Charts
12 chartsIdentity charts
Hardened Helm charts in the identity category. Each deploys our hardened image pinned by its signed digest, with production defaults.
0 CVE
authelia
Open-source authentication and authorization server providing single sign-on and two-factor authentication via a web portal, designed as a companion…
chart v0.0.30 · app v4.39.28
IdentitystandardApache-2.00 CVE
dex
Federated OpenID Connect (OIDC) identity provider. Acts as a portal to other identity providers (LDAP, SAML, GitHub, Google, OIDC) and issues OIDC…
chart v0.0.12 · app v2.45.1
IdentitystandardApache-2.00 CVE
hydra
Ory Hydra, an OAuth 2.0 and OpenID Connect provider. Issues and validates tokens for first- and third-party clients without owning user credentials…
chart v · app v26.2.0
IdentitystandardApache-2.00 CVE
Keycloak
Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.
chart v · app v26.7.5
IdentitystandardApache-2.00 CVE
kratos
Ory Kratos, an identity and user-management server covering registration, login, MFA, account recovery and profile self-service. Headless by design…
chart v · app v26.2.0
IdentitystandardApache-2.00 CVE
openfga
Fine-grained authorization engine (Zanzibar-style relationship-based access control) over HTTP and gRPC. From source on a hardened nonroot Wolfi…
chart v · app v1.21.0
IdentitystandardApache-2.00 CVE
openldap
OpenLDAP slapd, the reference open-source LDAP directory server, with the LMDB (back-mdb) backend and the client tools. Runs nonroot on unprivileged…
chart v · app v2.6.14
IdentitystandardOLDAP-2.80 CVE
ory-hydra
Ory Hydra, the OAuth 2.0 and OpenID Connect provider. Built from source like upstream's Linux release (cgo, sqlite, hsm, json1); one binary serves…
chart v · app v26.2.0
IdentitystandardApache-2.00 CVE
pinniped
Pinniped, identity services for Kubernetes (the Concierge federates cluster login to an OIDC or LDAP provider, the Supervisor is an OIDC issuer…
chart v · app v0.47.0
IdentitystandardApache-2.00 CVE
spicedb
Zanzibar-style authorization database for fine-grained permissions over gRPC. From source on a hardened nonroot Wolfi base; the operator supplies the…
chart v · app v1.56.2
IdentitystandardApache-2.00 CVE
spire
SPIRE, the SPIFFE runtime that attests nodes and workloads and issues them short-lived X.509 and JWT identities (spire-server and spire-agent in one…
chart v · app v1.15.3
IdentitystandardApache-2.00 CVE
zitadel
Cloud-native identity and access management (IAM) with OIDC/OAuth2/SAML, multi-tenancy, and a built-in admin console. Packaged from ZITADEL's…
chart v · app v4.19.4
IdentitystandardAGPL-3.0