Charts
136 chartsHardened Helm charts
Each chart deploys our hardened image pinned by its signed digest, with sensible production defaults. Cosign-signed and published as an ArtifactHub verified publisher. 136 charts.
No charts match that search.
C 2
InfluxDB
Time-series database purpose-built for ingesting and querying metrics, events, and IoT/sensor data at high write rates.
chart v0.0.11 · app v2.9.1
Time seriesstandardMITD 5
ingress-nginx
The Kubernetes NGINX Ingress Controller. Routes external HTTP/HTTPS traffic to in-cluster Services via Ingress resources, with TLS termination, path/host routing, and an admission webhook. The chart wires its RBAC, IngressClass, and webhook.
chart v0.0.7 · app v1.15.8
GatewaystandardApache-2.0B 1
jaeger
Distributed tracing platform (Jaeger v2, OpenTelemetry-collector based) with an embedded query UI. From source on a hardened nonroot Wolfi base; in-memory storage by default, badger under a volume.
chart v0.0.5 · app v2.19.0
ObservabilitystandardApache-2.0C 1
jenkins
The leading open-source automation server for building, testing, and deploying software, with thousands of plugins. Ships the architecture-independent jenkins.war LTS line on a hardened Wolfi JRE.
chart v0.0.6 · app v2.572
CI/CD & registrystandardMITA+
Kafka
Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.
chart v0.0.14 · app v4.3.1
MessagingcriticalApache-2.0A+
Keycloak
Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.
chart v0.0.14 · app v26.7.0
IdentitystandardApache-2.0B 2
kuma
CNCF service mesh control plane (Envoy-based) for multi-zone and multi-cluster meshes. Ships kuma-cp and kumactl with an embedded GUI, built from source on a hardened nonroot Wolfi base; default in-memory store runs standalone.
chart v0.0.6 · app v2.14.0
Coordination & meshstandardApache-2.00 CVE
lgtm-stack
Hardened, operator-free LGTM observability superset in one install: Loki (logs) + Grafana (the single pane) + Tempo (traces) + VictoriaMetrics (Prometheus-compatible metrics) + an OpenTelemetry Collector (OTLP ingest) + Alertmanager.
chart v0.0.4 · app v1.0.0
StacksstandardUnknownB 1
livekit
WebRTC SFU server for scalable real-time audio, video, and data. Single static Go binary on a hardened nonroot Wolfi base; config via mounted YAML or LIVEKIT_ env.
chart v0.0.6 · app v1.13.4
Media & streamingstandardApache-2.00 CVE
logging-stack
Hardened, operator-free logging stack: Loki + Grafana + Vector, wired together for cluster log aggregation and browsing.
chart v0.0.4 · app v1.0.0
StacksstandardUnknownB 2
Loki
Horizontally scalable log aggregation system from Grafana that indexes only labels, not full log text. Like Prometheus, but for logs. Licensed AGPL.
chart v0.0.14 · app v3.7.4
ObservabilitystandardAGPL-3.0A+
MariaDB
Community-developed relational database and drop-in MySQL successor, GPL-licensed and fully open. Default MySQL-compatible engine for the catalog.
chart v0.0.12 · app v12.3.2
RelationalcriticalGPL-2.0