - Rollback = redeploy the old tag (always available)
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āCI/CD Integration
GitHub Actions
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # werf needs full history
- name: Install werf
uses: werf/actions/install@v2
- name: Converge
uses: werf/actions/converge@v2
with:
env: production
env:
WERF_REPO: ghcr.io/myorg/ecommerce
WERF_NAMESPACE: production
WERF_KUBE_CONFIG_BASE64: ${{ secrets.KUBE_CONFIG }}GitLab CI
deploy:
stage: deploy
script:
- werf converge --repo $CI_REGISTRY_IMAGE
environment:
name: productionCleanup
Old images accumulate in registries. Werf cleans them up based on Git history:
# Remove images not referenced by any Git tag or branch
werf cleanup --repo ghcr.io/myorg/order-api# .werf-cleanup.yaml
policies:
- references:
branch: /^main$/
imagesPerReference:
last: 10 # Keep last 10 images on main
- references:
tag: /^v\d+\.\d+\.\d+$/
imagesPerReference:
last: 5 # Keep last 5 tagged releasesEnvironment Promotion
# Deploy to staging
werf converge --repo ghcr.io/myorg/order-api --env staging
# Promote to production (same images, different values)
werf converge --repo ghcr.io/myorg/order-api --env productionWerf vs Alternatives
| Feature | Werf | Skaffold | Helm + Docker | Argo CD |
|---|---|---|---|---|
| Build + Deploy | Single tool | Single tool | Separate tools | Deploy only |
| Content-based tags | Yes | No | No | N/A |
| Image cleanup | Built-in | No | Manual | No |
| Helm integration | Native | Plugin | Native | Native |
| CI/CD focus | Yes | Dev + CI | CI | GitOps |
Use werf for end-to-end CI/CD with automatic image management. Use Skaffold for local development. Use Argo CD for GitOps deployments.
---
Ready to go deeper? Master Kubernetes CI/CD with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Devtron Kubernetes Application Manager
Devtron provides a complete CI/CD platform for Kubernetes with a web UI, Helm chart management, and GitOps. Learn how Devtron simplifies application.
Flux GitOps Kubernetes Tutorial
Flux is a GitOps tool that continuously reconciles your Kubernetes cluster with a Git repository. Learn how to set up Flux, manage Helm releases, and handle.
Helm Charts Beginner Tutorial
Get started with Helm charts for Kubernetes. Install community charts, create custom charts, manage values files, and handle releases.
What is Context7?
Discover Context7, the tool that gives version-specific, accurate documentation to LLMs and AI code editors like Cursor and Claude. No more hallucinated APIs.
What is OpenClaw?
Discover OpenClaw ā the open-source platform that lets you run AI agents on your own infrastructure. Learn what it does, how it works, and why it matters.
What Is SELinux and Why It Matters
SELinux enforces mandatory access control on Linux. Learn what it is, why 87% of enterprises need it, and how it stops real attacks like Log4Shell.
Explore topics
Browse more articles on the topics covered here.