Files
wbsong111 16321b52c7 dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
2026-08-06 09:42:24 +09:00

28 KiB
Raw Permalink Blame History

By installing this application, you accept the End User License Agreement & Terms & Conditions.

Rancher

Rancher is open source software that combines everything an organization needs to adopt and run containers in production. Built on Kubernetes, Rancher makes it easy for DevOps teams to test, deploy and manage their applications.

Introduction

This chart bootstraps a Rancher Server on a Kubernetes cluster using the Helm package manager. For a Rancher Supported Deployment please follow our HA install instructions.

Prerequisites Details

For installations covered under Rancher Support SLA the target cluster must be RKE1, RKE2, K3s, AKS, EKS, or GKE.

Make sure the node(s) for the Rancher server fulfill the following requirements:

Operating Systems and Container Runtime Requirements Hardware Requirements

Networking Requirements

Install the Required CLI Tools

For a list of best practices that we recommend for running the Rancher server in production, refer to the best practices section.

Installing Rancher

For production environments, we recommend installing Rancher in a high-availability Kubernetes installation so that your user base can always access Rancher Server. When installed in a Kubernetes cluster, Rancher will integrate with the clusters etcd database and take advantage of Kubernetes scheduling for high-availability.

Optional: Installing Rancher on a Single-node Kubernetes Cluster

Add the Helm Chart Repository

Use helm repo add command to add the Helm chart repository that contains charts to install Rancher. For more information about the repository choices and which is best for your use case, see Choosing a Version of Rancher.

helm repo add rancher-latest https://releases.rancher.com/server-charts/latest

Create a Namespace for Rancher

Well need to define a Kubernetes namespace where the resources created by the Chart should be installed. This should always be cattle-system:

kubectl create namespace cattle-system

Choose your SSL Configuration

The Rancher management server is designed to be secure by default and requires SSL/TLS configuration.

There are three recommended options for the source of the certificate used for TLS termination at the Rancher server:

Install cert-manager

This step is only required to use certificates issued by Ranchers generated CA (ingress.tls.source=rancher) or to request Lets Encrypt issued certificates (ingress.tls.source=letsEncrypt).

These instructions are adapted from the official cert-manager documentation.

Install Rancher with Helm and Your Chosen Certificate Option

helm install rancher rancher-latest/rancher \
  --namespace cattle-system \
  --set hostname=rancher.my.org
helm install rancher rancher-latest/rancher \
  --namespace cattle-system \
  --set hostname=rancher.my.org \
  --set ingress.tls.source=letsEncrypt \
  --set letsEncrypt.email=me@example.org
helm install rancher rancher-latest/rancher \
  --namespace cattle-system \
  --set hostname=rancher.my.org \
  --set ingress.tls.source=secret

If you are using a Private CA signed certificate , add --set privateCA=true to the command:`

helm install rancher rancher-latest/rancher \
  --namespace cattle-system \
  --set hostname=rancher.my.org \
  --set ingress.tls.source=secret \
  --set privateCA=true

Verify that the Rancher Server is Successfully Deployed

After adding the secrets, check if Rancher was rolled out successfully:

kubectl -n cattle-system rollout status deploy/rancher
Waiting for deployment "rancher" rollout to finish: 0 of 3 updated replicas are available...
deployment "rancher" successfully rolled out

If you see the following error: error: deployment "rancher" exceeded its progress deadline, you can check the status of the deployment by running the following command:

kubectl -n cattle-system get deploy rancher
NAME      DESIRED   CURRENT   UP-TO-DATE   AVAILABLE   AGE
rancher   3         3         3            3           3m

It should show the same count for DESIRED and AVAILABLE.

Save Your Options

Make sure you save the --set options you used. You will need to use the same options when you upgrade Rancher to new versions with Helm.

Finishing Up

Thats it. You should have a functional Rancher server.

In a web browser, go to the DNS name that forwards traffic to your load balancer. Then you should be greeted by the colorful login page.

Doesnt work? Take a look at the Troubleshooting Page

All of these instructions are defined in detailed in the Rancher Documentation.

Helm Chart Options for Kubernetes Installations

The full Helm Chart Options can be found here.

Specify each parameter using the --set key=value[,key=value] argument to helm install.

