DirectorySecurity AdvisoriesPricing
Sign in
Directory
rancher logoHELM

rancher

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Rancher

Chainguard's redistribution of the Rancher Helm chart.

Rancher is an open-source, multi-cluster Kubernetes management platform that lets operators provision, upgrade, and manage clusters across on-premises, cloud, and edge environments from a single control plane. This chart installs the Rancher Server workloads (deployment, service, ingress) that expose the Rancher UI and API.

Prerequisites

Authentication is required to access this chart. First, authenticate with Chainguard and configure your environment:

chainctl auth login
chainctl auth configure-docker --pull-token --save
helm registry login cgr.dev

Rancher requires cert-manager when using the default ingress.tls.source=rancher or letsEncrypt TLS options. Install it before installing Rancher:

helm install cert-manager oci://cgr.dev/ORGANIZATION/charts/cert-manager \
  --namespace cert-manager \
  --create-namespace \
  --set crds.enabled=true

Installation

helm install rancher oci://cgr.dev/ORGANIZATION/charts/rancher \
  --namespace cattle-system \
  --create-namespace \
  --set hostname=rancher.my.org \
  --set bootstrapPassword=admin

Once the release is ready, open https://<hostname> and log in with the bootstrap password.

Configuration

Chainguard's chart is a redistribution of the upstream Rancher chart -- all upstream values and documentation apply. A few common overrides:

ValuePurpose

hostname

Fully-qualified name customers use to reach Rancher (drives the ingress).

replicas

Number of Rancher server replicas (default 3).

ingress.tls.source

rancher (self-signed), letsEncrypt, or secret (BYO TLS secret).

bootstrapPassword

Initial admin password; a random one is generated when empty.

auditLog.enabled

Enable API audit logging via the audit-log sidecar.

imagePullSecrets

Image pull secrets for the Rancher, shell, and audit-log images.

For the complete list of values and their defaults, see the upstream values.yaml and the Rancher installation guide.

Images

This chart is wired to the following Chainguard images:

  • cgr.dev/ORGANIZATION/rancher -- the Rancher Server (image.repository / image.tag).
  • cgr.dev/ORGANIZATION/rancher-shell -- used by the postDelete and preUpgrade Helm hook jobs.
  • cgr.dev/ORGANIZATION/busybox -- default for the optional auditLog sidecar; override auditLog.image.repository / auditLog.image.tag to point at your preferred log-tailing image.

Documentation

Chart versions
  • 2.12.13

    Latest
  • 2.12

  • 2

View all chart versions

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.