



  

<!DOCTYPE html>
<html
  lang="en"
  
  data-color-mode="auto" data-light-theme="light" data-dark-theme="dark"
  data-a11y-animated-images="system" data-a11y-link-underlines="true"
  
  >




  <head>
    <meta charset="utf-8">
  <link rel="dns-prefetch" href="https://github.githubassets.com">
  <link rel="dns-prefetch" href="https://avatars.githubusercontent.com">
  <link rel="dns-prefetch" href="https://github-cloud.s3.amazonaws.com">
  <link rel="dns-prefetch" href="https://user-images.githubusercontent.com/">
  <link rel="preconnect" href="https://github.githubassets.com" crossorigin>
  <link rel="preconnect" href="https://avatars.githubusercontent.com">

<script type="importmap">{"imports":{"react":"https://github.githubassets.com/assets/react-e27d1b3e03961e68.js","react-dom":"https://github.githubassets.com/assets/react-dom-e5fd46a22d5c4058.js","react-dom/client":"https://github.githubassets.com/assets/react-dom-client-1b4a3ee065998cea.js","react-is":"https://github.githubassets.com/assets/react-is-e0b593954b4706d8.js","react-reconciler":"https://github.githubassets.com/assets/react-reconciler-8e99e505c4429605.js","react/compiler-runtime":"https://github.githubassets.com/assets/react-compiler-runtime-4610bd6d3de9c049.js","react/jsx-dev-runtime":"https://github.githubassets.com/assets/react-jsx-dev-runtime-ea55d68667d559e5.js","react/jsx-runtime":"https://github.githubassets.com/assets/react-jsx-runtime-4915cb0f5b3aff04.js","scheduler":"https://github.githubassets.com/assets/scheduler-58b860b049ca307c.js"}}</script>
<meta name="react-profiling" content="0" data-turbo-transient="true" />
<meta name="react-import-map" content="react,react-dom,react-dom/client,react-dom/profiling,react-is,react-reconciler,react/compiler-runtime,react/jsx-dev-runtime,react/jsx-runtime,scheduler@777f63f87cd0" data-turbo-track="reload" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-e27d1b3e03961e68.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-compiler-runtime-4610bd6d3de9c049.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/scheduler-58b860b049ca307c.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-dom-e5fd46a22d5c4058.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-dom-client-1b4a3ee065998cea.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-is-e0b593954b4706d8.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-jsx-runtime-4915cb0f5b3aff04.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-reconciler-8e99e505c4429605.js" />

  


  <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/light-5c4e9fc574bf49f3.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/light_high_contrast-fb37c309e0603a69.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/dark-afff6c53aef9b9d1.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/dark_high_contrast-c409873d7987dffa.css" /><link data-color-theme="light" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light-5c4e9fc574bf49f3.css" /><link data-color-theme="light_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_high_contrast-fb37c309e0603a69.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_colorblind-0f910d8806d5761b.css" /><link data-color-theme="light_colorblind_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_colorblind_high_contrast-a7abd4d4c49ac593.css" /><link data-color-theme="light_tritanopia" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_tritanopia-5fc4c4a9cb41e596.css" /><link data-color-theme="light_tritanopia_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_tritanopia_high_contrast-ed0cee9214dedabd.css" /><link data-color-theme="dark" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark-afff6c53aef9b9d1.css" /><link data-color-theme="dark_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_high_contrast-c409873d7987dffa.css" /><link data-color-theme="dark_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-78a2491d538dab5a.css" /><link data-color-theme="dark_colorblind_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind_high_contrast-c26b63d7c532d0a2.css" /><link data-color-theme="dark_tritanopia" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_tritanopia-a6f60cea68c08405.css" /><link data-color-theme="dark_tritanopia_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_tritanopia_high_contrast-f66faf28b2ea18b6.css" /><link data-color-theme="dark_dimmed" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_dimmed-6701f6218c53cf5b.css" /><link data-color-theme="dark_dimmed_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_dimmed_high_contrast-7037fa46ae124d97.css" />

  <style type="text/css">
    :root {
      --tab-size-preference: 4;
    }

    pre, code {
      tab-size: var(--tab-size-preference);
    }
  </style>

    <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-primitives-97df7784617ce1ea.css" />
    <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-9be9fe6313f476af.css" />
    <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/global-62747e27e61258dc.css" />
    <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/github-b04ca6fccda778e2.css" />
  <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-72bd7d974b5ac1cc.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/code-4c5c0895f723f870.css" />

  

  <script type="application/json" id="client-env">{"locale":"en","featureFlags":["actions_caches_react_shell","actions_enable_background_steps","actions_new_hosted_runner_image_select_sizes_and_versions","actions_runners_react_shell","agent_author_search_expansion","agent_author_search_expansion_ui_pulls","alternate_user_config_repo","async_conversion_coverage_enabled","billing_billable_licenses_cost_center_bucket_fix","billing_budget_expiration","billing_cost_center_list_assigned_resources","billing_discount_threshold_notification","code_quality_enablement_banner_targeting","code_quality_remove_preview","code_view_raf_sticky_lines","codespaces_prebuild_region_target_update","coding_agent_third_party_model_ui","copilot_agent_snippy","copilot_ahp_tool_call_timing","copilot_api_agentic_issue_marshal_yaml","copilot_automation_repo_mcp_servers","copilot_automations_pagination","copilot_base_model_policy_row","copilot_chat_auto_mode_v2","copilot_chat_clear_model_selection_for_default_change","copilot_chat_early_task_provisioning","copilot_chat_persist_session_drafts","copilot_chat_vision_dotcom_chat_ga_gate","copilot_css_textarea_autosize","copilot_custom_copilots","copilot_custom_copilots_feature_preview","copilot_duplicate_thread","copilot_extensions_removal_on_marketplace","copilot_fix_failed_workflows_all_skus","copilot_hide_hovercard","copilot_immersive_task_hyperlinking","copilot_mc_cli_resume_any_users_task","copilot_mission_control_agent_merge_fix_ci","copilot_mission_control_agent_merge_resolve_conflicts","copilot_mission_control_awps_batching","copilot_mission_control_early_stop","copilot_mission_control_managed_sandbox_environments","copilot_mission_control_needs_attention","copilot_mission_control_reasoning_effort","copilot_mission_control_sandbox_remote_bypass","copilot_mission_control_task_alive_updates","copilot_mission_control_task_sharing","copilot_org_policy_page_focus_mode","copilot_share_active_subthread","copilot_spaces_ga","copilot_spaces_individual_policies_ga","copilot_swe_agent_authorization_status_ui","copilot_swe_agent_automation_resource_scoped_writes","copilot_swe_agent_discussion_comment_trigger","copilot_swe_agent_discussion_opened_trigger","copilot_swe_agent_discussion_updated_trigger","copilot_swe_agent_hide_model_picker_if_only_auto","copilot_swe_agent_issue_assigned_trigger","copilot_swe_agent_issue_comment_trigger","copilot_swe_agent_issue_labeled_trigger","copilot_swe_agent_pr_comment_model_picker","copilot_swe_agent_pull_request_assigned_trigger","copilot_swe_agent_pull_request_comment_trigger","copilot_swe_agent_pull_request_labeled_trigger","copilot_swe_agent_pull_request_merged_trigger","copilot_swe_agent_pull_request_opened_trigger","copilot_swe_agent_pull_request_ready_for_review_trigger","copilot_swe_agent_pull_request_review_requested_trigger","copilot_swe_agent_pull_request_review_submitted_trigger","copilot_swe_agent_pull_request_synchronize_trigger","copilot_swe_agent_sub_issue_added_trigger","copilot_swe_agent_use_subagents","copilot_task_api_github_rest_style","copilot_task_scoped_alive_channel","copilot_token_based_billing","copilot_unconfigured_is_inherited","copilot_user_can_upgrade_plan_field","copilot_web_integration_cutover","copilot_workbench_sunset_redirect","dashboard_agents_module_auth_token_check","dashboard_indexeddb_caching","fgpat_permissions_selector_redesign","glc_code_quality_repo_settings_workflow_config","hyperspace_2025_logged_out_batch_1","hyperspace_2025_logged_out_batch_2","hyperspace_2025_logged_out_batch_3","in_product_messaging_datadog_monitoring","ipm_ubb_individual_budget_banner","issue_fields_multi_select","issue_inline_avatars","issue_pinned_views","issue_pinned_views_team_vs_personal","issue_relative_time_micro","issue_viewer_paved_path","issues_expanded_file_types","issues_hide_closed_sub_issues","issues_lazy_load_comment_box_suggestions","issues_react_chrome_container_query_fix","labels_archiving","labels_archiving_info","landing_pages_ninetailed","lifecycle_label_name_updates","marketing_cookie_consent_banner","marketing_pages_search_explore_provider","memex_default_issue_create_repository","memex_live_update_hovercard","memex_mwl_filter_field_delimiter","memex_remove_deprecated_type_issue","merge_queue_restricted_pushers_warning","merge_status_header_feedback","milestone_closed_issues_prioritization","octocaptcha_origin_optimization","primer_react_css_anchor_positioning","primer_react_merged_forwarded_refs","primer_react_timeline_list_semantics","prs_copilot_app_open_action","prs_css_anchor_positioning","pull_request_copilot_attribution_header","pull_request_overview_merge_control","pull_request_overview_panel_edit_description","pull_request_persister","pull_request_stacks_navigation_shortcuts","pull_request_virtualization_image_estimate","pull_request_virtualization_loader_batching","pull_request_virtualization_scroll_compensation","pull_request_virtualization_scroll_intent","quick_search_lazy_suggestions","react_blob_isolate_code_lines","react_blob_ssr_content_visibility","react_data_router_tanstack_allowed","react_logged_out_repository_header","react_query_props_with_key","react_sandbox_future_tanstack","repo_app_turbo","repo_issues_sidebar_layout","repo_pulls_dashboard_declutter","repo_pulls_dashboard_ga","repo_pulls_dashboard_persistence","repos_contributors_limited_default_range","review_involves_filter","rule_ignored_file_paths","rulesets_actor_list_editor","sample_network_conn_type","security_center_artifact_filters_popover","see_who_reacted","semantic_similarity_duplicate_issue_detection","session_logs_ungroup_reasoning_text","set_sha256_on_repo_creation_form","site_banner_desktop_copilot_app","site_ghca_pixel_mona","site_github_app_ga_page","site_github_app_ga_page_highlight","site_github_app_mobile_native_share","site_global_banner_dev_days_attendee","site_global_nav_spark_models_removed","speculation_rules_ui_service","suggest_custom_property_values_copilot","suppress_automated_browser_vitals","swp_forms_disable_octocaptcha","thread_resolution_reason","update_issue_suggestions","viewscreen_sandbox","warn_inaccessible_attachments","webp_support","workstream_plugin_bootstrap"],"githubDomain":"https://github.com","copilotApiOverrideUrl":"https://api.githubcopilot.com","cmcApiUrl":"https://api.github.com/cmc_internal/api"}</script>
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/high-contrast-cookie-3663bcaacc724f4c.js"></script>
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/wp-runtime-721126455a2225e3.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/app-foundation-156c6259e31cc551.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/app-runtime-f6ce38f47c2e1d56.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/fetch-utilities-804a14996977c014.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ser-fb5d13278eb42203.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/tp-ea613009a991e211.js" />
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/environment-107a7753389a8a2d.js" defer="defer"></script>
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/app-runtime.25915bc98fb322a6.module.css" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/catalyst-52ed81112a548e10.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/selector-observer-e8810f64c443fb9b.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/relative-time-element-fe7e72f699fdf493.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/by-9da36843ba9d191d.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ja9-9a1160b939f2cd52.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/3h-55903cf2303047ad.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/hk-0d35a1220587d888.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/jz5-c964b1a3671f2a92.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/hj-1d800d09e9a8720a.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/j0-1ad12374da9777f2.js" />
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/github-elements-531d35538b61fd0d.js" defer="defer"></script>
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/element-registry-bf5e3b2aee197122.js" defer="defer"></script>
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/runtime-helpers-5e0b3ae3c4036207.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/aria-live-752acdc868e2da64.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/hotkey-e87ffadced20a3c9.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/react-core-75bc55d9971828b7.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/a9-34620c7b13885011.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ur-643d2814115561a9.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/4t6-5d0869970ac0aac0.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/pb0-a5c5ec36d311aeef.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/6n-afcf86ccabc4cad2.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/zj-f08c728cf00018aa.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/o6-2a1c68d269710ee9.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/h9a-c6405aa090de0e84.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/vy6-3c3e6e96629c2ce4.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/js-4eb97d5803e657c0.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/g7-baf9e817ae102b01.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/unc-96389cade7bad821.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/nu-65322a6997c6c93c.js" />
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/behaviors-5dd3809b5c8bac3c.js" defer="defer"></script>
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/react-core.3792087592bf207a.module.css" />
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/code-menu-4318f0f4c608f3dd.js" defer="defer"></script>
  
  <link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/primer-react-7afef75d393cf294.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/op-acddf38478d45ef9.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ncx-461e4b09f2e67ee5.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/qmp-c7cfba40cf5a93b0.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/j6-148a74299e5a01ab.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/t7l-a52ba56147f77909.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/4u-ec4874f70bfd5d76.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/s0-481bd34f90bc2bd7.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/y5-ed17e73b4c0bd15e.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/n4-be595475cdbf7d4b.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/j8-23a3c5ff8eef412d.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/la-27679061f16e1495.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/iu-9806a0291a782cbe.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ftx-39fb490e3c1d778f.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/zi-32a0c3c081ea5cce.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/sg-7a5d50475874c0e1.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/pd-6a8710840033e042.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/86g-ec28c25ed7d5de06.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/sn-1bab7384818953b7.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/iq-6d4ecf6d2fb6993c.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/p2-7d8e7cee5b46cb45.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/7d-2e3cc25d719f3a95.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/4d-76d8acdf21a33266.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/tsb-e0f6288ab985d9d2.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/lf-910ef220ce85c660.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/2j-2f19c1afd2ceaf93.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/me-f1476ec44a29f34a.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/p2u-e654a57b1a70c47d.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/5d-d97cc006d4da4d9b.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/r5-38f013bc2c0fd298.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/r6s-9039f5619230a653.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/9e-cece06724bf6ea3b.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/x9-3e077a3a37a73f9f.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/pj-87629cb5389d7663.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/eq-3764fd5f66494289.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/13-d889936dff7e5c0f.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/44-8193eea4af825ead.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/v4-9c1327d212e52a0d.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/id-7f39706ba9007db6.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ah-271362a1ed227d03.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/s1g-d434d712bca59d3a.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/vz-d7f4a583896f872e.js" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/47-c8c0ce2700acc5be.js" />
<script crossorigin="anonymous" type="module" src="https://github.githubassets.com/assets/code-view-4118a687d0150749.js" defer="defer"></script>
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-css.2d881b4d4a503d1c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/pj.75627bfeb9ceb1da.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/ah.2623f7c6ecbe2ecd.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/47.78770c57a48a810c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/code-view.37656c95a9729fb9.module.css" />


  <title>trustee/deployment/helm-chart/README.md at main · confidential-containers/trustee · GitHub</title>



  <meta name="route-pattern" content="/:user_id/:repository/blob/*name(/*path)" data-turbo-transient>
  <meta name="route-controller" content="blob" data-turbo-transient>
  <meta name="route-action" content="show" data-turbo-transient>
  <meta name="fetch-nonce" content="v2:5aea8fe5-548f-3091-6b07-6a7a7b1ed1e0">

    
  <meta name="current-catalog-service-hash" content="f3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb">


  <meta name="request-id" content="A65C:235FB4:B6D67AB:EE20683:6ACA6C6A" data-pjax-transient="true"/><meta name="html-safe-nonce" content="25a0857692588df9c4452af6f5d24df4d4de34be7be1970ee26011db64f77845" data-pjax-transient="true"/><meta name="visitor-payload" content="eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBNjVDOjIzNUZCNDpCNkQ2N0FCOkVFMjA2ODM6NkFDQTZDNkEiLCJ2aXNpdG9yX2lkIjoiNDMxMzUzNzg0MzAyNjM1NzM1NCIsInJlZ2lvbl9lZGdlIjoiZnJhIiwicmVnaW9uX3JlbmRlciI6ImZyYSJ9" data-pjax-transient="true"/><meta name="visitor-hmac" content="a344b3e3b82be15043f9a8eb1725e971b1422be55761f73ee23245cc01f1fe5e" data-pjax-transient="true"/>


    <meta name="hovercard-subject-tag" content="repository:485367944" data-turbo-transient>


  <meta name="github-keyboard-shortcuts" content="repository,source-code,file-tree,copilot" data-turbo-transient="true" />
  

  <meta name="selected-link" value="repo_source" data-turbo-transient>
  <link rel="assets" href="https://github.githubassets.com/">

    <meta name="google-site-verification" content="Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I">

<meta name="octolytics-url" content="https://collector.github.com/github/collect" />





  <meta name="analytics-location" content="/&lt;user-name&gt;/&lt;repo-name&gt;/blob/show" data-turbo-transient="true" />

  




    <meta name="user-login" content="">

  

    <meta name="viewport" content="width=device-width">

    

      <meta name="description" content="Attestation and Secret Delivery Components. Contribute to confidential-containers/trustee development by creating an account on GitHub.">

      <link rel="search" type="application/opensearchdescription+xml" href="/opensearch.xml" title="GitHub">

    <link rel="fluid-icon" href="https://github.com/fluidicon.png" title="GitHub">
    <meta property="fb:app_id" content="1401488693436528">
    <meta name="apple-itunes-app" content="app-id=1477376905, app-argument=https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md" />

      <meta name="twitter:image" content="https://opengraph.githubassets.com/7d5e38b648d127c94bb936d1fcaedd784e1e3e0cfe24fbb0a38952eb9840a0fe/confidential-containers/trustee" /><meta name="twitter:site" content="@github" /><meta name="twitter:card" content="summary_large_image" /><meta name="twitter:title" content="trustee/deployment/helm-chart/README.md at main · confidential-containers/trustee" /><meta name="twitter:description" content="Attestation and Secret Delivery Components. Contribute to confidential-containers/trustee development by creating an account on GitHub." />
  <meta property="og:image" content="https://opengraph.githubassets.com/7d5e38b648d127c94bb936d1fcaedd784e1e3e0cfe24fbb0a38952eb9840a0fe/confidential-containers/trustee" /><meta property="og:image:alt" content="Attestation and Secret Delivery Components. Contribute to confidential-containers/trustee development by creating an account on GitHub." /><meta property="og:image:width" content="1200" /><meta property="og:image:height" content="600" /><meta property="og:site_name" content="GitHub" /><meta property="og:type" content="object" /><meta property="og:title" content="trustee/deployment/helm-chart/README.md at main · confidential-containers/trustee" /><meta property="og:url" content="https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md" /><meta property="og:description" content="Attestation and Secret Delivery Components. Contribute to confidential-containers/trustee development by creating an account on GitHub." />
  




      <meta name="hostname" content="github.com">



        <meta name="expected-hostname" content="github.com">


  <meta http-equiv="x-pjax-version" content="d05be8f8b6905b6460fc264e80447721dfee1e32cf9e4291c4bf58f160c9f705" data-turbo-track="reload">
  <meta http-equiv="x-pjax-csp-version" content="c4a65e47b0c850e1157ae8e66298070851d7e3b558038de5a3b4ff7a93e630ed" data-turbo-track="reload">
  <meta http-equiv="x-pjax-css-version" content="a80b0545b169f440b929ce2b977c76b6988f014cca6513fb83c5df6581635fb3" data-turbo-track="reload">
  <meta http-equiv="x-pjax-js-version" content="af51c6f9d659be0324665373df3ee542f817dbd7f66f352a087935f2ceabe545" data-turbo-track="reload">

  <meta name="turbo-cache-control" content="no-preview" data-turbo-transient="">

      <meta name="turbo-cache-control" content="no-cache" data-turbo-transient>

    <meta data-hydrostats="publish">

  <meta name="go-import" content="github.com/confidential-containers/trustee git https://github.com/confidential-containers/trustee.git">

  <meta name="octolytics-dimension-user_id" content="90701811" /><meta name="octolytics-dimension-user_login" content="confidential-containers" /><meta name="octolytics-dimension-repository_id" content="485367944" /><meta name="octolytics-dimension-repository_nwo" content="confidential-containers/trustee" /><meta name="octolytics-dimension-repository_public" content="true" /><meta name="octolytics-dimension-repository_is_fork" content="false" /><meta name="octolytics-dimension-repository_network_root_id" content="485367944" /><meta name="octolytics-dimension-repository_network_root_nwo" content="confidential-containers/trustee" />
  



    

    <meta name="turbo-body-classes" content="logged-out env-production page-responsive">
  <meta name="disable-turbo" content="false">


  <meta name="browser-stats-url" content="https://api.github.com/_private/browser/stats">


  <meta name="browser-errors-url" content="https://api.github.com/_private/browser/errors">

  <meta name="release" content="3b1bb5b10f5c7fd1769d56e38b15dfddb34052a8" data-turbo-track="reload">
  <meta name="ui-target" content="full">

  <link rel="mask-icon" href="https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg" color="#000000">
  <link rel="alternate icon" class="js-site-favicon" type="image/png" href="https://github.githubassets.com/favicons/favicon.png">
  <link rel="icon" class="js-site-favicon" type="image/svg+xml" href="https://github.githubassets.com/favicons/favicon.svg" data-base-href="https://github.githubassets.com/favicons/favicon">

<meta name="theme-color" content="#1e2327">
<meta name="color-scheme" content="light dark" />


  <link rel="manifest" href="/manifest.json" crossOrigin="use-credentials">

  </head>

  <body class="logged-out env-production page-responsive" style="word-wrap: break-word;" >
    <div data-turbo-body class="logged-out env-production page-responsive" style="word-wrap: break-word;" >
      <div id="__primerPortalRoot__" style="z-index: 1000; position: absolute; width: 100%;" data-turbo-permanent></div>
      

    <div class="position-relative header-wrapper js-header-wrapper ">
      <a href="#start-of-content" data-skip-target-assigned="false" class="px-2 tmp-py-4 color-bg-accent-emphasis color-fg-on-emphasis show-on-focus js-skip-to-content">Skip to content</a>

      <span data-view-component="true" class="progress-pjax-loader Progress position-fixed width-full">
    <span style="width: 0%;" data-view-component="true" class="Progress-item progress-pjax-loader-bar left-0 top-0 color-bg-accent-emphasis"></span>
</span>      
      <link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/19-c660652a0a1639be.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/keyboard-shortcuts-dialog-47c5223d8d1af8ef.js" fetchpriority="low" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-css.2d881b4d4a503d1c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/keyboard-shortcuts-dialog.d53d993320d57e14.module.css" />

<react-partial
  partial-name="keyboard-shortcuts-dialog"
  data-ssr="false"
  data-attempted-ssr="false"
  data-react-profiling="false"
>
  
  <script type="application/json" data-target="react-partial.embeddedData">{"props":{"docsUrl":"https://docs.github.com/get-started/accessibility/keyboard-shortcuts"}}</script>
  <div data-target="react-partial.reactRoot"></div>
</react-partial>





      

          <link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/app-install-banner-partial-3c87deb7f0f20434.js" fetchpriority="low" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-css.2d881b4d4a503d1c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/app-install-banner-partial.7b357012e82003e7.module.css" />

<react-partial
  partial-name="app-install-banner-partial"
  data-ssr="false"
  data-attempted-ssr="false"
  data-react-profiling="false"
>
  
  <script type="application/json" data-target="react-partial.embeddedData">{"props":{}}</script>
  <div data-target="react-partial.reactRoot"></div>
</react-partial>


          

                <link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/et9-7eeec247c287fca4.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/94v-e20946127faa8f6e.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/fz5-892a9e99cc92858d.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/jag-441e702bfd4c7904.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/hw-8ce7888b57d0a23c.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/rq-0ec82a12cf538a4d.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/1m-a7a4c022483b2713.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/marketing-header-70703fe17422eb58.js" fetchpriority="low" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-css.2d881b4d4a503d1c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-brand-css.fbc35b3d20e988ff.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/1m.fec8b575d0e5234f.module.css" />

<react-partial
  partial-name="marketing-header"
  data-ssr="true"
  data-attempted-ssr="true"
  data-react-profiling="false"
>
  
  <script type="application/json" data-target="react-partial.embeddedData">{"props":{"color_mode":"dark","logged_in":false,"marketing_page":false,"home_path":"/","login_path":"/login?return_to=https%3A%2F%2Fgithub.com%2Fconfidential-containers%2Ftrustee%2Fblob%2Fmain%2Fdeployment%2Fhelm-chart%2FREADME.md","signup_path":"/signup?ref_cta=Sign+up\u0026ref_loc=header+logged+out\u0026ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fblob%2Fshow\u0026source=header-repo\u0026source_repo=confidential-containers%2Ftrustee","signup_enabled":true,"is_signup_controller":false,"show_search_and_nav":true,"hide_search":false,"private_mode_enabled":false,"should_use_dotcom_links":true,"auth_hydro_click":"{\"event_type\":\"authentication.click\",\"payload\":{\"location_in_page\":\"site header menu\",\"repository_id\":null,\"auth_type\":\"SIGN_UP\",\"originating_url\":\"https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md\",\"user_id\":null}}","auth_hydro_click_hmac":"67b86208b48273018bc7bf3542ca71b4faa39c3ae9a8f1989542ecdbf1112083","overlay":false,"fixed":false}}</script>
  <div data-target="react-partial.reactRoot"><div data-color-mode="dark" data-light-theme="light" data-dark-theme="dark"><header class="MarketingHeader-module__root__Tk7n3 HeaderMktg header-logged-out" role="banner" data-marketing-header="true" data-color-mode="dark" data-light-theme="light" data-dark-theme="dark" data-is-top="true"><h2 class="MarketingHeader-module__visuallyHidden__sqKsl">Navigation Menu</h2><button type="button" class="MarketingHeader-module__backdrop__sw4RU" aria-label="Close navigation menu"></button><div class="MarketingHeader-module__bar__mBSyE"><div class="MarketingHeader-module__topRow__yeury"><div class="MarketingHeader-module__toggleSlot__hDxbh"><button type="button" class="HeaderMenuToggle-module__toggle__i8EiC" aria-label="Toggle navigation" aria-expanded="false"><span class="HeaderMenuToggle-module__toggleBar__jVN0H"></span><span class="HeaderMenuToggle-module__toggleBar__jVN0H"></span><span class="HeaderMenuToggle-module__toggleBar__jVN0H"></span></button></div><a href="/" aria-label="Homepage" class="HeaderLogo-module__logo__UFyHI" data-analytics-event="{&quot;action&quot;:&quot;homepage&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;logo&quot;,&quot;location&quot;:&quot;header&quot;,&quot;label&quot;:&quot;homepage_link_logo_header&quot;}"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-mark-github" viewBox="0 0 24 24" width="32" height="32" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M10.226 17.284c-2.965-.36-5.054-2.493-5.054-5.256 0-1.123.404-2.336 1.078-3.144-.292-.741-.247-2.314.09-2.965.898-.112 2.111.36 2.83 1.01.853-.269 1.752-.404 2.853-.404 1.1 0 1.999.135 2.807.382.696-.629 1.932-1.1 2.83-.988.315.606.36 2.179.067 2.942.72.854 1.101 2 1.101 3.167 0 2.763-2.089 4.852-5.098 5.234.763.494 1.28 1.572 1.28 2.807v2.336c0 .674.561 1.056 1.235.786 4.066-1.55 7.255-5.615 7.255-10.646C23.5 6.188 18.334 1 11.978 1 5.62 1 .5 6.188.5 12.545c0 4.986 3.167 9.12 7.435 10.669.606.225 1.19-.18 1.19-.786V20.63a2.9 2.9 0 0 1-1.078.224c-1.483 0-2.359-.808-2.987-2.313-.247-.607-.517-.966-1.034-1.033-.27-.023-.359-.135-.359-.27 0-.27.45-.471.898-.471.652 0 1.213.404 1.797 1.235.45.651.921.943 1.483.943.561 0 .92-.202 1.437-.719.382-.381.674-.718.944-.943"></path></svg></a><div class="AuthCTAs-module__mobileActions__NNzeV"><a class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--subtle___F7pEE Primer_Brand__Button-module__Button--size-small___zQrEw AuthCTAs-module__cta__WpwQq" href="/login?return_to=https%3A%2F%2Fgithub.com%2Fconfidential-containers%2Ftrustee%2Fblob%2Fmain%2Fdeployment%2Fhelm-chart%2FREADME.md" data-analytics-event="{&quot;action&quot;:&quot;sign_in&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;auth_cta&quot;,&quot;location&quot;:&quot;header&quot;,&quot;label&quot;:&quot;sign_in_link_auth_cta_header&quot;}" data-hydro-click="{&quot;event_type&quot;:&quot;authentication.click&quot;,&quot;payload&quot;:{&quot;location_in_page&quot;:&quot;site header menu&quot;,&quot;repository_id&quot;:null,&quot;auth_type&quot;:&quot;SIGN_UP&quot;,&quot;originating_url&quot;:&quot;https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md&quot;,&quot;user_id&quot;:null}}" data-hydro-click-hmac="67b86208b48273018bc7bf3542ca71b4faa39c3ae9a8f1989542ecdbf1112083"><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-subtle___8ndWH">Sign in</span></span></a><button class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--subtle___F7pEE Primer_Brand__Button-module__Button--size-small___zQrEw HeaderAppearanceSettings-module__trigger__hUheK" type="button" aria-haspopup="dialog" aria-labelledby="_R_3dd_"><span class="Primer_Brand__Button-module__Button__leading-visual___jjtTe" data-testid="Button-leading-visual"><svg data-component="Octicon" focusable="false" aria-hidden="true" class="octicon octicon-sliders Primer_Brand__Button-module__Button__icon-visual____qybb" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M15 2.75a.75.75 0 0 1-.75.75h-4a.75.75 0 0 1 0-1.5h4a.75.75 0 0 1 .75.75Zm-8.5.75v1.25a.75.75 0 0 0 1.5 0v-4a.75.75 0 0 0-1.5 0V2H1.75a.75.75 0 0 0 0 1.5H6.5Zm1.25 5.25a.75.75 0 0 0 0-1.5h-6a.75.75 0 0 0 0 1.5h6ZM15 8a.75.75 0 0 1-.75.75H11.5V10a.75.75 0 1 1-1.5 0V6a.75.75 0 0 1 1.5 0v1.25h2.75A.75.75 0 0 1 15 8Zm-9 5.25v-2a.75.75 0 0 0-1.5 0v1.25H1.75a.75.75 0 0 0 0 1.5H4.5v1.25a.75.75 0 0 0 1.5 0v-2Zm9 0a.75.75 0 0 1-.75.75h-6a.75.75 0 0 1 0-1.5h6a.75.75 0 0 1 .75.75Z"></path></svg></span><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-subtle___8ndWH"></span></span></button><div class="Primer_Brand__Tooltip-module__Tooltip___0Eipx" data-direction="s" aria-hidden="true" id="_R_3dd_">Appearance settings</div></div></div><div class="MarketingHeader-module__menu__GIy3y"><div class="MarketingHeader-module__menuWrapper__owstH"><nav class="MarketingNavigation-module__nav__W0KYY" aria-label="Global"><ul class="MarketingNavigation-module__list__tFbMb"><li><div class="NavDropdown-module__container__l2YeI"><button type="button" class="NavDropdown-module__button__PEHWX" aria-expanded="false" aria-controls="_R_nd_">Platform<svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-right NavDropdown-module__buttonIcon__Tkl8_" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m6.427 4.427 3.396 3.396a.25.25 0 0 1 0 .354l-3.396 3.396A.25.25 0 0 1 6 11.396V4.604a.25.25 0 0 1 .427-.177Z"></path></svg></button><div id="_R_nd_" class="NavDropdown-module__dropdown__xm1jd"><ul class="NavDropdown-module__list__zuCgG"><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_5knd_">AI CODE CREATION</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_5knd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/copilot" data-analytics-event="{&quot;action&quot;:&quot;github_copilot&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_copilot_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-copilot NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M7.998 15.035c-4.562 0-7.873-2.914-7.998-3.749V9.338c.085-.628.677-1.686 1.588-2.065.013-.07.024-.143.036-.218.029-.183.06-.384.126-.612-.201-.508-.254-1.084-.254-1.656 0-.87.128-1.769.693-2.484.579-.733 1.494-1.124 2.724-1.261 1.206-.134 2.262.034 2.944.765.05.053.096.108.139.165.044-.057.094-.112.143-.165.682-.731 1.738-.899 2.944-.765 1.23.137 2.145.528 2.724 1.261.566.715.693 1.614.693 2.484 0 .572-.053 1.148-.254 1.656.066.228.098.429.126.612.012.076.024.148.037.218.924.385 1.522 1.471 1.591 2.095v1.872c0 .766-3.351 3.795-8.002 3.795Zm0-1.485c2.28 0 4.584-1.11 5.002-1.433V7.862l-.023-.116c-.49.21-1.075.291-1.727.291-1.146 0-2.059-.327-2.71-.991A3.222 3.222 0 0 1 8 6.303a3.24 3.24 0 0 1-.544.743c-.65.664-1.563.991-2.71.991-.652 0-1.236-.081-1.727-.291l-.023.116v4.255c.419.323 2.722 1.433 5.002 1.433ZM6.762 2.83c-.193-.206-.637-.413-1.682-.297-1.019.113-1.479.404-1.713.7-.247.312-.369.789-.369 1.554 0 .793.129 1.171.308 1.371.162.181.519.379 1.442.379.853 0 1.339-.235 1.638-.54.315-.322.527-.827.617-1.553.117-.935-.037-1.395-.241-1.614Zm4.155-.297c-1.044-.116-1.488.091-1.681.297-.204.219-.359.679-.242 1.614.091.726.303 1.231.618 1.553.299.305.784.54 1.638.54.922 0 1.28-.198 1.442-.379.179-.2.308-.578.308-1.371 0-.765-.123-1.242-.37-1.554-.233-.296-.693-.587-1.713-.7Z"></path><path d="M6.25 9.037a.75.75 0 0 1 .75.75v1.501a.75.75 0 0 1-1.5 0V9.787a.75.75 0 0 1 .75-.75Zm4.25.75v1.501a.75.75 0 0 1-1.5 0V9.787a.75.75 0 0 1 1.5 0Z"></path></svg>GitHub Copilot</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Write better code with AI</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/ai/github-app" data-analytics-event="{&quot;action&quot;:&quot;github_copilot_app&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_copilot_app_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-mark-github NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M6.766 11.328c-2.063-.25-3.516-1.734-3.516-3.656 0-.781.281-1.625.75-2.188-.203-.515-.172-1.609.063-2.062.625-.078 1.468.25 1.968.703.594-.187 1.219-.281 1.985-.281.765 0 1.39.094 1.953.265.484-.437 1.344-.765 1.969-.687.218.422.25 1.515.046 2.047.5.593.766 1.39.766 2.203 0 1.922-1.453 3.375-3.547 3.64.531.344.89 1.094.89 1.954v1.625c0 .468.391.734.86.547C13.781 14.359 16 11.53 16 8.03 16 3.61 12.406 0 7.984 0 3.563 0 0 3.61 0 8.031a7.88 7.88 0 0 0 5.172 7.422c.422.156.828-.125.828-.547v-1.25c-.219.094-.5.156-.75.156-1.031 0-1.64-.562-2.078-1.609-.172-.422-.36-.672-.719-.719-.187-.015-.25-.093-.25-.187 0-.188.313-.328.625-.328.453 0 .844.281 1.25.86.313.452.64.655 1.031.655s.641-.14 1-.5c.266-.265.47-.5.657-.656"></path></svg>GitHub Copilot app</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Direct agents from issue to merge</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/mcp" data-analytics-event="{&quot;action&quot;:&quot;mcp_registry&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;mcp_registry_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-mcp NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M5.52 1.12a3.578 3.578 0 0 1 6.078 2.98 3.578 3.578 0 0 1 2.982 6.08l-3.292 3.293a.252.252 0 0 0 0 .354l.843.843a.749.749 0 1 1-1.06 1.06l-.844-.843a1.75 1.75 0 0 1 0-2.474L13.52 9.12a2.08 2.08 0 0 0 0-2.94 2.08 2.08 0 0 0-2.94 0L7.731 9.03A.75.75 0 0 1 6.67 7.97l2.85-2.85a2.08 2.08 0 0 0 0-2.94 2.08 2.08 0 0 0-2.94 0l-4.799 4.8A.75.75 0 0 1 .72 5.92Z"></path><path d="M7.52 3.12a.749.749 0 1 1 1.06 1.06L5.731 7.03A2.079 2.079 0 0 0 8.67 9.97l2.85-2.85a.749.749 0 1 1 1.06 1.06l-2.849 2.85A3.578 3.578 0 0 1 4.67 5.97Z"></path></svg>MCP Registry</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Integrate external tools</span></span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_9knd_">DEVELOPER WORKFLOWS</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_9knd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/actions" data-analytics-event="{&quot;action&quot;:&quot;actions&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;actions_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-workflow NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 1.75C0 .784.784 0 1.75 0h3.5C6.216 0 7 .784 7 1.75v3.5A1.75 1.75 0 0 1 5.25 7H4v4a1 1 0 0 0 1 1h4v-1.25C9 9.784 9.784 9 10.75 9h3.5c.966 0 1.75.784 1.75 1.75v3.5A1.75 1.75 0 0 1 14.25 16h-3.5A1.75 1.75 0 0 1 9 14.25v-.75H5A2.5 2.5 0 0 1 2.5 11V7h-.75A1.75 1.75 0 0 1 0 5.25Zm1.75-.25a.25.25 0 0 0-.25.25v3.5c0 .138.112.25.25.25h3.5a.25.25 0 0 0 .25-.25v-3.5a.25.25 0 0 0-.25-.25Zm9 9a.25.25 0 0 0-.25.25v3.5c0 .138.112.25.25.25h3.5a.25.25 0 0 0 .25-.25v-3.5a.25.25 0 0 0-.25-.25Z"></path></svg>Actions</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Automate any workflow</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/codespaces" data-analytics-event="{&quot;action&quot;:&quot;codespaces&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;codespaces_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-codespaces NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 11.25c0-.966.784-1.75 1.75-1.75h12.5c.966 0 1.75.784 1.75 1.75v3A1.75 1.75 0 0 1 14.25 16H1.75A1.75 1.75 0 0 1 0 14.25Zm2-9.5C2 .784 2.784 0 3.75 0h8.5C13.216 0 14 .784 14 1.75v5a1.75 1.75 0 0 1-1.75 1.75h-8.5A1.75 1.75 0 0 1 2 6.75Zm1.75-.25a.25.25 0 0 0-.25.25v5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-5a.25.25 0 0 0-.25-.25Zm-2 9.5a.25.25 0 0 0-.25.25v3c0 .138.112.25.25.25h12.5a.25.25 0 0 0 .25-.25v-3a.25.25 0 0 0-.25-.25Z"></path><path d="M7 12.75a.75.75 0 0 1 .75-.75h4.5a.75.75 0 0 1 0 1.5h-4.5a.75.75 0 0 1-.75-.75Zm-4 0a.75.75 0 0 1 .75-.75h.5a.75.75 0 0 1 0 1.5h-.5a.75.75 0 0 1-.75-.75Z"></path></svg>Codespaces</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Instant dev environments</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/issues" data-analytics-event="{&quot;action&quot;:&quot;issues&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;issues_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-issue-opened NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path><path d="M8 0a8 8 0 1 1 0 16A8 8 0 0 1 8 0ZM1.5 8a6.5 6.5 0 1 0 13 0 6.5 6.5 0 0 0-13 0Z"></path></svg>Issues</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Plan and track work</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/code-review" data-analytics-event="{&quot;action&quot;:&quot;code_review&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;code_review_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-code NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m11.28 3.22 4.25 4.25a.75.75 0 0 1 0 1.06l-4.25 4.25a.749.749 0 0 1-1.275-.326.749.749 0 0 1 .215-.734L13.94 8l-3.72-3.72a.749.749 0 0 1 .326-1.275.749.749 0 0 1 .734.215Zm-6.56 0a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042L2.06 8l3.72 3.72a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L.47 8.53a.75.75 0 0 1 0-1.06Z"></path></svg>Code Review</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Manage code changes</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/code-quality" data-analytics-event="{&quot;action&quot;:&quot;code_quality&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;code_quality_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-codescan-checkmark NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M10.28 6.28a.75.75 0 1 0-1.06-1.06L6.25 8.19l-.97-.97a.75.75 0 0 0-1.06 1.06l1.5 1.5a.75.75 0 0 0 1.06 0l3.5-3.5Z"></path><path d="M7.5 15a7.5 7.5 0 1 1 5.807-2.754l2.473 2.474a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215l-2.474-2.473A7.472 7.472 0 0 1 7.5 15Zm0-13.5a6 6 0 1 0 4.094 10.386.748.748 0 0 1 .293-.292 6.002 6.002 0 0 0 1.117-6.486A6.002 6.002 0 0 0 7.5 1.5Z"></path></svg>Code Quality</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Enforce quality at merge</span></span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_dknd_">APPLICATION SECURITY</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_dknd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/security/advanced-security" data-analytics-event="{&quot;action&quot;:&quot;github_advanced_security&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_advanced_security_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-shield-check NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m8.533.133 5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667l5.25-1.68a1.748 1.748 0 0 1 1.066 0Zm-.61 1.429.001.001-5.25 1.68a.251.251 0 0 0-.174.237V7c0 1.36.275 2.666 1.057 3.859.784 1.194 2.121 2.342 4.366 3.298a.196.196 0 0 0 .154 0c2.245-.957 3.582-2.103 4.366-3.297C13.225 9.666 13.5 8.358 13.5 7V3.48a.25.25 0 0 0-.174-.238l-5.25-1.68a.25.25 0 0 0-.153 0ZM11.28 6.28l-3.5 3.5a.75.75 0 0 1-1.06 0l-1.5-1.5a.749.749 0 0 1 .326-1.275.749.749 0 0 1 .734.215l.97.97 2.97-2.97a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042Z"></path></svg>GitHub Advanced Security</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Find and fix vulnerabilities</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/security/advanced-security/code-security" data-analytics-event="{&quot;action&quot;:&quot;code_security&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;code_security_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-code-square NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 1.75C0 .784.784 0 1.75 0h12.5C15.216 0 16 .784 16 1.75v12.5A1.75 1.75 0 0 1 14.25 16H1.75A1.75 1.75 0 0 1 0 14.25Zm1.75-.25a.25.25 0 0 0-.25.25v12.5c0 .138.112.25.25.25h12.5a.25.25 0 0 0 .25-.25V1.75a.25.25 0 0 0-.25-.25Zm7.47 3.97a.75.75 0 0 1 1.06 0l2 2a.75.75 0 0 1 0 1.06l-2 2a.749.749 0 0 1-1.275-.326.749.749 0 0 1 .215-.734L10.69 8 9.22 6.53a.75.75 0 0 1 0-1.06ZM6.78 6.53 5.31 8l1.47 1.47a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215l-2-2a.75.75 0 0 1 0-1.06l2-2a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042Z"></path></svg>Code security</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Secure your code as you build</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/security/advanced-security/secret-protection" data-analytics-event="{&quot;action&quot;:&quot;secret_protection&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;secret_protection_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-lock NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M4 4a4 4 0 0 1 8 0v2h.25c.966 0 1.75.784 1.75 1.75v5.5A1.75 1.75 0 0 1 12.25 15h-8.5A1.75 1.75 0 0 1 2 13.25v-5.5C2 6.784 2.784 6 3.75 6H4Zm8.25 3.5h-8.5a.25.25 0 0 0-.25.25v5.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-5.5a.25.25 0 0 0-.25-.25ZM10.5 6V4a2.5 2.5 0 1 0-5 0v2Z"></path></svg>Secret protection</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Stop leaks before they start</span></span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ NavGroup-module__hasSeparator__FnMrN"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_hknd_">EXPLORE</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_hknd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/why-github" data-analytics-event="{&quot;action&quot;:&quot;why_github&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;why_github_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Why GitHub</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://docs.github.com" data-analytics-event="{&quot;action&quot;:&quot;documentation&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;documentation_link_platform_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Documentation</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://github.blog" data-analytics-event="{&quot;action&quot;:&quot;blog&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;blog_link_platform_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Blog</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://github.blog/changelog" data-analytics-event="{&quot;action&quot;:&quot;changelog&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;changelog_link_platform_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Changelog</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/marketplace" data-analytics-event="{&quot;action&quot;:&quot;marketplace&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;marketplace_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Marketplace</span></a></li></ul></div></li></ul><div class="NavDropdown-module__trailingLinkContainer__VgJGL"><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/features" data-analytics-event="{&quot;action&quot;:&quot;view_all_features&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;platform&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_features_link_platform_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all features</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></div></div></div></li><li><div class="NavDropdown-module__container__l2YeI"><button type="button" class="NavDropdown-module__button__PEHWX" aria-expanded="false" aria-controls="_R_17d_">Solutions<svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-right NavDropdown-module__buttonIcon__Tkl8_" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m6.427 4.427 3.396 3.396a.25.25 0 0 1 0 .354l-3.396 3.396A.25.25 0 0 1 6 11.396V4.604a.25.25 0 0 1 .427-.177Z"></path></svg></button><div id="_R_17d_" class="NavDropdown-module__dropdown__xm1jd"><ul class="NavDropdown-module__list__zuCgG"><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_5l7d_">BY COMPANY SIZE</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_5l7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/enterprise" data-analytics-event="{&quot;action&quot;:&quot;enterprises&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;enterprises_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Enterprises</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/team" data-analytics-event="{&quot;action&quot;:&quot;small_and_medium_teams&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;small_and_medium_teams_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Small and medium teams</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/enterprise/startups" data-analytics-event="{&quot;action&quot;:&quot;startups&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;startups_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Startups</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/industry/nonprofits" data-analytics-event="{&quot;action&quot;:&quot;nonprofits&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;nonprofits_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Nonprofits</span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_9l7d_">BY USE CASE</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_9l7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/use-case/app-modernization" data-analytics-event="{&quot;action&quot;:&quot;app_modernization&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;app_modernization_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">App Modernization</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/use-case/devsecops" data-analytics-event="{&quot;action&quot;:&quot;devsecops&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;devsecops_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">DevSecOps</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/use-case/devops" data-analytics-event="{&quot;action&quot;:&quot;devops&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;devops_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">DevOps</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/use-case/ci-cd" data-analytics-event="{&quot;action&quot;:&quot;ci/cd&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;ci/cd_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">CI/CD</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/solutions/use-case" data-analytics-event="{&quot;action&quot;:&quot;view_all_use_cases&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_use_cases_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all use cases</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_dl7d_">BY INDUSTRY</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_dl7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/industry/healthcare" data-analytics-event="{&quot;action&quot;:&quot;healthcare&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;healthcare_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Healthcare</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/industry/financial-services" data-analytics-event="{&quot;action&quot;:&quot;financial_services&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;financial_services_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Financial services</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/industry/manufacturing" data-analytics-event="{&quot;action&quot;:&quot;manufacturing&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;manufacturing_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Manufacturing</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/industry/government" data-analytics-event="{&quot;action&quot;:&quot;government&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;government_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Government</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/solutions/industry" data-analytics-event="{&quot;action&quot;:&quot;view_all_industries&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_industries_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all industries</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></li></ul></div></li></ul><div class="NavDropdown-module__trailingLinkContainer__VgJGL"><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/solutions" data-analytics-event="{&quot;action&quot;:&quot;view_all_solutions&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;solutions&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_solutions_link_solutions_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all solutions</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></div></div></div></li><li><div class="NavDropdown-module__container__l2YeI"><button type="button" class="NavDropdown-module__button__PEHWX" aria-expanded="false" aria-controls="_R_1nd_">Resources<svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-right NavDropdown-module__buttonIcon__Tkl8_" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m6.427 4.427 3.396 3.396a.25.25 0 0 1 0 .354l-3.396 3.396A.25.25 0 0 1 6 11.396V4.604a.25.25 0 0 1 .427-.177Z"></path></svg></button><div id="_R_1nd_" class="NavDropdown-module__dropdown__xm1jd"><ul class="NavDropdown-module__list__zuCgG"><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_5lnd_">EXPLORE BY TOPIC</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_5lnd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/articles?topic=ai" data-analytics-event="{&quot;action&quot;:&quot;ai&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;ai_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">AI</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/articles?topic=software-development" data-analytics-event="{&quot;action&quot;:&quot;software_development&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;software_development_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Software Development</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/articles?topic=devops" data-analytics-event="{&quot;action&quot;:&quot;devops&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;devops_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">DevOps</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/articles?topic=security" data-analytics-event="{&quot;action&quot;:&quot;security&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;security_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Security</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/resources/articles" data-analytics-event="{&quot;action&quot;:&quot;view_all_topics&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_topics_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all topics</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_9lnd_">EXPLORE BY TYPE</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_9lnd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/customer-stories" data-analytics-event="{&quot;action&quot;:&quot;customer_stories&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;customer_stories_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Customer stories</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/events" data-analytics-event="{&quot;action&quot;:&quot;events__webinars&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;events__webinars_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Events &amp; webinars</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/resources/whitepapers" data-analytics-event="{&quot;action&quot;:&quot;ebooks__reports&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;ebooks__reports_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Ebooks &amp; reports</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/solutions/executive-insights" data-analytics-event="{&quot;action&quot;:&quot;business_insights&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;business_insights_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Business insights</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://skills.github.com" data-analytics-event="{&quot;action&quot;:&quot;github_skills&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_skills_link_resources_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">GitHub Skills</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_dlnd_">SUPPORT &amp; SERVICES</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_dlnd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://docs.github.com" data-analytics-event="{&quot;action&quot;:&quot;documentation&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;documentation_link_resources_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Documentation</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://support.github.com" data-analytics-event="{&quot;action&quot;:&quot;customer_support&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;customer_support_link_resources_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Customer support</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/orgs/community/discussions" data-analytics-event="{&quot;action&quot;:&quot;community_forum&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;community_forum_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Community forum</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/trust-center" data-analytics-event="{&quot;action&quot;:&quot;trust_center&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;trust_center_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Trust center</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/partners" data-analytics-event="{&quot;action&quot;:&quot;partners&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;partners_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Partners</span></a></li></ul></div></li></ul><div class="NavDropdown-module__trailingLinkContainer__VgJGL"><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--arrow-end___esdN8" href="https://github.com/resources" data-analytics-event="{&quot;action&quot;:&quot;view_all_resources&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;resources&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;view_all_resources_link_resources_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">View all resources</span><svg class="Primer_Brand__ExpandableArrow-module__ExpandableArrow___aaZs9 Primer_Brand__Link-module__Link-arrow___yd78i" width="16" height="16" viewBox="0 0 16 16" fill="none" aria-hidden="true" focusable="false"><path fill="currentColor" d="M7.28033 3.21967C6.98744 2.92678 6.51256 2.92678 6.21967 3.21967C5.92678 3.51256 5.92678 3.98744 6.21967 4.28033L7.28033 3.21967ZM11 8L11.5303 8.53033C11.8232 8.23744 11.8232 7.76256 11.5303 7.46967L11 8ZM6.21967 11.7197C5.92678 12.0126 5.92678 12.4874 6.21967 12.7803C6.51256 13.0732 6.98744 13.0732 7.28033 12.7803L6.21967 11.7197ZM6.21967 4.28033L10.4697 8.53033L11.5303 7.46967L7.28033 3.21967L6.21967 4.28033ZM10.4697 7.46967L6.21967 11.7197L7.28033 12.7803L11.5303 8.53033L10.4697 7.46967Z"></path><path class="Primer_Brand__ExpandableArrow-module__ExpandableArrow-stem___0K8Hz" stroke="currentColor" d="M1.75 8H11" stroke-width="1.5" stroke-linecap="round"></path></svg></a></div></div></div></li><li><div class="NavDropdown-module__container__l2YeI"><button type="button" class="NavDropdown-module__button__PEHWX" aria-expanded="false" aria-controls="_R_27d_">Open Source<svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-right NavDropdown-module__buttonIcon__Tkl8_" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m6.427 4.427 3.396 3.396a.25.25 0 0 1 0 .354l-3.396 3.396A.25.25 0 0 1 6 11.396V4.604a.25.25 0 0 1 .427-.177Z"></path></svg></button><div id="_R_27d_" class="NavDropdown-module__dropdown__xm1jd"><ul class="NavDropdown-module__list__zuCgG"><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_5m7d_">COMMUNITY</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_5m7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/open-source/sponsors" data-analytics-event="{&quot;action&quot;:&quot;github_sponsors&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_sponsors_link_open_source_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-sponsor-tiers NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M10.586 1C12.268 1 13.5 2.37 13.5 4.25c0 1.745-.996 3.359-2.622 4.831-.166.15-.336.297-.509.438l1.116 5.584a.75.75 0 0 1-.991.852l-2.409-.876a.25.25 0 0 0-.17 0l-2.409.876a.75.75 0 0 1-.991-.852L5.63 9.519a13.78 13.78 0 0 1-.51-.438C3.497 7.609 2.5 5.995 2.5 4.25 2.5 2.37 3.732 1 5.414 1c.963 0 1.843.403 2.474 1.073L8 2.198l.112-.125a3.385 3.385 0 0 1 2.283-1.068L10.586 1Zm-3.621 9.495-.718 3.594 1.155-.42a1.75 1.75 0 0 1 1.028-.051l.168.051 1.154.42-.718-3.592c-.199.13-.37.235-.505.314l-.169.097a.75.75 0 0 1-.72 0 9.54 9.54 0 0 1-.515-.308l-.16-.105ZM10.586 2.5c-.863 0-1.611.58-1.866 1.459-.209.721-1.231.721-1.44 0C7.025 3.08 6.277 2.5 5.414 2.5 4.598 2.5 4 3.165 4 4.25c0 1.23.786 2.504 2.128 3.719.49.443 1.018.846 1.546 1.198l.325.21.076-.047.251-.163a13.341 13.341 0 0 0 1.546-1.198C11.214 6.754 12 5.479 12 4.25c0-1.085-.598-1.75-1.414-1.75Z"></path></svg>GitHub Sponsors</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Fund open source developers</span></span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_9m7d_">PROGRAMS</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_9m7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://securitylab.github.com" data-analytics-event="{&quot;action&quot;:&quot;security_lab&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;security_lab_link_open_source_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Security Lab</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://maintainers.github.com" data-analytics-event="{&quot;action&quot;:&quot;maintainer_community&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;maintainer_community_link_open_source_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Maintainer Community</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://stars.github.com" data-analytics-event="{&quot;action&quot;:&quot;github_stars&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_stars_link_open_source_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">GitHub Stars</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 Primer_Brand__Link-module__Link--is-external___xsncV" href="https://archiveprogram.github.com" data-analytics-event="{&quot;action&quot;:&quot;archive_program&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;archive_program_link_open_source_navbar&quot;}" target="_blank" rel="noreferrer"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Archive Program</span><svg data-component="Octicon" focusable="false" aria-label="External link" class="octicon octicon-link-external" role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.75 2h3.5a.75.75 0 0 1 0 1.5h-3.5a.25.25 0 0 0-.25.25v8.5c0 .138.112.25.25.25h8.5a.25.25 0 0 0 .25-.25v-3.5a.75.75 0 0 1 1.5 0v3.5A1.75 1.75 0 0 1 12.25 14h-8.5A1.75 1.75 0 0 1 2 12.25v-8.5C2 2.784 2.784 2 3.75 2Zm6.854-1h4.146a.25.25 0 0 1 .25.25v4.146a.25.25 0 0 1-.427.177L13.03 4.03 9.28 7.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.75-3.75-1.543-1.543A.25.25 0 0 1 10.604 1Z"></path></svg></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_dm7d_">REPOSITORIES</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_dm7d_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/topics" data-analytics-event="{&quot;action&quot;:&quot;topics&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;topics_link_open_source_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Topics</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/trending" data-analytics-event="{&quot;action&quot;:&quot;trending&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;trending_link_open_source_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Trending</span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0" href="https://github.com/collections" data-analytics-event="{&quot;action&quot;:&quot;collections&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;open_source&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;collections_link_open_source_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty">Collections</span></a></li></ul></div></li></ul></div></div></li><li><div class="NavDropdown-module__container__l2YeI"><button type="button" class="NavDropdown-module__button__PEHWX" aria-expanded="false" aria-controls="_R_2nd_">Enterprise<svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-right NavDropdown-module__buttonIcon__Tkl8_" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m6.427 4.427 3.396 3.396a.25.25 0 0 1 0 .354l-3.396 3.396A.25.25 0 0 1 6 11.396V4.604a.25.25 0 0 1 .427-.177Z"></path></svg></button><div id="_R_2nd_" class="NavDropdown-module__dropdown__xm1jd"><ul class="NavDropdown-module__list__zuCgG"><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_5mnd_">ENTERPRISE SOLUTIONS</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_5mnd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/enterprise" data-analytics-event="{&quot;action&quot;:&quot;enterprise_platform&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;enterprise&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;enterprise_platform_link_enterprise_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-stack NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M7.122.392a1.75 1.75 0 0 1 1.756 0l5.003 2.902c.83.481.83 1.68 0 2.162L8.878 8.358a1.75 1.75 0 0 1-1.756 0L2.119 5.456a1.251 1.251 0 0 1 0-2.162ZM8.125 1.69a.248.248 0 0 0-.25 0l-4.63 2.685 4.63 2.685a.248.248 0 0 0 .25 0l4.63-2.685ZM1.601 7.789a.75.75 0 0 1 1.025-.273l5.249 3.044a.248.248 0 0 0 .25 0l5.249-3.044a.75.75 0 0 1 .752 1.298l-5.248 3.044a1.75 1.75 0 0 1-1.756 0L1.874 8.814A.75.75 0 0 1 1.6 7.789Zm0 3.5a.75.75 0 0 1 1.025-.273l5.249 3.044a.248.248 0 0 0 .25 0l5.249-3.044a.75.75 0 0 1 .752 1.298l-5.248 3.044a1.75 1.75 0 0 1-1.756 0l-5.248-3.044a.75.75 0 0 1-.273-1.025Z"></path></svg>Enterprise platform</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">AI-powered developer platform</span></span></a></li></ul></div></li><li><div class="NavGroup-module__group__W8SqJ"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--monospace___QXHDQ Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavGroup-module__title__Wzxz2" id="_R_9mnd_">AVAILABLE ADD-ONS</span><ul class="NavGroup-module__list__UCOFy" aria-labelledby="_R_9mnd_"><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/security/advanced-security" data-analytics-event="{&quot;action&quot;:&quot;github_advanced_security&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;enterprise&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;github_advanced_security_link_enterprise_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-shield-check NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m8.533.133 5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667l5.25-1.68a1.748 1.748 0 0 1 1.066 0Zm-.61 1.429.001.001-5.25 1.68a.251.251 0 0 0-.174.237V7c0 1.36.275 2.666 1.057 3.859.784 1.194 2.121 2.342 4.366 3.298a.196.196 0 0 0 .154 0c2.245-.957 3.582-2.103 4.366-3.297C13.225 9.666 13.5 8.358 13.5 7V3.48a.25.25 0 0 0-.174-.238l-5.25-1.68a.25.25 0 0 0-.153 0ZM11.28 6.28l-3.5 3.5a.75.75 0 0 1-1.06 0l-1.5-1.5a.749.749 0 0 1 .326-1.275.749.749 0 0 1 .734.215l.97.97 2.97-2.97a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042Z"></path></svg>GitHub Advanced Security</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Enterprise-grade security features</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/features/copilot/copilot-business" data-analytics-event="{&quot;action&quot;:&quot;copilot_for_business&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;enterprise&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;copilot_for_business_link_enterprise_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-copilot NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M7.998 15.035c-4.562 0-7.873-2.914-7.998-3.749V9.338c.085-.628.677-1.686 1.588-2.065.013-.07.024-.143.036-.218.029-.183.06-.384.126-.612-.201-.508-.254-1.084-.254-1.656 0-.87.128-1.769.693-2.484.579-.733 1.494-1.124 2.724-1.261 1.206-.134 2.262.034 2.944.765.05.053.096.108.139.165.044-.057.094-.112.143-.165.682-.731 1.738-.899 2.944-.765 1.23.137 2.145.528 2.724 1.261.566.715.693 1.614.693 2.484 0 .572-.053 1.148-.254 1.656.066.228.098.429.126.612.012.076.024.148.037.218.924.385 1.522 1.471 1.591 2.095v1.872c0 .766-3.351 3.795-8.002 3.795Zm0-1.485c2.28 0 4.584-1.11 5.002-1.433V7.862l-.023-.116c-.49.21-1.075.291-1.727.291-1.146 0-2.059-.327-2.71-.991A3.222 3.222 0 0 1 8 6.303a3.24 3.24 0 0 1-.544.743c-.65.664-1.563.991-2.71.991-.652 0-1.236-.081-1.727-.291l-.023.116v4.255c.419.323 2.722 1.433 5.002 1.433ZM6.762 2.83c-.193-.206-.637-.413-1.682-.297-1.019.113-1.479.404-1.713.7-.247.312-.369.789-.369 1.554 0 .793.129 1.171.308 1.371.162.181.519.379 1.442.379.853 0 1.339-.235 1.638-.54.315-.322.527-.827.617-1.553.117-.935-.037-1.395-.241-1.614Zm4.155-.297c-1.044-.116-1.488.091-1.681.297-.204.219-.359.679-.242 1.614.091.726.303 1.231.618 1.553.299.305.784.54 1.638.54.922 0 1.28-.198 1.442-.379.179-.2.308-.578.308-1.371 0-.765-.123-1.242-.37-1.554-.233-.296-.693-.587-1.713-.7Z"></path><path d="M6.25 9.037a.75.75 0 0 1 .75.75v1.501a.75.75 0 0 1-1.5 0V9.787a.75.75 0 0 1 .75-.75Zm4.25.75v1.501a.75.75 0 0 1-1.5 0V9.787a.75.75 0 0 1 1.5 0Z"></path></svg>Copilot for Business</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Enterprise-grade AI features</span></span></a></li><li><a class="Primer_Brand__Link-module__Link___lF11y Primer_Brand__Link-module__Link--default___VRVW0 NavLink-module__link__EG3d4" href="https://github.com/enterprise/premium-support" data-analytics-event="{&quot;action&quot;:&quot;premium_support&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;enterprise&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;premium_support_link_enterprise_navbar&quot;}"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Link-module__Link--label___jM8Ty"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS Primer_Brand__Text-module__Text--weight-medium___qJKf_ NavLink-module__title__Q7t0p"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-comment-discussion NavLink-module__icon__ltGNM" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M1.75 1h8.5c.966 0 1.75.784 1.75 1.75v5.5A1.75 1.75 0 0 1 10.25 10H7.061l-2.574 2.573A1.458 1.458 0 0 1 2 11.543V10h-.25A1.75 1.75 0 0 1 0 8.25v-5.5C0 1.784.784 1 1.75 1ZM1.5 2.75v5.5c0 .138.112.25.25.25h1a.75.75 0 0 1 .75.75v2.19l2.72-2.72a.749.749 0 0 1 .53-.22h3.5a.25.25 0 0 0 .25-.25v-5.5a.25.25 0 0 0-.25-.25h-8.5a.25.25 0 0 0-.25.25Zm13 2a.25.25 0 0 0-.25-.25h-.5a.75.75 0 0 1 0-1.5h.5c.966 0 1.75.784 1.75 1.75v5.5A1.75 1.75 0 0 1 14.25 12H14v1.543a1.458 1.458 0 0 1-2.487 1.03L9.22 12.28a.749.749 0 0 1 .326-1.275.749.749 0 0 1 .734.215l2.22 2.22v-2.19a.75.75 0 0 1 .75-.75h1a.25.25 0 0 0 .25-.25Z"></path></svg>Premium Support</span><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--muted___rE6mh Primer_Brand__Text-module__Text--200____P1wy Primer_Brand__Text-module__Text--antialiased___TYoXS NavLink-module__subtitle__X4gkW">Enterprise-grade 24/7 support</span></span></a></li></ul></div></li></ul></div></div></li><li><a href="https://github.com/pricing" data-analytics-event="{&quot;action&quot;:&quot;pricing&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;pricing&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;pricing_link_pricing_navbar&quot;}" class="MarketingNavigation-module__navLink__hUomM">Pricing</a></li></ul></nav><div class="MarketingHeader-module__ctaContainer__tBmPz"><div class="HeaderSearch-module__searchSlot__oVOUS"><button class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--subtle___F7pEE Primer_Brand__Button-module__Button--size-small___zQrEw HeaderSearch-module__trigger__zsF9q" type="button" aria-haspopup="dialog" aria-expanded="false" aria-label="Search or jump to, type / to search" data-analytics-event="{&quot;action&quot;:&quot;searchbar&quot;,&quot;tag&quot;:&quot;input&quot;,&quot;context&quot;:&quot;global&quot;,&quot;location&quot;:&quot;navbar&quot;,&quot;label&quot;:&quot;searchbar_input_global_navbar&quot;}"><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-subtle___8ndWH"><span class="HeaderSearch-module__content__kMpxU"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-search HeaderSearch-module__icon__wcrHX" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M10.68 11.74a6 6 0 0 1-7.922-8.982 6 6 0 0 1 8.982 7.922l3.04 3.04a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215ZM11.5 7a4.499 4.499 0 1 0-8.997 0A4.499 4.499 0 0 0 11.5 7Z"></path></svg><span class="HeaderSearch-module__label__d1iWG">Search</span><kbd class="HeaderSearch-module__kbd__HNG0o" aria-hidden="true">/</kbd></span></span></span></button><div class="d-none"></div></div><div class="AuthCTAs-module__signInWrap__q2P60"><a class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--subtle___F7pEE Primer_Brand__Button-module__Button--size-small___zQrEw AuthCTAs-module__cta__WpwQq AuthCTAs-module__desktopActionGap__UZuXT AuthCTAs-module__hiddenBelowLg__BfKBw" href="/login?return_to=https%3A%2F%2Fgithub.com%2Fconfidential-containers%2Ftrustee%2Fblob%2Fmain%2Fdeployment%2Fhelm-chart%2FREADME.md" data-analytics-event="{&quot;action&quot;:&quot;sign_in&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;auth_cta&quot;,&quot;location&quot;:&quot;header&quot;,&quot;label&quot;:&quot;sign_in_link_auth_cta_header&quot;}" data-hydro-click="{&quot;event_type&quot;:&quot;authentication.click&quot;,&quot;payload&quot;:{&quot;location_in_page&quot;:&quot;site header menu&quot;,&quot;repository_id&quot;:null,&quot;auth_type&quot;:&quot;SIGN_UP&quot;,&quot;originating_url&quot;:&quot;https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md&quot;,&quot;user_id&quot;:null}}" data-hydro-click-hmac="67b86208b48273018bc7bf3542ca71b4faa39c3ae9a8f1989542ecdbf1112083"><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-subtle___8ndWH">Sign in</span></span></a></div><a class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--secondary___gHnw_ Primer_Brand__Button-module__Button--size-small___zQrEw AuthCTAs-module__cta__WpwQq" href="/signup?ref_cta=Sign+up&amp;ref_loc=header+logged+out&amp;ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fblob%2Fshow&amp;source=header-repo&amp;source_repo=confidential-containers%2Ftrustee" data-analytics-event="{&quot;action&quot;:&quot;sign_up&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;context&quot;:&quot;auth_cta&quot;,&quot;location&quot;:&quot;header&quot;,&quot;label&quot;:&quot;sign_up_link_auth_cta_header&quot;}" data-hydro-click="{&quot;event_type&quot;:&quot;authentication.click&quot;,&quot;payload&quot;:{&quot;location_in_page&quot;:&quot;site header menu&quot;,&quot;repository_id&quot;:null,&quot;auth_type&quot;:&quot;SIGN_UP&quot;,&quot;originating_url&quot;:&quot;https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md&quot;,&quot;user_id&quot;:null}}" data-hydro-click-hmac="67b86208b48273018bc7bf3542ca71b4faa39c3ae9a8f1989542ecdbf1112083"><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-secondary___eJ0_a">Sign up</span></span></a><button class="Primer_Brand__Button-module__Button___scH9Z Primer_Brand__Button-module__Button--subtle___F7pEE Primer_Brand__Button-module__Button--size-small___zQrEw HeaderAppearanceSettings-module__trigger__hUheK" type="button" aria-haspopup="dialog" aria-labelledby="_R_fbd_"><span class="Primer_Brand__Button-module__Button__leading-visual___jjtTe" data-testid="Button-leading-visual"><svg data-component="Octicon" focusable="false" aria-hidden="true" class="octicon octicon-sliders Primer_Brand__Button-module__Button__icon-visual____qybb" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M15 2.75a.75.75 0 0 1-.75.75h-4a.75.75 0 0 1 0-1.5h4a.75.75 0 0 1 .75.75Zm-8.5.75v1.25a.75.75 0 0 0 1.5 0v-4a.75.75 0 0 0-1.5 0V2H1.75a.75.75 0 0 0 0 1.5H6.5Zm1.25 5.25a.75.75 0 0 0 0-1.5h-6a.75.75 0 0 0 0 1.5h6ZM15 8a.75.75 0 0 1-.75.75H11.5V10a.75.75 0 1 1-1.5 0V6a.75.75 0 0 1 1.5 0v1.25h2.75A.75.75 0 0 1 15 8Zm-9 5.25v-2a.75.75 0 0 0-1.5 0v1.25H1.75a.75.75 0 0 0 0 1.5H4.5v1.25a.75.75 0 0 0 1.5 0v-2Zm9 0a.75.75 0 0 1-.75.75h-6a.75.75 0 0 1 0-1.5h6a.75.75 0 0 1 .75.75Z"></path></svg></span><span class="Primer_Brand__Button-module__Button__text___ED0bX"><span class="Primer_Brand__Text-module__Text___XeGJJ Primer_Brand__Text-module__Text-font--mona-sans___a8XJD Primer_Brand__Text-module__Text--default___GhPh_ Primer_Brand__Text-module__Text--100___B2ueX Primer_Brand__Text-module__Text--weight-medium___qJKf_ Primer_Brand__Button-module__Button--label___qrkyz Primer_Brand__Button-module__Button--label-subtle___8ndWH"></span></span></button><div class="Primer_Brand__Tooltip-module__Tooltip___0Eipx" data-direction="s" aria-hidden="true" id="_R_fbd_">Appearance settings</div></div></div></div></div><div class="MarketingHeader-module__bottomBorder__uZT38" aria-hidden="true"></div></header></div></div>
</react-partial>



      <div hidden="hidden" data-view-component="true" class="js-stale-session-flash stale-session-flash flash flash-warn flash-full">
  
        <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-alert">
    <path d="M6.457 1.047c.659-1.234 2.427-1.234 3.086 0l6.082 11.378A1.75 1.75 0 0 1 14.082 15H1.918a1.75 1.75 0 0 1-1.543-2.575Zm1.763.707a.25.25 0 0 0-.44 0L1.698 13.132a.25.25 0 0 0 .22.368h12.164a.25.25 0 0 0 .22-.368Zm.53 3.996v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 11a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path>
</svg>
        <span class="js-stale-session-flash-signed-in" hidden>You signed in with another tab or window. <a class="Link--inTextBlock" href="">Reload</a> to refresh your session.</span>
        <span class="js-stale-session-flash-signed-out" hidden>You signed out in another tab or window. <a class="Link--inTextBlock" href="">Reload</a> to refresh your session.</span>
        <span class="js-stale-session-flash-switched" hidden>You switched accounts on another tab or window. <a class="Link--inTextBlock" href="">Reload</a> to refresh your session.</span>

    <button id="icon-button-62a87a5e-d7d1-4165-aada-7c5d1ca2191a" aria-labelledby="tooltip-d1ef9eec-4389-4418-b9df-47007f6152a2" type="button" data-view-component="true" class="Button Button--iconOnly Button--invisible Button--medium flash-close js-flash-close">  <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-x Button-visual">
    <path d="M3.72 3.72a.75.75 0 0 1 1.06 0L8 6.94l3.22-3.22a.749.749 0 0 1 1.275.326.749.749 0 0 1-.215.734L9.06 8l3.22 3.22a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L8 9.06l-3.22 3.22a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L6.94 8 3.72 4.78a.75.75 0 0 1 0-1.06Z"></path>
</svg>
</button><tool-tip id="tooltip-d1ef9eec-4389-4418-b9df-47007f6152a2" for="icon-button-62a87a5e-d7d1-4165-aada-7c5d1ca2191a" popover="manual" data-direction="s" data-type="label" data-view-component="true" class="sr-only position-absolute">Dismiss alert</tool-tip>


  
</div>
    </div>

  <div id="start-of-content" class="show-on-focus"></div>








    <div id="js-flash-container" class="flash-container" data-turbo-replace>






  <template class="js-flash-template">
    
<div class="flash flash-full   {{ className }}">
  <div >
    <button autofocus class="flash-close js-flash-close" type="button" aria-label="Dismiss this message">
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-x">
    <path d="M3.72 3.72a.75.75 0 0 1 1.06 0L8 6.94l3.22-3.22a.749.749 0 0 1 1.275.326.749.749 0 0 1-.215.734L9.06 8l3.22 3.22a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L8 9.06l-3.22 3.22a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L6.94 8 3.72 4.78a.75.75 0 0 1 0-1.06Z"></path>
</svg>
    </button>
    <div aria-atomic="true" role="alert" class="js-flash-alert">
      
      <div>{{ message }}</div>

    </div>
  </div>
</div>
  </template>
</div>


    






  <div
    class="application-main "
    data-commit-hovercards-enabled
    data-discussion-hovercards-enabled
    data-issue-and-pr-hovercards-enabled
    data-project-hovercards-enabled
  >
        <div itemscope itemtype="http://schema.org/SoftwareSourceCode" class="">
    <main id="js-repo-pjax-container" >
      
      
    


    








  

    <link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ym-6bc2c9bf8112c038.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/sk2-8deeef9351be3911.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/ni-3e194d222c7770bf.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/7x-71d30cb240cd901f.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/wwk-ad869086822937b1.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/a1-9f79841ecac1da8e.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/wzg-40a3213b3e83400b.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/5f-64f8e7d5bcbd4787.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/z5-b53a93078d026f1e.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/8h-cef26f68c1331011.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/fq-3ce13a77e863807a.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/a7-596b507bd20acddc.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/xfx-c82d8352413aea0a.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/j4-b3a9e87fa7878a98.js" fetchpriority="low" />
<link crossorigin="anonymous" rel="modulepreload" href="https://github.githubassets.com/assets/global-nav-bar-29c7aef68ee9db41.js" fetchpriority="low" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react-css.2d881b4d4a503d1c.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/pj.75627bfeb9ceb1da.module.css" />
<link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/global-nav-bar.2f2560cba06ab359.module.css" />

<react-partial
  partial-name="global-nav-bar"
  data-ssr="true"
  data-attempted-ssr="true"
  data-react-profiling="false"
>
  
  <script type="application/json" data-target="react-partial.embeddedData">{"props":{"contextRegion":{"crumbs":[{"crumb_type":"organization","label":"confidential-containers","is_root":false,"href":"/confidential-containers"},{"crumb_type":"repository","label":"trustee","is_root":false,"href":"/confidential-containers/trustee"}],"localNavigation":[{"id":"code","icon":"code","label":"Code","href":"/confidential-containers/trustee","selectedLinks":["repo_source","repo_downloads","repo_commits","repo_releases","repo_tags","repo_branches","repo_packages","repo_deployments","repo_attestations"],"popoverTarget":false,"commandId":"repositories:go-to-code","reactNav":{"appTarget":"code-view","anchor":"code-view-repo-link"},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"issues","icon":"issue-opened","label":"Issues","href":"/confidential-containers/trustee/issues","selectedLinks":["repo_issues","repo_labels","repo_milestones"],"count":107,"popoverTarget":false,"commandId":"repositories:go-to-issues","reactNav":{"appTarget":"repo","anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"pull-requests","icon":"git-pull-request","label":"Pull requests","href":"/confidential-containers/trustee/pulls","selectedLinks":["repo_pulls","checks"],"count":35,"popoverTarget":false,"commandId":"repositories:go-to-pull-requests","reactNav":{"appTarget":null,"anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"actions","icon":"play","label":"Actions","href":"/confidential-containers/trustee/actions","selectedLinks":["repo_actions"],"popoverTarget":false,"commandId":"repositories:go-to-actions","reactNav":{"appTarget":"actions-workflows","anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"projects","icon":"table","label":"Projects","href":"/confidential-containers/trustee/projects","selectedLinks":["repo_projects","new_repo_project","repo_project"],"popoverTarget":false,"commandId":"repositories:go-to-projects","reactNav":{"appTarget":"repo","anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"security-and-quality","icon":"shield","label":"Security and quality","href":"/confidential-containers/trustee/security","selectedLinks":["security","overview","alerts","policy","token_scanning","code_scanning"],"count":2,"popoverTarget":false,"commandId":"repositories:go-to-security","reactNav":{"appTarget":null,"anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}},{"id":"insights","icon":"graph","label":"Insights","href":"/confidential-containers/trustee/pulse","selectedLinks":["repo_graphs","repo_contributors","dependency_graph","dependabot_updates","pulse","people","community"],"popoverTarget":false,"commandId":"repositories:go-to-insights","reactNav":{"appTarget":null,"anchor":null},"turboNav":{"frame":"repo-content-turbo-frame"}}],"localNavigationUpdateChannel":null,"selectedLink":"repo_source"},"owner":null,"headerLogo":{"href":"/","aria-label":"Homepage "},"notifications":{"indicatorMode":"disabled","websocketChannel":null,"fetchIndicatorSrc":"/notifications/indicator","fetchIndicatorEnabled":false},"issues":{"href":"/issues"},"pulls":{"href":"/pulls"},"contributedRepos":{"href":"/repos"},"copilot":{"show":false,"showAgentsButton":false,"showRelaunchAnnouncement":false,"copilotChatUrl":null,"copilotApiUrl":"https://api.githubcopilot.com"},"search":{"show":true,"showCommandPalette":false,"isSearchPage":false,"isJumpToSearch":false,"searchContext":{"scope":"repo:confidential-containers/trustee","current_repo_name":"trustee","current_repo_nwo":"confidential-containers/trustee","current_repo_org":"confidential-containers","user_id":"confidential-containers"}},"commandPalette":null,"enterpriseBar":{"show":false},"globalTransactionalMessage":[],"payloadsUrl":"/_global-navigation/payloads.json?can_toggle_site_admin_and_employee_status=0\u0026is_admin_mode_on=0\u0026is_ui_opted_out=0\u0026show_ui_opt_out=0\u0026v=7","contextRegionUrl":"/_global-navigation/context-region.json"}}</script>
  <div data-target="react-partial.reactRoot"><header aria-label="Global navigation menu" data-component="Stack" class="GlobalNav styles-module__appHeader__YzYWk prc-Stack-Stack-UQ9k6" data-gap="none" data-direction="vertical" data-align="stretch" data-wrap="nowrap" data-justify="start" data-padding="none"><div data-component="Stack" class="prc-Stack-Stack-UQ9k6" data-direction="horizontal" data-align="center" data-wrap="nowrap" data-justify="center" data-padding="none"><div data-testid="top-nav-center" data-component="Stack" class="styles-module__center__R3QRv styles-module__withLocalNavigation__rjTJ_ GlobalNavBar-module__loggedOut__Jv1rk prc-Stack-Stack-UQ9k6" data-gap="condensed" data-direction="horizontal" data-align="stretch" data-wrap="nowrap" data-justify="start" data-padding="normal"><nav class="styles-module__contextRegion__VbSp2 prc-Breadcrumbs-BreadcrumbsBase-3Gb-B" aria-label="Breadcrumbs" data-overflow="menu" data-variant="normal" data-component="Breadcrumbs"><ol class="prc-Breadcrumbs-BreadcrumbsList-BKjpe"><li class="prc-Breadcrumbs-ItemWrapper-k0NLn"><a class="styles-module__contextCrumb__IzGIq prc-Breadcrumbs-Item-jcraJ" data-component="Breadcrumbs.Item" href="/confidential-containers" data-discover="true"><span class="">confidential-containers</span></a></li><li class="prc-Breadcrumbs-ItemWrapper-k0NLn"><a class="styles-module__contextCrumb__IzGIq prc-Breadcrumbs-Item-jcraJ" data-component="Breadcrumbs.Item" href="/confidential-containers/trustee" data-discover="true"><span class="styles-module__contextCrumbLast__tI2e3">trustee</span></a></li></ol></nav></div><div data-testid="top-nav-right" data-component="Stack" class="styles-module__right__mlBQg styles-module__withLocalNavigation__rjTJ_ styles-module__rightWithResponsiveCreateButton__SKn2W prc-Stack-Stack-UQ9k6" data-gap="condensed" data-direction="horizontal" data-align="center" data-wrap="nowrap" data-justify="start" data-padding="normal"></div></div><h2 class="prc-src-InternalVisuallyHidden-2YaI6">Repository navigation</h2><nav class="prc-components-UnderlineWrapper-eT-Yj prc-UnderlineNav-UnderlineWrapper-GWONT LocalNavigation-module__LocalNavigation__b0Xc0" aria-label="Repository" data-variant="inset" data-overflow-mode="wrap" data-hide-icons-breakpoint="medium"><ul class="prc-UnderlineNav-ItemsList-oj8gN prc-components-UnderlineItemList-xKlKC" role="list"><li role="presentation" aria-hidden="true" class="prc-UnderlineNav-WrapSpacer--aLgz"></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a aria-current="page" data-tab-item="code" data-react-nav="code-view" data-react-nav-anchor="code-view-repo-link" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-code" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m11.28 3.22 4.25 4.25a.75.75 0 0 1 0 1.06l-4.25 4.25a.749.749 0 0 1-1.275-.326.749.749 0 0 1 .215-.734L13.94 8l-3.72-3.72a.749.749 0 0 1 .326-1.275.749.749 0 0 1 .734.215Zm-6.56 0a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042L2.06 8l3.72 3.72a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L.47 8.53a.75.75 0 0 1 0-1.06Z"></path></svg></span><span data-component="text" data-content="Code">Code</span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="issues" data-react-nav="repo" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/issues" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-issue-opened" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 9.5a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path><path d="M8 0a8 8 0 1 1 0 16A8 8 0 0 1 8 0ZM1.5 8a6.5 6.5 0 1 0 13 0 6.5 6.5 0 0 0-13 0Z"></path></svg></span><span data-component="text" data-content="Issues">Issues</span><span data-component="counter"><span aria-hidden="true" data-variant="secondary" data-component="CounterLabel" class="prc-CounterLabel-CounterLabel-X-kRU">107</span><span class="prc-VisuallyHidden-VisuallyHidden-Q0qSB"> (<!-- -->107<!-- -->)</span></span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="pull-requests" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/pulls" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-git-pull-request" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M1.5 3.25a2.25 2.25 0 1 1 3 2.122v5.256a2.251 2.251 0 1 1-1.5 0V5.372A2.25 2.25 0 0 1 1.5 3.25Zm5.677-.177L9.573.677A.25.25 0 0 1 10 .854V2.5h1A2.5 2.5 0 0 1 13.5 5v5.628a2.251 2.251 0 1 1-1.5 0V5a1 1 0 0 0-1-1h-1v1.646a.25.25 0 0 1-.427.177L7.177 3.427a.25.25 0 0 1 0-.354ZM3.75 2.5a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5Zm0 9.5a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5Zm8.25.75a.75.75 0 1 0 1.5 0 .75.75 0 0 0-1.5 0Z"></path></svg></span><span data-component="text" data-content="Pull requests">Pull requests</span><span data-component="counter"><span aria-hidden="true" data-variant="secondary" data-component="CounterLabel" class="prc-CounterLabel-CounterLabel-X-kRU">35</span><span class="prc-VisuallyHidden-VisuallyHidden-Q0qSB"> (<!-- -->35<!-- -->)</span></span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="actions" data-react-nav="actions-workflows" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/actions" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-play" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 0a8 8 0 1 1 0 16A8 8 0 0 1 8 0ZM1.5 8a6.5 6.5 0 1 0 13 0 6.5 6.5 0 0 0-13 0Zm4.879-2.773 4.264 2.559a.25.25 0 0 1 0 .428l-4.264 2.559A.25.25 0 0 1 6 10.559V5.442a.25.25 0 0 1 .379-.215Z"></path></svg></span><span data-component="text" data-content="Actions">Actions</span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="projects" data-react-nav="repo" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/projects" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-table" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 1.75C0 .784.784 0 1.75 0h12.5C15.216 0 16 .784 16 1.75v12.5A1.75 1.75 0 0 1 14.25 16H1.75A1.75 1.75 0 0 1 0 14.25ZM6.5 6.5v8h7.75a.25.25 0 0 0 .25-.25V6.5Zm8-1.5V1.75a.25.25 0 0 0-.25-.25H6.5V5Zm-13 1.5v7.75c0 .138.112.25.25.25H5v-8ZM5 5V1.5H1.75a.25.25 0 0 0-.25.25V5Z"></path></svg></span><span data-component="text" data-content="Projects">Projects</span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="security-and-quality" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/security" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-shield" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg></span><span data-component="text" data-content="Security and quality">Security and quality</span><span data-component="counter"><span aria-hidden="true" data-variant="secondary" data-component="CounterLabel" class="prc-CounterLabel-CounterLabel-X-kRU">2</span><span class="prc-VisuallyHidden-VisuallyHidden-Q0qSB"> (<!-- -->2<!-- -->)</span></span></a></li><li class="prc-UnderlineNav-UnderlineNavItem-syRjR"><a data-tab-item="insights" data-turbo-frame="repo-content-turbo-frame" class="prc-components-UnderlineItem-7fP-n" href="/confidential-containers/trustee/pulse" data-discover="true"><span data-component="icon"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-graph" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M1.5 1.75V13.5h13.75a.75.75 0 0 1 0 1.5H.75a.75.75 0 0 1-.75-.75V1.75a.75.75 0 0 1 1.5 0Zm14.28 2.53-5.25 5.25a.75.75 0 0 1-1.06 0L7 7.06 4.28 9.78a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042l3.25-3.25a.75.75 0 0 1 1.06 0L10 7.94l4.72-4.72a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042Z"></path></svg></span><span data-component="text" data-content="Insights">Insights</span></a></li></ul><div class="prc-UnderlineNav-MoreButtonContainer-Dnrq6"><div class="prc-UnderlineNav-MoreButtonDivider-dN0a-"></div><button data-component="overflow-menu-button" type="button" aria-haspopup="true" aria-expanded="false" tabindex="0" class="prc-Button-ButtonBase-9n-Xk prc-UnderlineNav-MoreButton-Y8soj" data-loading="false" data-size="medium" data-variant="invisible" id="_R_2ktp_"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="text" class="prc-Button-Label-FWkx3"><span>More<span class="prc-src-InternalVisuallyHidden-2YaI6"> items</span></span></span></span><span data-component="trailingAction" class="prc-Button-Visual-YNt2F prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-down" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m4.427 7.427 3.396 3.396a.25.25 0 0 0 .354 0l3.396-3.396A.25.25 0 0 0 11.396 7H4.604a.25.25 0 0 0-.177.427Z"></path></svg></span></button></div></nav><div class="d-none"></div></header></div>
</react-partial>


  



<turbo-frame id="repo-content-turbo-frame" target="_top" data-turbo-action="advance" class="">
    <div id="repo-content-pjax-container" class="repository-content " >
    



    
      
    








<react-app
  app-name="code-view"
  initial-path="/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md"
  style="display: block; min-height: calc(100vh - 64px);"
  data-attempted-ssr="true"
  data-ssr="true"
  data-lazy="false"
  data-alternate="false"
  data-data-router-enabled="true"
  data-react-profiling="false"
>
  
  <script type="application/json" data-target="react-app.embeddedData">{"payload":{"codeViewBlobRoute":{"csv":null,"csvError":null,"headerInfo":{"toc":[{"level":1,"text":"Trustee Helm Chart","anchor":"trustee-helm-chart","htmlText":"Trustee Helm Chart"},{"level":2,"text":"Install","anchor":"install","htmlText":"Install"},{"level":2,"text":"Typical scenarios","anchor":"typical-scenarios","htmlText":"Typical scenarios"},{"level":3,"text":"Default: LocalFs storage","anchor":"default-localfs-storage","htmlText":"Default: LocalFs storage"},{"level":3,"text":"PostgreSQL as storage backend + in-memory KBS sessions","anchor":"postgresql-as-storage-backend--in-memory-kbs-sessions","htmlText":"PostgreSQL as storage backend + in-memory KBS sessions"},{"level":3,"text":"External PostgreSQL","anchor":"external-postgresql","htmlText":"External PostgreSQL"},{"level":3,"text":"Valkey (Redis protocol) for KBS sessions","anchor":"valkey-redis-protocol-for-kbs-sessions","htmlText":"Valkey (Redis protocol) for KBS sessions"},{"level":3,"text":"External Redis-compatible service","anchor":"external-redis-compatible-service","htmlText":"External Redis-compatible service"},{"level":3,"text":"Bring your own keys (BYOK)","anchor":"bring-your-own-keys-byok","htmlText":"Bring your own keys (BYOK)"},{"level":3,"text":"Native KBS HTTPS","anchor":"native-kbs-https","htmlText":"Native KBS HTTPS"},{"level":3,"text":"IBM Secure Execution (s390x)","anchor":"ibm-secure-execution-s390x","htmlText":"IBM Secure Execution (s390x)"},{"level":3,"text":"AMD SEV-SNP offline VCEK store","anchor":"amd-sev-snp-offline-vcek-store","htmlText":"AMD SEV-SNP offline VCEK store"},{"level":2,"text":"Testing","anchor":"testing","htmlText":"Testing"},{"level":2,"text":"Configuration","anchor":"configuration","htmlText":"Configuration"},{"level":2,"text":"Values","anchor":"values","htmlText":"Values"},{"level":2,"text":"End-to-end test","anchor":"end-to-end-test","htmlText":"End-to-end test"},{"level":2,"text":"Development notes","anchor":"development-notes","htmlText":"Development notes"}]},"issueTemplate":null,"discussionTemplate":null,"richText":"\u003carticle class=\"markdown-body entry-content container-lg\" itemprop=\"text\"\u003e\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch1 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eTrustee Helm Chart\u003c/h1\u003e\u003ca id=\"user-content-trustee-helm-chart\" class=\"anchor\" aria-label=\"Permalink: Trustee Helm Chart\" href=\"#trustee-helm-chart\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eHelm chart for \u003ca href=\"https://github.com/confidential-containers\"\u003eConfidential Containers\u003c/a\u003e \u003cstrong\u003eTrustee\u003c/strong\u003e on Kubernetes: \u003cstrong\u003eKBS\u003c/strong\u003e, \u003cstrong\u003egRPC AS\u003c/strong\u003e, and \u003cstrong\u003eRVPS\u003c/strong\u003e, with optional bundled \u003cstrong\u003ePostgreSQL\u003c/strong\u003e (\u003ca href=\"https://artifacthub.io/packages/helm/bitnami/postgresql\" rel=\"nofollow\"\u003eBitnami chart\u003c/a\u003e) and \u003cstrong\u003eValkey\u003c/strong\u003e (\u003ca href=\"https://artifacthub.io/packages/helm/bitnami/valkey\" rel=\"nofollow\"\u003eBitnami chart\u003c/a\u003e, a Redis-protocol store for KBS sessions). KBS is wired to remote \u003cstrong\u003e\u003ccode\u003ecoco_as_grpc\u003c/code\u003e\u003c/strong\u003e Attestation Service.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eInstall\u003c/h2\u003e\u003ca id=\"user-content-install\" class=\"anchor\" aria-label=\"Permalink: Install\" href=\"#install\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003e\u003cstrong\u003eRequirements\u003c/strong\u003e: Kubernetes 1.19+, Helm 3. If bundled Postgres is needed (when \u003cstrong\u003e\u003ccode\u003estorageBackend.type: Postgres\u003c/code\u003e\u003c/strong\u003e or \u003cstrong\u003e\u003ccode\u003esessionStorageType: Postgres\u003c/code\u003e\u003c/strong\u003e), the Bitnami subchart uses PVC-backed storage, so your cluster must provide a usable \u003cstrong\u003eStorageClass\u003c/strong\u003e (or you must bind an existing claim).\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eFrom the \u003cstrong\u003erepository root\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace\"\u003e\u003cpre\u003ehelm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWait for workloads, then port-forward KBS (default HTTP \u003cstrong\u003e8080\u003c/strong\u003e). The internal ClusterIP Service is \u003cstrong\u003e\u003ccode\u003e\u0026lt;Helm fullname\u0026gt;-kbs\u003c/code\u003e\u003c/strong\u003e (with the install command below, \u003cstrong\u003e\u003ccode\u003etrustee-kbs\u003c/code\u003e\u003c/strong\u003e):\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl get pods -n coco-trustee -w\nkubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080\"\u003e\u003cpre\u003ekubectl get pods -n coco-trustee -w\nkubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eUninstall the release:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm uninstall trustee -n coco-trustee\"\u003e\u003cpre\u003ehelm uninstall trustee -n coco-trustee\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"markdown-alert markdown-alert-note\" dir=\"auto\"\u003e\u003cp class=\"markdown-alert-title\" dir=\"auto\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-info mr-2\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z\"\u003e\u003c/path\u003e\u003c/svg\u003eNote\u003c/p\u003e\u003cp dir=\"auto\"\u003eWhen \u003ccode\u003esecrets.useEphemeralGeneratedKeys\u003c/code\u003e is \u003ccode\u003etrue\u003c/code\u003e (default), a \u003cstrong\u003epost-delete\u003c/strong\u003e Helm hook removes the release-scoped \u003ccode\u003e*-bootstrap-user-keys\u003c/code\u003e Secret automatically.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eTypical scenarios\u003c/h2\u003e\u003ca id=\"user-content-typical-scenarios\" class=\"anchor\" aria-label=\"Permalink: Typical scenarios\" href=\"#typical-scenarios\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eDefault: LocalFs storage\u003c/h3\u003e\u003ca id=\"user-content-default-localfs-storage\" class=\"anchor\" aria-label=\"Permalink: Default: LocalFs storage\" href=\"#default-localfs-storage\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eSame as \u003cstrong\u003eInstall\u003c/strong\u003e above. If neither \u003cstrong\u003e\u003ccode\u003estorageBackend.type\u003c/code\u003e\u003c/strong\u003e nor \u003cstrong\u003e\u003ccode\u003esessionStorageType\u003c/code\u003e\u003c/strong\u003e is \u003cstrong\u003e\u003ccode\u003ePostgres\u003c/code\u003e\u003c/strong\u003e, the chart does not deploy bundled Postgres; components use the default \u003cstrong\u003e\u003ccode\u003estorageBackend\u003c/code\u003e\u003c/strong\u003e (e.g. \u003cstrong\u003eLocalFs\u003c/strong\u003e).\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003ePostgreSQL as storage backend + in-memory KBS sessions\u003c/h3\u003e\u003ca id=\"user-content-postgresql-as-storage-backend--in-memory-kbs-sessions\" class=\"anchor\" aria-label=\"Permalink: PostgreSQL as storage backend + in-memory KBS sessions\" href=\"#postgresql-as-storage-backend--in-memory-kbs-sessions\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml\"\u003e\u003cpre\u003ehelm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eThis enables the \u003cstrong\u003eBitnami PostgreSQL\u003c/strong\u003e subchart (\u003ccode\u003epostgresql.enabled: true\u003c/code\u003e) and sets \u003cstrong\u003e\u003ccode\u003estorageBackend.type: Postgres\u003c/code\u003e\u003c/strong\u003e. KBS sessions stay in memory (\u003ccode\u003esessionStorageType: Memory\u003c/code\u003e). Demo credentials default to \u003ccode\u003etrustee\u003c/code\u003e / \u003ccode\u003etrustee\u003c/code\u003e / \u003ccode\u003etrustee\u003c/code\u003e (override via \u003ccode\u003epostgresql.auth.*\u003c/code\u003e).\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eExternal PostgreSQL\u003c/h3\u003e\u003ca id=\"user-content-external-postgresql\" class=\"anchor\" aria-label=\"Permalink: External PostgreSQL\" href=\"#external-postgresql\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWhen an external Postgres service is used, set \u003cstrong\u003e\u003ccode\u003estorageBackend.postgres.mode=external\u003c/code\u003e\u003c/strong\u003e, pre-create a Secret with a \u003cstrong\u003e\u003ccode\u003ePOSTGRES_URL\u003c/code\u003e\u003c/strong\u003e key, and point the chart at it:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl create secret generic trustee-external-postgres -n coco-trustee \\\n  --from-literal=POSTGRES_URL='postgresql://user:password@postgres.example.com:5432/trustee?sslmode=require'\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set storageBackend.type=Postgres \\\n  --set storageBackend.postgres.mode=external \\\n  --set storageBackend.postgres.external.existingSecretName=trustee-external-postgres \\\n  --set storageBackend.postgres.external.existingSecretKey=POSTGRES_URL\"\u003e\u003cpre\u003ekubectl create secret generic trustee-external-postgres -n coco-trustee \\\n  --from-literal=POSTGRES_URL=\u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003epostgresql://user:password@postgres.example.com:5432/trustee?sslmode=require\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e\u003c/span\u003e\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set storageBackend.type=Postgres \\\n  --set storageBackend.postgres.mode=external \\\n  --set storageBackend.postgres.external.existingSecretName=trustee-external-postgres \\\n  --set storageBackend.postgres.external.existingSecretKey=POSTGRES_URL\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWhen \u003ccode\u003estorageBackend.postgres.mode=external\u003c/code\u003e, the chart does \u003cstrong\u003eNOT\u003c/strong\u003e deploy the Bitnami subchart (\u003ccode\u003epostgresql.enabled\u003c/code\u003e stays \u003ccode\u003efalse\u003c/code\u003e), even if Postgres is required by \u003ccode\u003estorageBackend.type\u003c/code\u003e or \u003ccode\u003esessionStorageType\u003c/code\u003e.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eValkey (Redis protocol) for KBS sessions\u003c/h3\u003e\u003ca id=\"user-content-valkey-redis-protocol-for-kbs-sessions\" class=\"anchor\" aria-label=\"Permalink: Valkey (Redis protocol) for KBS sessions\" href=\"#valkey-redis-protocol-for-kbs-sessions\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eThe KBS \u003cstrong\u003e\u003ccode\u003eRedis\u003c/code\u003e\u003c/strong\u003e session backend speaks the Redis wire protocol. The chart bundles \u003cstrong\u003eValkey\u003c/strong\u003e (BSD-licensed) instead of Redis, whose license is no longer OSI-approved; any Redis-protocol-compatible service works. Storing sessions outside the KBS Pod allows running several KBS replicas.\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml\"\u003e\u003cpre\u003ehelm dependency update ./deployment/helm-chart\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eThis enables the \u003cstrong\u003eBitnami Valkey\u003c/strong\u003e subchart (\u003ccode\u003evalkey.enabled: true\u003c/code\u003e) and sets \u003cstrong\u003e\u003ccode\u003esessionStorageType: Redis\u003c/code\u003e\u003c/strong\u003e. The chart writes the connection URL into a release-scoped Secret and injects it into KBS as \u003cstrong\u003e\u003ccode\u003eREDIS_URL\u003c/code\u003e\u003c/strong\u003e. The demo password defaults to \u003ccode\u003etrustee\u003c/code\u003e (override via \u003ccode\u003evalkey.auth.password\u003c/code\u003e). Sessions are short-lived, so the bundled Valkey runs \u003ccode\u003estandalone\u003c/code\u003e without a PVC by default (\u003ccode\u003evalkey.primary.persistence.enabled: false\u003c/code\u003e).\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eThe default Valkey image is pulled from \u003cstrong\u003edocker.io\u003c/strong\u003e, where anonymous pulls are rate-limited. Override the image source to use a private mirror:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm upgrade --install trustee ./deployment/helm-chart ... \\\n  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml \\\n  --set valkey.image.registry=mirror.example.com \\\n  --set valkey.image.repository=bitnami/valkey \\\n  --set valkey.image.tag=9.1.0\"\u003e\u003cpre\u003ehelm upgrade --install trustee ./deployment/helm-chart ... \\\n  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml \\\n  --set valkey.image.registry=mirror.example.com \\\n  --set valkey.image.repository=bitnami/valkey \\\n  --set valkey.image.tag=9.1.0\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003e(A chart-wide \u003ccode\u003eglobal.imageRegistry\u003c/code\u003e is also honored by the Bitnami subcharts.)\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eExternal Redis-compatible service\u003c/h3\u003e\u003ca id=\"user-content-external-redis-compatible-service\" class=\"anchor\" aria-label=\"Permalink: External Redis-compatible service\" href=\"#external-redis-compatible-service\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWhen an external Redis-compatible service is used, set \u003cstrong\u003e\u003ccode\u003estorageBackend.redis.mode=external\u003c/code\u003e\u003c/strong\u003e, pre-create a Secret with the connection URL, and point the chart at it:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl create secret generic trustee-external-redis -n coco-trustee \\\n  --from-literal=REDIS_URL='redis://:password@redis.example.com:6379'\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set sessionStorageType=Redis \\\n  --set storageBackend.redis.mode=external \\\n  --set storageBackend.redis.external.existingSecretName=trustee-external-redis \\\n  --set storageBackend.redis.external.existingSecretKey=REDIS_URL\"\u003e\u003cpre\u003ekubectl create secret generic trustee-external-redis -n coco-trustee \\\n  --from-literal=REDIS_URL=\u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003eredis://:password@redis.example.com:6379\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e\u003c/span\u003e\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set sessionStorageType=Redis \\\n  --set storageBackend.redis.mode=external \\\n  --set storageBackend.redis.external.existingSecretName=trustee-external-redis \\\n  --set storageBackend.redis.external.existingSecretKey=REDIS_URL\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWhen \u003ccode\u003estorageBackend.redis.mode=external\u003c/code\u003e, the chart does \u003cstrong\u003eNOT\u003c/strong\u003e deploy the Valkey subchart (\u003ccode\u003evalkey.enabled\u003c/code\u003e stays \u003ccode\u003efalse\u003c/code\u003e).\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eBring your own keys (BYOK)\u003c/h3\u003e\u003ca id=\"user-content-bring-your-own-keys-byok\" class=\"anchor\" aria-label=\"Permalink: Bring your own keys (BYOK)\" href=\"#bring-your-own-keys-byok\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eKey material is controlled only by \u003cstrong\u003e\u003ccode\u003esecrets.useEphemeralGeneratedKeys\u003c/code\u003e\u003c/strong\u003e:\u003c/p\u003e\n\u003cul dir=\"auto\"\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003etrue\u003c/code\u003e (default):\u003c/strong\u003e a Helm \u003cstrong\u003epre-install / pre-upgrade hook\u003c/strong\u003e Job generates ephemeral demo keys into a release-scoped Secret (name ends with \u003cstrong\u003e\u003ccode\u003ebootstrap-user-keys\u003c/code\u003e\u003c/strong\u003e). \u003cstrong\u003e\u003ccode\u003ehelm uninstall\u003c/code\u003e\u003c/strong\u003e runs a \u003cstrong\u003epost-delete\u003c/strong\u003e hook that removes that Secret.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003efalse\u003c/code\u003e:\u003c/strong\u003e you must \u003cstrong\u003epre-create\u003c/strong\u003e a Kubernetes \u003cstrong\u003e\u003ccode\u003eSecret\u003c/code\u003e\u003c/strong\u003e in the target namespace, then set \u003cstrong\u003e\u003ccode\u003esecrets.existingSecretName\u003c/code\u003e\u003c/strong\u003e to that name. The bootstrap hook is \u003cstrong\u003enot\u003c/strong\u003e rendered.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp dir=\"auto\"\u003eWhen ephemeral generation is enabled, the hook uses:\u003c/p\u003e\n\u003cul dir=\"auto\"\u003e\n\u003cli\u003ean \u003ccode\u003einitContainer\u003c/code\u003e (OpenSSL image) to generate keys into an \u003ccode\u003eemptyDir\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ea \u003ccode\u003equay.io/kata-containers/kubectl\u003c/code\u003e container to create the Secret from generated files\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp dir=\"auto\"\u003eBoth images are overridable via \u003ccode\u003ebootstrapUserKeysJob.keygenImage.*\u003c/code\u003e and \u003ccode\u003ebootstrapUserKeysJob.kubectlImage.*\u003c/code\u003e.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eWhen ephemeral generation is disabled, the Secret must define these \u003cstrong\u003edata keys\u003c/strong\u003e (values are PEM text or base64-encoded PEM, same as any \u003ccode\u003ekubectl create secret generic --from-file=...\u003c/code\u003e):\u003c/p\u003e\n\u003cmarkdown-accessiblity-table\u003e\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eSecret key\u003c/th\u003e\n\u003cth\u003eRole\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003e\u003ccode\u003eKBS_ADMIN_PRIVATE_KEY\u003c/code\u003e\u003c/strong\u003e / \u003cstrong\u003e\u003ccode\u003eKBS_ADMIN_PUBKEY\u003c/code\u003e\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eKBS admin API Ed25519 keypair (used to sign admin JWTs).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003e\u003ccode\u003eKBS_ADMIN_TOKEN\u003c/code\u003e\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003ePre-signed admin bearer JWT for \u003ccode\u003ekbs-client --admin-token-file\u003c/code\u003e (generated by the bootstrap hook when ephemeral keys are enabled).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003e\u003ccode\u003eAS_TOKEN_SIGNING_PRIVATE_KEY\u003c/code\u003e\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eAttestation Service: sign attestation tokens.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003e\u003ccode\u003eAS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN\u003c/code\u003e\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eAS: \u003ccode\u003ex5c\u003c/code\u003e / cert chain; KBS: trust anchor for token verification.\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\u003c/markdown-accessiblity-table\u003e\n\u003cp dir=\"auto\"\u003eThe chart mounts that Secret on KBS and gRPC AS and \u003cstrong\u003emaps\u003c/strong\u003e those keys to in-container paths \u003cstrong\u003e\u003ccode\u003eprivate.key\u003c/code\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ccode\u003epublic.pub\u003c/code\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ccode\u003etoken.key\u003c/code\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ccode\u003etoken-cert-chain.pem\u003c/code\u003e\u003c/strong\u003e under \u003cstrong\u003e\u003ccode\u003e/opt/confidential-containers/kbs/user-keys\u003c/code\u003e\u003c/strong\u003e.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eExample (create Secret, then install):\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl create secret generic trustee-byok-keys -n coco-trustee \\\n  --from-file=KBS_ADMIN_PRIVATE_KEY=./admin.key.pem \\\n  --from-file=KBS_ADMIN_PUBKEY=./admin.pub.pem \\\n  --from-file=AS_TOKEN_SIGNING_PRIVATE_KEY=./token.key.pem \\\n  --from-file=AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN=./token-chain.pem\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set secrets.useEphemeralGeneratedKeys=false \\\n  --set secrets.existingSecretName=trustee-byok-keys\"\u003e\u003cpre\u003ekubectl create secret generic trustee-byok-keys -n coco-trustee \\\n  --from-file=KBS_ADMIN_PRIVATE_KEY=./admin.key.pem \\\n  --from-file=KBS_ADMIN_PUBKEY=./admin.pub.pem \\\n  --from-file=AS_TOKEN_SIGNING_PRIVATE_KEY=./token.key.pem \\\n  --from-file=AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN=./token-chain.pem\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set secrets.useEphemeralGeneratedKeys=false \\\n  --set secrets.existingSecretName=trustee-byok-keys\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eOr use \u003cstrong\u003e\u003ccode\u003escenarios/bring-your-own-keys.yaml\u003c/code\u003e\u003c/strong\u003e (adjust Secret name / file paths in the comments there).\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eNative KBS HTTPS\u003c/h3\u003e\u003ca id=\"user-content-native-kbs-https\" class=\"anchor\" aria-label=\"Permalink: Native KBS HTTPS\" href=\"#native-kbs-https\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eThe default KBS listener uses plaintext HTTP. For a KBS endpoint that clients or\nconfidential guests reach directly, enable native HTTPS and provide an existing\nSecret containing the endpoint private key and certificate chain. The chart does\nnot generate this identity material because its certificate SAN must match the\naddress used by KBS clients.\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl create namespace coco-trustee\nkubectl create secret tls trustee-kbs-tls \\\n  --namespace coco-trustee \\\n  --key ./kbs.key \\\n  --cert ./kbs.crt\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee \\\n  -f ./deployment/helm-chart/scenarios/native-tls.yaml\"\u003e\u003cpre\u003ekubectl create namespace coco-trustee\nkubectl create secret tls trustee-kbs-tls \\\n  --namespace coco-trustee \\\n  --key ./kbs.key \\\n  --cert ./kbs.crt\n\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee \\\n  -f ./deployment/helm-chart/scenarios/native-tls.yaml\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eWith \u003ccode\u003ekbs.tls.enabled=true\u003c/code\u003e, the chart leaves \u003ccode\u003einsecure_http\u003c/code\u003e at its secure\ndefault (\u003ccode\u003efalse\u003c/code\u003e), mounts the standard \u003ccode\u003etls.key\u003c/code\u003e and \u003ccode\u003etls.crt\u003c/code\u003e data keys from the\nselected Kubernetes TLS Secret, and changes the KBS health probes to HTTPS.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eKBS does not reload endpoint identity material dynamically, so restart the KBS\nDeployment after replacing the TLS Secret contents.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eIngress TLS termination is a separate mode: leave native KBS TLS disabled and\nconfigure \u003ccode\u003eingress.tls\u003c/code\u003e when the Ingress controller should serve HTTPS and\nforward plaintext HTTP to KBS. Do not combine native KBS TLS with Ingress unless\nthe chosen Ingress controller is explicitly configured to use HTTPS for its\nbackend connection.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eIBM Secure Execution (s390x)\u003c/h3\u003e\u003ca id=\"user-content-ibm-secure-execution-s390x\" class=\"anchor\" aria-label=\"Permalink: IBM Secure Execution (s390x)\" href=\"#ibm-secure-execution-s390x\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eOn \u003cstrong\u003es390x\u003c/strong\u003e, the \u003cstrong\u003eIBM Secure Execution (SE)\u003c/strong\u003e verifier needs attestation materials at runtime. Because KBS talks to a \u003cstrong\u003eremote \u003ccode\u003ecoco_as_grpc\u003c/code\u003e AS\u003c/strong\u003e, the verifier runs inside the \u003cstrong\u003eAS Pod\u003c/strong\u003e, so these materials must be mounted on \u003cstrong\u003eAS\u003c/strong\u003e, not KBS. (This differs from the builtin-AS kustomize overlay in \u003ccode\u003ekbs/config/kubernetes/overlays/ibm-se\u003c/code\u003e, which mounts them on KBS.)\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eThe verifier reads materials from fixed paths under \u003cstrong\u003e\u003ccode\u003e/run/confidential-containers/ibmse/\u003c/code\u003e\u003c/strong\u003e (overridable via \u003ccode\u003eSE_*\u003c/code\u003e env vars; see \u003ccode\u003edeps/verifier/src/se/README.md\u003c/code\u003e). The chart mounts them from a \u003cstrong\u003elocal node path\u003c/strong\u003e via a PersistentVolume / PersistentVolumeClaim — set \u003cstrong\u003e\u003ccode\u003eas.verifier.se.credsDir\u003c/code\u003e\u003c/strong\u003e to the directory on the node that contains the materials (equivalent to \u003ccode\u003eIBM_SE_CREDS_DIR\u003c/code\u003e used in the kustomize overlay), and \u003cstrong\u003e\u003ccode\u003eas.verifier.se.nodeName\u003c/code\u003e\u003c/strong\u003e to the name of that node.  The chart then creates a \u003ccode\u003elocal\u003c/code\u003e-type PV + PVC and mounts the whole directory at \u003ccode\u003e/run/confidential-containers/ibmse/\u003c/code\u003e on the AS Pod.\u003c/p\u003e\n\u003cmarkdown-accessiblity-table\u003e\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eMaterial\u003c/th\u003e\n\u003cth\u003eExpected path under \u003ccode\u003ecredsDir\u003c/code\u003e\u003c/th\u003e\n\u003cth\u003eNotes\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eRSA measurement key pair\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003ersa/encrypt_key.{pem,pub}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePrivate key is \u003cstrong\u003esensitive\u003c/strong\u003e — restrict node access.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eSigning / intermediate certs\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003ecerts/\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eDirectory\u003c/strong\u003e; all files are read.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCRLs\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003ecrls/\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eDirectory\u003c/strong\u003e; all files are read.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eHost Key Documents (HKD)\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003ehkds/\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eDirectory\u003c/strong\u003e; all files are read.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eSE image header\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003ehdr/hdr.bin\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBinary file.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eRoot CA (optional)\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003eroot_ca.crt\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eSingle file.\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\u003c/markdown-accessiblity-table\u003e\n\u003cp dir=\"auto\"\u003eSet \u003cstrong\u003e\u003ccode\u003eCERTS_OFFLINE_VERIFICATION=true\u003c/code\u003e\u003c/strong\u003e (via \u003ccode\u003eas.extraEnvVars\u003c/code\u003e) to verify the HKD certificate chain offline. Do \u003cstrong\u003enot\u003c/strong\u003e set \u003ccode\u003eSE_SKIP_CERTS_VERIFICATION=true\u003c/code\u003e outside development — it disables HKD certificate chain verification.\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"# 1. Place all materials under a directory on the target s390x node, e.g.:\n#    $IBM_SE_CREDS_DIR/{rsa/,certs/,crls/,hkds/,hdr/hdr.bin}\n#    See deps/verifier/src/se/README.md for how to obtain the materials.\n\n# 2. Install, pointing the chart at the node and directory:\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/ibm-se.yaml \\\n  --set as.verifier.se.credsDir=$IBM_SE_CREDS_DIR \\\n  --set as.verifier.se.nodeName=\u0026lt;your-s390x-node-name\u0026gt;\"\u003e\u003cpre\u003e\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e 1. Place all materials under a directory on the target s390x node, e.g.:\u003c/span\u003e\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e    $IBM_SE_CREDS_DIR/{rsa/,certs/,crls/,hkds/,hdr/hdr.bin}\u003c/span\u003e\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e    See deps/verifier/src/se/README.md for how to obtain the materials.\u003c/span\u003e\n\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e 2. Install, pointing the chart at the node and directory:\u003c/span\u003e\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  -f ./deployment/helm-chart/scenarios/ibm-se.yaml \\\n  --set as.verifier.se.credsDir=\u003cspan class=\"pl-smi\"\u003e$IBM_SE_CREDS_DIR\u003c/span\u003e \\\n  --set as.verifier.se.nodeName=\u003cspan class=\"pl-k\"\u003e\u0026lt;\u003c/span\u003eyour-s390x-node-name\u003cspan class=\"pl-k\"\u003e\u0026gt;\u003c/span\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eUse an \u003cstrong\u003es390x\u003c/strong\u003e AS image built with the \u003ccode\u003ese-verifier\u003c/code\u003e feature (\u003ccode\u003eas.image.repository\u003c/code\u003e / \u003ccode\u003eas.image.tag\u003c/code\u003e). See \u003cstrong\u003e\u003ccode\u003escenarios/ibm-se.yaml\u003c/code\u003e\u003c/strong\u003e for the full override. Set the SE attestation policy afterwards as documented in \u003ccode\u003edeps/verifier/src/se/README.md\u003c/code\u003e.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eAMD SEV-SNP offline VCEK store\u003c/h3\u003e\u003ca id=\"user-content-amd-sev-snp-offline-vcek-store\" class=\"anchor\" aria-label=\"Permalink: AMD SEV-SNP offline VCEK store\" href=\"#amd-sev-snp-offline-vcek-store\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eThe \u003cstrong\u003eSNP\u003c/strong\u003e verifier needs a \u003cstrong\u003eVCEK\u003c/strong\u003e certificate to validate an attestation report. By default it fetches one from \u003cstrong\u003eAMD KDS\u003c/strong\u003e, which requires outbound connectivity from the AS Pod. Air-gapped clusters can instead stage the certificates on the node and have the verifier read them locally.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eSet \u003cstrong\u003e\u003ccode\u003eas.verifier.snp.kdsStoreHostPath\u003c/code\u003e\u003c/strong\u003e to the directory on the node that holds the store, \u003cstrong\u003e\u003ccode\u003eas.verifier.snp.nodeName\u003c/code\u003e\u003c/strong\u003e to the name of that node, and add an \u003cstrong\u003e\u003ccode\u003eOfflineStore\u003c/code\u003e\u003c/strong\u003e entry to \u003cstrong\u003e\u003ccode\u003eas.verifier.snp.vcekSources\u003c/code\u003e\u003c/strong\u003e. The chart then creates a \u003ccode\u003elocal\u003c/code\u003e-type PV + PVC and mounts the directory at \u003ccode\u003e/opt/confidential-containers/attestation-service/kds-store\u003c/code\u003e on the AS Pod. The three values are required together: rendering fails if the store is mounted without an \u003ccode\u003eOfflineStore\u003c/code\u003e source, or an \u003ccode\u003eOfflineStore\u003c/code\u003e source is configured without the mount, so a misconfiguration cannot silently fall back to KDS.\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"# 1. Place the certificates under a directory on the target SNP node, laid out as\n#    $KDS_STORE/vcek/{hwid}/{tcb_prefix}_vcek.der  (preferred)\n#    $KDS_STORE/vcek/{hwid}/vcek.der               (fallback)\n\n# 2. Install, pointing the chart at the node and directory:\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set as.verifier.snp.kdsStoreHostPath=$KDS_STORE \\\n  --set as.verifier.snp.nodeName=\u0026lt;your-snp-node-name\u0026gt; \\\n  --set 'as.verifier.snp.vcekSources[0].type=OfflineStore'\"\u003e\u003cpre\u003e\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e 1. Place the certificates under a directory on the target SNP node, laid out as\u003c/span\u003e\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e    $KDS_STORE/vcek/{hwid}/{tcb_prefix}_vcek.der  (preferred)\u003c/span\u003e\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e    $KDS_STORE/vcek/{hwid}/vcek.der               (fallback)\u003c/span\u003e\n\n\u003cspan class=\"pl-c\"\u003e\u003cspan class=\"pl-c\"\u003e#\u003c/span\u003e 2. Install, pointing the chart at the node and directory:\u003c/span\u003e\nhelm upgrade --install trustee ./deployment/helm-chart \\\n  --namespace coco-trustee --create-namespace \\\n  --set as.verifier.snp.kdsStoreHostPath=\u003cspan class=\"pl-smi\"\u003e$KDS_STORE\u003c/span\u003e \\\n  --set as.verifier.snp.nodeName=\u003cspan class=\"pl-k\"\u003e\u0026lt;\u003c/span\u003eyour-snp-node-name\u003cspan class=\"pl-k\"\u003e\u0026gt;\u003c/span\u003e \\\n  --set \u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003eas.verifier.snp.vcekSources[0].type=OfflineStore\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e\u003c/span\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eSources are tried in the order given, so appending \u003ccode\u003e--set 'as.verifier.snp.vcekSources[1].type=KDS'\u003c/code\u003e keeps AMD KDS as a fallback for certificates that are missing locally. See \u003ca href=\"/confidential-containers/trustee/blob/main/attestation-service/docs/amd-offline-certificate-cache.md\"\u003ethe AMD offline certificate cache guide\u003c/a\u003e for how to build the \u003ccode\u003evcek/\u003c/code\u003e directory and when it has to be refreshed.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eTesting\u003c/h2\u003e\u003ca id=\"user-content-testing\" class=\"anchor\" aria-label=\"Permalink: Testing\" href=\"#testing\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003e\u003cstrong\u003eInspect resources\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl get deploy,pods,svc -n coco-trustee\nhelm status trustee -n coco-trustee\"\u003e\u003cpre\u003ekubectl get deploy,pods,svc -n coco-trustee\nhelm status trustee -n coco-trustee\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003e\u003cstrong\u003eRender-only check\u003c/strong\u003e (no install):\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"helm dependency update ./deployment/helm-chart\n\nhelm template trustee ./deployment/helm-chart \\\n  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml \\\n  --namespace coco-trustee \u0026gt; /tmp/trustee-render.yaml\"\u003e\u003cpre\u003ehelm dependency update ./deployment/helm-chart\n\nhelm template trustee ./deployment/helm-chart \\\n  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml \\\n  --namespace coco-trustee \u003cspan class=\"pl-k\"\u003e\u0026gt;\u003c/span\u003e /tmp/trustee-render.yaml\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eIf your cluster cannot resolve \u003ccode\u003e*.svc.cluster.local\u003c/code\u003e from Pods, set \u003ccode\u003ednsHostAliasWorkaround: true\u003c/code\u003e in your override values and then run \u003ccode\u003ehelm upgrade\u003c/code\u003e again after Services exist so Helm \u003ccode\u003elookup\u003c/code\u003e can resolve ClusterIPs.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003e\u003cstrong\u003ekbs-client\u003c/strong\u003e (build from the repo: \u003ccode\u003ecargo build -p kbs-client --release\u003c/code\u003e): with ephemeral keys, the hook-created Secret (name ends with \u003cstrong\u003e\u003ccode\u003ebootstrap-user-keys\u003c/code\u003e\u003c/strong\u003e) includes a pre-signed admin JWT under \u003cstrong\u003e\u003ccode\u003eKBS_ADMIN_TOKEN\u003c/code\u003e\u003c/strong\u003e. KBS expects \u003ccode\u003eauthorization_mode = \"AuthenticatedAuthorization\"\u003c/code\u003e with a bearer JWT that includes a \u003cstrong\u003e\u003ccode\u003erole\u003c/code\u003e\u003c/strong\u003e claim matching \u003ccode\u003e[admin.authorization.regex_acl]\u003c/code\u003e (default role \u003cstrong\u003e\u003ccode\u003eadmin\u003c/code\u003e\u003c/strong\u003e).\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080 \u0026amp;\nSECRET=$(kubectl get secrets -n coco-trustee -o name | grep bootstrap-user-keys | head -1 | cut -d/ -f2)\nkubectl get secret \u0026quot;$SECRET\u0026quot; -n coco-trustee -o jsonpath='{.data.KBS_ADMIN_TOKEN}' | base64 -d \u0026gt;/tmp/admin-token\nkbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource-policy --allow-all\"\u003e\u003cpre\u003ekubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080 \u003cspan class=\"pl-k\"\u003e\u0026amp;\u003c/span\u003e\nSECRET=\u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e$(\u003c/span\u003ekubectl get secrets -n coco-trustee -o name \u003cspan class=\"pl-k\"\u003e|\u003c/span\u003e grep bootstrap-user-keys \u003cspan class=\"pl-k\"\u003e|\u003c/span\u003e head -1 \u003cspan class=\"pl-k\"\u003e|\u003c/span\u003e cut -d/ -f2\u003cspan class=\"pl-pds\"\u003e)\u003c/span\u003e\u003c/span\u003e\nkubectl get secret \u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e\"\u003c/span\u003e\u003cspan class=\"pl-smi\"\u003e$SECRET\u003c/span\u003e\u003cspan class=\"pl-pds\"\u003e\"\u003c/span\u003e\u003c/span\u003e -n coco-trustee -o jsonpath=\u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e{.data.KBS_ADMIN_TOKEN}\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e\u003c/span\u003e \u003cspan class=\"pl-k\"\u003e|\u003c/span\u003e base64 -d \u003cspan class=\"pl-k\"\u003e\u0026gt;\u003c/span\u003e/tmp/admin-token\nkbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource-policy --allow-all\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eSet a confidential resource (\u003ccode\u003econfig\u003c/code\u003e + \u003ccode\u003e--admin-token-file\u003c/code\u003e, then \u003ccode\u003eset-resource\u003c/code\u003e):\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"echo 'demo-payload' \u0026gt;/tmp/demo-resource.txt\nkbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource \\\n  --path my_repo/resource_type/demo --resource-file /tmp/demo-resource.txt\"\u003e\u003cpre\u003e\u003cspan class=\"pl-c1\"\u003eecho\u003c/span\u003e \u003cspan class=\"pl-s\"\u003e\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003edemo-payload\u003cspan class=\"pl-pds\"\u003e'\u003c/span\u003e\u003c/span\u003e \u003cspan class=\"pl-k\"\u003e\u0026gt;\u003c/span\u003e/tmp/demo-resource.txt\nkbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource \\\n  --path my_repo/resource_type/demo --resource-file /tmp/demo-resource.txt\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eFetch a resource by KBS URI path (\u003ccode\u003eget-resource\u003c/code\u003e is a top-level subcommand; it follows the normal attestation / token flow for your client build and policy):\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kbs-client --url http://127.0.0.1:8080 get-resource --path my_repo/resource_type/demo\"\u003e\u003cpre\u003ekbs-client --url http://127.0.0.1:8080 get-resource --path my_repo/resource_type/demo\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eConfiguration\u003c/h2\u003e\u003ca id=\"user-content-configuration\" class=\"anchor\" aria-label=\"Permalink: Configuration\" href=\"#configuration\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eDefault \u003cstrong\u003e\u003ccode\u003evalues.yaml\u003c/code\u003e\u003c/strong\u003e is intentionally small. Fixed on-disk paths for \u003cstrong\u003eLocalFs\u003c/strong\u003e / \u003cstrong\u003eLocalJson\u003c/strong\u003e are defined in \u003cstrong\u003e\u003ccode\u003etemplates/_helpers.tpl\u003c/code\u003e\u003c/strong\u003e (not overridable via values). You can still merge extra keys with \u003ccode\u003e-f\u003c/code\u003e / \u003ccode\u003e--set\u003c/code\u003e (Helm merges arbitrary values).\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eValues\u003c/h2\u003e\u003ca id=\"user-content-values\" class=\"anchor\" aria-label=\"Permalink: Values\" href=\"#values\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cmarkdown-accessiblity-table\u003e\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eKey\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eDefault\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.affinity\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAffinity and anti-affinity scheduling rules for AS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.extraEnvVars\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra environment variables for the AS container (for example \u003ccode\u003eHTTP(S)_PROXY\u003c/code\u003e and \u003ccode\u003eNO_PROXY\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.image.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"Always\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAS container image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.image.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"ghcr.io/confidential-containers/staged-images/coco-as-grpc\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAS container image repository.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.image.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"latest\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAS container image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.imagePullSecrets\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOptional image pull secrets for private registries.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.nodeSelector\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNode label selection constraints for AS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.podAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra Pod annotations.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.podSecurityContext\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePod-level security context overrides.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.replicaCount\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e1\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNumber of Attestation Service Pod replicas.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"4\",\"memory\":\"4Gi\"},\"requests\":{\"cpu\":\"500m\",\"memory\":\"1Gi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eContainer CPU/memory requests and limits for AS.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.service.loadBalancerAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAnnotations applied when \u003ccode\u003eas.service.type\u003c/code\u003e is \u003ccode\u003eLoadBalancer\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.service.port\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e50004\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAS Service port.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.service.type\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"ClusterIP\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAS Service type (\u003ccode\u003eClusterIP\u003c/code\u003e or \u003ccode\u003eLoadBalancer\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.tolerations\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eTolerations for scheduling AS Pods onto tainted nodes.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.dcap.collateral_service\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"https://api.trustedservices.intel.com/sgx/certification/v4/\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eIntel DCAP collateral service URL. Required when \u003ccode\u003eas.verifier.dcap\u003c/code\u003e is configured.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.dcap.tcb_update_type\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"early\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eDCAP TCB update type (for example \u003ccode\u003eearly\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.nvidia.type\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"Local\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNVIDIA verifier type: \u003ccode\u003eLocal\u003c/code\u003e or \u003ccode\u003eRemote\u003c/code\u003e. When \u003ccode\u003eRemote\u003c/code\u003e, \u003ccode\u003everifierUrl\u003c/code\u003e must be set.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.nvidia.verifierUrl\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"https://nras.attestation.nvidia.com/v4/attest\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNRAS URL when \u003ccode\u003eas.verifier.nvidia.type\u003c/code\u003e is \u003ccode\u003eRemote\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.se.credsDir\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAbsolute path on the target node to the directory containing IBM SE attestation materials (\u003ccode\u003ersa/\u003c/code\u003e, \u003ccode\u003ecerts/\u003c/code\u003e, \u003ccode\u003ecrls/\u003c/code\u003e, \u003ccode\u003ehkds/\u003c/code\u003e, \u003ccode\u003ehdr/hdr.bin\u003c/code\u003e). When non-empty, the chart creates a \u003ccode\u003elocal\u003c/code\u003e-type PersistentVolume + PersistentVolumeClaim and mounts the directory at \u003ccode\u003e/run/confidential-containers/ibmse/\u003c/code\u003e on the AS Pod. Requires \u003ccode\u003eas.verifier.se.nodeName\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.se.nodeName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKubernetes node name where the IBM SE materials directory (\u003ccode\u003eas.verifier.se.credsDir\u003c/code\u003e) resides. Required when \u003ccode\u003eas.verifier.se.credsDir\u003c/code\u003e is set; used in the PersistentVolume \u003ccode\u003enodeAffinity\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.snp.kdsStoreHostPath\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAbsolute path on the target node to the directory containing the AMD SNP offline VCEK certificate store (must contain a \u003ccode\u003evcek/\u003c/code\u003e subdirectory). When non-empty, the chart creates a \u003ccode\u003elocal\u003c/code\u003e-type PV + PVC and mounts it at \u003ccode\u003e/opt/confidential-containers/attestation-service/kds-store\u003c/code\u003e on the AS Pod, which is where an \u003ccode\u003eOfflineStore\u003c/code\u003e entry in \u003ccode\u003eas.verifier.snp.vcekSources\u003c/code\u003e reads from. Requires \u003ccode\u003eas.verifier.snp.nodeName\u003c/code\u003e. See \u003ca href=\"/confidential-containers/trustee/blob/main/attestation-service/docs/amd-offline-certificate-cache.md\"\u003ethe offline certificate cache guide\u003c/a\u003e for the directory layout.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.snp.nodeName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKubernetes node name where the kds-store directory (\u003ccode\u003eas.verifier.snp.kdsStoreHostPath\u003c/code\u003e) resides. Required when \u003ccode\u003eas.verifier.snp.kdsStoreHostPath\u003c/code\u003e is set; used in the PV \u003ccode\u003enodeAffinity\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eas.verifier.snp.vcekSources\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eVCEK certificate sources for the SNP verifier, tried in the order given. When empty (the default), no \u003ccode\u003esnp_verifier\u003c/code\u003e block is emitted and the AS uses its built-in default (KDS). \u003ccode\u003eKDS\u003c/code\u003e fetches from AMD's Key Distribution Service and requires outbound connectivity. To configure an \u003ccode\u003eOfflineStore\u003c/code\u003e source, \u003ccode\u003eas.verifier.snp.nodeName\u003c/code\u003e and \u003ccode\u003eas.verifier.snp.kdsStoreHostPath\u003c/code\u003e must be provided as well, so the certificate store gets mounted into the AS Pod.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"keygenImage\":{\"pullPolicy\":\"IfNotPresent\",\"repository\":\"alpine/openssl\",\"tag\":\"3.5.6\"},\"kubectlImage\":{\"pullPolicy\":\"IfNotPresent\",\"repository\":\"quay.io/kata-containers/kubectl\",\"tag\":\"20260112\"},\"resources\":{\"limits\":{\"cpu\":\"200m\",\"memory\":\"256Mi\"},\"requests\":{\"cpu\":\"50m\",\"memory\":\"64Mi\"}}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBootstrap hook Job settings (pre-install/pre-upgrade key generation and post-delete cleanup when \u003ccode\u003esecrets.useEphemeralGeneratedKeys=true\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.keygenImage.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"IfNotPresent\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOpenSSL \u003ccode\u003einitContainer\u003c/code\u003e image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.keygenImage.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"alpine/openssl\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOpenSSL \u003ccode\u003einitContainer\u003c/code\u003e image repository that generates demo keys.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.keygenImage.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"3.5.6\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOpenSSL \u003ccode\u003einitContainer\u003c/code\u003e image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.kubectlImage.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"IfNotPresent\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ekubectl container image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.kubectlImage.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"quay.io/kata-containers/kubectl\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ekubectl container image repository that creates or updates the release-scoped Secret.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.kubectlImage.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"20260112\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ekubectl container image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ebootstrapUserKeysJob.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"200m\",\"memory\":\"256Mi\"},\"requests\":{\"cpu\":\"50m\",\"memory\":\"64Mi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eCPU/memory requests and limits for the bootstrap hook Job.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ednsHostAliasWorkaround\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eWhen \u003ccode\u003etrue\u003c/code\u003e, templates use Helm \u003ccode\u003elookup\u003c/code\u003e to write Service \u003ccode\u003eclusterIP\u003c/code\u003e entries into \u003ccode\u003ehostAliases\u003c/code\u003e for clusters that cannot resolve \u003ccode\u003e*.svc.cluster.local\u003c/code\u003e. If Services are missing on first render, rerun \u003ccode\u003ehelm upgrade\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003efullnameOverride\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOverride the fully qualified release name (truncated to 63 characters).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"annotations\":{},\"className\":\"\",\"enabled\":false,\"host\":\"\",\"tls\":[]}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOptional Kubernetes Ingress for the KBS Service.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress.annotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eIngress annotations.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress.className\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eIngressClass name.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable Ingress for KBS.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress.host\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eHost-based routing. Leave empty to match all hosts (IP-only access).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eingress.tls\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eTLS configuration entries.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.affinity\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAffinity and anti-affinity scheduling rules for KBS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.config.admin.audience\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"KBS\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eJWT \u003ccode\u003eaudience\u003c/code\u003e claim for the bootstrap-generated admin token.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.config.admin.issuer\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"TrusteeInHelm\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eJWT \u003ccode\u003eissuer\u003c/code\u003e claim for the bootstrap-generated admin token; must match \u003ccode\u003e[admin.authentication.bearer_jwt]\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.config.admin.role\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"admin\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eJWT \u003ccode\u003erole\u003c/code\u003e claim and matching \u003ccode\u003e[admin.authorization.regex_acl]\u003c/code\u003e role.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.config.attestationService.poolSize\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e200\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eConnection pool size for the KBS -\u0026gt; gRPC AS client (\u003ccode\u003epool_size\u003c/code\u003e in \u003ccode\u003efiles/kbs-config.toml.template\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.config.attestationService.timeout\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e30\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequest timeout in seconds for the KBS -\u0026gt; gRPC AS client (\u003ccode\u003etimeout\u003c/code\u003e in \u003ccode\u003efiles/kbs-config.toml.template\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.extraEnvVars\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra environment variables to inject into the KBS container.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.extraVolumeMounts\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra volume mounts for the KBS container.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.extraVolumes\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra volumes to attach to the KBS Pod.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.image.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"Always\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS container image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.image.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"ghcr.io/confidential-containers/staged-images/kbs-grpc-as\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS container image repository.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.image.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"latest\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS container image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.imagePullSecrets\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOptional image pull secrets for private registries.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.nodeSelector\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNode label selection constraints for KBS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.podAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra Pod annotations (for example Prometheus scrape or service mesh integration).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.podSecurityContext\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePod-level security context overrides.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.replicaCount\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e1\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNumber of KBS Pod replicas.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.resourceRepository\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS resource repository configuration (passed through to KBS config).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"2\",\"memory\":\"2Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eContainer CPU/memory requests and limits for KBS.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.service.exposeLoadBalancer\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eWhen \u003ccode\u003etrue\u003c/code\u003e, create an additional external \u003ccode\u003eLoadBalancer\u003c/code\u003e Service (\u003ccode\u003e\u0026lt;fullname\u0026gt;-kbs-lb\u003c/code\u003e). The primary KBS Service (\u003ccode\u003e\u0026lt;fullname\u0026gt;-kbs\u003c/code\u003e) is always internal \u003ccode\u003eClusterIP\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.service.loadBalancerAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAnnotations applied to the optional KBS \u003ccode\u003eLoadBalancer\u003c/code\u003e Service when \u003ccode\u003eexposeLoadBalancer=true\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.service.port\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e8080\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eService port for KBS; used by both the internal \u003ccode\u003eClusterIP\u003c/code\u003e Service and the optional external \u003ccode\u003eLoadBalancer\u003c/code\u003e Service.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.tls.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable native HTTPS on the KBS listener. Requires \u003ccode\u003esecretName\u003c/code\u003e; the chart does not generate endpoint identity material.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.tls.secretName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eSecret containing the KBS HTTPS private key and certificate chain. Required when \u003ccode\u003eenabled=true\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ekbs.tolerations\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eTolerations for scheduling KBS Pods onto tainted nodes.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003elog_level\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"info\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eContainer \u003ccode\u003eRUST_LOG\u003c/code\u003e for KBS, AS, and RVPS (\u003ccode\u003einfo\u003c/code\u003e, \u003ccode\u003edebug\u003c/code\u003e, \u003ccode\u003ewarn\u003c/code\u003e, \u003ccode\u003eerror\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003enameOverride\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOverride the chart name used in labels and resource names.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003enodePort\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"enabled\":false,\"port\":\"\"}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExpose the KBS Service via a NodePort.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003enodePort.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable a NodePort Service for KBS.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003enodePort.port\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eFixed NodePort number; empty assigns a random port from the NodePort range.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"auth\":{\"database\":\"trustee\",\"password\":\"trustee\",\"username\":\"trustee\"},\"enabled\":false,\"nameOverride\":\"postgres\",\"primary\":{\"initdb\":{\"scriptsConfigMap\":\"trustee-postgres-initdb\"},\"persistence\":{\"enabled\":true,\"existingClaim\":\"\",\"size\":\"8Gi\",\"storageClass\":\"\"},\"resources\":{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}},\"service\":{\"ports\":{\"postgresql\":5432}}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://artifacthub.io/packages/helm/bitnami/postgresql\" rel=\"nofollow\"\u003eBitnami PostgreSQL\u003c/a\u003e subchart. Set \u003ccode\u003eenabled: true\u003c/code\u003e when bundled Postgres is required (\u003ccode\u003estorageBackend.postgres.mode=internal\u003c/code\u003e and Postgres storage is needed; see \u003ccode\u003escenarios/postgres-backend.yaml\u003c/code\u003e). Additional subchart keys (image, metrics, replication, and so on) are supported; see upstream docs.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.auth.database\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"trustee\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Postgres database name (also used for the Trustee \u003ccode\u003ePOSTGRES_URL\u003c/code\u003e Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.auth.password\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"trustee\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Postgres password (also used for the Trustee \u003ccode\u003ePOSTGRES_URL\u003c/code\u003e Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.auth.username\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"trustee\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Postgres username (also used for the Trustee \u003ccode\u003ePOSTGRES_URL\u003c/code\u003e Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable the Bitnami PostgreSQL subchart. Must be \u003ccode\u003etrue\u003c/code\u003e when \u003ccode\u003estorageBackend.postgres.mode=internal\u003c/code\u003e and Postgres storage is required.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.nameOverride\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"postgres\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eSubchart service name override; release Service becomes \u003ccode\u003e{Helm release}-postgres\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.initdb.scriptsConfigMap\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"trustee-postgres-initdb\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eConfigMap wired to \u003ccode\u003efiles/postgres-initkv.sql\u003c/code\u003e via \u003ccode\u003etemplates/postgres-initdb-configmap.yaml\u003c/code\u003e (do not override unless you know what you are doing).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.persistence.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003etrue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable PVC-backed storage for bundled Postgres.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.persistence.existingClaim\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExisting PVC name to reuse for bundled Postgres.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.persistence.size\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"8Gi\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequested size for the auto-created bundled Postgres PVC (for example \u003ccode\u003e8Gi\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.persistence.storageClass\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eStorageClass for the auto-created bundled Postgres PVC; empty uses the cluster default.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.primary.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eCPU/memory requests and limits for bundled Postgres.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003epostgresql.service.ports.postgresql\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e5432\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Postgres Service port (used in \u003ccode\u003ePOSTGRES_URL\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.affinity\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAffinity and anti-affinity scheduling rules for RVPS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.extraEnvVars\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra environment variables for the RVPS container (for example \u003ccode\u003eHTTP(S)_PROXY\u003c/code\u003e and \u003ccode\u003eNO_PROXY\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.image.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"Always\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRVPS container image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.image.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"ghcr.io/confidential-containers/staged-images/rvps\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRVPS container image repository.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.image.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"latest\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRVPS container image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.imagePullSecrets\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eOptional image pull secrets for private registries.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.nodeSelector\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNode label selection constraints for RVPS Pods.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.podAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eExtra Pod annotations.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.podSecurityContext\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePod-level security context overrides.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.replicaCount\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e1\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eNumber of RVPS Pod replicas.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eContainer CPU/memory requests and limits for RVPS.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.service.loadBalancerAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAnnotations for the internal RVPS LoadBalancer Service.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.service.loadBalancerType\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"internal\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eLoad balancer kind when \u003ccode\u003ervps.service.type\u003c/code\u003e is \u003ccode\u003eLoadBalancer\u003c/code\u003e: \u003ccode\u003einternal\u003c/code\u003e or \u003ccode\u003epublic\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.service.port\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e50003\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRVPS Service port.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.service.publicLoadBalancerAnnotations\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eAnnotations for the public RVPS LoadBalancer Service when \u003ccode\u003eloadBalancerType=public\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.service.type\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"ClusterIP\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRVPS Service type (\u003ccode\u003eClusterIP\u003c/code\u003e or \u003ccode\u003eLoadBalancer\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ervps.tolerations\u003c/td\u003e\n\u003ctd\u003elist\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e[]\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eTolerations for scheduling RVPS Pods onto tainted nodes.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003esecrets.existingSecretName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequired when \u003ccode\u003euseEphemeralGeneratedKeys=false\u003c/code\u003e. Secret must contain \u003ccode\u003eKBS_ADMIN_PRIVATE_KEY\u003c/code\u003e, \u003ccode\u003eKBS_ADMIN_PUBKEY\u003c/code\u003e, \u003ccode\u003eAS_TOKEN_SIGNING_PRIVATE_KEY\u003c/code\u003e, and \u003ccode\u003eAS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN\u003c/code\u003e. Optionally include \u003ccode\u003eKBS_ADMIN_TOKEN\u003c/code\u003e (see \u003ccode\u003ekbs/config/docker-compose/setup.sh\u003c/code\u003e for claim layout).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003esecrets.useEphemeralGeneratedKeys\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003etrue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eWhen \u003ccode\u003etrue\u003c/code\u003e, a pre-install/pre-upgrade hook generates demo keys into a release-scoped Secret; when \u003ccode\u003efalse\u003c/code\u003e, you must pre-create a Secret and set \u003ccode\u003eexistingSecretName\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003esessionStorageType\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"Memory\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS protocol session store: \u003ccode\u003eMemory\u003c/code\u003e, \u003ccode\u003eLocalJson\u003c/code\u003e, \u003ccode\u003eLocalFs\u003c/code\u003e, \u003ccode\u003ePostgres\u003c/code\u003e, or \u003ccode\u003eRedis\u003c/code\u003e. When empty, follows \u003ccode\u003estorageBackend.type\u003c/code\u003e. \u003ccode\u003eRedis\u003c/code\u003e speaks the Redis protocol and is served by the bundled Valkey subchart (or an external Redis-compatible service).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"localFs\":{\"persistence\":{\"as\":\"\",\"kbs\":\"\",\"rvps\":\"\"}},\"localJson\":{\"persistence\":{\"as\":\"\",\"kbs\":\"\",\"rvps\":\"\"}},\"postgres\":{\"external\":{\"existingSecretKey\":\"\",\"existingSecretName\":\"\"},\"internal\":{\"initKvTables\":true},\"mode\":\"internal\"},\"redis\":{\"external\":{\"existingSecretKey\":\"\",\"existingSecretName\":\"\"},\"mode\":\"internal\"},\"type\":\"LocalFs\"}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eUnified KV backend for KBS, AS, and RVPS (same \u003ccode\u003estorage_type\u003c/code\u003e in each service config).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localFs.persistence.as\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for AS local storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localFs.persistence.kbs\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for KBS local storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localFs.persistence.rvps\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for RVPS local storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localJson.persistence.as\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for AS local JSON storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localJson.persistence.kbs\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for KBS local JSON storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.localJson.persistence.rvps\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePVC claim name for RVPS local JSON storage; empty uses \u003ccode\u003eemptyDir\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.postgres.external.existingSecretKey\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequired when \u003ccode\u003emode\u003c/code\u003e is \u003ccode\u003eexternal\u003c/code\u003e: Secret key name for the Postgres URL.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.postgres.external.existingSecretName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequired when \u003ccode\u003emode\u003c/code\u003e is \u003ccode\u003eexternal\u003c/code\u003e: Secret containing the Postgres URL.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.postgres.internal.initKvTables\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003etrue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eWhen \u003ccode\u003etrue\u003c/code\u003e, run KV table init SQL from \u003ccode\u003efiles/postgres-initkv.sql\u003c/code\u003e on first database init (via a chart-managed ConfigMap). When \u003ccode\u003efalse\u003c/code\u003e, also set \u003ccode\u003epostgresql.primary.initdb.scriptsConfigMap\u003c/code\u003e to \u003ccode\u003e\"\"\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.postgres.mode\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"internal\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003ePostgres source: \u003ccode\u003einternal\u003c/code\u003e (Bitnami subchart) or \u003ccode\u003eexternal\u003c/code\u003e (pre-created Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.redis.external.existingSecretKey\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequired when \u003ccode\u003emode\u003c/code\u003e is \u003ccode\u003eexternal\u003c/code\u003e: Secret key name for the Redis URL.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.redis.external.existingSecretName\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequired when \u003ccode\u003emode\u003c/code\u003e is \u003ccode\u003eexternal\u003c/code\u003e: Secret containing the Redis URL (e.g. \u003ccode\u003eredis://:password@redis.example.com:6379\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.redis.mode\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"internal\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRedis-protocol source: \u003ccode\u003einternal\u003c/code\u003e (Bitnami Valkey subchart) or \u003ccode\u003eexternal\u003c/code\u003e (pre-created Secret with a Redis URL).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003estorageBackend.type\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"LocalFs\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBackend type: \u003ccode\u003eLocalFs\u003c/code\u003e, \u003ccode\u003eLocalJson\u003c/code\u003e, \u003ccode\u003ePostgres\u003c/code\u003e, or \u003ccode\u003eMemory\u003c/code\u003e. When \u003ccode\u003ePostgres\u003c/code\u003e (or \u003ccode\u003esessionStorageType\u003c/code\u003e is \u003ccode\u003ePostgres\u003c/code\u003e), the chart injects \u003ccode\u003ePOSTGRES_URL\u003c/code\u003e. Only settings for the selected type take effect.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"architecture\":\"standalone\",\"auth\":{\"enabled\":true,\"password\":\"trustee\"},\"enabled\":false,\"image\":{\"pullPolicy\":\"IfNotPresent\",\"registry\":\"registry-1.docker.io\",\"repository\":\"bitnami/valkey\",\"tag\":\"latest\"},\"nameOverride\":\"valkey\",\"primary\":{\"persistence\":{\"enabled\":false},\"resources\":{\"limits\":{\"cpu\":\"1\",\"memory\":\"512Mi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}},\"service\":{\"ports\":{\"valkey\":6379}}}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://artifacthub.io/packages/helm/bitnami/valkey\" rel=\"nofollow\"\u003eBitnami Valkey\u003c/a\u003e subchart, a Redis-protocol-compatible store used for the KBS \u003ccode\u003eRedis\u003c/code\u003e session backend (Valkey is BSD-licensed; it replaces Redis, whose license is no longer OSI-approved). Set \u003ccode\u003eenabled: true\u003c/code\u003e when the bundled store is required (\u003ccode\u003estorageBackend.redis.mode=internal\u003c/code\u003e and \u003ccode\u003esessionStorageType\u003c/code\u003e or \u003ccode\u003estorageBackend.type\u003c/code\u003e is \u003ccode\u003eRedis\u003c/code\u003e; see \u003ccode\u003escenarios/valkey-sessions.yaml\u003c/code\u003e). Additional subchart keys (metrics, replication, TLS, and so on) are supported; see upstream docs.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.architecture\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"standalone\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eSingle Valkey primary; sessions do not need replicas. Set \u003ccode\u003ereplication\u003c/code\u003e plus \u003ccode\u003ereplica.*\u003c/code\u003e keys for HA (see upstream docs).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.auth.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003etrue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eRequire a password for the bundled Valkey (also used for the Trustee \u003ccode\u003eREDIS_URL\u003c/code\u003e Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.auth.password\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"trustee\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Valkey password (also used for the Trustee \u003ccode\u003eREDIS_URL\u003c/code\u003e Secret).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eEnable the Bitnami Valkey subchart. Must be \u003ccode\u003etrue\u003c/code\u003e when \u003ccode\u003estorageBackend.redis.mode=internal\u003c/code\u003e and Redis storage is required.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.image\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"pullPolicy\":\"IfNotPresent\",\"registry\":\"registry-1.docker.io\",\"repository\":\"bitnami/valkey\",\"tag\":\"latest\"}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Valkey container image. The default comes from \u003ccode\u003edocker.io\u003c/code\u003e, where anonymous pulls are rate-limited; point \u003ccode\u003eregistry\u003c/code\u003e/\u003ccode\u003erepository\u003c/code\u003e at a private mirror to avoid pull failures (a chart-wide \u003ccode\u003eglobal.imageRegistry\u003c/code\u003e is also honored by the subchart).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.image.pullPolicy\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"IfNotPresent\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eValkey image pull policy.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.image.registry\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"registry-1.docker.io\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eValkey image registry; override with a mirror to avoid docker.io rate limits.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.image.repository\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"bitnami/valkey\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eValkey image repository.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.image.tag\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"latest\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eValkey image tag.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.nameOverride\u003c/td\u003e\n\u003ctd\u003estring\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e\"valkey\"\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eSubchart name override; the primary Service becomes \u003ccode\u003e{Helm release}-valkey-primary\u003c/code\u003e.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.primary.persistence.enabled\u003c/td\u003e\n\u003ctd\u003ebool\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003efalse\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eKBS sessions are short-lived, so the bundled Valkey defaults to no PVC; set \u003ccode\u003etrue\u003c/code\u003e (plus optional \u003ccode\u003estorageClass\u003c/code\u003e/\u003ccode\u003esize\u003c/code\u003e) to persist sessions across Pod restarts.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.primary.resources\u003c/td\u003e\n\u003ctd\u003eobject\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e{\"limits\":{\"cpu\":\"1\",\"memory\":\"512Mi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}}\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eCPU/memory requests and limits for the bundled Valkey primary.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003evalkey.primary.service.ports.valkey\u003c/td\u003e\n\u003ctd\u003eint\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003e6379\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003eBundled Valkey Service port (used in \u003ccode\u003eREDIS_URL\u003c/code\u003e).\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\u003c/markdown-accessiblity-table\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eEnd-to-end test\u003c/h2\u003e\u003ca id=\"user-content-end-to-end-test\" class=\"anchor\" aria-label=\"Permalink: End-to-end test\" href=\"#end-to-end-test\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eProvision a \u003cstrong\u003ekind\u003c/strong\u003e cluster out of band, preload the Trustee images into it, point \u003ccode\u003ekubectl\u003c/code\u003e at it, then from the repository root:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"kind create cluster --name kind --wait 5m\nmake -C deployment/helm-chart load-e2e-images-into-kind\nmake test-helm-e2e\"\u003e\u003cpre\u003ekind create cluster --name kind --wait 5m\nmake -C deployment/helm-chart load-e2e-images-into-kind\nmake test-helm-e2e\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003e\u003ccode\u003emake e2e-test\u003c/code\u003e assumes \u003cstrong\u003eKBS / AS / RVPS\u003c/strong\u003e images are already loaded into the cluster and deploys with \u003ca href=\"/confidential-containers/trustee/blob/main/deployment/helm-chart/scenarios/e2e-local-images.yaml\"\u003escenarios/e2e-local-images.yaml\u003c/a\u003e. The Makefile injects image repositories, tags, and \u003ccode\u003epullPolicy: Never\u003c/code\u003e at install time so local runs and CI can use different preloaded image names without changing the scenario file.\u003c/p\u003e\n\u003cul dir=\"auto\"\u003e\n\u003cli\u003e\u003cstrong\u003eLocal preloaded images\u003c/strong\u003e: \u003ccode\u003etrustee-e2e/*:e2e\u003c/code\u003e, \u003ccode\u003epullPolicy: Never\u003c/code\u003e (not GHCR \u003ccode\u003e:latest\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCI images\u003c/strong\u003e: reuses \u003ccode\u003edocker-e2e-images-linux-amd64\u003c/code\u003e from \u003ccode\u003eworkflow-call-build-docker-e2e-materials.yml\u003c/code\u003e as \u003ccode\u003eghcr.io/confidential-containers/staged-images/*:latest\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eStorage\u003c/strong\u003e: bundled Postgres KV backend (\u003ccode\u003estorageBackend.type: Postgres\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKBS sessions\u003c/strong\u003e: bundled Valkey (\u003ccode\u003esessionStorageType: Redis\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKBS endpoint\u003c/strong\u003e: native HTTPS using an ephemeral, test-only certificate\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp dir=\"auto\"\u003eSteps:\u003c/p\u003e\n\u003col dir=\"auto\"\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ehelm-dependency-build\u003c/code\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ehelm-lint\u003c/code\u003e\u003c/strong\u003e — validates the default HTTP, e2e, and native-HTTPS configurations\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eprepare-e2e-tls\u003c/code\u003e\u003c/strong\u003e — creates a test Kubernetes TLS Secret\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003edeploy\u003c/code\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003etest-client\u003c/code\u003e\u003c/strong\u003e — \u003ca href=\"/confidential-containers/trustee/blob/main/deployment/helm-chart/e2e/test.sh\"\u003ee2e/test.sh\u003c/a\u003e validates the certificate and exercises KBS over HTTPS\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003edump-logs\u003c/code\u003e\u003c/strong\u003e — on failure only: pod status, events, describe, and container logs (current + previous), while the namespace still exists\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eundeploy\u003c/code\u003e\u003c/strong\u003e — always attempted, even after failures\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp dir=\"auto\"\u003eDebug individually:\u003c/p\u003e\n\u003cdiv class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"make -C deployment/helm-chart load-e2e-images-into-kind\nmake -C deployment/helm-chart helm-lint\nmake -C deployment/helm-chart prepare-e2e-tls\nmake -C deployment/helm-chart deploy\nmake -C deployment/helm-chart test-client\nmake -C deployment/helm-chart dump-logs\nmake -C deployment/helm-chart undeploy\"\u003e\u003cpre\u003emake -C deployment/helm-chart load-e2e-images-into-kind\nmake -C deployment/helm-chart helm-lint\nmake -C deployment/helm-chart prepare-e2e-tls\nmake -C deployment/helm-chart deploy\nmake -C deployment/helm-chart test-client\nmake -C deployment/helm-chart dump-logs\nmake -C deployment/helm-chart undeploy\u003c/pre\u003e\u003c/div\u003e\n\u003cp dir=\"auto\"\u003eOptional variables: \u003ccode\u003eE2E_IMAGE_PREFIX\u003c/code\u003e, \u003ccode\u003eE2E_IMAGE_TAG\u003c/code\u003e, \u003ccode\u003eKBS_CLIENT\u003c/code\u003e.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003eCI (\u003ccode\u003etest-e2e-kbs.yml\u003c/code\u003e) reuses the Docker Compose e2e image build workflow artifacts: it loads the pre-built Trustee images into kind and uses the pre-built \u003ccode\u003ekbs-client\u003c/code\u003e binary before running Helm e2e.\u003c/p\u003e\n\u003cp dir=\"auto\"\u003e\u003ccode\u003emake test-client\u003c/code\u003e alone does not build images or undeploy.\u003c/p\u003e\n\u003cdiv class=\"markdown-heading\" dir=\"auto\"\u003e\u003ch2 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\"\u003eDevelopment notes\u003c/h2\u003e\u003ca id=\"user-content-development-notes\" class=\"anchor\" aria-label=\"Permalink: Development notes\" href=\"#development-notes\"\u003e\u003csvg data-component=\"Octicon\" class=\"octicon octicon-link\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"\u003e\u003cpath d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\u003e\u003c/path\u003e\u003c/svg\u003e\u003c/a\u003e\u003c/div\u003e\n\u003col dir=\"auto\"\u003e\n\u003cli\u003eDo not change the files under \u003ca href=\"/confidential-containers/trustee/blob/main/deployment/helm-chart/files\"\u003efiles\u003c/a\u003e unless you are updating the corresponding Helm template logic. Service config is rendered from \u003ccode\u003e*.template\u003c/code\u003e files; Postgres KV init SQL lives in \u003ccode\u003efiles/postgres-initkv.sql\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAfter changing \u003ccode\u003eChart.yaml\u003c/code\u003e dependencies, run \u003ccode\u003ehelm dependency update ./deployment/helm-chart\u003c/code\u003e and commit \u003ccode\u003eChart.lock\u003c/code\u003e plus \u003ccode\u003echarts/\u003c/code\u003e if your packaging workflow vendors subcharts.\u003c/li\u003e\n\u003cli\u003eAfter changing \u003ccode\u003evalues.yaml\u003c/code\u003e comments or keys, regenerate this README from \u003ca href=\"/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md.gotmpl\"\u003eREADME.md.gotmpl\u003c/a\u003e: \u003ccode\u003ehelm-docs -c .\u003c/code\u003e (run from this directory).\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/article\u003e","richTextTruncated":false,"renderedFileInfo":null,"symbols":{"timed_out":false,"not_analyzed":false,"symbols":[{"name":"Trustee Helm Chart","fully_qualified_name":"Trustee Helm Chart","kind":"section_1","ident_start":2,"ident_end":20,"extent_start":0,"extent_end":39805,"ident_utf16":{"start":{"line_number":0,"utf16_col":2},"end":{"line_number":0,"utf16_col":20}},"extent_utf16":{"start":{"line_number":0,"utf16_col":0},"end":{"line_number":477,"utf16_col":0}}},{"name":"Install","fully_qualified_name":"Install","kind":"section_2","ident_start":477,"ident_end":484,"extent_start":474,"extent_end":1522,"ident_utf16":{"start":{"line_number":4,"utf16_col":3},"end":{"line_number":4,"utf16_col":10}},"extent_utf16":{"start":{"line_number":4,"utf16_col":0},"end":{"line_number":33,"utf16_col":0}}},{"name":"Typical scenarios","fully_qualified_name":"Typical scenarios","kind":"section_2","ident_start":1525,"ident_end":1542,"extent_start":1522,"extent_end":13973,"ident_utf16":{"start":{"line_number":33,"utf16_col":3},"end":{"line_number":33,"utf16_col":20}},"extent_utf16":{"start":{"line_number":33,"utf16_col":0},"end":{"line_number":241,"utf16_col":0}}},{"name":"Default: LocalFs storage","fully_qualified_name":"Default: LocalFs storage","kind":"section_3","ident_start":1548,"ident_end":1572,"extent_start":1544,"extent_end":1799,"ident_utf16":{"start":{"line_number":35,"utf16_col":4},"end":{"line_number":35,"utf16_col":28}},"extent_utf16":{"start":{"line_number":35,"utf16_col":0},"end":{"line_number":39,"utf16_col":0}}},{"name":"PostgreSQL as storage backend + in-memory KBS sessions","fully_qualified_name":"PostgreSQL as storage backend + in-memory KBS sessions","kind":"section_3","ident_start":1803,"ident_end":1857,"extent_start":1799,"extent_end":2369,"ident_utf16":{"start":{"line_number":39,"utf16_col":4},"end":{"line_number":39,"utf16_col":58}},"extent_utf16":{"start":{"line_number":39,"utf16_col":0},"end":{"line_number":51,"utf16_col":0}}},{"name":"External PostgreSQL","fully_qualified_name":"External PostgreSQL","kind":"section_3","ident_start":2373,"ident_end":2392,"extent_start":2369,"extent_end":3329,"ident_utf16":{"start":{"line_number":51,"utf16_col":4},"end":{"line_number":51,"utf16_col":23}},"extent_utf16":{"start":{"line_number":51,"utf16_col":0},"end":{"line_number":69,"utf16_col":0}}},{"name":"Valkey (Redis protocol) for KBS sessions","fully_qualified_name":"Valkey (Redis protocol) for KBS sessions","kind":"section_3","ident_start":3333,"ident_end":3373,"extent_start":3329,"extent_end":4826,"ident_utf16":{"start":{"line_number":69,"utf16_col":4},"end":{"line_number":69,"utf16_col":44}},"extent_utf16":{"start":{"line_number":69,"utf16_col":0},"end":{"line_number":95,"utf16_col":0}}},{"name":"External Redis-compatible service","fully_qualified_name":"External Redis-compatible service","kind":"section_3","ident_start":4830,"ident_end":4863,"extent_start":4826,"extent_end":5651,"ident_utf16":{"start":{"line_number":95,"utf16_col":4},"end":{"line_number":95,"utf16_col":37}},"extent_utf16":{"start":{"line_number":95,"utf16_col":0},"end":{"line_number":113,"utf16_col":0}}},{"name":"Bring your own keys (BYOK)","fully_qualified_name":"Bring your own keys (BYOK)","kind":"section_3","ident_start":5655,"ident_end":5681,"extent_start":5651,"extent_end":8150,"ident_utf16":{"start":{"line_number":113,"utf16_col":4},"end":{"line_number":113,"utf16_col":30}},"extent_utf16":{"start":{"line_number":113,"utf16_col":0},"end":{"line_number":155,"utf16_col":0}}},{"name":"Native KBS HTTPS","fully_qualified_name":"Native KBS HTTPS","kind":"section_3","ident_start":8154,"ident_end":8170,"extent_start":8150,"extent_end":9526,"ident_utf16":{"start":{"line_number":155,"utf16_col":4},"end":{"line_number":155,"utf16_col":20}},"extent_utf16":{"start":{"line_number":155,"utf16_col":0},"end":{"line_number":188,"utf16_col":0}}},{"name":"IBM Secure Execution (s390x)","fully_qualified_name":"IBM Secure Execution (s390x)","kind":"section_3","ident_start":9530,"ident_end":9558,"extent_start":9526,"extent_end":12126,"ident_utf16":{"start":{"line_number":188,"utf16_col":4},"end":{"line_number":188,"utf16_col":32}},"extent_utf16":{"start":{"line_number":188,"utf16_col":0},"end":{"line_number":220,"utf16_col":0}}},{"name":"AMD SEV-SNP offline VCEK store","fully_qualified_name":"AMD SEV-SNP offline VCEK store","kind":"section_3","ident_start":12130,"ident_end":12160,"extent_start":12126,"extent_end":13973,"ident_utf16":{"start":{"line_number":220,"utf16_col":4},"end":{"line_number":220,"utf16_col":34}},"extent_utf16":{"start":{"line_number":220,"utf16_col":0},"end":{"line_number":241,"utf16_col":0}}},{"name":"Testing","fully_qualified_name":"Testing","kind":"section_2","ident_start":13976,"ident_end":13983,"extent_start":13973,"extent_end":15980,"ident_utf16":{"start":{"line_number":241,"utf16_col":3},"end":{"line_number":241,"utf16_col":10}},"extent_utf16":{"start":{"line_number":241,"utf16_col":0},"end":{"line_number":285,"utf16_col":0}}},{"name":"Configuration","fully_qualified_name":"Configuration","kind":"section_2","ident_start":15983,"ident_end":15996,"extent_start":15980,"extent_end":16258,"ident_utf16":{"start":{"line_number":285,"utf16_col":3},"end":{"line_number":285,"utf16_col":16}},"extent_utf16":{"start":{"line_number":285,"utf16_col":0},"end":{"line_number":289,"utf16_col":0}}},{"name":"Values","fully_qualified_name":"Values","kind":"section_2","ident_start":16261,"ident_end":16267,"extent_start":16258,"extent_end":36900,"ident_utf16":{"start":{"line_number":289,"utf16_col":3},"end":{"line_number":289,"utf16_col":9}},"extent_utf16":{"start":{"line_number":289,"utf16_col":0},"end":{"line_number":426,"utf16_col":0}}},{"name":"End-to-end test","fully_qualified_name":"End-to-end test","kind":"section_2","ident_start":36903,"ident_end":36918,"extent_start":36900,"extent_end":39213,"ident_utf16":{"start":{"line_number":426,"utf16_col":3},"end":{"line_number":426,"utf16_col":18}},"extent_utf16":{"start":{"line_number":426,"utf16_col":0},"end":{"line_number":472,"utf16_col":0}}},{"name":"Development notes","fully_qualified_name":"Development notes","kind":"section_2","ident_start":39216,"ident_end":39233,"extent_start":39213,"extent_end":39805,"ident_utf16":{"start":{"line_number":472,"utf16_col":3},"end":{"line_number":472,"utf16_col":20}},"extent_utf16":{"start":{"line_number":472,"utf16_col":0},"end":{"line_number":477,"utf16_col":0}}}]}},"codeViewLayoutRoute":{"repo":{"id":485367944,"defaultBranch":"main","name":"trustee","ownerLogin":"confidential-containers","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2022-04-25T12:45:02.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/90701811?v=4","public":true,"private":false,"isOrgOwned":true,"isArchived":false},"currentUser":null,"uploadToken":"HsQZk7HB7bMzYZcp1zJc4VxXPhYJvRzQdFMCW0IQEY9XspqirwCrnG8XRbsvu39EbwIV_BKa9OS-W6MihFqHKQ","allShortcutsEnabled":false,"treeExpanded":true,"path":"deployment/helm-chart/README.md","symbolsExpanded":false,"refInfo":{"name":"main","listCacheKey":"v0:1791598245.0","canEdit":false,"currentOid":"ed8ab62f9325271d43cd812276621cf3d6e0ebd1"},"helpUrl":"https://docs.github.com","githubDevUrl":null},"codeViewFileTreeLayoutRoute":{"fileTree":{"deployment/helm-chart":{"items":[{"name":"e2e","path":"deployment/helm-chart/e2e","contentType":"directory"},{"name":"files","path":"deployment/helm-chart/files","contentType":"directory"},{"name":"scenarios","path":"deployment/helm-chart/scenarios","contentType":"directory"},{"name":"templates","path":"deployment/helm-chart/templates","contentType":"directory"},{"name":".helmignore","path":"deployment/helm-chart/.helmignore","contentType":"file"},{"name":"Chart.lock","path":"deployment/helm-chart/Chart.lock","contentType":"file"},{"name":"Chart.yaml","path":"deployment/helm-chart/Chart.yaml","contentType":"file"},{"name":"Makefile","path":"deployment/helm-chart/Makefile","contentType":"file"},{"name":"README.md","path":"deployment/helm-chart/README.md","contentType":"file"},{"name":"README.md.gotmpl","path":"deployment/helm-chart/README.md.gotmpl","contentType":"file"},{"name":"values.yaml","path":"deployment/helm-chart/values.yaml","contentType":"file"}],"totalCount":11},"deployment":{"items":[{"name":"helm-chart","path":"deployment/helm-chart","contentType":"directory"}],"totalCount":1},"":{"items":[{"name":".devcontainer","path":".devcontainer","contentType":"directory"},{"name":".github","path":".github","contentType":"directory"},{"name":"attestation-service","path":"attestation-service","contentType":"directory"},{"name":"deployment","path":"deployment","contentType":"directory"},{"name":"deps","path":"deps","contentType":"directory"},{"name":"docs","path":"docs","contentType":"directory"},{"name":"hack","path":"hack","contentType":"directory"},{"name":"integration-tests","path":"integration-tests","contentType":"directory"},{"name":"kbs","path":"kbs","contentType":"directory"},{"name":"protos","path":"protos","contentType":"directory"},{"name":"rvps","path":"rvps","contentType":"directory"},{"name":"tools","path":"tools","contentType":"directory"},{"name":".dockerignore","path":".dockerignore","contentType":"file"},{"name":".gitignore","path":".gitignore","contentType":"file"},{"name":".lycheeignore","path":".lycheeignore","contentType":"file"},{"name":"AGENTS.md","path":"AGENTS.md","contentType":"file"},{"name":"CODEOWNERS","path":"CODEOWNERS","contentType":"file"},{"name":"Cargo.lock","path":"Cargo.lock","contentType":"file"},{"name":"Cargo.toml","path":"Cargo.toml","contentType":"file"},{"name":"DEVELOPMENT.md","path":"DEVELOPMENT.md","contentType":"file"},{"name":"LICENSE","path":"LICENSE","contentType":"file"},{"name":"Makefile","path":"Makefile","contentType":"file"},{"name":"README.md","path":"README.md","contentType":"file"},{"name":"docker-compose.yml","path":"docker-compose.yml","contentType":"file"},{"name":"release-guide.md","path":"release-guide.md","contentType":"file"},{"name":"rust-toolchain.toml","path":"rust-toolchain.toml","contentType":"file"}],"totalCount":26}},"fileTreeProcessingTime":55.249941,"foldersToFetch":[]},"codeViewBlobLayoutRoute":{"codeLineWrapEnabled":false,"refInfo":{"name":"main","listCacheKey":"v0:1791598245.0","canEdit":false,"refType":"branch","currentOid":"ed8ab62f9325271d43cd812276621cf3d6e0ebd1","canEditOnDefaultBranch":false,"fileExistsOnDefault":true},"path":"deployment/helm-chart/README.md","blob":{"copilotSWEAgentEnabled":false,"dependabotInfo":{"showConfigurationBanner":false,"configFilePath":null,"networkDependabotPath":"/confidential-containers/trustee/network/updates","dismissConfigurationNoticePath":"/settings/dismiss-notice/dependabot_configuration_notice","configurationNoticeDismissed":null},"displayName":"README.md","displayUrl":"https://github.com/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md?raw=true","headerInfo":{"blobSize":"38.9 KB","deleteTooltip":"You must be signed in to make or propose changes","editTooltip":"You must be signed in to make or propose changes","ghDesktopPath":"https://desktop.github.com","isGitLfs":false,"onBranch":true,"shortPath":"1e4604e","siteNavLoginPath":"/login?return_to=https%3A%2F%2Fgithub.com%2Fconfidential-containers%2Ftrustee%2Fblob%2Fmain%2Fdeployment%2Fhelm-chart%2FREADME.md","isCSV":false,"isRichtext":true,"lineInfo":{"truncatedLoc":"477","truncatedSloc":"376"},"mode":"file"},"image":false,"isCodeownersFile":null,"isPlain":false,"isValidLegacyIssueTemplate":false,"isIssueTemplate":false,"isDiscussionTemplate":false,"language":"Markdown","languageID":222,"large":false,"planSupportInfo":{"repoIsFork":null,"repoOwnedByCurrentUser":null,"requestFullPath":"/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md","showFreeOrgGatedFeatureMessage":null,"showPlanSupportBanner":null,"upgradeDataAttributes":null,"upgradePath":null},"publishBannersInfo":{"dismissActionNoticePath":"/settings/dismiss-notice/publish_action_from_dockerfile","releasePath":"/confidential-containers/trustee/releases/new?marketplace=true","showPublishActionBanner":false},"rawBlobUrl":"https://github.com/confidential-containers/trustee/raw/refs/heads/main/deployment/helm-chart/README.md","renderImageOrRaw":false,"shortPath":null,"symbolsEnabled":true,"tabSize":4,"topBannersInfo":{"overridingGlobalFundingFile":false,"globalPreferredFundingPath":null,"showInvalidCitationWarning":false,"citationHelpUrl":"https://docs.github.com/github/creating-cloning-and-archiving-repositories/creating-a-repository-on-github/about-citation-files","actionsOnboardingTip":null},"truncated":false,"viewable":true,"workflowRedirectUrl":null},"copilotInfo":null,"copilotAccessAllowed":false,"copilotSpacesEnabled":false,"modelsAccessAllowed":false,"modelsRepoIntegrationEnabled":false,"isMarketplaceEnabled":true},"codeViewBlobLayoutRoute.StyledBlob":{"rawLines":["# Trustee Helm Chart","","Helm chart for [Confidential Containers](https://github.com/confidential-containers) **Trustee** on Kubernetes: **KBS**, **gRPC AS**, and **RVPS**, with optional bundled **PostgreSQL** ([Bitnami chart](https://artifacthub.io/packages/helm/bitnami/postgresql)) and **Valkey** ([Bitnami chart](https://artifacthub.io/packages/helm/bitnami/valkey), a Redis-protocol store for KBS sessions). KBS is wired to remote **`coco_as_grpc`** Attestation Service.","","## Install","","**Requirements**: Kubernetes 1.19+, Helm 3. If bundled Postgres is needed (when **`storageBackend.type: Postgres`** or **`sessionStorageType: Postgres`**), the Bitnami subchart uses PVC-backed storage, so your cluster must provide a usable **StorageClass** (or you must bind an existing claim).","","From the **repository root**:","","```bash","helm dependency update ./deployment/helm-chart","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace","```","","Wait for workloads, then port-forward KBS (default HTTP **8080**). The internal ClusterIP Service is **`\u003cHelm fullname\u003e-kbs`** (with the install command below, **`trustee-kbs`**):","","```bash","kubectl get pods -n coco-trustee -w","kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080","```","","Uninstall the release:","","```bash","helm uninstall trustee -n coco-trustee","```","","\u003e [!NOTE]","\u003e When `secrets.useEphemeralGeneratedKeys` is `true` (default), a **post-delete** Helm hook removes the release-scoped `*-bootstrap-user-keys` Secret automatically.","","## Typical scenarios","","### Default: LocalFs storage","","Same as **Install** above. If neither **`storageBackend.type`** nor **`sessionStorageType`** is **`Postgres`**, the chart does not deploy bundled Postgres; components use the default **`storageBackend`** (e.g. **LocalFs**).","","### PostgreSQL as storage backend + in-memory KBS sessions","","```bash","helm dependency update ./deployment/helm-chart","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml","```","","This enables the **Bitnami PostgreSQL** subchart (`postgresql.enabled: true`) and sets **`storageBackend.type: Postgres`**. KBS sessions stay in memory (`sessionStorageType: Memory`). Demo credentials default to `trustee` / `trustee` / `trustee` (override via `postgresql.auth.*`).","","### External PostgreSQL","","When an external Postgres service is used, set **`storageBackend.postgres.mode=external`**, pre-create a Secret with a **`POSTGRES_URL`** key, and point the chart at it:","","```bash","kubectl create secret generic trustee-external-postgres -n coco-trustee \\","  --from-literal=POSTGRES_URL='postgresql://user:password@postgres.example.com:5432/trustee?sslmode=require'","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  --set storageBackend.type=Postgres \\","  --set storageBackend.postgres.mode=external \\","  --set storageBackend.postgres.external.existingSecretName=trustee-external-postgres \\","  --set storageBackend.postgres.external.existingSecretKey=POSTGRES_URL","```","","When `storageBackend.postgres.mode=external`, the chart does **NOT** deploy the Bitnami subchart (`postgresql.enabled` stays `false`), even if Postgres is required by `storageBackend.type` or `sessionStorageType`.","","### Valkey (Redis protocol) for KBS sessions","","The KBS **`Redis`** session backend speaks the Redis wire protocol. The chart bundles **Valkey** (BSD-licensed) instead of Redis, whose license is no longer OSI-approved; any Redis-protocol-compatible service works. Storing sessions outside the KBS Pod allows running several KBS replicas.","","```bash","helm dependency update ./deployment/helm-chart","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml","```","","This enables the **Bitnami Valkey** subchart (`valkey.enabled: true`) and sets **`sessionStorageType: Redis`**. The chart writes the connection URL into a release-scoped Secret and injects it into KBS as **`REDIS_URL`**. The demo password defaults to `trustee` (override via `valkey.auth.password`). Sessions are short-lived, so the bundled Valkey runs `standalone` without a PVC by default (`valkey.primary.persistence.enabled: false`).","","The default Valkey image is pulled from **docker.io**, where anonymous pulls are rate-limited. Override the image source to use a private mirror:","","```bash","helm upgrade --install trustee ./deployment/helm-chart ... \\","  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml \\","  --set valkey.image.registry=mirror.example.com \\","  --set valkey.image.repository=bitnami/valkey \\","  --set valkey.image.tag=9.1.0","```","","(A chart-wide `global.imageRegistry` is also honored by the Bitnami subcharts.)","","### External Redis-compatible service","","When an external Redis-compatible service is used, set **`storageBackend.redis.mode=external`**, pre-create a Secret with the connection URL, and point the chart at it:","","```bash","kubectl create secret generic trustee-external-redis -n coco-trustee \\","  --from-literal=REDIS_URL='redis://:password@redis.example.com:6379'","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  --set sessionStorageType=Redis \\","  --set storageBackend.redis.mode=external \\","  --set storageBackend.redis.external.existingSecretName=trustee-external-redis \\","  --set storageBackend.redis.external.existingSecretKey=REDIS_URL","```","","When `storageBackend.redis.mode=external`, the chart does **NOT** deploy the Valkey subchart (`valkey.enabled` stays `false`).","","### Bring your own keys (BYOK)","","Key material is controlled only by **`secrets.useEphemeralGeneratedKeys`**:","","- **`true` (default):** a Helm **pre-install / pre-upgrade hook** Job generates ephemeral demo keys into a release-scoped Secret (name ends with **`bootstrap-user-keys`**). **`helm uninstall`** runs a **post-delete** hook that removes that Secret.","- **`false`:** you must **pre-create** a Kubernetes **`Secret`** in the target namespace, then set **`secrets.existingSecretName`** to that name. The bootstrap hook is **not** rendered.","","When ephemeral generation is enabled, the hook uses:","","- an `initContainer` (OpenSSL image) to generate keys into an `emptyDir`","- a `quay.io/kata-containers/kubectl` container to create the Secret from generated files","","Both images are overridable via `bootstrapUserKeysJob.keygenImage.*` and `bootstrapUserKeysJob.kubectlImage.*`.","","When ephemeral generation is disabled, the Secret must define these **data keys** (values are PEM text or base64-encoded PEM, same as any `kubectl create secret generic --from-file=...`):","","| Secret key | Role |","|------------|------|","| **`KBS_ADMIN_PRIVATE_KEY`** / **`KBS_ADMIN_PUBKEY`** | KBS admin API Ed25519 keypair (used to sign admin JWTs). |","| **`KBS_ADMIN_TOKEN`** | Pre-signed admin bearer JWT for `kbs-client --admin-token-file` (generated by the bootstrap hook when ephemeral keys are enabled). |","| **`AS_TOKEN_SIGNING_PRIVATE_KEY`** | Attestation Service: sign attestation tokens. |","| **`AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN`** | AS: `x5c` / cert chain; KBS: trust anchor for token verification. |","","The chart mounts that Secret on KBS and gRPC AS and **maps** those keys to in-container paths **`private.key`**, **`public.pub`**, **`token.key`**, **`token-cert-chain.pem`** under **`/opt/confidential-containers/kbs/user-keys`**.","","Example (create Secret, then install):","","```bash","kubectl create secret generic trustee-byok-keys -n coco-trustee \\","  --from-file=KBS_ADMIN_PRIVATE_KEY=./admin.key.pem \\","  --from-file=KBS_ADMIN_PUBKEY=./admin.pub.pem \\","  --from-file=AS_TOKEN_SIGNING_PRIVATE_KEY=./token.key.pem \\","  --from-file=AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN=./token-chain.pem","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  --set secrets.useEphemeralGeneratedKeys=false \\","  --set secrets.existingSecretName=trustee-byok-keys","```","","Or use **`scenarios/bring-your-own-keys.yaml`** (adjust Secret name / file paths in the comments there).","","### Native KBS HTTPS","","The default KBS listener uses plaintext HTTP. For a KBS endpoint that clients or","confidential guests reach directly, enable native HTTPS and provide an existing","Secret containing the endpoint private key and certificate chain. The chart does","not generate this identity material because its certificate SAN must match the","address used by KBS clients.","","```bash","kubectl create namespace coco-trustee","kubectl create secret tls trustee-kbs-tls \\","  --namespace coco-trustee \\","  --key ./kbs.key \\","  --cert ./kbs.crt","","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee \\","  -f ./deployment/helm-chart/scenarios/native-tls.yaml","```","","With `kbs.tls.enabled=true`, the chart leaves `insecure_http` at its secure","default (`false`), mounts the standard `tls.key` and `tls.crt` data keys from the","selected Kubernetes TLS Secret, and changes the KBS health probes to HTTPS.","","KBS does not reload endpoint identity material dynamically, so restart the KBS","Deployment after replacing the TLS Secret contents.","","Ingress TLS termination is a separate mode: leave native KBS TLS disabled and","configure `ingress.tls` when the Ingress controller should serve HTTPS and","forward plaintext HTTP to KBS. Do not combine native KBS TLS with Ingress unless","the chosen Ingress controller is explicitly configured to use HTTPS for its","backend connection.","","### IBM Secure Execution (s390x)","","On **s390x**, the **IBM Secure Execution (SE)** verifier needs attestation materials at runtime. Because KBS talks to a **remote `coco_as_grpc` AS**, the verifier runs inside the **AS Pod**, so these materials must be mounted on **AS**, not KBS. (This differs from the builtin-AS kustomize overlay in `kbs/config/kubernetes/overlays/ibm-se`, which mounts them on KBS.)","","The verifier reads materials from fixed paths under **`/run/confidential-containers/ibmse/`** (overridable via `SE_*` env vars; see `deps/verifier/src/se/README.md`). The chart mounts them from a **local node path** via a PersistentVolume / PersistentVolumeClaim — set **`as.verifier.se.credsDir`** to the directory on the node that contains the materials (equivalent to `IBM_SE_CREDS_DIR` used in the kustomize overlay), and **`as.verifier.se.nodeName`** to the name of that node.  The chart then creates a `local`-type PV + PVC and mounts the whole directory at `/run/confidential-containers/ibmse/` on the AS Pod.","","| Material | Expected path under `credsDir` | Notes |","|----------|-------------------------------|-------|","| RSA measurement key pair | `rsa/encrypt_key.{pem,pub}` | Private key is **sensitive** — restrict node access. |","| Signing / intermediate certs | `certs/` | **Directory**; all files are read. |","| CRLs | `crls/` | **Directory**; all files are read. |","| Host Key Documents (HKD) | `hkds/` | **Directory**; all files are read. |","| SE image header | `hdr/hdr.bin` | Binary file. |","| Root CA (optional) | `root_ca.crt` | Single file. |","","Set **`CERTS_OFFLINE_VERIFICATION=true`** (via `as.extraEnvVars`) to verify the HKD certificate chain offline. Do **not** set `SE_SKIP_CERTS_VERIFICATION=true` outside development — it disables HKD certificate chain verification.","","```bash","# 1. Place all materials under a directory on the target s390x node, e.g.:","#    $IBM_SE_CREDS_DIR/{rsa/,certs/,crls/,hkds/,hdr/hdr.bin}","#    See deps/verifier/src/se/README.md for how to obtain the materials.","","# 2. Install, pointing the chart at the node and directory:","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  -f ./deployment/helm-chart/scenarios/ibm-se.yaml \\","  --set as.verifier.se.credsDir=$IBM_SE_CREDS_DIR \\","  --set as.verifier.se.nodeName=\u003cyour-s390x-node-name\u003e","```","","Use an **s390x** AS image built with the `se-verifier` feature (`as.image.repository` / `as.image.tag`). See **`scenarios/ibm-se.yaml`** for the full override. Set the SE attestation policy afterwards as documented in `deps/verifier/src/se/README.md`.","","### AMD SEV-SNP offline VCEK store","","The **SNP** verifier needs a **VCEK** certificate to validate an attestation report. By default it fetches one from **AMD KDS**, which requires outbound connectivity from the AS Pod. Air-gapped clusters can instead stage the certificates on the node and have the verifier read them locally.","","Set **`as.verifier.snp.kdsStoreHostPath`** to the directory on the node that holds the store, **`as.verifier.snp.nodeName`** to the name of that node, and add an **`OfflineStore`** entry to **`as.verifier.snp.vcekSources`**. The chart then creates a `local`-type PV + PVC and mounts the directory at `/opt/confidential-containers/attestation-service/kds-store` on the AS Pod. The three values are required together: rendering fails if the store is mounted without an `OfflineStore` source, or an `OfflineStore` source is configured without the mount, so a misconfiguration cannot silently fall back to KDS.","","```bash","# 1. Place the certificates under a directory on the target SNP node, laid out as","#    $KDS_STORE/vcek/{hwid}/{tcb_prefix}_vcek.der  (preferred)","#    $KDS_STORE/vcek/{hwid}/vcek.der               (fallback)","","# 2. Install, pointing the chart at the node and directory:","helm upgrade --install trustee ./deployment/helm-chart \\","  --namespace coco-trustee --create-namespace \\","  --set as.verifier.snp.kdsStoreHostPath=$KDS_STORE \\","  --set as.verifier.snp.nodeName=\u003cyour-snp-node-name\u003e \\","  --set 'as.verifier.snp.vcekSources[0].type=OfflineStore'","```","","Sources are tried in the order given, so appending `--set 'as.verifier.snp.vcekSources[1].type=KDS'` keeps AMD KDS as a fallback for certificates that are missing locally. See [the AMD offline certificate cache guide](../../attestation-service/docs/amd-offline-certificate-cache.md) for how to build the `vcek/` directory and when it has to be refreshed.","","## Testing","","**Inspect resources**:","","```bash","kubectl get deploy,pods,svc -n coco-trustee","helm status trustee -n coco-trustee","```","","**Render-only check** (no install):","","```bash","helm dependency update ./deployment/helm-chart","","helm template trustee ./deployment/helm-chart \\","  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml \\","  --namespace coco-trustee \u003e /tmp/trustee-render.yaml","```","","If your cluster cannot resolve `*.svc.cluster.local` from Pods, set `dnsHostAliasWorkaround: true` in your override values and then run `helm upgrade` again after Services exist so Helm `lookup` can resolve ClusterIPs.","","**kbs-client** (build from the repo: `cargo build -p kbs-client --release`): with ephemeral keys, the hook-created Secret (name ends with **`bootstrap-user-keys`**) includes a pre-signed admin JWT under **`KBS_ADMIN_TOKEN`**. KBS expects `authorization_mode = \"AuthenticatedAuthorization\"` with a bearer JWT that includes a **`role`** claim matching `[admin.authorization.regex_acl]` (default role **`admin`**).","","```bash","kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080 \u0026","SECRET=$(kubectl get secrets -n coco-trustee -o name | grep bootstrap-user-keys | head -1 | cut -d/ -f2)","kubectl get secret \"$SECRET\" -n coco-trustee -o jsonpath='{.data.KBS_ADMIN_TOKEN}' | base64 -d \u003e/tmp/admin-token","kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource-policy --allow-all","```","","Set a confidential resource (`config` + `--admin-token-file`, then `set-resource`):","","```bash","echo 'demo-payload' \u003e/tmp/demo-resource.txt","kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource \\","  --path my_repo/resource_type/demo --resource-file /tmp/demo-resource.txt","```","","Fetch a resource by KBS URI path (`get-resource` is a top-level subcommand; it follows the normal attestation / token flow for your client build and policy):","","```bash","kbs-client --url http://127.0.0.1:8080 get-resource --path my_repo/resource_type/demo","```","","## Configuration","","Default **`values.yaml`** is intentionally small. Fixed on-disk paths for **LocalFs** / **LocalJson** are defined in **`templates/_helpers.tpl`** (not overridable via values). You can still merge extra keys with `-f` / `--set` (Helm merges arbitrary values).","","## Values","","| Key | Type | Default | Description |","|-----|------|---------|-------------|","| as.affinity | object | `{}` | Affinity and anti-affinity scheduling rules for AS Pods. |","| as.extraEnvVars | list | `[]` | Extra environment variables for the AS container (for example `HTTP(S)_PROXY` and `NO_PROXY`). |","| as.image.pullPolicy | string | `\"Always\"` | AS container image pull policy. |","| as.image.repository | string | `\"ghcr.io/confidential-containers/staged-images/coco-as-grpc\"` | AS container image repository. |","| as.image.tag | string | `\"latest\"` | AS container image tag. |","| as.imagePullSecrets | list | `[]` | Optional image pull secrets for private registries. |","| as.nodeSelector | object | `{}` | Node label selection constraints for AS Pods. |","| as.podAnnotations | object | `{}` | Extra Pod annotations. |","| as.podSecurityContext | object | `{}` | Pod-level security context overrides. |","| as.replicaCount | int | `1` | Number of Attestation Service Pod replicas. |","| as.resources | object | `{\"limits\":{\"cpu\":\"4\",\"memory\":\"4Gi\"},\"requests\":{\"cpu\":\"500m\",\"memory\":\"1Gi\"}}` | Container CPU/memory requests and limits for AS. |","| as.service.loadBalancerAnnotations | object | `{}` | Annotations applied when `as.service.type` is `LoadBalancer`. |","| as.service.port | int | `50004` | AS Service port. |","| as.service.type | string | `\"ClusterIP\"` | AS Service type (`ClusterIP` or `LoadBalancer`). |","| as.tolerations | list | `[]` | Tolerations for scheduling AS Pods onto tainted nodes. |","| as.verifier.dcap.collateral_service | string | `\"https://api.trustedservices.intel.com/sgx/certification/v4/\"` | Intel DCAP collateral service URL. Required when `as.verifier.dcap` is configured. |","| as.verifier.dcap.tcb_update_type | string | `\"early\"` | DCAP TCB update type (for example `early`). |","| as.verifier.nvidia.type | string | `\"Local\"` | NVIDIA verifier type: `Local` or `Remote`. When `Remote`, `verifierUrl` must be set. |","| as.verifier.nvidia.verifierUrl | string | `\"https://nras.attestation.nvidia.com/v4/attest\"` | NRAS URL when `as.verifier.nvidia.type` is `Remote`. |","| as.verifier.se.credsDir | string | `\"\"` | Absolute path on the target node to the directory containing IBM SE attestation materials (`rsa/`, `certs/`, `crls/`, `hkds/`, `hdr/hdr.bin`). When non-empty, the chart creates a `local`-type PersistentVolume + PersistentVolumeClaim and mounts the