Common Options

Parameter Default Value Description
hostname " " string - the Fully Qualified Domain Name for your Rancher Server
ingress.tls.source "rancher" string - Where to get the cert for the ingress. - "rancher, letsEncrypt, secret"
letsEncrypt.email " " string - Your email address
letsEncrypt.environment "production" string - Valid options: "staging, production"
privateCA false bool - Set to true if your cert is signed by a private CA

Advanced Options

Parameter Default Value Description
additionalTrustedCAs false bool - See Additional Trusted CAs Server
addLocal "true" string - As of Rancher v2.5.0 this flag is deprecated and must be set to "true"
antiAffinity "preferred" string - AntiAffinity rule for Rancher pods - "preferred, required"
replicas 3 int - Number of replicas of Rancher pods
auditLog.destination "sidecar" string - Stream to sidecar container console or hostPath volume - "sidecar, hostPath"
auditLog.hostPath "/var/log/rancher/audit" string - log file destination on host (only applies when auditLog.destination is set to hostPath)
auditLog.level 0 int - set the API Audit Log level
auditLog.enabled false bool - enable the rancher audit logging system
auditLog.maxAge 1 int - maximum number of days to retain old audit log files (only applies when auditLog.destination is set to hostPath)
auditLog.maxBackup 1 int - maximum number of audit log files to retain (only applies when auditLog.destination is set to hostPath)
auditLog.maxSize 100 int - maximum size in megabytes of the audit log file before it gets rotated (only applies when auditLog.destination is set to hostPath)
auditLog.image.repository "rancher/mirrored-bci-micro" string - Location for the image used to collect audit logs Note: Available as of v2.7.0
auditLog.image.tag "15.4.14.3" string - Tag for the image used to collect audit logs Note: Available as of v2.7.0
auditLog.image.pullPolicy "IfNotPresent" string - Override imagePullPolicy for auditLog images - "Always", "Never", "IfNotPresent" Note: Available as of v2.7.0
busyboxImage "" string - Deprecated auditlog.image.repository should be used to control auditing sidecar image. Image location for busybox image used to collect audit logs Note: Available as of v2.2.0, and Deprecated as of v2.7.0
busyboxImagePullPolicy "IfNotPresent" string - - Deprecated auditlog.image.pullPolicy should be used to control auditing sidecar image. Override imagePullPolicy for busybox images - "Always", "Never", "IfNotPresent" Deprecated as of v2.7.0
debug false bool - set debug flag on rancher server
certmanager.version " " string - set cert-manager compatibility
extraEnv [] list - set additional environment variables for Rancher Note: Available as of v2.2.0
imagePullSecrets [] list - list of names of Secret resource containing private registry credentials
ingress.enabled true bool - install ingress resource
ingress.ingressClassName " " string - class name of ingress if not set manually or by the ingress controller's defaults
ingress.includeDefaultExtraAnnotations true bool - Add default nginx annotations
ingress.extraAnnotations {} map - additional annotations to customize the ingress
ingress.configurationSnippet " " string - Add additional Nginx configuration. Can be used for proxy configuration. Note: Available as of v2.0.15, v2.1.10 and v2.2.4
service.annotations {} map - annotations to customize the service
service.type " " string - Override the type used for the service - "NodePort", "LoadBalancer", "ClusterIP"
letsEncrypt.ingress.class " " string - optional ingress class for the cert-manager acmesolver ingress that responds to the Lets Encrypt ACME challenges
proxy " " *string - HTTP[S] proxy server for Rancher
noProxy "127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local" string - comma separated list of hostnames or ip address not to use the proxy
resources {} map - rancher pod resource requests & limits
rancherImage "rancher/rancher" string - rancher image source
rancherImageTag same as chart version string - rancher/rancher image tag
rancherImagePullPolicy "IfNotPresent" string - Override imagePullPolicy for rancher server images - "Always", "Never", "IfNotPresent"
tls "ingress" string - See External TLS Termination for details. - "ingress, external"
systemDefaultRegistry "" string - private registry to be used for all system Docker images, e.g., [http://registry.example.com/] Available as of v2.3.0
useBundledSystemChart false bool - select to use the system-charts packaged with Rancher server. This option is used for air gapped installations. Available as of v2.3.0
customLogos.enabled false bool - Enabled Ember Rancher UI (cluster manager) custom logos and Vue Rancher UI (cluster explorer) custom logos persistence volume
customLogos.volumeSubpaths.emberUi "ember" string - Volume subpath for Ember Rancher UI (cluster manager) custom logos persistence
customLogos.volumeSubpaths.vueUi "vue" string - Volume subpath for Vue Rancher UI (cluster explorer) custom logos persistence
customLogos.volumeName "" string - Use an existing volume. Custom logos should be copied to the proper volume/subpath folder by the user. Optional for persistentVolumeClaim, required for configMap
customLogos.storageClass "" string - Set custom logos persistentVolumeClaim storage class. Required for dynamic pv
customLogos.accessMode "ReadWriteOnce" string - Set custom persistentVolumeClaim access mode
customLogos.size "1Gi" string - Set custom persistentVolumeClaim size