Helm charts for m0sh1.cc self-hosted services and GitOps deployments.
  • Shell 84.2%
  • Go Template 12.9%
  • JavaScript 2.9%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Yael cbaf29f73f
All checks were successful
ci/woodpecker/push/build Pipeline was successful
ci/woodpecker/push/release-all Pipeline was successful
Tag published charts / release (push) Successful in 2m41s
Merge pull request 'chore(deps): update forgejo-runner docker tag to v0.1.23' (#542) from renovate/patch-forgejo-helm-chart into main
Reviewed-on: ⁨#542⁩
2026-10-02 12:03:53 +00:00
.ci Fix maintained CSI S3 image tag contract 2026-09-30 21:24:08 +02:00
.forgejo/workflows ci: gate releases and enable persistent caching 2026-08-11 03:01:26 +02:00
.woodpecker ci: validate changed charts on main pushes 2026-09-25 23:34:37 +02:00
charts Fix vendored Forgejo Runner dependency archive 2026-10-02 13:56:57 +02:00
examples/argocd fix(charts): refresh audit metadata and ArgoCD examples 2026-09-25 13:11:43 +02:00
hack ci: gate releases and enable persistent caching 2026-08-11 03:01:26 +02:00
.gitignore chore(ci): new helm-lint, remove ct/release 2026-09-25 11:58:00 +02:00
.kube-linter.yaml feat: harden Helm chart CI and publishing 2026-06-14 07:39:22 +02:00
.pre-commit-config.yaml chore(ci): new helm-lint, remove ct/release 2026-09-25 11:58:00 +02:00
.rumdl.toml Update tooling configs for helm-charts 2025-12-30 11:42:51 +01:00
.yamllint.yml Update tooling configs for helm-charts 2025-12-30 11:42:51 +01:00
artifacthub-repo.yml chore(ci): streamline ct config, hooks, docs, and Artifact Hub metadata 2025-12-30 03:26:35 +01:00
CHANGELOG.md fix(charts): refresh audit metadata and ArgoCD examples 2026-09-25 13:11:43 +02:00
cliff.toml chore: add SonarQube CI and refresh tooling 2026-01-19 20:29:46 +01:00
CONTRIBUTING.md docs: describe the current CI and release flow 2026-09-25 11:59:43 +02:00
LICENSE Initial commit 2025-12-29 22:22:37 +01:00
mise.toml fix(charts): refresh audit metadata and ArgoCD examples 2026-09-25 13:11:43 +02:00
README.md docs: describe the current CI and release flow 2026-09-25 11:59:43 +02:00
renovate.json feat(csi-s3): driver v0.43.9-yael.1 2026-09-25 17:57:06 +02:00

Helm Charts

Helm charts published as OCI artefacts to oci://ghcr.io/isityael/charts.

Usage

# Pull a chart
helm pull oci://ghcr.io/isityael/charts/<chart-name> --version <version>

# Install directly from OCI
helm install <release-name> oci://ghcr.io/isityael/charts/<chart-name> --version <version>

Charts

Chart Description
basic-memory Basic Memory MCP server with an optional Obsidian LiveSync integration
cloudflared Cloudflare Tunnel connector
cnpg-stack CloudNativePG operator, cluster, Barman Cloud plugin, PgBouncer pooler and scrape objects
csi-driver-nfs NFS CSI driver (isityael fork with configurable fsGroupPolicy)
csi-s3 k8s-csi-s3 with an owned driver image and multiple StorageClasses
forgejo Forgejo with custom image defaults and an optional runner
forgejo-runner Forgejo Actions runner with optional Docker-in-Docker
m0sh1-exporter Network exporters for OPNsense, SNMP and Proxmox VE
proxmox-csi-plugin Proxmox CSI plugin (isityael fork)
tailscale-webhook-relay Relays Tailscale webhook events to ntfy
traefik Traefik on Docker Hardened Images with m0sh1 edge defaults
wakapi-dhi Wakapi, the WakaTime-compatible coding statistics server, on Docker Hardened Images

Current versions are in each charts/<chart>/Chart.yaml and on GHCR. Retired charts are kept outside Git in charts/deprecated/ (ignored).

Publishing

On every push to main that touches charts/**, Woodpecker's release-all pipeline publishes each chart version that isn't on GHCR yet. It runs only after the build pipeline passes, and it can also be triggered manually.

Forgejo Actions (.forgejo/workflows/release-tag.yaml) then tags each published version as <chart>-v<version>. It first waits for both Woodpecker pipelines to succeed on that commit.

The publish script records pushed immutable OCI digest references in .ci/published-oci-refs.txt. If COSIGN_PRIVATE_KEY and COSIGN_PASSWORD are present in the script environment, those digest references are signed with cosign sign --key env://COSIGN_PRIVATE_KEY.

Artifact Hub OCI metadata

The release pipeline also publishes repository metadata to the artifacthub.io tag of every active chart repository. The OCI payload contains the owners from artifacthub-repo.yml, but deliberately omits its repositoryID: that ID belongs to the legacy HTTP chart repository and is not valid for OCI charts.

Artifact Hub requires one repository registration per OCI chart. Register each chart in the Artifact Hub control panel with a URL in this form:

oci://ghcr.io/isityael/charts/<chart-name>

Each registration receives a unique repository ID. Add per-chart IDs only if Verified Publisher status is needed; never reuse the legacy HTTP repository ID.

Development

# Install the prek hooks (YAML checks, chart version bump, Helm lint)
mise run hooks-install

# Lint and render all charts, or only the ones given
mise run helm-lint
mise run helm-lint charts/<chart-name>

# Validate the rendered manifests in .ci/rendered
mise run kube-linter

# Run the repository contract tests
mise run test-shell

Licence

See LICENSE.