Skip to content
QuenchWorks

coolify

Chart · Datastore · standard · v0.0.10

digest pinnedcosign signedSPDX SBOMSLSA provenanceamd64 · arm64

Hardened coolify image, built from source on Wolfi.

Version

The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version.

Deployed image digest

sha256:909af37137204709bfeea44319676405d50530227d04c96599b9b09bc90b563e

Chart OCI version

oci://ghcr.io/quenchworks/charts/coolify:0.0.10

The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.

Signed
cosign keyless
SBOM
SPDX, on image
Provenance
SLSA build
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Root filesystem
read-only

Install the chart

Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.

Install (latest)

helm install my-coolify oci://ghcr.io/quenchworks/charts/coolify --version 0.0.10

Deploys image (digest-pinned)

ghcr.io/quenchworks/images/coolify-app@sha256:909af37137204709bfeea44319676405d50530227d04c96599b9b09bc90b563e
ghcr.io/quenchworks/images/coolify-realtime@sha256:91e80b74ab6614367a8f72c36af202ca9799d83099d2546d4746bce79cd4d558
ghcr.io/quenchworks/images/coolify-helper@sha256:3ac8c059ddec50582bb80d6f9626f2e2d06fd7ff67b99f8204976fe3cfd5815b
ghcr.io/quenchworks/images/postgresql-15@sha256:037f012988d7de9e7fad2d4407c3179c37dc8aeff0c616d010a77ea8b16615b6
ghcr.io/quenchworks/images/redis@sha256:f027d0109a0bdd1779bfac85a10744336f4af80518e9bc2c290984e206b3bf14
Chart version
0.0.10
App version
4.1.2
Chart license
Apache-2.0
App license
Unknown
Signed
cosign (keyless)
Values schema
yes
Last published
2026-07-15

Verify the chart

cosign verify ghcr.io/quenchworks/charts/coolify:0.0.10 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Transparency

The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.

Upstream project: https://quench-works.com