Skip to content
QuenchWorks

Stacks

Full systems, one helm install

Stacks are curated umbrella charts that bundle the same hardened building blocks as our individual charts (0-CVE, nonroot, cosign-signed, digest-pinned, multi-arch) and pre-wire them together. Instead of assembling six charts by hand and figuring out how they talk to each other, you get a working system from a single install.

Most stacks are operator-free: plain Helm, no CRDs and no operators to run, and what you deploy is exactly the wiring you can read in the chart. Four are built around a controller and install its CRDs: GitOps (Argo), backup (Velero), ingress (cert-manager) and supply chain (Kyverno).

Observability Stack

Metrics, alerting, and populated Kubernetes dashboards from a single install.

PrometheusGrafanaAlertmanagerkube-state-metricsnode-exportercAdvisor
helm install observability-stack oci://ghcr.io/quenchworks/charts/observability-stack
View chart

LGTM Stack

The logs + metrics + traces superset, all in one pane of glass.

LokiGrafanaTempoVictoriaMetricsOpenTelemetry CollectorAlertmanager
helm install lgtm-stack oci://ghcr.io/quenchworks/charts/lgtm-stack
View chart

Logging Stack

Cluster-wide log aggregation and browsing, ready to query.

LokiGrafanaVector
helm install logging-stack oci://ghcr.io/quenchworks/charts/logging-stack
View chart

Tracing Stack

Distributed tracing with an OTLP ingest gateway, ready for your services.

TempoGrafanaOpenTelemetry Collector
helm install tracing-stack oci://ghcr.io/quenchworks/charts/tracing-stack
View chart

Identity Stack

SSO via OIDC and SAML in front of your apps, with a database that comes with it.

KeycloakPostgreSQLoauth2-proxy
helm install identity-stack oci://ghcr.io/quenchworks/charts/identity-stack
View chart

Postgres HA Stack

A 3-node PostgreSQL cluster that fails over on its own, with pooling and dashboards.

PostgreSQLPatroniPgBouncerpostgres_exporterPrometheusGrafana
helm install postgres-ha-stack oci://ghcr.io/quenchworks/charts/postgres-ha-stack
View chart

Cache Stack

A Redis-compatible cache with its metrics already on a dashboard.

Valkeyredis_exporterPrometheusGrafana
helm install cache-stack oci://ghcr.io/quenchworks/charts/cache-stack
View chart

Streaming Stack

Kafka with a schema registry, a REST proxy and a web console, already connected.

KafkaKarapaceAKHQ
helm install streaming-stack oci://ghcr.io/quenchworks/charts/streaming-stack
View chart

Secrets Stack

A self-initializing secrets vault with single sign-on for people and tokens for services.

OpenBaoKeycloak
helm install secrets-stack oci://ghcr.io/quenchworks/charts/secrets-stack
View chart

ML Stack

Notebooks, experiment tracking and data labeling, with every notebook already pointed at MLflow.

JupyterHubMLflowLabel StudioPostgreSQL
helm install ml-stack oci://ghcr.io/quenchworks/charts/ml-stack
View chart

Sigstore Stack

Your own keyless signing: a certificate authority, a transparency log and a timestamp authority for cosign.

FulcioRekor v2Timestamp AuthorityCaddy
helm install sigstore-stack oci://ghcr.io/quenchworks/charts/sigstore-stack
View chart

GitOps Stack

Git-driven deploys, canary releases and pipelines, with webhooks already able to start a workflow.

Argo CDArgo RolloutsArgo WorkflowsArgo EventsNATS
helm install gitops-stack oci://ghcr.io/quenchworks/charts/gitops-stack
View chart

LLM Stack

Local models behind one OpenAI-compatible API, with a vector database for retrieval and the models pulled at install.

OllamaLiteLLMQdrant
helm install llm-stack oci://ghcr.io/quenchworks/charts/llm-stack
View chart

Lakehouse Stack

SQL over Apache Iceberg tables on your own S3 storage, with the catalog, keys and bucket already wired.

TrinoNessieSeaweedFSApache Iceberg
helm install lakehouse-stack oci://ghcr.io/quenchworks/charts/lakehouse-stack
View chart

Backup Stack

Back up and restore namespaces to S3 storage installed beside it, with the keys, bucket and backup location already set.

VeleroVelero AWS pluginSeaweedFS
helm install backup-stack oci://ghcr.io/quenchworks/charts/backup-stack
View chart

Ingress Stack

An ingress controller and cert-manager with a cluster CA, so an Ingress gets a TLS certificate from one annotation.

ingress-nginxcert-managerCluster CA issuer
helm install ingress-stack oci://ghcr.io/quenchworks/charts/ingress-stack
View chart

DNS Stack

PowerDNS serves your zones and external-dns fills them from annotated Services and Ingresses, through one generated API key.

PowerDNS Authoritativeexternal-dnsZone setup Job
helm install dns-stack oci://ghcr.io/quenchworks/charts/dns-stack
View chart

Supply Chain Stack

Admit only signed QuenchWorks images in the namespaces you label, checked against Sigstore, and scan what runs.

Kyvernotrivy-operatorSigned-image policy
helm install supply-chain-stack oci://ghcr.io/quenchworks/charts/supply-chain-stack
View chart

Same hardened parts, pre-assembled.

Browse every chart, or read the quickstart to deploy your first one.