{"id":13843801,"url":"https://github.com/aquasecurity/aqua-helm","last_synced_at":"2025-10-13T07:21:49.215Z","repository":{"id":37405960,"uuid":"92829645","full_name":"aquasecurity/aqua-helm","owner":"aquasecurity","description":"Helm Charts For Installing Aqua Security Components ","archived":false,"fork":false,"pushed_at":"2025-09-15T11:13:48.000Z","size":2640,"stargazers_count":87,"open_issues_count":7,"forks_count":189,"subscribers_count":13,"default_branch":"2022.4","last_synced_at":"2025-09-27T10:27:24.593Z","etag":null,"topics":["aqua-agent","aqua-server","enforcer","helm-charts","kubernetes","scanner","security-tools"],"latest_commit_sha":null,"homepage":"http://aquasec.com","language":"Mustache","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aquasecurity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2017-05-30T12:16:16.000Z","updated_at":"2025-09-19T17:14:55.000Z","dependencies_parsed_at":"2023-02-15T17:01:37.765Z","dependency_job_id":"bc522038-55f3-484e-b631-b70298156ae3","html_url":"https://github.com/aquasecurity/aqua-helm","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/aquasecurity/aqua-helm","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aquasecurity%2Faqua-helm","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aquasecurity%2Faqua-helm/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aquasecurity%2Faqua-helm/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aquasecurity%2Faqua-helm/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aquasecurity","download_url":"https://codeload.github.com/aquasecurity/aqua-helm/tar.gz/refs/heads/2022.4","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aquasecurity%2Faqua-helm/sbom","scorecard":{"id":204650,"data":{"date":"2025-08-11","repo":{"name":"github.com/aquasecurity/aqua-helm","commit":"8d7f231c71b032321b5d959afddfa419f7c52171"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":6.3,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":9,"reason":"Found 21/22 approved changesets -- score normalized to 9","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 29 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-16T23:27:29.305Z","repository_id":37405960,"created_at":"2025-08-16T23:27:29.305Z","updated_at":"2025-08-16T23:27:29.305Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279014111,"owners_count":26085463,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-13T02:00:06.723Z","response_time":61,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aqua-agent","aqua-server","enforcer","helm-charts","kubernetes","scanner","security-tools"],"created_at":"2024-08-04T17:02:27.615Z","updated_at":"2025-10-13T07:21:49.209Z","avatar_url":"https://github.com/aquasecurity.png","language":"Mustache","funding_links":[],"categories":["Mustache"],"sub_categories":[],"readme":"\u003cimg src=\"https://avatars3.githubusercontent.com/u/12783832?s=200\u0026v=4\" height=\"100\" width=\"100\" /\u003e\u003cimg src=\"https://avatars3.githubusercontent.com/u/15859888?s=200\u0026v=4\" width=\"100\" height=\"100\"/\u003e\n\n# Overview\n\n\nThis page contains instructions for deploying Aqua Enterprise in a Kubernetes cluster, using the [Helm package manager](https://helm.sh/).\n\nRefer to the Aqua Enterprise product documentation for the broader context: [Kubernetes with Helm Charts](https://docs.aquasec.com/v2022.4/docs/kubernetes-with-helm).\n\n## Contents\n\n- [Overview](#overview)\n  - [Contents](#contents)\n  - [Helm charts](#helm-charts)\n- [Deployment instructions](#deployment-instructions)\n    - [(Optional) Add the Aqua Helm repository](#optional-add-the-aqua-helm-repository)\n        - [For Helm 2.x](#for-helm-2x)\n        - [For Helm 3.x](#for-helm-3x)\n    - [Deploy the Helm charts](#deploy-the-helm-charts)\n      - [Error 2](#error-2)\n      - [Error 3](#error-3)\n- [Quick-start deployment (not for production purposes)](#quick-start-deployment-not-for-production-purposes)\n- [Issues and feedback](#issues-and-feedback)\n\n## Helm charts\n\nThis repository includes the following charts; they can be deployed separately:\n\n| Chart                               | Description                                                                                                                                                   | Latest Chart Version |\n|-------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------|\n| [Server](server/)                   | Deploys the Console, Database, and Gateway components; optionally deploys Envoy component                                                                     | 2022.4.34            |\n| [Enforcer](enforcer/)               | Deploys the Aqua Enforcer daemonset                                                                                                                           | 2022.4.25            |\n| [Scanner](scanner/)                 | Deploys the Aqua Scanner deployment                                                                                                                           | 2022.4.13            |\n| [KubeEnforcer](kube-enforcer/)      | Deploys Aqua KubeEnforcer                                                                                                                                     | 2022.4.67            |\n| [Gateway](gateway)                  | Deploys the Aqua Standalone Gateway                                                                                                                           | 2022.4.17            |\n| [Tenant-Manager](tenant-manager/)   | Deploys the Aqua Tenant Manager                                                                                                                               | 2022.4.1             |\n| [Cyber Center](cyber-center/)       | Deploys Aqua CyberCenter offline for air-gap environment                                                                                                      | 2022.4.6             |\n| [Cloud Connector](cloud-connector/) | Deploys the Aqua Cloud Connector                                                                                                                              | 2022.4.5             |\n| [QuickStart](aqua-quickstart/)      | Not for production use (see [below](#quick-start-deployment-not-for-production-purposes)). Deploys the Console, Database, Gateway and KubeEnforcer components | 2022.4.2             |\n| [Codesec-Agent](codesec-agent/)     | Argon Broker Deployment                                                                                                                                       | 1.2.11               |\n\n# Deployment instructions\n\nAqua Enterprise deployments include the following components:\n- Server (Console, Database, and Gateway)\n- Enforcer\n- KubeEnforcer\n- Scanner (Optional)\n\nFollow the steps in this section for production-grade deployments. You can either clone the aqua-helm git repo or you can add our Helm private repository ([https://helm.aquasec.com](https://helm.aquasec.com)).\n\n### (Optional) Add the Aqua Helm repository\n\n1. Add the Aqua Helm repository to your local Helm repos by executing the following command:\n ```shell\n helm repo add aqua-helm https://helm.aquasec.com\n helm repo update\n ```\n\n2. Search for all components of the latest version in our Aqua Helm repository\n\n##### For Helm 2.x\n```shell\nhelm search aqua-helm\n# Examples\nhelm search aqua-helm --versions\nhelm search aqua-helm --version 2022.4\n```\n\n##### For Helm 3.x\n```shell\nhelm search repo aqua-helm\n# Examples\nhelm search repo aqua-helm --versions\nhelm search repo aqua-helm --version 2022.4\n```\n\nExample output:\n```csv\nNAME                            CHART VERSION   APP VERSION     DESCRIPTION\naqua-helm/codesec-agent         1.2.11          2022.4          A Helm chart for the Argon Broker Deployment\naqua-helm/cloud-connector       2022.4.4        2022.4          A Helm chart for Aqua Cloud-Connector\naqua-helm/cyber-center          2022.4.6        2022.4          A Helm chart for Aqua CyberCenter\naqua-helm/enforcer              2022.4.25       2022.4          A Helm chart for the Aqua Enforcer\naqua-helm/kube-enforcer         2022.4.67       2022.4          A Helm chart for the Aqua KubeEnforcer Starboard/Trivy\naqua-helm/gateway               2022.4.17       2022.4          A Helm chart for the Aqua Gateway\naqua-helm/scanner               2022.4.13       2022.4          A Helm chart for the Aqua Scanner CLI component\naqua-helm/server                2022.4.34       2022.4          A Helm chart for the Aqua Console components\naqua-helm/tenant-manager        2022.4.1        2022.4          A Helm chart for the Aqua Tenant Manager\n```\n\n### Deploy the Helm charts\n\n1. Add Aqua Helm Repository\n   ```\n   helm repo add aqua-helm https://helm.aquasec.com\n   helm repo update\n   ```\n   Check for available chart versions either from [Changelog](./CHANGELOG.md) or by running the below command.\n    ```\n   helm search repo aqua-helm/enforcer --versions\n   ```\n\n   Create the `aqua` namespace.\n    ```shell\n    kubectl create namespace aqua\n    ```\n   Create `aqua-registry` secret\n   ```\n   kubectl create secret docker-registry aqua-registry-secret \\\n    --docker-server=registry.aquasec.com \\\n    --docker-username=$YOUR_REGISTRY_USER \\\n    --docker-password=$YOUR_REGISTRY_PASSWORD \\\n    -n aqua\n   ```\n2. Deploy the [**Server**](server/) chart.\n    ```\n   helm upgrade --install --namespace aqua aqua aqua-helm/server --version $VERSION \\\n   --set imageCredentials.create=false \\\n   --set global.platform=$PLATFORM\n    ```\n3. Deploy the [**Enforcer**](enforcer/) chart.\n    ```\n   helm upgrade --install --namespace aqua aqua-enforcer aqua-helm/enforcer --version $VERSION \\\n   --set imageCredentials.create=false \\\n   --set global.platform=$PLATFORM\n    ```\n4. Deploy the [**KubeEnforcer**](kube-enforcer/) chart.\n    ```\n   helm upgrade --install --namespace aqua kube-enforcer aqua-helm/kube-enforcer --version $VERSION \\\n    --set global.platform=$PLATFORM \\\n    --set certsSecret.autoGenerate=true\n    ```\n5. (Optional) Deploy the [**Scanner**](scanner/) chart.\n    ```\n   helm upgrade --install --namespace aqua scanner aqua-helm/scanner --version $VERSION \\\n    --set user=$AQUA_CONSOLE_USERNAME \\\n    --set password=$AQUA_CONSOLE_PASSWORD\n    ```\n6. Gateway is Deployed by default with Server chart, advanced Gateway Deployment options can be found [**Here**](gateway/).\n7. (Optional) Deploy the [**TenantManager**](tenant-manager/) chart.\n    ```\n   helm upgrade --install --namespace aqua tenant-manager aqua-helm/tenant-manager --version $VERSION \\\n   --set platform=$PLATFORM\n    ```\n8. (Optional) Deploy the [**Cyber-Center**](cyber-center/) chart.\n    ```\n   helm upgrade --install --namespace aqua aqua-cyber-center aqua-helm/cyber-center --version $VERSION \\\n   --set imageCredentials.create=false\n    ```\n9. (Optional) Deploy the [**Cloud-Connector**](cloud-connector) chart.\n    ```\n    helm upgrade --install --namespace aqua aqua-cloud-connector aqua-helm/cloud-connector --version $VERSION \\\n   --set userCreds.username=$AQUA_CONSOLE_USERNAME \\\n   --set userCreds.password=$AQUA_CONSOLE_PASSWORD \\\n   --set authType.tokenAuth=false \\\n   --set authType.userCreds=true\n    ```\n10. Access the Aqua UI in browser with {{ .Release.Name }}-console-svc service and port, to check the service details:\n      ```shell\n      kubectl get svc -n aqua\n      ```\n    * Example:\n        * http://\u003c Console IP/DNS \u003e:8080* (default access without SSL) or\n        * https://\u003c Console IP/DNS \u003e:443* (If SSL configured to console component in server chart)\n### Troubleshooting\n\n**This section not all-inclusive. It describes some common issues that we have encountered during deployments.**\n\n#### Error 1\n\n* Error message: **UPGRADE/INSTALL FAILED, configmaps is forbidden.**\n* Example:\n\n```shell\nError: UPGRADE FAILED: configmaps is forbidden: User \"system:serviceaccount:kube-system:default\" cannot list configmaps in the namespace \"kube-system\"\n```\n\n* Solution: Create a service account for Tiller to utilize.\n```shell\nkubectl create serviceaccount --namespace kube-system tiller\nkubectl create clusterrolebinding tiller-cluster-rule --clusterrole=cluster-admin --serviceaccount=kube-system:tiller\nkubectl patch deploy --namespace kube-system tiller-deploy -p '{\"spec\":{\"template\":{\"spec\":{\"serviceAccount\":\"tiller\"}}}}'\nhelm init --service-account tiller --upgrade\n```\n\n#### Error 2\n\n* Error message: **No persistent volumes available for this claim and no storage class is set.**\n* Solution: Most managed Kubernetes deployments do NOT include all possible storage provider variations at setup time. Refer to the [official Kubernetes guidance on storage classes](https://kubernetes.io/docs/concepts/storage/storage-classes/) for your platform.\n  For more information see the [storage documentation](docs/storage.md).\n\n#### Error 3\n\n* Error message: When executing `kubectl get events -n aqua` you might encounter either **No persistent volumes available for this claim and no storage class is set** or\n  **PersistentVolumeClaim is not bound**.\n* Solution: If you encounter either of these errors, you need to create a persistent volume prior to chart deployment with a generic or existing storage class. Specify `db.persistence.storageClass` in the values.yaml file. A sample file using `aqua-storage` is included in the repo.\n\n```shell\nkubectl apply -f pv-example.yaml\n```\n\n# Quick-start deployment (not for production purposes)\n\nQuick-start deployments are fast and easy.\nThey are intended for deploying Aqua Enterprise for non-production purposes, such as proofs-of-concept (POCs) and environments intended for instruction, development, and test.\n\nUse the [**aqua-quickstart**](aqua-quickstart) chart to\n\n1. Clone the GitHub repository\n  ```shell\n  git clone https://github.com/aquasecurity/aqua-helm.git\n  cd aqua-helm/\n  ```\n\n2. Create the `aqua` namespace.\n  ```shell\n  kubectl create namespace aqua\n  ```\n\n3. Deploy aqua-quickstart chart\n  ```shell\n  helm upgrade --install --namespace aqua aqua ./aqua-quickstart --set imageCredentials.username=\u003c\u003e,imageCredentials.password=\u003c\u003e\n  ```\n\n# Issues and feedback\n\nIf you encounter any problems or would like to give us feedback on deployments, we encourage you to raise issues here on GitHub.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faquasecurity%2Faqua-helm","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faquasecurity%2Faqua-helm","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faquasecurity%2Faqua-helm/lists"}