Helm chart for AGLedger: change control for AI agents on a self-hosted signed ledger.
3.2K
Helm chart for AGLedger, change control for AI agents on a self-hosted signed ledger. Deploys the API server and worker against the bundled PostgreSQL or your own (17+), with the Node.js Permission Model hardening, read-only filesystem, and non-root security context on by default.
The container image lives at agledger/agledger.
The guided installer generates the signing key, picks the database, and runs the install in one step:
curl -fsSL https://agledger.ai/helm-install.sh | bash
To install by hand, take <version> from the Tags tab, generate the vault signing key with the matching image, then install:
umask 077
docker run --rm agledger/agledger:<version> dist/scripts/generate-signing-key.js > signing-key.txt
sed -n 's/^VAULT_SIGNING_KEY=//p' signing-key.txt | tr -d '\n' > vault-signing-key
helm install agledger oci://registry-1.docker.io/agledger/agledger-chart \
--version <version> \
--set config.externalUrl=https://agledger.example.com \
--set postgres.bundled.enabled=true \
--set-file secrets.vaultSigningKey=./vault-signing-key
config.externalUrl is the public URL this Server will be reachable at. It is signed into every record as the issuer and is permanent, so set the real one (https://localhost for a single node with no domain). signing-key.txt also holds the key's Pin: line, which you give to anyone who verifies this install offline; keep the file private, since it holds the private key too. To use your own PostgreSQL (17+) instead of the bundled one, replace --set postgres.bundled.enabled=true with --set database.externalUrl='postgres://...'. The chart's appVersion selects the matching server image, so pinning the chart pins the server.
Values reference: agledger-ai/install/helm/agledger/values.yaml. Full setup and production guidance at agledger.ai/docs.
Every chart version is keyless-signed (GitHub OIDC -> Sigstore Fulcio -> public Rekor); the same release workflow signs the container image. Requires cosign 3.0+:
cosign verify \
--certificate-identity-regexp '^https://github\.com/agledger-ai/agledger-api/\.github/workflows/.+@refs/tags/v.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
registry-1.docker.io/agledger/agledger-chart:<version>
Full verification recipe (image signature, SBOM, OpenVEX, malware-scan attestation, SLSA provenance): SECURITY.md.
Content type
Helm
Digest
sha256:a7e98fa8b…
Size
117.2 kB
Last updated
1 day ago
helm pull oci://registry-1.docker.io/agledger/agledger-chart --version 2.0.0