{"id":13478942,"url":"https://github.com/regel/cardano-charts","last_synced_at":"2025-03-27T08:31:11.660Z","repository":{"id":43814982,"uuid":"396404194","full_name":"regel/cardano-charts","owner":"regel","description":"Helm Charts to deploy a secure Cardano node in Kubernetes","archived":false,"fork":false,"pushed_at":"2023-01-08T21:10:04.000Z","size":1574,"stargazers_count":28,"open_issues_count":1,"forks_count":5,"subscribers_count":3,"default_branch":"master","last_synced_at":"2024-04-14T04:08:50.234Z","etag":null,"topics":["azure","blockchain","cardano","cardano-node","helm","kubernetes","opensource","vault"],"latest_commit_sha":null,"homepage":"","language":"Smarty","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/regel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-08-15T15:52:58.000Z","updated_at":"2024-04-10T17:27:22.000Z","dependencies_parsed_at":"2023-02-08T07:31:32.886Z","dependency_job_id":null,"html_url":"https://github.com/regel/cardano-charts","commit_stats":null,"previous_names":[],"tags_count":12,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/regel%2Fcardano-charts","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/regel%2Fcardano-charts/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/regel%2Fcardano-charts/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/regel%2Fcardano-charts/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/regel","download_url":"https://codeload.github.com/regel/cardano-charts/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245809795,"owners_count":20676054,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["azure","blockchain","cardano","cardano-node","helm","kubernetes","opensource","vault"],"created_at":"2024-07-31T16:02:06.298Z","updated_at":"2025-03-27T08:31:10.971Z","avatar_url":"https://github.com/regel.png","language":"Smarty","funding_links":["https://opencollective.com/gh-regel"],"categories":["Smarty"],"sub_categories":[],"readme":"# Cardano Charts\n\n[![Checkov](https://github.com/regel/cardano-charts/actions/workflows/checkov.yml/badge.svg)](https://github.com/regel/cardano-charts/actions/workflows/checkov.yml) [![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\nContains Helm Charts for operating **the most secure** Cardano nodes in Kubernetes:\n- [charts/cardano](./charts/cardano/README.md)\n\nThis Chart solves common pain points of Cardano node operations:\n- Long bootstrap time for new nodes: this chart can restore testnet or mainnet data at the given epoch using a compressed file archive\n- Security measures: combine this chart with Terraform [modules](https://github.com/regel/terraform-azure-cardano) to enforce best security practices in multiple areas (vault, acls, policies, etc)\n- Upgrades: facilitate upgrades using infrastructure-as-code best practices\n\n## Backers :dart: :heart_eyes:\n\nThank you to all our backers! 🙏 [[Become a backer](https://opencollective.com/gh-regel#backer)]\n\n\u003ca href=\"https://opencollective.com/gh-regel#backers\" target=\"_blank\"\u003e\u003cimg src=\"https://opencollective.com/gh-regel/backers.svg?width=890\"\u003e\u003c/a\u003e\n\n## Sponsors :whale:\n\nSupport this project by becoming a sponsor. Your logo will show up here with a\nlink to your website. [[Become a\nsponsor](https://opencollective.com/gh-regel#sponsor)]\n\n## Donations in ADA :gem:\n\nCardano hodlers can send donations to this wallet address: `addr1q973kf48y9vxqareqvxr7flacx3pl3rz0m9lmwt4nej0zr99dw6mre74f2g48nntw5ar6mz58fm09sk70e0k4vgmkess27g47n`\n\n## Demo\n\n![helm install](./recording/render1645130824759-min.gif)\n\n## Security Measures Every Stake Pool Operator Should Implement\n\nRefer to the Cardano forum [guide](https://forum.cardano.org/t/back-to-basics-security-measures-every-cardano-stake-pool-operators-should-know-and-implement/38166) for keys and secrets management.\n\n### How This Cardano Helm Chart Implements Security Guidelines\n\nThis Cloud Native Helm Chart leverages advanced security features provided in Kubernetes and Cloud vendors extensions. :rotating_light: Ensure that you understand these concepts before using this Chart:\n\n- [Calico](https://docs.microsoft.com/en-us/azure/aks/use-network-policies) plugin: see how this network plugin in Kubernetes enforces `ingress` and `egress` traffic between pods and external IPs using [Network Policies](https://kubernetes.io/docs/concepts/services-networking/network-policies/)\n- Watch this [KubeCon](https://www.youtube.com/watch?v=3gGpMmYeEO8) talk or check out the recipes on [Network Policies](https://github.com/ahmetb/kubernetes-network-policy-recipes). Credits: Ahmet Balkan, Google\n- Key Vault: all secret keys required to run a Cardano node are stored inside a Vault and only mounted where the least access privilege applies. The Azure Vault used in this Chart requires the configuration of a [User Assigned Managed Identity](https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview)\n- Run As NonRoot and set root filesystems Read-Only: Containers run using non-root users according to best Docker practices\n\n## Frequently Asked Questions :question:\n\n### How can Cardano Charts be so Awesome?\n\nHelp me grow this project by becoming a backer and making a [[donation](https://opencollective.com/gh-regel#backer)]\n\n### Where Can I Find Documentation on Azure Key Vault?\n\nHere: [Azure Key Vault](https://docs.microsoft.com/en-us/azure/key-vault/general/basic-concepts)\n\n### Storing Cold Keys in Luna HSM when Using Azure Key Vault? \n\n[Microsoft](https://azure.microsoft.com/): [[Become a sponsor](https://opencollective.com/gh-regel#sponsor)]\n\nTo use Azure HSM for key storage and signature, two things must happen first:\n\n- Azure Key Vault must add support for the [ed25519](https://fr.wikipedia.org/wiki/Curve25519) crypto algorithm used in Cardano. At this time, the current generation of managed HSM hardware does not seem to support it yet\n- `cardano-cli` or another tool must be able to sign Tx raw transactions using the Azure Key Vault [REST API](https://docs.microsoft.com/en-us/rest/api/keyvault/)\n\n### Where Can I Find Documentation on Network Policies?\n\n[Tigera](https://tigera.io): [[Become a sponsor](https://opencollective.com/gh-regel#sponsor)]\n\nTigera web site is a good place to start reading about [Calico](https://docs.projectcalico.org/reference/public-cloud/azure). Also, check their [Definitive guide to container networking, security, and troubleshooting](https://www.tigera.io/lp/calico-open-source-white-paper/)\n\n### Can You Add Support For Other Vaults And Other Cloud Vendors?\n\nSee [CONTRIBUTING](./CONTRIBUTING.md).\n\n### Where To File Issues?\n\nIf you are a vulnerability reporter (for example, a security researcher) who would like to report a vulnerability, first contact me privately via the Telegram link below.\n\nOther issues can be reported on Github.\n\n### How to Contact?\n\nChat :speech_balloon: with me on [Telegram](https://t.me/ghregel)\n\n### Want to Offer A Dream Job? :necktie:\n\nYou know the saying, anything is possible. Just know that I am in Geneva, CH, and therefore I have high expectations. :four_leaf_clover:\n\n## Documentation\n\nThe README documentation is generated by [helm-docs](https://github.com/norwoodj/helm-docs)\n\n### Deploy Using Terraform\n\nYou may find useful resources below:\n\n- [terraform-azure-cardano](https://github.com/regel/terraform-azure-cardano): This repo contains a set of modules in the [modules folder](https://github.com/regel/terraform-azure-cardano/tree/main/modules) for deploying a Cardano node on [Azure](https://portal.azure.com/) using [Terraform](https://www.terraform.io/). \n\n#### Running this Helm Chart :rocket: the hard way\n\nInstall the Azure Key Vault provider:\n\n```\nhelm repo add csi-secrets-store-provider-azure https://azure.github.io/secrets-store-csi-driver-provider-azure/charts\nhelm install csi-secrets-store-provider-azure/csi-secrets-store-provider-azure --generate-name --set secrets-store-csi-driver.syncSecret.enabled=true --namespace kube-system\n```\n\nCustomize the options as needed, and install this Chart:\n\n```\nhelm repo add cardano https://regel.github.io/cardano-charts\nhelm upgrade --install pool \\\n  --values cardano/values.yaml \\\n  --set vault.csi.enabled=false \\\n  --set producer.enabled=false \\\n  --set environment.name=testnet \\\n  --set persistence.sourceFile.enabled=true \\\n  --set persistence.sourceFile.url=$(curl -s https://downloads.csnapshots.io/snapshots/testnet/testnet-db-snapshot.json| jq -r .[].file_name) \\\n    cardano/cardano\n```\n\n#### Query the Blockchain Tip :rocket:\n\nChange the pod namespace and `cardano-cli` options according to the chain id, chart namespace and release name, and run:\n\n```\nkubectl exec -ti -n mainnet mainnet-cardano-relay-0 -c node -- cardano-cli query tip --mainnet\n```\n\n## FAQ\n\n### Solving Init:Error when producer starts for the first time\n\nSynchronizing the Cardano blockchain from scratch takes a long time. To prevent long waiting times, the Init container\nattempts to download a snapshot of the blockchain during their first installation. However, egress traffic\nis blocked for producer nodes and the 'restore' init container cannot download the snapshot:\n\n```\n$ kubectl get po -w\nNAME                     READY   STATUS     RESTARTS   AGE\npool-cardano-producer-0  0/1     Init:3/4   0          46s\npool-cardano-relay-0     2/2     Running    0          52m\npool-cardano-producer-0  0/1     Init:Error   0          2m35s\n```\n\nThe workaround is to disable network policies manually during Init:\n\n```\n$ kubectl delete networkpolicy -l app.kubernetes.io/name=cardano,app.kubernetes.io/component=producer\n```\n\nEnable policies again with `helm upgrade` when the producer node is running.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fregel%2Fcardano-charts","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fregel%2Fcardano-charts","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fregel%2Fcardano-charts/lists"}