Charts
136 chartsHardened Helm charts
Each chart deploys our hardened image pinned by its signed digest, with sensible production defaults. Cosign-signed and published as an ArtifactHub verified publisher. 136 charts.
No charts match that search.
A+
Garage
Lightweight, S3-compatible object store for small, self-hosted, geo-distributed deployments that stays available across node failures. Licensed AGPL; runs well on modest hardware.
chart v0.0.9 · app v2.3.0
Object storagestandardAGPL-3.0D 4
ghost
Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.
chart v0.0.8 · app v6.54.1
Apps & productivitystandardMITC 2
Gitea
Lightweight self-hosted Git service with repositories, issues, pull requests, and built-in CI/CD (Actions). A low-footprint GitHub alternative.
chart v0.0.13 · app v1.27.1
GitstandardMITB 1
gotify
Self-hosted server for sending and receiving real-time push messages over WebSocket, with a web UI and app tokens. From source (UI embedded, CGO+static-musl SQLite) on a hardened nonroot Wolfi base; data on a writable volume.
chart v0.0.5 · app v2.9.1
MessagingstandardMIT0 CVE
Grafana
Hardened grafana image, built from source on Wolfi.
chart v0.0.10 · app v13.1.0
DatastorestandardUnknownC 1
graylog
Graylog, the log-management and analysis server (search, dashboards, alerting, GELF/Beats inputs). Built clean-room on a hardened Wolfi JRE (nonroot, read-only rootfs); the chart provides MongoDB (metadata) and OpenSearch (log storage) backends. Graylog Server is SSPL-1.0 (source-available, not OSI-approved).
chart v0.0.5 · app v7.1.6
ObservabilitystandardSSPL-1.0A+
HAProxy
High-performance TCP and HTTP load balancer and reverse proxy known for reliability and fine-grained traffic control at scale.
chart v0.0.9 · app v3.4.0
GatewaystandardGPL-2.0+0 CVE
harbor
Hardened harbor image, built from source on Wolfi.
chart v0.0.13 · app v2.15.2
DatastorestandardUnknown0 CVE
Harbor observability
Hardened harbor-observability image, built from source on Wolfi.
chart v0.0.7 · app v2.14.4
DatastorestandardUnknownB 1
headscale
Open-source, self-hosted implementation of the Tailscale control server for coordinating a WireGuard mesh. Single static Go binary on a hardened nonroot Wolfi base; config and state on writable volumes.
chart v0.0.5 · app v0.29.2
Coordination & meshstandardBSD-3-ClauseA+
httpd
Apache HTTP Server, the long-standing open-source web server and reverse proxy for serving static content and fronting application backends (mod_proxy).
chart v0.0.4 · app v2.4.68
GatewaycriticalApache-2.00 CVE
identity-stack
Hardened, operator-free self-hosted SSO/identity stack: Keycloak (OIDC/SAML identity provider) + PostgreSQL (Keycloak's database) + oauth2-proxy (an auth proxy you place in front of any upstream app to authenticate users against Keycloak), wired together so you get single sign-on in front of your apps out of the box.
chart v0.0.5 · app v1.0.0
StacksstandardUnknown