Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.
Chainguard's redistribution of the Kates chart, configured with Chainguard images for Kates, PostgreSQL, database readiness, backup, migration, and cleanup.
Authenticate to the chart registry:
Kates requires a reachable Kafka cluster and PostgreSQL. Configure Kafka authentication and network-policy egress for your environment. Bundled PostgreSQL is enabled by default; an external database is also supported.
Configure registry credentials for every workload in the namespace. Upstream only attaches imagePullSecrets to the Kates Deployment. For a new evaluation namespace, attach the pull secret to the default service account used by PostgreSQL and the jobs:
This is a sample value set for evaluation, not a production-ready configuration. Save the following as sample-values.yaml, replacing the database password and Kafka address for your environment:
The chart binds PostgreSQL and its backup client to PostgreSQL 16. This sample keeps the upstream PostgreSQL security-context defaults.
The sample assumes Kafka is reachable in namespace kafka on port 9092, matching the default network-policy egress. Adjust networkPolicy.kafka.port for another port and add networkPolicy.egressRules for brokers outside that namespace; the upstream Kafka namespace selector is hardcoded to kafka. API-key authentication remains enabled; the chart generates a key when none is supplied.
For an existing PostgreSQL database, replace the postgresql block in the sample above with the following and add externalDatabase. Replace the hostname, database, and username for your environment:
The chart imports the existing Secret directly as environment variables. Supply both Quarkus credential keys; the advertised passwordKey value does not remap them:
This is also a connection example, not a production deployment recipe. Configure database availability, backups, TLS, credentials, and network access for your environment. Upstream recommends an external managed cluster for production HA; bundled PostgreSQL is a single-instance StatefulSet. Neither database choice requires enabling the optional migration hook: the application runs Flyway migrations at startup for both.
Select the chart's -fips version tag with helm install --version <chart-version>-fips and retain the image's Bouncy Castle module path when setting jvm.options. Add this to your values, adjusting heap sizes to your resource limits:
Use Kafka TLS/SASL settings and BCFKS truststores appropriate to your environment. The TCP readiness helper is shared between variants and performs no cryptographic operations.
migration.enabled defaults to false. It is not required for normal startup migrations or for production releases. If you choose to run the separate pre-upgrade hook, its upstream command assumes /deployments/quarkus-run.jar; the Chainguard image uses /app/quarkus-run.jar.
The following sample overrides that command and waits for Quarkus startup after Flyway completes. The hook does not mount API-key or Kafka secrets, so this short-lived process binds HTTP to loopback, disables its own API authentication, and points Kafka at an unused loopback port. These settings do not change the application Deployment's authentication or Kafka connection. Add the complete block to your values only when enabling this hook:
Backup is disabled by default. backup.enabled=true only runs with bundled PostgreSQL; enable backup.persistence.enabled to retain output. External-database backups are managed separately.
Keep cleanup.enabled=false (the default): the upstream cleanup job omits API-key authentication and requests COMPLETED, which the application does not recognize (DONE is the completed status). Substituting a Chainguard image does not correct that command.
The three upstream helm test hooks use curlimages/curl:8.7.1, not Chainguard images, and require access to that registry.
See the upstream chart documentation for other configuration options.
0.10.7-fips
0.10.7
0.10-fips
0.10