dns-stack
Chart · Stacks · standard · v0.0.3
Self-hosted DNS for Kubernetes: PowerDNS Authoritative serves the zones and external-dns writes records into it from annotated Services and Ingresses, through the PowerDNS API with a key the stack generates.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version.
Deployed image digest
sha256:a9a0c1b66f1513e309a60eda1dfbca732fc07c8f374f0d549fcb316da000fa34Chart OCI version
oci://ghcr.io/quenchworks/charts/dns-stack:0.0.3The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Install the chart
Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-dns-stack oci://ghcr.io/quenchworks/charts/dns-stack --version 0.0.3Deploys image (digest-pinned)
ghcr.io/quenchworks/images/powerdns@sha256:a9a0c1b66f1513e309a60eda1dfbca732fc07c8f374f0d549fcb316da000fa34
ghcr.io/quenchworks/images/external-dns@sha256:14f9278bfae70142de8c149409f78b29ed34e7ddcdd22742d7ceb2bcf0162d79
ghcr.io/quenchworks/images/busybox@sha256:b851333cd0a8a05a4b7569f4f1007f4e237b34295f84033e6ab6aa428fb33eefCharts used:
- Chart version
- 0.0.3
- App version
- 1.0.0
- Chart license
- Apache-2.0
- App license
- Unknown
- Signed
- cosign (keyless)
- Values schema
- yes
- Last published
- 2026-10-05
Verify the chart
cosign verify ghcr.io/quenchworks/charts/dns-stack:0.0.3 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.