Skip to content
QuenchWorks

rook-ceph

Chart · Datastore · standard · v0.0.4

digest pinnedcosign signedSPDX SBOMSLSA provenanceamd64 · arm64

Hardened rook-ceph image, built from source on Wolfi.

Deployed image digest

sha256:a2ff9329d16068ac9dabc605f9d4cb39ad758c2a3a80fd0194c7db1f4dfea9e0

Chart OCI version

oci://ghcr.io/quenchworks/charts/rook-ceph:0.0.4

The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.

Signed
cosign keyless
SBOM
SPDX, on image
Provenance
SLSA build
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Root filesystem
read-only

Install the chart

Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.

Install (latest)

helm install my-rook-ceph oci://ghcr.io/quenchworks/charts/rook-ceph --version 0.0.4

Deploys image (digest-pinned)

ghcr.io/quenchworks/images/rook@sha256:a2ff9329d16068ac9dabc605f9d4cb39ad758c2a3a80fd0194c7db1f4dfea9e0
ghcr.io/quenchworks/images/ceph@sha256:684f5f8a3fac736e38abee6d97c2061123bcf31f1fe71ca2260c37f65b363635
ghcr.io/quenchworks/images/ceph-csi-operator@sha256:3924621c5a1e707aceaad8a88c27781150e86532cd71db2160752f174b8d8fc2
ghcr.io/quenchworks/images/cephcsi@sha256:ae2ee763fd858b9cbe05edbc5d5a045af4e722a5dda02dfcfef102916322739d
ghcr.io/quenchworks/images/csi-provisioner@sha256:ffb81c18d8d2b7cec0ecd81036e58ec8b2f068e26bb0943bbd334d1e017c89de
ghcr.io/quenchworks/images/csi-attacher@sha256:bf14937a85f247b933558b50c9ccf52b323066401a97a765f02035f9c9b3e633
ghcr.io/quenchworks/images/csi-resizer@sha256:62a5a52174790c92c6fdbd1878479b790499253ed5548b08eec02869e855a4a6
ghcr.io/quenchworks/images/csi-snapshotter@sha256:ac11531dc4b5de882e4b55f196e0396248f3db557ac53ce73983d648eac7dca7
ghcr.io/quenchworks/images/csi-node-driver-registrar@sha256:8e5b9942dd60eb3b520fda8559993a28f44a755a04167315d586c8d5b9169e54
Chart version
0.0.4
App version
1.21.0
Chart license
MIT
App license
Unknown
Signed
cosign (keyless)
Values schema
no

Verify the chart

cosign verify ghcr.io/quenchworks/charts/rook-ceph:0.0.4 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Transparency

The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.

Upstream project: https://quench-works.com