Stacks
Full systems, one helm install
Stacks are curated umbrella charts that bundle the same hardened building blocks as our individual charts (0-CVE, nonroot, cosign-signed, digest-pinned, multi-arch) and pre-wire them together. Instead of assembling six charts by hand and figuring out how they talk to each other, you get a working system from a single install.
Most stacks are operator-free: plain Helm, no CRDs and no operators to run, and what you deploy is exactly the wiring you can read in the chart. Four are built around a controller and install its CRDs: GitOps (Argo), backup (Velero), ingress (cert-manager) and supply chain (Kyverno).
Observability Stack
Metrics, alerting, and populated Kubernetes dashboards from a single install.
helm install observability-stack oci://ghcr.io/quenchworks/charts/observability-stackView chartLGTM Stack
The logs + metrics + traces superset, all in one pane of glass.
helm install lgtm-stack oci://ghcr.io/quenchworks/charts/lgtm-stackView chartLogging Stack
Cluster-wide log aggregation and browsing, ready to query.
helm install logging-stack oci://ghcr.io/quenchworks/charts/logging-stackView chartTracing Stack
Distributed tracing with an OTLP ingest gateway, ready for your services.
helm install tracing-stack oci://ghcr.io/quenchworks/charts/tracing-stackView chartIdentity Stack
SSO via OIDC and SAML in front of your apps, with a database that comes with it.
helm install identity-stack oci://ghcr.io/quenchworks/charts/identity-stackView chartPostgres HA Stack
A 3-node PostgreSQL cluster that fails over on its own, with pooling and dashboards.
helm install postgres-ha-stack oci://ghcr.io/quenchworks/charts/postgres-ha-stackView chartCache Stack
A Redis-compatible cache with its metrics already on a dashboard.
helm install cache-stack oci://ghcr.io/quenchworks/charts/cache-stackView chartStreaming Stack
Kafka with a schema registry, a REST proxy and a web console, already connected.
helm install streaming-stack oci://ghcr.io/quenchworks/charts/streaming-stackView chartSecrets Stack
A self-initializing secrets vault with single sign-on for people and tokens for services.
helm install secrets-stack oci://ghcr.io/quenchworks/charts/secrets-stackView chartML Stack
Notebooks, experiment tracking and data labeling, with every notebook already pointed at MLflow.
helm install ml-stack oci://ghcr.io/quenchworks/charts/ml-stackView chartSigstore Stack
Your own keyless signing: a certificate authority, a transparency log and a timestamp authority for cosign.
helm install sigstore-stack oci://ghcr.io/quenchworks/charts/sigstore-stackView chartGitOps Stack
Git-driven deploys, canary releases and pipelines, with webhooks already able to start a workflow.
helm install gitops-stack oci://ghcr.io/quenchworks/charts/gitops-stackView chartLLM Stack
Local models behind one OpenAI-compatible API, with a vector database for retrieval and the models pulled at install.
helm install llm-stack oci://ghcr.io/quenchworks/charts/llm-stackView chartLakehouse Stack
SQL over Apache Iceberg tables on your own S3 storage, with the catalog, keys and bucket already wired.
helm install lakehouse-stack oci://ghcr.io/quenchworks/charts/lakehouse-stackView chartBackup Stack
Back up and restore namespaces to S3 storage installed beside it, with the keys, bucket and backup location already set.
helm install backup-stack oci://ghcr.io/quenchworks/charts/backup-stackView chartIngress Stack
An ingress controller and cert-manager with a cluster CA, so an Ingress gets a TLS certificate from one annotation.
helm install ingress-stack oci://ghcr.io/quenchworks/charts/ingress-stackView chartDNS Stack
PowerDNS serves your zones and external-dns fills them from annotated Services and Ingresses, through one generated API key.
helm install dns-stack oci://ghcr.io/quenchworks/charts/dns-stackView chartSupply Chain Stack
Admit only signed QuenchWorks images in the namespaces you label, checked against Sigstore, and scan what runs.
helm install supply-chain-stack oci://ghcr.io/quenchworks/charts/supply-chain-stackView chartSame hardened parts, pre-assembled.
Browse every chart, or read the quickstart to deploy your first one.