failed to create helm release with error namespaces is forbidden: user cannot create resource "namespaces"
Routes helm install --create-namespace RBAC failures. Use when helm reports namespaces is forbidden and the user cannot create resource namespaces. Not for other forbidden resources or chart render errors.
Your kubeconfig identity can not create namespaces, so helm install --create-namespace dies on the RBAC check before anything installs. Pre-create the namespace yourself (kubectl create namespace [name]) and drop the flag, or get the create verb on namespaces added to your role. Re-run the install and it proceeds.
The error
failed to create helm release with error namespaces "default" is forbidden: user cannot create resource "namespaces" in API group "" at the cluster scopeWhat to do
- Confirm the gap:
kubectl auth can-i create namespaces Expected: Prints no.
- Pre-create the namespace (needs someone with rights):
kubectl create namespace [name]Expected: namespace/[name] created.
- Re-run without the flag:
helm install [release] [chart] -n [name]Expected: Install proceeds past the namespace check.
- Lasting fix: have an admin add
createonnamespacesto your ClusterRole, thenkubectl auth can-i create namespaces
Expected: Prints yes.
When this applies
- helm install with --create-namespace
- the exact namespaces is forbidden message
- locked-down clusters where users get narrow roles
When it does NOT apply
- forbidden on other resources (deployments, clusterroles) - different rule needed
- namespace already exists (drop the flag)
Works with
helm 3.x; RBAC-enabled clusters
INSTALLATION FAILED: ... is forbidden on deployments, serviceaccounts, etc
Same RBAC shape, different resource. Grant the verb on that resource instead.
Why it happens
--create-namespace makes helm call the namespaces create API before rendering anything. Cluster-scoped, so it needs a ClusterRole rule - a namespaced Role can never grant it.
Edge cases
- In CI, prefer pre-creating namespaces in a setup step over granting namespace-create to deploy identities.
- Some platforms forbid namespace creation entirely - then the namespace must come from the platform team.
Resolved from
gh:helm/helm#32511 - https://github.com/helm/helm/issues/32511
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.