Skip to content

Repository files navigation

UnMango Charts

CI Release License Helm repo Built with Nix Last commit

Random Helm charts you may or may not find useful. Use at your own risk.

Usage

helm repo add unmango https://unmango.github.io/charts
helm install filebrowser unmango/filebrowser

Every chart is also published as an OCI artifact under ghcr.io/unmango/charts, with identical contents:

helm install filebrowser oci://ghcr.io/unmango/charts/filebrowser --version <version>

Each chart is its own repository, tagged only with released chart versions, so --version is required. There is no latest tag. The version table below links to the releases each tag corresponds to.

Charts

Chart Upstream Version Status
actions-runner unmango/containers actions-runner Library chart
deemix bambanah/deemix deemix Revived fork
deluge linuxserver/docker-deluge deluge Active
filebrowser filebrowser/filebrowser filebrowser Upstream archived
gha-runner-scale-set actions/actions-runner-controller gha-runner-scale-set Patched fork
gluetun qdm12/gluetun gluetun Library chart
hercules-ci-agent hercules-ci/hercules-ci-agent hercules-ci-agent Active
knot tangled.org/core knot Active
mage-server magefree/mage mage-server Active
qbittorrent linuxserver/docker-qbittorrent qbittorrent Active
unifi linuxserver/docker-unifi-network-application unifi Active

Remarks

actions-runner

Library chart, installs nothing. Provides pod spec fragments (store volume, mount, NIX_CONFIG) for building with Nix. Templates take the nix block as an argument, not .Values; see charts/gha-runner-scale-set/values.yaml for its shape.

gluetun

Library chart, installs nothing. Provides a gluetun VPN sidecar, a Private Internet Access config generator, and the pod DNS setting they need. Its defaults land in the consumer under gluetun, so a consumer's users override them there; templates take that block plus the ports the firewall must admit.

  • pia.enabled (default) needs pia.existingSecret with the PIA account. For any other provider, set pia.enabled: false and configure it through env.
  • firewall.outboundSubnets is empty by default and must be set: the firewall covers the whole pod, so without the cluster's Service CIDR the workload cannot reach the cluster DNS Service and every lookup fails. Add the pod CIDR for direct pod traffic.
  • gluetun runs as a native sidecar, so consumers need Kubernetes 1.29 or newer.

gha-runner-scale-set

Upstream chart, patched to wire in a Nix store. templates/ and values.yaml are generated (make chart-gha-runner-scale-set); edit patches/, never the generated files.

  • nix.store.backing: hostPath needs the node directory pre-created and writable; prefer existingClaim unless you need a shared warm store.
  • Never backing: none for a runner that builds (overlayfs breaks nix's build-dir teardown).
  • Never share one store via ReadWriteMany (SQLite + flock corrupts over NFS/CephFS).
  • Set nix.maxJobs/nix.cores explicitly, nix ignores cgroup CPU limits and defaults to 1 job.
  • containerMode: kubernetes-novolume mounts nothing; not for a runner that builds.
  • Keeps upstream's labels helper, since the controller keys on app.kubernetes.io/name.

Hercules CI Agent

No upstream image or chart; uses unmango/containers.

  • Set clusterJoinToken or existingSecret (cluster-join-token.key, binary-caches.json, secrets.json); rotating existingSecret needs a manual pod restart.
  • Chart overrides the image's broken SSL_CERT_FILE/NIX_SSL_CERT_FILE paths.
  • No /nix/var/nix; Nix chroots into the persistent volume, so persistence.size defaults to 100Gi and losing the volume also loses the agent's session key.
  • effects.enabled: true runs the pod privileged.
  • Excluded from ct install: without a real join token it never reaches Ready.

Knot

A Tangled knot, the git server behind Tangled repositories. Runs knot 2, the Rust implementation, which serves SSH itself and keeps its state in git rather than SQLite. Upstream's image at atcr.io requires credentials to pull, so the chart uses ghcr.io/unmango/knot from unmango/containers.

  • hostname and admins are required. The hostname becomes the knot's did:web identity and cannot change later; the first admin is the owner you register on tangled.org.
  • The appview builds SSH clone URLs with no port, so users expect SSH on port 22 of hostname. Set ssh.service.type: LoadBalancer, or route port 22 to the -ssh Service some other way.
  • The master key is generated into a Secret that uninstall keeps. Back it up with the state volume: the sealed key store there is useless without it, and the knot cannot prove ownership of its repository DIDs without both.
  • Behind an Ingress or Gateway, set trustedProxyHeader and trustedProxies, or the knot rate limits every client as the proxy.
  • Configuration is passed as KNOT_* environment variables. extraEnv reaches any other setting, and config mounts a raw config.toml for the [messages] block, which has no variables.
  • Moving from the Go knot is a one-off knot-migrate run, which the image carries; see Migrating to knot 2.

XMage

No upstream image; uses xmage-docker. server.* values map to XMAGE_* env vars; existingConfigMap bypasses that mapping entirely.

  • Raw TCP on 17171/17179, no Ingress/HTTPRoute, expose via LoadBalancer, NodePort, or TCPRoute.
  • server.secondaryBindPort must be a fixed port (not -1).
  • First start takes minutes to load the card database; readiness probe allows 10 minutes.
  • Runs as root; capabilities are dropped but runAsNonRoot is not set.

UniFi

Uses the linuxserver image, which needs a separate MongoDB service; the chart deploys one or connects to yours through database.host.

  • mongodb.enabled: true (default) deploys mongo:8.0 beside the controller; set it false and fill database.host to use your own.
  • MongoDB 8.0 is the newest the controller supports; Renovate holds the bundled image below 8.1.
  • Passwords are generated and kept across upgrades unless set; database.existingSecret needs mongodb-password, plus mongodb-root-password with the bundled MongoDB.
  • The init script creates the controller user only on an empty data directory; changing database.* later does not alter it.
  • Devices need inform (TCP 8080) and stun (UDP 3478) on the Service; discovery does not cross subnets, so devices elsewhere need set-inform.
  • The UI serves a self-signed certificate on 8443, so there is no Ingress or HTTPRoute.
  • mongodb.tls.enabled serves TLS from a secret holding the certificate and its key in one PEM file, the layout cert-manager's CombinedPEM output format writes; database.tls points the controller at it and is first-run-only, like the rest of database.*.
  • The controller validates that certificate against the JVM truststore, so a privately issued one needs truststore.existingConfigMap or truststore.existingSecret holding a PKCS12 truststore. It replaces the JVM's own, so keep the public CAs in it.

Filebrowser

Upstream is archived (2026-09-01), no further releases or fixes. The chart still works against the final image.

Deemix

Upstream (RemixDev) is abandoned. The chart deploys the maintained fork at bambanah/deemix.

Deluge and qBittorrent

linuxserver images behind the gluetun library's VPN sidecar.

  • gluetun.pia.existingSecret is required unless gluetun.enabled is false.
  • The pod is Ready only once the tunnel is up.
  • qBittorrent: auth.password or auth.existingSecret is written into qBittorrent.conf as a PBKDF2 hash on every start; without either, the log shows a temporary password.
  • Deluge: torrentPort must match the incoming port in Deluge's preferences, since the image does not read it from the environment. The WebUI starts with the password deluge.

About

Smörgåsbord of Helm charts

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages