A collection of Helm charts for Kubernetes deployments, published to GitHub Container Registry (GHCR) as OCI artifacts.
All charts are published to GHCR with cosign signatures for verification.
Deploy Cloudflare Tunnel (cloudflared) for secure Zero Trust access to Kubernetes services without exposing inbound ports.
Key Features:
- Zero Trust network access with Cloudflare's edge
- Dual deployment modes (Deployment/DaemonSet)
- Prometheus metrics and high availability support
- Hardened security (non-root, read-only filesystem)
Per-node TCP load balancer for Kubernetes API server high availability, inspired by Talos KubePrism.
Key Features:
- No VIP dependency — each node connects to localhost, eliminating VRRP/keepalived single points of failure
- Two-level discovery: static bootstrap endpoints + dynamic Kubernetes EndpointSlice watch
- CNI-independent bootstrap via hostNetwork and static endpoints
- Health-checked upstreams with automatic failover
Kubernetes-native controller for automated node upgrades using declarative Plans. Based on Rancher System Upgrade Controller.
Key Features:
- Declarative upgrade plans via CRDs
- Rolling upgrades with concurrency control
- Node drain and cordon automation
- K3s, RKE2, and generic Kubernetes support
Transmission BitTorrent client deployment with NFS and PVC storage support.
VRRP-based Virtual IP management for Kubernetes control plane high availability using keepalived.
Key Features:
- Static pod mode for Day 1 cluster bootstrap
- DaemonSet deployment for Day 2 operations
- No CNI dependency (minimal system intrusion)
- Configurable VRRP priority and authentication
All charts are published to GitHub Container Registry as OCI artifacts.
Check latest versions: GitHub Releases
# Install cloudflare-tunnel chart
helm install my-tunnel \
oci://ghcr.io/lexfrei/charts/cloudflare-tunnel \
--version <VERSION> \
--values values.yaml
# Install extractedprism
helm install extractedprism \
oci://ghcr.io/lexfrei/charts/extractedprism \
--version <VERSION> \
--set endpoints="CP1_IP:6443,CP2_IP:6443,CP3_IP:6443"
# Install system-upgrade-controller
helm install system-upgrade-controller \
oci://ghcr.io/lexfrei/charts/system-upgrade-controller \
--version <VERSION>
# Install transmission
helm install transmission \
oci://ghcr.io/lexfrei/charts/transmission \
--version <VERSION>
# Install vipalived
helm install vipalived \
oci://ghcr.io/lexfrei/charts/vipalived \
--version <VERSION> \
--set keepalived.vrrpInstance.virtualIpAddress=YOUR_VIP_ADDRESS/CIDRAll charts are signed with cosign using keyless signing:
cosign verify \
ghcr.io/lexfrei/charts/<CHART-NAME>:<VERSION> \
--certificate-identity "https://github.com/lexfrei/charts/.github/workflows/publish-oci.yaml@refs/heads/master" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"Example:
cosign verify \
ghcr.io/lexfrei/charts/cloudflare-tunnel:0.12.6 \
--certificate-identity "https://github.com/lexfrei/charts/.github/workflows/publish-oci.yaml@refs/heads/master" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"All charts in this repository include comprehensive unit tests using helm-unittest.
# Install dependencies
helm plugin install https://github.com/helm-unittest/helm-unittest.git
pip install check-jsonschema
# Run tests
helm unittest charts/cloudflare-tunnel --color
# Validate schema
check-jsonschema --schemafile charts/cloudflare-tunnel/values.schema.json charts/cloudflare-tunnel/values.yaml
# Lint chart
helm lint charts/cloudflare-tunnelSee TESTING.md for detailed testing documentation.
All pull requests automatically run:
- Helm lint
- Schema validation
- Unit tests
Only charts modified in the PR are tested for efficiency.
Contributions are welcome! Please follow these guidelines:
- Fork the repository
- Create a feature branch
- Make your changes following the PR template checklist
- Submit a pull request
When contributing chart changes:
- Always bump the chart version in
Chart.yaml - Update
values.schema.jsonif adding new values - Add/update tests in the
tests/directory - Update the chart README.md with new parameters
- Update the changelog in
Chart.yamlannotations - Follow Helm best practices for template formatting
- Test your changes locally before submitting
- Aleksei Sviridkin - [email protected] - https://me.lex.la
- 🐛 Bug reports: Open an issue
- 💡 Feature requests: Open an issue
- 💬 Questions: Open an issue