Charts
140 chartsHardened Helm charts
Each chart deploys our hardened image pinned by its signed digest, with sensible production defaults. Cosign-signed and published as an ArtifactHub verified publisher. 140 charts.
No charts match that search.
0 CVE
CockroachDB
Hardened cockroachdb image, built from source on Wolfi.
chart v0.0.8 · app v26.2.2
DatastorestandardUnknownD 13
code-server
VS Code in the browser (Coder's code-server), a full IDE served over HTTP. Ships Coder's official prebuilt release (bundled Node 24 + compiled VS Code) hardened on a minimal, nonroot Wolfi base; runs as a single-replica Deployment with a persistent workspace and PASSWORD login.
chart v0.0.5 · app v4.131.0
Developer tools / IDEstandardMIT0 CVE
coolify
Hardened coolify image, built from source on Wolfi.
chart v0.0.11 · app v4.1.2
DatastorestandardUnknownD 5
Coolify Realtime
Realtime server component of Coolify, providing the websocket connections and terminal/log gateway for the dashboard. Licensed AGPL.
chart v0.0.4 · app v1.0.16
PaaSstandardAGPL-3.0+B 1
coredns
Fast, flexible DNS server that chains plugins to serve DNS and service discovery, the default cluster DNS for Kubernetes.
chart v0.0.9 · app v1.14.6
CoordinationstandardApache-2.0B 1
coroot
Coroot — open-source observability/APM (eBPF-based metrics, logs, traces, cost insights and service maps) with an embedded Vue UI. Built from source on Wolfi (go:embedded frontend, cgo lz4), prometheus/ch-go bumped to their fixed lines. Image only, no chart.
chart v0.1.3 · app v1.23.3
ObservabilitystandardApache-2.0A+
cosmian-kms
KMIP 2.1 key management server with PKCS#11 and Google/Microsoft CSE support -- the only KMIP speaker in this catalog. Shipped under BUSL-1.1, which is NOT OSI-approved AND caps production use at 2 vCPUs (1 physical core) while barring third-party offering; read the licence before deploying. Built non-FIPS against Wolfi's OpenSSL, so it is NOT FIPS 140-3 validated despite upstream's description.
chart v · app v5.25.0
SecretslowBUSL-1.1A+
CouchDB
Document database with an HTTP/JSON API and multi-master replication, designed for offline-first sync across nodes and devices.
chart v0.0.6 · app v3.5.2
DocumentstandardApache-2.0B 2
crossplane
Crossplane, the CNCF control-plane framework that turns Kubernetes into a universal API for infrastructure. Installs Providers, Functions and Configurations as OCI packages, and lets platform teams publish their own composite APIs from CompositeResourceDefinitions and Compositions.
chart v0.0.1 · app v2.3.4
GitOpsstandardApache-2.0B 1
descheduler
Kubernetes descheduler that evicts pods so the scheduler can re-place them for better cluster balance. Single static Go binary on a hardened nonroot Wolfi base.
chart v0.0.7 · app v0.36.0
CoordinationstandardApache-2.0B 1
dex
Federated OpenID Connect (OIDC) identity provider. Acts as a portal to other identity providers (LDAP, SAML, GitHub, Google, OIDC) and issues OIDC tokens to apps and Kubernetes.
chart v0.0.10 · app v2.45.1
IdentitystandardApache-2.0B 1
distribution
The CNCF reference OCI and Docker registry server for storing and distributing container images and other OCI artifacts.
chart v0.0.9 · app v3.1.1
RegistrystandardApache-2.0