Sign inSign up

agledger/agledger-chart

By agledger

•Updated 1 day ago

Helm chart for AGLedger: change control for AI agents on a self-hosted signed ledger.

Helm
0

3.2K

agledger/agledger-chart repository overview

⁠AGLedger Helm chart

Helm chart for AGLedger⁠, change control for AI agents on a self-hosted signed ledger. Deploys the API server and worker against the bundled PostgreSQL or your own (17+), with the Node.js Permission Model hardening, read-only filesystem, and non-root security context on by default.

The container image lives at agledger/agledger⁠.

⁠Install

The guided installer generates the signing key, picks the database, and runs the install in one step:

curl -fsSL https://agledger.ai/helm-install.sh | bash

To install by hand, take <version> from the Tags tab, generate the vault signing key with the matching image, then install:

umask 077
docker run --rm agledger/agledger:<version> dist/scripts/generate-signing-key.js > signing-key.txt
sed -n 's/^VAULT_SIGNING_KEY=//p' signing-key.txt | tr -d '\n' > vault-signing-key

helm install agledger oci://registry-1.docker.io/agledger/agledger-chart \
  --version <version> \
  --set config.externalUrl=https://agledger.example.com \
  --set postgres.bundled.enabled=true \
  --set-file secrets.vaultSigningKey=./vault-signing-key

config.externalUrl is the public URL this Server will be reachable at. It is signed into every record as the issuer and is permanent, so set the real one (https://localhost for a single node with no domain). signing-key.txt also holds the key's Pin: line, which you give to anyone who verifies this install offline; keep the file private, since it holds the private key too. To use your own PostgreSQL (17+) instead of the bundled one, replace --set postgres.bundled.enabled=true with --set database.externalUrl='postgres://...'. The chart's appVersion selects the matching server image, so pinning the chart pins the server.

Values reference: agledger-ai/install/helm/agledger/values.yaml⁠. Full setup and production guidance at agledger.ai/docs⁠.

⁠Verify the chart

Every chart version is keyless-signed (GitHub OIDC -> Sigstore Fulcio -> public Rekor); the same release workflow signs the container image. Requires cosign 3.0+:

cosign verify \
  --certificate-identity-regexp '^https://github\.com/agledger-ai/agledger-api/\.github/workflows/.+@refs/tags/v.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  registry-1.docker.io/agledger/agledger-chart:<version>

Full verification recipe (image signature, SBOM, OpenVEX, malware-scan attestation, SLSA provenance): SECURITY.md⁠.

Tag summary

Content type

Helm

Digest

sha256:a7e98fa8b…

Size

117.2 kB

Last updated

1 day ago

helm pull oci://registry-1.docker.io/agledger/agledger-chart --version 2.0.0