Charts
4 chartsSecurity & supply chain charts
Hardened Helm charts in the security & supply chain category. Each deploys our hardened image pinned by its signed digest, with production defaults.
0 CVE
external-secrets
External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into Kubernetes Secrets. The single controller binary also serves the webhook and cert-controller, with every provider compiled in.
chart v0.0.8 · app v2.8.0
Seguridad y cadena de suministrostandardApache-2.00 CVE
opa
Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control, and configuration rules across the stack.
chart v · app v1.18.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
sealed-secrets
Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into ordinary Kubernetes Secrets, so the encrypted form is the only thing that ever leaves the cluster.
chart v · app v0.38.4
Seguridad y cadena de suministrostandardApache-2.00 CVE
step-ca
Online private certificate authority and ACME server for issuing X.509 and SSH certificates. Single static Go binary on a hardened nonroot Wolfi base; config and data live under a writable volume.
chart v · app v0.30.2
Seguridad y cadena de suministrostandardApache-2.0