Skip to content
lexfreiPublic

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

1 watching

Forks

Latest commit

 

History

340 Commits

Folders and files

Repository files navigation

Helm Charts Repository

GitHub Release GitHub Release Date Lint and Test License

A collection of Helm charts for Kubernetes deployments, published to GitHub Container Registry (GHCR) as OCI artifacts.

Available Charts

All charts are published to GHCR with cosign signatures for verification.

Kubernetes

Deploy Cloudflare Tunnel (cloudflared) for secure Zero Trust access to Kubernetes services without exposing inbound ports.

Key Features:

  • Zero Trust network access with Cloudflare's edge
  • Dual deployment modes (Deployment/DaemonSet)
  • Prometheus metrics and high availability support
  • Hardened security (non-root, read-only filesystem)

📖 Documentation | 🔧 Values

Kubernetes

Per-node TCP load balancer for Kubernetes API server high availability, inspired by Talos KubePrism.

Key Features:

  • No VIP dependency — each node connects to localhost, eliminating VRRP/keepalived single points of failure
  • Two-level discovery: static bootstrap endpoints + dynamic Kubernetes EndpointSlice watch
  • CNI-independent bootstrap via hostNetwork and static endpoints
  • Health-checked upstreams with automatic failover

📖 Documentation | 🔧 Values

Kubernetes

Kubernetes-native controller for automated node upgrades using declarative Plans. Based on Rancher System Upgrade Controller.

Key Features:

  • Declarative upgrade plans via CRDs
  • Rolling upgrades with concurrency control
  • Node drain and cordon automation
  • K3s, RKE2, and generic Kubernetes support

📖 Documentation | 🔧 Values

Kubernetes

Transmission BitTorrent client deployment with NFS and PVC storage support.

📖 Documentation | 🔧 Values

Kubernetes

VRRP-based Virtual IP management for Kubernetes control plane high availability using keepalived.

Key Features:

  • Static pod mode for Day 1 cluster bootstrap
  • DaemonSet deployment for Day 2 operations
  • No CNI dependency (minimal system intrusion)
  • Configurable VRRP priority and authentication

📖 Documentation | 🔧 Values

Installation

All charts are published to GitHub Container Registry as OCI artifacts.

Check latest versions: GitHub Releases

Install a Chart

# Install cloudflare-tunnel chart
helm install my-tunnel \
  oci://ghcr.io/lexfrei/charts/cloudflare-tunnel \
  --version <VERSION> \
  --values values.yaml

# Install extractedprism
helm install extractedprism \
  oci://ghcr.io/lexfrei/charts/extractedprism \
  --version <VERSION> \
  --set endpoints="CP1_IP:6443,CP2_IP:6443,CP3_IP:6443"

# Install system-upgrade-controller
helm install system-upgrade-controller \
  oci://ghcr.io/lexfrei/charts/system-upgrade-controller \
  --version <VERSION>

# Install transmission
helm install transmission \
  oci://ghcr.io/lexfrei/charts/transmission \
  --version <VERSION>

# Install vipalived
helm install vipalived \
  oci://ghcr.io/lexfrei/charts/vipalived \
  --version <VERSION> \
  --set keepalived.vrrpInstance.virtualIpAddress=YOUR_VIP_ADDRESS/CIDR

Verify Chart Signatures

All charts are signed with cosign using keyless signing:

cosign verify \
  ghcr.io/lexfrei/charts/<CHART-NAME>:<VERSION> \
  --certificate-identity "https://github.com/lexfrei/charts/.github/workflows/publish-oci.yaml@refs/heads/master" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

Example:

cosign verify \
  ghcr.io/lexfrei/charts/cloudflare-tunnel:0.12.6 \
  --certificate-identity "https://github.com/lexfrei/charts/.github/workflows/publish-oci.yaml@refs/heads/master" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

Testing

All charts in this repository include comprehensive unit tests using helm-unittest.

Running Tests Locally

# Install dependencies
helm plugin install https://github.com/helm-unittest/helm-unittest.git
pip install check-jsonschema

# Run tests
helm unittest charts/cloudflare-tunnel --color

# Validate schema
check-jsonschema --schemafile charts/cloudflare-tunnel/values.schema.json charts/cloudflare-tunnel/values.yaml

# Lint chart
helm lint charts/cloudflare-tunnel

See TESTING.md for detailed testing documentation.

CI/CD

All pull requests automatically run:

  • Helm lint
  • Schema validation
  • Unit tests

Only charts modified in the PR are tested for efficiency.

Contributing

Contributions are welcome! Please follow these guidelines:

  1. Fork the repository
  2. Create a feature branch
  3. Make your changes following the PR template checklist
  4. Submit a pull request

Chart Development Guidelines

When contributing chart changes:

  • Always bump the chart version in Chart.yaml
  • Update values.schema.json if adding new values
  • Add/update tests in the tests/ directory
  • Update the chart README.md with new parameters
  • Update the changelog in Chart.yaml annotations
  • Follow Helm best practices for template formatting
  • Test your changes locally before submitting

License

BSD-3-Clause

Maintainer

Support

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages