Skip to content

Latest commit

 

History

188 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Governance Platform Deployment

Helm CI Release Platform Package

Helm charts, deployment guides, and helper tooling for deploying the EQTY Lab Governance Platform on Kubernetes. Supports Auth0, Microsoft Entra ID, and Keycloak as identity providers, with cloud-agnostic storage and key vault integration (AWS, Azure, GCP).

🚀 Quick Start

  1. Review the prerequisites. Use the existing GHCR installation path until your version has a verified cloudsmith-delivery.json; then follow Cloudsmith setup.
  2. Pick your identity provider and follow the matching guide in docs/:
  3. Use govctl to generate Helm values and secrets (--artifact-source github for GHCR; the Cloudsmith default only for verified deliveries), then install the governance-platform umbrella chart.

✅ Prerequisites

  • Kubernetes 1.29+
  • Helm 4.0+
  • kubectl configured for your target cluster
  • GitHub package read credentials for GHCR, or an EQTY-issued Cloudsmith prod entitlement for a version with verified delivery
  • A configured identity provider (Auth0, Microsoft Entra ID, or Keycloak)
  • A cloud account (AWS, Azure, or GCP) with object storage and a key/secret vault provisioned for the platform

📁 Repository Structure

  • charts/ — Helm charts for the Governance Platform services (auth, governance, integrity, studio) plus per-IdP bootstrap charts.
  • docs/ — Step-by-step deployment guides for each identity provider, with per-cloud variants (AWS, Azure, GCP), plus the optional OpenBao custody delivery notes.
  • govctl/ — CLI tool for generating Helm values, bootstrap configs, and secrets files interactively.
  • scripts/ — Helper scripts for NGINX ingress setup, cert-manager installation, IdP bootstrap, post-install database seeding, OpenBao operator setup, and release packaging checks.
  • releases/ — Per-version release manifests pinning chart versions, image digests, and source refs for each platform release.
  • containers/ — Custom container image builds (e.g. patched PostgreSQL) used by the platform.
  • schemas/ — JSON schemas for release manifests and other structured artifacts in this repo.

📦 Versioning

Each platform release has a manifest under releases/ that pins the exact chart versions, image digests, and source refs that make up that release. Match the release version to the chart and image versions you deploy — do not mix versions across releases.

The optional openbao-custody delivery has its own wrapper version and Kubernetes 1.30+ minimum. It is published and packaged only when explicitly selected in the release manifest; it is never an umbrella dependency. OpenBao application use remains development-only.

💬 Support

For questions, deployment assistance, or issues, contact your EQTY Lab representative or open an issue in this repository.

Release operators: Cloudsmith mirroring and activation. Internal infrastructure continues to use GHCR; use govctl init --artifact-source github.

About

Helm charts, guides, and CLI tooling for self-hosting the EQTY Lab Governance Platform on Kubernetes

Topics

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages