Random Helm charts you may or may not find useful. Use at your own risk.
helm repo add unmango https://unmango.github.io/charts
helm install filebrowser unmango/filebrowserEvery chart is also published as an OCI artifact under ghcr.io/unmango/charts, with identical contents:
helm install filebrowser oci://ghcr.io/unmango/charts/filebrowser --version <version>Each chart is its own repository, tagged only with released chart versions, so --version is required.
There is no latest tag.
The version table below links to the releases each tag corresponds to.
Library chart, installs nothing.
Provides pod spec fragments (store volume, mount, NIX_CONFIG) for building with Nix.
Templates take the nix block as an argument, not .Values; see charts/gha-runner-scale-set/values.yaml for its shape.
Library chart, installs nothing.
Provides a gluetun VPN sidecar, a Private Internet Access config generator, and the pod DNS setting they need.
Its defaults land in the consumer under gluetun, so a consumer's users override them there; templates take that block plus the ports the firewall must admit.
pia.enabled(default) needspia.existingSecretwith the PIA account. For any other provider, setpia.enabled: falseand configure it throughenv.firewall.outboundSubnetsis empty by default and must be set: the firewall covers the whole pod, so without the cluster's Service CIDR the workload cannot reach the cluster DNS Service and every lookup fails. Add the pod CIDR for direct pod traffic.- gluetun runs as a native sidecar, so consumers need Kubernetes 1.29 or newer.
Upstream chart, patched to wire in a Nix store.
templates/ and values.yaml are generated (make chart-gha-runner-scale-set); edit patches/, never the generated files.
nix.store.backing: hostPathneeds the node directory pre-created and writable; preferexistingClaimunless you need a shared warm store.- Never
backing: nonefor a runner that builds (overlayfs breaks nix's build-dir teardown). - Never share one store via
ReadWriteMany(SQLite + flock corrupts over NFS/CephFS). - Set
nix.maxJobs/nix.coresexplicitly, nix ignores cgroup CPU limits and defaults to 1 job. containerMode: kubernetes-novolumemounts nothing; not for a runner that builds.- Keeps upstream's
labelshelper, since the controller keys onapp.kubernetes.io/name.
No upstream image or chart; uses unmango/containers.
- Set
clusterJoinTokenorexistingSecret(cluster-join-token.key,binary-caches.json,secrets.json); rotatingexistingSecretneeds a manual pod restart. - Chart overrides the image's broken
SSL_CERT_FILE/NIX_SSL_CERT_FILEpaths. - No
/nix/var/nix; Nix chroots into the persistent volume, sopersistence.sizedefaults to100Giand losing the volume also loses the agent's session key. effects.enabled: trueruns the pod privileged.- Excluded from
ct install: without a real join token it never reaches Ready.
A Tangled knot, the git server behind Tangled repositories.
Runs knot 2, the Rust implementation, which serves SSH itself and keeps its state in git rather than SQLite.
Upstream's image at atcr.io requires credentials to pull, so the chart uses ghcr.io/unmango/knot from unmango/containers.
hostnameandadminsare required. The hostname becomes the knot'sdid:webidentity and cannot change later; the first admin is the owner you register on tangled.org.- The appview builds SSH clone URLs with no port, so users expect SSH on port 22 of
hostname. Setssh.service.type: LoadBalancer, or route port 22 to the-sshService some other way. - The master key is generated into a Secret that uninstall keeps. Back it up with the
statevolume: the sealed key store there is useless without it, and the knot cannot prove ownership of its repository DIDs without both. - Behind an Ingress or Gateway, set
trustedProxyHeaderandtrustedProxies, or the knot rate limits every client as the proxy. - Configuration is passed as
KNOT_*environment variables.extraEnvreaches any other setting, andconfigmounts a rawconfig.tomlfor the[messages]block, which has no variables. - Moving from the Go knot is a one-off
knot-migraterun, which the image carries; see Migrating to knot 2.
No upstream image; uses xmage-docker.
server.* values map to XMAGE_* env vars; existingConfigMap bypasses that mapping entirely.
- Raw TCP on
17171/17179, no Ingress/HTTPRoute, expose via LoadBalancer, NodePort, or TCPRoute. server.secondaryBindPortmust be a fixed port (not-1).- First start takes minutes to load the card database; readiness probe allows 10 minutes.
- Runs as root; capabilities are dropped but
runAsNonRootis not set.
Uses the linuxserver image, which needs a separate MongoDB service; the chart deploys one or connects to yours through database.host.
mongodb.enabled: true(default) deploysmongo:8.0beside the controller; set itfalseand filldatabase.hostto use your own.- MongoDB 8.0 is the newest the controller supports; Renovate holds the bundled image below 8.1.
- Passwords are generated and kept across upgrades unless set;
database.existingSecretneedsmongodb-password, plusmongodb-root-passwordwith the bundled MongoDB. - The init script creates the controller user only on an empty data directory; changing
database.*later does not alter it. - Devices need
inform(TCP 8080) andstun(UDP 3478) on the Service; discovery does not cross subnets, so devices elsewhere needset-inform. - The UI serves a self-signed certificate on 8443, so there is no Ingress or HTTPRoute.
mongodb.tls.enabledserves TLS from a secret holding the certificate and its key in one PEM file, the layout cert-manager'sCombinedPEMoutput format writes;database.tlspoints the controller at it and is first-run-only, like the rest ofdatabase.*.- The controller validates that certificate against the JVM truststore, so a privately issued one needs
truststore.existingConfigMaportruststore.existingSecretholding a PKCS12 truststore. It replaces the JVM's own, so keep the public CAs in it.
Upstream is archived (2026-09-01), no further releases or fixes. The chart still works against the final image.
Upstream (RemixDev) is abandoned. The chart deploys the maintained fork at bambanah/deemix.
linuxserver images behind the gluetun library's VPN sidecar.
gluetun.pia.existingSecretis required unlessgluetun.enabledis false.- The pod is Ready only once the tunnel is up.
- qBittorrent:
auth.passwordorauth.existingSecretis written intoqBittorrent.confas a PBKDF2 hash on every start; without either, the log shows a temporary password. - Deluge:
torrentPortmust match the incoming port in Deluge's preferences, since the image does not read it from the environment. The WebUI starts with the passworddeluge.