directory at `/run/confidential-containers/ibmse/` on the AS Pod. Requires `as.verifier.se.nodeName`. |","| as.verifier.se.nodeName | string | `\"\"` | Kubernetes node name where the IBM SE materials directory (`as.verifier.se.credsDir`) resides. Required when `as.verifier.se.credsDir` is set; used in the PersistentVolume `nodeAffinity`. |","| as.verifier.snp.kdsStoreHostPath | string | `\"\"` | Absolute path on the target node to the directory containing the AMD SNP offline VCEK certificate store (must contain a `vcek/` subdirectory). When non-empty, the chart creates a `local`-type PV + PVC and mounts it at `/opt/confidential-containers/attestation-service/kds-store` on the AS Pod, which is where an `OfflineStore` entry in `as.verifier.snp.vcekSources` reads from. Requires `as.verifier.snp.nodeName`. See [the offline certificate cache guide](../../attestation-service/docs/amd-offline-certificate-cache.md) for the directory layout. |","| as.verifier.snp.nodeName | string | `\"\"` | Kubernetes node name where the kds-store directory (`as.verifier.snp.kdsStoreHostPath`) resides. Required when `as.verifier.snp.kdsStoreHostPath` is set; used in the PV `nodeAffinity`. |","| as.verifier.snp.vcekSources | list | `[]` | VCEK certificate sources for the SNP verifier, tried in the order given. When empty (the default), no `snp_verifier` block is emitted and the AS uses its built-in default (KDS). `KDS` fetches from AMD's Key Distribution Service and requires outbound connectivity. To configure an `OfflineStore` source, `as.verifier.snp.nodeName` and `as.verifier.snp.kdsStoreHostPath` must be provided as well, so the certificate store gets mounted into the AS Pod. |","| bootstrapUserKeysJob | object | `{\"keygenImage\":{\"pullPolicy\":\"IfNotPresent\",\"repository\":\"alpine/openssl\",\"tag\":\"3.5.6\"},\"kubectlImage\":{\"pullPolicy\":\"IfNotPresent\",\"repository\":\"quay.io/kata-containers/kubectl\",\"tag\":\"20260112\"},\"resources\":{\"limits\":{\"cpu\":\"200m\",\"memory\":\"256Mi\"},\"requests\":{\"cpu\":\"50m\",\"memory\":\"64Mi\"}}}` | Bootstrap hook Job settings (pre-install/pre-upgrade key generation and post-delete cleanup when `secrets.useEphemeralGeneratedKeys=true`). |","| bootstrapUserKeysJob.keygenImage.pullPolicy | string | `\"IfNotPresent\"` | OpenSSL `initContainer` image pull policy. |","| bootstrapUserKeysJob.keygenImage.repository | string | `\"alpine/openssl\"` | OpenSSL `initContainer` image repository that generates demo keys. |","| bootstrapUserKeysJob.keygenImage.tag | string | `\"3.5.6\"` | OpenSSL `initContainer` image tag. |","| bootstrapUserKeysJob.kubectlImage.pullPolicy | string | `\"IfNotPresent\"` | kubectl container image pull policy. |","| bootstrapUserKeysJob.kubectlImage.repository | string | `\"quay.io/kata-containers/kubectl\"` | kubectl container image repository that creates or updates the release-scoped Secret. |","| bootstrapUserKeysJob.kubectlImage.tag | string | `\"20260112\"` | kubectl container image tag. |","| bootstrapUserKeysJob.resources | object | `{\"limits\":{\"cpu\":\"200m\",\"memory\":\"256Mi\"},\"requests\":{\"cpu\":\"50m\",\"memory\":\"64Mi\"}}` | CPU/memory requests and limits for the bootstrap hook Job. |","| dnsHostAliasWorkaround | bool | `false` | When `true`, templates use Helm `lookup` to write Service `clusterIP` entries into `hostAliases` for clusters that cannot resolve `*.svc.cluster.local`. If Services are missing on first render, rerun `helm upgrade`. |","| fullnameOverride | string | `\"\"` | Override the fully qualified release name (truncated to 63 characters). |","| ingress | object | `{\"annotations\":{},\"className\":\"\",\"enabled\":false,\"host\":\"\",\"tls\":[]}` | Optional Kubernetes Ingress for the KBS Service. |","| ingress.annotations | object | `{}` | Ingress annotations. |","| ingress.className | string | `\"\"` | IngressClass name. |","| ingress.enabled | bool | `false` | Enable Ingress for KBS. |","| ingress.host | string | `\"\"` | Host-based routing. Leave empty to match all hosts (IP-only access). |","| ingress.tls | list | `[]` | TLS configuration entries. |","| kbs.affinity | object | `{}` | Affinity and anti-affinity scheduling rules for KBS Pods. |","| kbs.config.admin.audience | string | `\"KBS\"` | JWT `audience` claim for the bootstrap-generated admin token. |","| kbs.config.admin.issuer | string | `\"TrusteeInHelm\"` | JWT `issuer` claim for the bootstrap-generated admin token; must match `[admin.authentication.bearer_jwt]`. |","| kbs.config.admin.role | string | `\"admin\"` | JWT `role` claim and matching `[admin.authorization.regex_acl]` role. |","| kbs.config.attestationService.poolSize | int | `200` | Connection pool size for the KBS -\u003e gRPC AS client (`pool_size` in `files/kbs-config.toml.template`). |","| kbs.config.attestationService.timeout | int | `30` | Request timeout in seconds for the KBS -\u003e gRPC AS client (`timeout` in `files/kbs-config.toml.template`). |","| kbs.extraEnvVars | list | `[]` | Extra environment variables to inject into the KBS container. |","| kbs.extraVolumeMounts | list | `[]` | Extra volume mounts for the KBS container. |","| kbs.extraVolumes | list | `[]` | Extra volumes to attach to the KBS Pod. |","| kbs.image.pullPolicy | string | `\"Always\"` | KBS container image pull policy. |","| kbs.image.repository | string | `\"ghcr.io/confidential-containers/staged-images/kbs-grpc-as\"` | KBS container image repository. |","| kbs.image.tag | string | `\"latest\"` | KBS container image tag. |","| kbs.imagePullSecrets | list | `[]` | Optional image pull secrets for private registries. |","| kbs.nodeSelector | object | `{}` | Node label selection constraints for KBS Pods. |","| kbs.podAnnotations | object | `{}` | Extra Pod annotations (for example Prometheus scrape or service mesh integration). |","| kbs.podSecurityContext | object | `{}` | Pod-level security context overrides. |","| kbs.replicaCount | int | `1` | Number of KBS Pod replicas. |","| kbs.resourceRepository | list | `[]` | KBS resource repository configuration (passed through to KBS config). |","| kbs.resources | object | `{\"limits\":{\"cpu\":\"2\",\"memory\":\"2Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}` | Container CPU/memory requests and limits for KBS. |","| kbs.service.exposeLoadBalancer | bool | `false` | When `true`, create an additional external `LoadBalancer` Service (`\u003cfullname\u003e-kbs-lb`). The primary KBS Service (`\u003cfullname\u003e-kbs`) is always internal `ClusterIP`. |","| kbs.service.loadBalancerAnnotations | object | `{}` | Annotations applied to the optional KBS `LoadBalancer` Service when `exposeLoadBalancer=true`. |","| kbs.service.port | int | `8080` | Service port for KBS; used by both the internal `ClusterIP` Service and the optional external `LoadBalancer` Service. |","| kbs.tls.enabled | bool | `false` | Enable native HTTPS on the KBS listener. Requires `secretName`; the chart does not generate endpoint identity material. |","| kbs.tls.secretName | string | `\"\"` | Secret containing the KBS HTTPS private key and certificate chain. Required when `enabled=true`. |","| kbs.tolerations | list | `[]` | Tolerations for scheduling KBS Pods onto tainted nodes. |","| log_level | string | `\"info\"` | Container `RUST_LOG` for KBS, AS, and RVPS (`info`, `debug`, `warn`, `error`). |","| nameOverride | string | `\"\"` | Override the chart name used in labels and resource names. |","| nodePort | object | `{\"enabled\":false,\"port\":\"\"}` | Expose the KBS Service via a NodePort. |","| nodePort.enabled | bool | `false` | Enable a NodePort Service for KBS. |","| nodePort.port | string | `\"\"` | Fixed NodePort number; empty assigns a random port from the NodePort range. |","| postgresql | object | `{\"auth\":{\"database\":\"trustee\",\"password\":\"trustee\",\"username\":\"trustee\"},\"enabled\":false,\"nameOverride\":\"postgres\",\"primary\":{\"initdb\":{\"scriptsConfigMap\":\"trustee-postgres-initdb\"},\"persistence\":{\"enabled\":true,\"existingClaim\":\"\",\"size\":\"8Gi\",\"storageClass\":\"\"},\"resources\":{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}},\"service\":{\"ports\":{\"postgresql\":5432}}}` | [Bitnami PostgreSQL](https://artifacthub.io/packages/helm/bitnami/postgresql) subchart. Set `enabled: true` when bundled Postgres is required (`storageBackend.postgres.mode=internal` and Postgres storage is needed; see `scenarios/postgres-backend.yaml`). Additional subchart keys (image, metrics, replication, and so on) are supported; see upstream docs. |","| postgresql.auth.database | string | `\"trustee\"` | Bundled Postgres database name (also used for the Trustee `POSTGRES_URL` Secret). |","| postgresql.auth.password | string | `\"trustee\"` | Bundled Postgres password (also used for the Trustee `POSTGRES_URL` Secret). |","| postgresql.auth.username | string | `\"trustee\"` | Bundled Postgres username (also used for the Trustee `POSTGRES_URL` Secret). |","| postgresql.enabled | bool | `false` | Enable the Bitnami PostgreSQL subchart. Must be `true` when `storageBackend.postgres.mode=internal` and Postgres storage is required. |","| postgresql.nameOverride | string | `\"postgres\"` | Subchart service name override; release Service becomes `{Helm release}-postgres`. |","| postgresql.primary.initdb.scriptsConfigMap | string | `\"trustee-postgres-initdb\"` | ConfigMap wired to `files/postgres-initkv.sql` via `templates/postgres-initdb-configmap.yaml` (do not override unless you know what you are doing). |","| postgresql.primary.persistence.enabled | bool | `true` | Enable PVC-backed storage for bundled Postgres. |","| postgresql.primary.persistence.existingClaim | string | `\"\"` | Existing PVC name to reuse for bundled Postgres. |","| postgresql.primary.persistence.size | string | `\"8Gi\"` | Requested size for the auto-created bundled Postgres PVC (for example `8Gi`). |","| postgresql.primary.persistence.storageClass | string | `\"\"` | StorageClass for the auto-created bundled Postgres PVC; empty uses the cluster default. |","| postgresql.primary.resources | object | `{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"250m\",\"memory\":\"256Mi\"}}` | CPU/memory requests and limits for bundled Postgres. |","| postgresql.service.ports.postgresql | int | `5432` | Bundled Postgres Service port (used in `POSTGRES_URL`). |","| rvps.affinity | object | `{}` | Affinity and anti-affinity scheduling rules for RVPS Pods. |","| rvps.extraEnvVars | list | `[]` | Extra environment variables for the RVPS container (for example `HTTP(S)_PROXY` and `NO_PROXY`). |","| rvps.image.pullPolicy | string | `\"Always\"` | RVPS container image pull policy. |","| rvps.image.repository | string | `\"ghcr.io/confidential-containers/staged-images/rvps\"` | RVPS container image repository. |","| rvps.image.tag | string | `\"latest\"` | RVPS container image tag. |","| rvps.imagePullSecrets | list | `[]` | Optional image pull secrets for private registries. |","| rvps.nodeSelector | object | `{}` | Node label selection constraints for RVPS Pods. |","| rvps.podAnnotations | object | `{}` | Extra Pod annotations. |","| rvps.podSecurityContext | object | `{}` | Pod-level security context overrides. |","| rvps.replicaCount | int | `1` | Number of RVPS Pod replicas. |","| rvps.resources | object | `{\"limits\":{\"cpu\":\"1\",\"memory\":\"1Gi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}}` | Container CPU/memory requests and limits for RVPS. |","| rvps.service.loadBalancerAnnotations | object | `{}` | Annotations for the internal RVPS LoadBalancer Service. |","| rvps.service.loadBalancerType | string | `\"internal\"` | Load balancer kind when `rvps.service.type` is `LoadBalancer`: `internal` or `public`. |","| rvps.service.port | int | `50003` | RVPS Service port. |","| rvps.service.publicLoadBalancerAnnotations | object | `{}` | Annotations for the public RVPS LoadBalancer Service when `loadBalancerType=public`. |","| rvps.service.type | string | `\"ClusterIP\"` | RVPS Service type (`ClusterIP` or `LoadBalancer`). |","| rvps.tolerations | list | `[]` | Tolerations for scheduling RVPS Pods onto tainted nodes. |","| secrets.existingSecretName | string | `\"\"` | Required when `useEphemeralGeneratedKeys=false`. Secret must contain `KBS_ADMIN_PRIVATE_KEY`, `KBS_ADMIN_PUBKEY`, `AS_TOKEN_SIGNING_PRIVATE_KEY`, and `AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN`. Optionally include `KBS_ADMIN_TOKEN` (see `kbs/config/docker-compose/setup.sh` for claim layout). |","| secrets.useEphemeralGeneratedKeys | bool | `true` | When `true`, a pre-install/pre-upgrade hook generates demo keys into a release-scoped Secret; when `false`, you must pre-create a Secret and set `existingSecretName`. |","| sessionStorageType | string | `\"Memory\"` | KBS protocol session store: `Memory`, `LocalJson`, `LocalFs`, `Postgres`, or `Redis`. When empty, follows `storageBackend.type`. `Redis` speaks the Redis protocol and is served by the bundled Valkey subchart (or an external Redis-compatible service). |","| storageBackend | object | `{\"localFs\":{\"persistence\":{\"as\":\"\",\"kbs\":\"\",\"rvps\":\"\"}},\"localJson\":{\"persistence\":{\"as\":\"\",\"kbs\":\"\",\"rvps\":\"\"}},\"postgres\":{\"external\":{\"existingSecretKey\":\"\",\"existingSecretName\":\"\"},\"internal\":{\"initKvTables\":true},\"mode\":\"internal\"},\"redis\":{\"external\":{\"existingSecretKey\":\"\",\"existingSecretName\":\"\"},\"mode\":\"internal\"},\"type\":\"LocalFs\"}` | Unified KV backend for KBS, AS, and RVPS (same `storage_type` in each service config). |","| storageBackend.localFs.persistence.as | string | `\"\"` | PVC claim name for AS local storage; empty uses `emptyDir`. |","| storageBackend.localFs.persistence.kbs | string | `\"\"` | PVC claim name for KBS local storage; empty uses `emptyDir`. |","| storageBackend.localFs.persistence.rvps | string | `\"\"` | PVC claim name for RVPS local storage; empty uses `emptyDir`. |","| storageBackend.localJson.persistence.as | string | `\"\"` | PVC claim name for AS local JSON storage; empty uses `emptyDir`. |","| storageBackend.localJson.persistence.kbs | string | `\"\"` | PVC claim name for KBS local JSON storage; empty uses `emptyDir`. |","| storageBackend.localJson.persistence.rvps | string | `\"\"` | PVC claim name for RVPS local JSON storage; empty uses `emptyDir`. |","| storageBackend.postgres.external.existingSecretKey | string | `\"\"` | Required when `mode` is `external`: Secret key name for the Postgres URL. |","| storageBackend.postgres.external.existingSecretName | string | `\"\"` | Required when `mode` is `external`: Secret containing the Postgres URL. |","| storageBackend.postgres.internal.initKvTables | bool | `true` | When `true`, run KV table init SQL from `files/postgres-initkv.sql` on first database init (via a chart-managed ConfigMap). When `false`, also set `postgresql.primary.initdb.scriptsConfigMap` to `\"\"`. |","| storageBackend.postgres.mode | string | `\"internal\"` | Postgres source: `internal` (Bitnami subchart) or `external` (pre-created Secret). |","| storageBackend.redis.external.existingSecretKey | string | `\"\"` | Required when `mode` is `external`: Secret key name for the Redis URL. |","| storageBackend.redis.external.existingSecretName | string | `\"\"` | Required when `mode` is `external`: Secret containing the Redis URL (e.g. `redis://:password@redis.example.com:6379`). |","| storageBackend.redis.mode | string | `\"internal\"` | Redis-protocol source: `internal` (Bitnami Valkey subchart) or `external` (pre-created Secret with a Redis URL). |","| storageBackend.type | string | `\"LocalFs\"` | Backend type: `LocalFs`, `LocalJson`, `Postgres`, or `Memory`. When `Postgres` (or `sessionStorageType` is `Postgres`), the chart injects `POSTGRES_URL`. Only settings for the selected type take effect. |","| valkey | object | `{\"architecture\":\"standalone\",\"auth\":{\"enabled\":true,\"password\":\"trustee\"},\"enabled\":false,\"image\":{\"pullPolicy\":\"IfNotPresent\",\"registry\":\"registry-1.docker.io\",\"repository\":\"bitnami/valkey\",\"tag\":\"latest\"},\"nameOverride\":\"valkey\",\"primary\":{\"persistence\":{\"enabled\":false},\"resources\":{\"limits\":{\"cpu\":\"1\",\"memory\":\"512Mi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}},\"service\":{\"ports\":{\"valkey\":6379}}}}` | [Bitnami Valkey](https://artifacthub.io/packages/helm/bitnami/valkey) subchart, a Redis-protocol-compatible store used for the KBS `Redis` session backend (Valkey is BSD-licensed; it replaces Redis, whose license is no longer OSI-approved). Set `enabled: true` when the bundled store is required (`storageBackend.redis.mode=internal` and `sessionStorageType` or `storageBackend.type` is `Redis`; see `scenarios/valkey-sessions.yaml`). Additional subchart keys (metrics, replication, TLS, and so on) are supported; see upstream docs. |","| valkey.architecture | string | `\"standalone\"` | Single Valkey primary; sessions do not need replicas. Set `replication` plus `replica.*` keys for HA (see upstream docs). |","| valkey.auth.enabled | bool | `true` | Require a password for the bundled Valkey (also used for the Trustee `REDIS_URL` Secret). |","| valkey.auth.password | string | `\"trustee\"` | Bundled Valkey password (also used for the Trustee `REDIS_URL` Secret). |","| valkey.enabled | bool | `false` | Enable the Bitnami Valkey subchart. Must be `true` when `storageBackend.redis.mode=internal` and Redis storage is required. |","| valkey.image | object | `{\"pullPolicy\":\"IfNotPresent\",\"registry\":\"registry-1.docker.io\",\"repository\":\"bitnami/valkey\",\"tag\":\"latest\"}` | Bundled Valkey container image. The default comes from `docker.io`, where anonymous pulls are rate-limited; point `registry`/`repository` at a private mirror to avoid pull failures (a chart-wide `global.imageRegistry` is also honored by the subchart). |","| valkey.image.pullPolicy | string | `\"IfNotPresent\"` | Valkey image pull policy. |","| valkey.image.registry | string | `\"registry-1.docker.io\"` | Valkey image registry; override with a mirror to avoid docker.io rate limits. |","| valkey.image.repository | string | `\"bitnami/valkey\"` | Valkey image repository. |","| valkey.image.tag | string | `\"latest\"` | Valkey image tag. |","| valkey.nameOverride | string | `\"valkey\"` | Subchart name override; the primary Service becomes `{Helm release}-valkey-primary`. |","| valkey.primary.persistence.enabled | bool | `false` | KBS sessions are short-lived, so the bundled Valkey defaults to no PVC; set `true` (plus optional `storageClass`/`size`) to persist sessions across Pod restarts. |","| valkey.primary.resources | object | `{\"limits\":{\"cpu\":\"1\",\"memory\":\"512Mi\"},\"requests\":{\"cpu\":\"100m\",\"memory\":\"128Mi\"}}` | CPU/memory requests and limits for the bundled Valkey primary. |","| valkey.primary.service.ports.valkey | int | `6379` | Bundled Valkey Service port (used in `REDIS_URL`). |","","## End-to-end test","","Provision a **kind** cluster out of band, preload the Trustee images into it, point `kubectl` at it, then from the repository root:","","```bash","kind create cluster --name kind --wait 5m","make -C deployment/helm-chart load-e2e-images-into-kind","make test-helm-e2e","```","","`make e2e-test` assumes **KBS / AS / RVPS** images are already loaded into the cluster and deploys with [scenarios/e2e-local-images.yaml](./scenarios/e2e-local-images.yaml). The Makefile injects image repositories, tags, and `pullPolicy: Never` at install time so local runs and CI can use different preloaded image names without changing the scenario file.","","- **Local preloaded images**: `trustee-e2e/*:e2e`, `pullPolicy: Never` (not GHCR `:latest`)","- **CI images**: reuses `docker-e2e-images-linux-amd64` from `workflow-call-build-docker-e2e-materials.yml` as `ghcr.io/confidential-containers/staged-images/*:latest`","- **Storage**: bundled Postgres KV backend (`storageBackend.type: Postgres`)","- **KBS sessions**: bundled Valkey (`sessionStorageType: Redis`)","- **KBS endpoint**: native HTTPS using an ephemeral, test-only certificate","","Steps:","","1. **`helm-dependency-build`**","2. **`helm-lint`** — validates the default HTTP, e2e, and native-HTTPS configurations","3. **`prepare-e2e-tls`** — creates a test Kubernetes TLS Secret","4. **`deploy`**","5. **`test-client`** — [e2e/test.sh](./e2e/test.sh) validates the certificate and exercises KBS over HTTPS","6. **`dump-logs`** — on failure only: pod status, events, describe, and container logs (current + previous), while the namespace still exists","7. **`undeploy`** — always attempted, even after failures","","Debug individually:","","```bash","make -C deployment/helm-chart load-e2e-images-into-kind","make -C deployment/helm-chart helm-lint","make -C deployment/helm-chart prepare-e2e-tls","make -C deployment/helm-chart deploy","make -C deployment/helm-chart test-client","make -C deployment/helm-chart dump-logs","make -C deployment/helm-chart undeploy","```","","Optional variables: `E2E_IMAGE_PREFIX`, `E2E_IMAGE_TAG`, `KBS_CLIENT`.","","CI (`test-e2e-kbs.yml`) reuses the Docker Compose e2e image build workflow artifacts: it loads the pre-built Trustee images into kind and uses the pre-built `kbs-client` binary before running Helm e2e.","","`make test-client` alone does not build images or undeploy.","","## Development notes","","1. Do not change the files under [files](./files/) unless you are updating the corresponding Helm template logic. Service config is rendered from `*.template` files; Postgres KV init SQL lives in `files/postgres-initkv.sql`.","2. After changing `Chart.yaml` dependencies, run `helm dependency update ./deployment/helm-chart` and commit `Chart.lock` plus `charts/` if your packaging workflow vendors subcharts.","3. After changing `values.yaml` comments or keys, regenerate this README from [README.md.gotmpl](./README.md.gotmpl): `helm-docs -c .` (run from this directory)."],"stylingDirectives":[[[0,20,"pl-mh"],[2,20,"pl-en"]],[],[[15,16,"pl-s"],[39,40,"pl-s"],[40,41,"pl-s"],[41,83,"pl-corl"],[83,84,"pl-s"],[85,87,"pl-s"],[94,96,"pl-s"],[112,114,"pl-s"],[117,119,"pl-s"],[121,123,"pl-s"],[130,132,"pl-s"],[138,140,"pl-s"],[144,146,"pl-s"],[170,172,"pl-s"],[182,184,"pl-s"],[186,187,"pl-s"],[200,201,"pl-s"],[201,202,"pl-s"],[202,257,"pl-corl"],[257,258,"pl-s"],[264,266,"pl-s"],[272,274,"pl-s"],[276,277,"pl-s"],[290,291,"pl-s"],[291,292,"pl-s"],[292,343,"pl-corl"],[343,344,"pl-s"],[411,413,"pl-s"],[413,414,"pl-s"],[414,426,"pl-c1"],[426,427,"pl-s"],[427,429,"pl-s"]],[],[[0,10,"pl-mh"],[3,10,"pl-en"]],[],[[0,2,"pl-s"],[14,16,"pl-s"],[80,82,"pl-s"],[82,83,"pl-s"],[83,112,"pl-c1"],[112,113,"pl-s"],[113,115,"pl-s"],[119,121,"pl-s"],[121,122,"pl-s"],[122,150,"pl-c1"],[150,151,"pl-s"],[151,153,"pl-s"],[240,242,"pl-s"],[254,256,"pl-s"]],[],[[9,11,"pl-s"],[26,28,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[[0,3,"pl-s"]],[],[[56,58,"pl-s"],[62,64,"pl-s"],[101,103,"pl-s"],[103,104,"pl-s"],[104,123,"pl-c1"],[123,124,"pl-s"],[124,126,"pl-s"],[160,162,"pl-s"],[162,163,"pl-s"],[163,174,"pl-c1"],[174,175,"pl-s"],[175,177,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[[0,3,"pl-s"]],[],[],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[[0,3,"pl-s"]],[],[[0,9,"pl-ent"],[0,2,"pl-ent"],[2,3,"pl-s"],[8,9,"pl-s"]],[[0,164,"pl-ent"],[0,2,"pl-ent"],[7,8,"pl-s"],[8,41,"pl-c1"],[41,42,"pl-s"],[46,47,"pl-s"],[47,51,"pl-c1"],[51,52,"pl-s"],[66,68,"pl-s"],[79,81,"pl-s"],[119,120,"pl-s"],[120,141,"pl-c1"],[141,142,"pl-s"]],[[0,0,"pl-ent"]],[[0,20,"pl-mh"],[3,20,"pl-en"]],[],[[0,28,"pl-mh"],[4,28,"pl-en"]],[],[[8,10,"pl-s"],[17,19,"pl-s"],[38,40,"pl-s"],[40,41,"pl-s"],[41,60,"pl-c1"],[60,61,"pl-s"],[61,63,"pl-s"],[68,70,"pl-s"],[70,71,"pl-s"],[71,89,"pl-c1"],[89,90,"pl-s"],[90,92,"pl-s"],[96,98,"pl-s"],[98,99,"pl-s"],[99,107,"pl-c1"],[107,108,"pl-s"],[108,110,"pl-s"],[183,185,"pl-s"],[185,186,"pl-s"],[186,200,"pl-c1"],[200,201,"pl-s"],[201,203,"pl-s"],[210,212,"pl-s"],[219,221,"pl-s"]],[],[[0,58,"pl-mh"],[4,58,"pl-en"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[[0,3,"pl-s"]],[],[[17,19,"pl-s"],[37,39,"pl-s"],[50,51,"pl-s"],[51,75,"pl-c1"],[75,76,"pl-s"],[87,89,"pl-s"],[89,90,"pl-s"],[90,119,"pl-c1"],[119,120,"pl-s"],[120,122,"pl-s"],[153,154,"pl-s"],[154,180,"pl-c1"],[180,181,"pl-s"],[212,213,"pl-s"],[213,220,"pl-c1"],[220,221,"pl-s"],[224,225,"pl-s"],[225,232,"pl-c1"],[232,233,"pl-s"],[236,237,"pl-s"],[237,244,"pl-c1"],[244,245,"pl-s"],[260,261,"pl-s"],[261,278,"pl-c1"],[278,279,"pl-s"]],[],[[0,23,"pl-mh"],[4,23,"pl-en"]],[],[[47,49,"pl-s"],[49,50,"pl-s"],[50,87,"pl-c1"],[87,88,"pl-s"],[88,90,"pl-s"],[119,121,"pl-s"],[121,122,"pl-s"],[122,134,"pl-c1"],[134,135,"pl-s"],[135,137,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[[30,108,"pl-s"],[30,31,"pl-pds"],[107,108,"pl-pds"]],[],[],[],[],[],[],[],[[0,3,"pl-s"]],[],[[5,6,"pl-s"],[6,43,"pl-c1"],[43,44,"pl-s"],[61,63,"pl-s"],[66,68,"pl-s"],[98,99,"pl-s"],[99,117,"pl-c1"],[117,118,"pl-s"],[125,126,"pl-s"],[126,131,"pl-c1"],[131,132,"pl-s"],[167,168,"pl-s"],[168,187,"pl-c1"],[187,188,"pl-s"],[192,193,"pl-s"],[193,211,"pl-c1"],[211,212,"pl-s"]],[],[[0,44,"pl-mh"],[4,44,"pl-en"]],[],[[8,10,"pl-s"],[10,11,"pl-s"],[11,16,"pl-c1"],[16,17,"pl-s"],[17,19,"pl-s"],[86,88,"pl-s"],[94,96,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[[0,3,"pl-s"]],[],[[17,19,"pl-s"],[33,35,"pl-s"],[46,47,"pl-s"],[47,67,"pl-c1"],[67,68,"pl-s"],[79,81,"pl-s"],[81,82,"pl-s"],[82,107,"pl-c1"],[107,108,"pl-s"],[108,110,"pl-s"],[204,206,"pl-s"],[206,207,"pl-s"],[207,216,"pl-c1"],[216,217,"pl-s"],[217,219,"pl-s"],[251,252,"pl-s"],[252,259,"pl-c1"],[259,260,"pl-s"],[275,276,"pl-s"],[276,296,"pl-c1"],[296,297,"pl-s"],[353,354,"pl-s"],[354,364,"pl-c1"],[364,365,"pl-s"],[392,393,"pl-s"],[393,434,"pl-c1"],[434,435,"pl-s"]],[],[[40,42,"pl-s"],[51,53,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[[0,3,"pl-s"]],[],[[14,15,"pl-s"],[15,35,"pl-c1"],[35,36,"pl-s"]],[],[[0,37,"pl-mh"],[4,37,"pl-en"]],[],[[55,57,"pl-s"],[57,58,"pl-s"],[58,92,"pl-c1"],[92,93,"pl-s"],[93,95,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[[27,69,"pl-s"],[27,28,"pl-pds"],[68,69,"pl-pds"]],[],[],[],[],[],[],[],[[0,3,"pl-s"]],[],[[5,6,"pl-s"],[6,40,"pl-c1"],[40,41,"pl-s"],[58,60,"pl-s"],[63,65,"pl-s"],[94,95,"pl-s"],[95,109,"pl-c1"],[109,110,"pl-s"],[117,118,"pl-s"],[118,123,"pl-c1"],[123,124,"pl-s"]],[],[[0,30,"pl-mh"],[4,30,"pl-en"]],[],[[35,37,"pl-s"],[37,38,"pl-s"],[38,71,"pl-c1"],[71,72,"pl-s"],[72,74,"pl-s"]],[],[[0,1,"pl-v"],[2,4,"pl-s"],[4,5,"pl-s"],[5,9,"pl-c1"],[9,10,"pl-s"],[21,23,"pl-s"],[31,33,"pl-s"],[63,65,"pl-s"],[145,147,"pl-s"],[147,148,"pl-s"],[148,167,"pl-c1"],[167,168,"pl-s"],[168,170,"pl-s"],[173,175,"pl-s"],[175,176,"pl-s"],[176,190,"pl-c1"],[190,191,"pl-s"],[191,193,"pl-s"],[201,203,"pl-s"],[214,216,"pl-s"]],[[0,1,"pl-v"],[2,4,"pl-s"],[4,5,"pl-s"],[5,10,"pl-c1"],[10,11,"pl-s"],[12,14,"pl-s"],[24,26,"pl-s"],[36,38,"pl-s"],[52,54,"pl-s"],[54,55,"pl-s"],[55,61,"pl-c1"],[61,62,"pl-s"],[62,64,"pl-s"],[99,101,"pl-s"],[101,102,"pl-s"],[102,128,"pl-c1"],[128,129,"pl-s"],[129,131,"pl-s"],[168,170,"pl-s"],[173,175,"pl-s"]],[],[],[],[[0,1,"pl-v"],[5,6,"pl-s"],[6,19,"pl-c1"],[19,20,"pl-s"],[62,63,"pl-s"],[63,71,"pl-c1"],[71,72,"pl-s"]],[[0,1,"pl-v"],[4,5,"pl-s"],[5,36,"pl-c1"],[36,37,"pl-s"]],[],[[32,33,"pl-s"],[33,67,"pl-c1"],[67,68,"pl-s"],[73,74,"pl-s"],[74,109,"pl-c1"],[109,110,"pl-s"]],[],[[68,70,"pl-s"],[79,81,"pl-s"],[138,139,"pl-s"],[139,184,"pl-c1"],[184,185,"pl-s"]],[],[[0,1,"pl-ml"],[13,14,"pl-ml"],[20,21,"pl-ml"]],[[0,1,"pl-ml"],[13,14,"pl-ml"],[20,21,"pl-ml"]],[[0,1,"pl-ml"],[2,4,"pl-s"],[4,5,"pl-s"],[5,26,"pl-c1"],[26,27,"pl-s"],[27,29,"pl-s"],[32,34,"pl-s"],[34,35,"pl-s"],[35,51,"pl-c1"],[51,52,"pl-s"],[52,54,"pl-s"],[55,56,"pl-ml"],[114,115,"pl-ml"]],[[0,1,"pl-ml"],[2,4,"pl-s"],[4,5,"pl-s"],[5,20,"pl-c1"],[20,21,"pl-s"],[21,23,"pl-s"],[24,25,"pl-ml"],[58,59,"pl-s"],[59,88,"pl-c1"],[88,89,"pl-s"],[157,158,"pl-ml"]],[[0,1,"pl-ml"],[2,4,"pl-s"],[4,5,"pl-s"],[5,33,"pl-c1"],[33,34,"pl-s"],[34,36,"pl-s"],[37,38,"pl-ml"],[85,86,"pl-ml"]],[[0,1,"pl-ml"],[2,4,"pl-s"],[4,5,"pl-s"],[5,48,"pl-c1"],[48,49,"pl-s"],[49,51,"pl-s"],[52,53,"pl-ml"],[58,59,"pl-s"],[59,62,"pl-c1"],[62,63,"pl-s"],[120,121,"pl-ml"]],[],[[52,54,"pl-s"],[58,60,"pl-s"],[94,96,"pl-s"],[96,97,"pl-s"],[97,108,"pl-c1"],[108,109,"pl-s"],[109,111,"pl-s"],[113,115,"pl-s"],[115,116,"pl-s"],[116,126,"pl-c1"],[126,127,"pl-s"],[127,129,"pl-s"],[131,133,"pl-s"],[133,134,"pl-s"],[134,143,"pl-c1"],[143,144,"pl-s"],[144,146,"pl-s"],[148,150,"pl-s"],[150,151,"pl-s"],[151,171,"pl-c1"],[171,172,"pl-s"],[172,174,"pl-s"],[181,183,"pl-s"],[183,184,"pl-s"],[184,226,"pl-c1"],[226,227,"pl-s"],[227,229,"pl-s"]],[],[],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[],[],[],[],[],[[0,3,"pl-s"]],[],[[7,9,"pl-s"],[9,10,"pl-s"],[10,44,"pl-c1"],[44,45,"pl-s"],[45,47,"pl-s"]],[],[[0,20,"pl-mh"],[4,20,"pl-en"]],[],[],[],[],[],[],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[],[],[],[],[[0,3,"pl-s"]],[],[[5,6,"pl-s"],[6,26,"pl-c1"],[26,27,"pl-s"],[46,47,"pl-s"],[47,60,"pl-c1"],[60,61,"pl-s"]],[[9,10,"pl-s"],[10,15,"pl-c1"],[15,16,"pl-s"],[39,40,"pl-s"],[40,47,"pl-c1"],[47,48,"pl-s"],[53,54,"pl-s"],[54,61,"pl-c1"],[61,62,"pl-s"]],[],[],[],[],[],[],[[10,11,"pl-s"],[11,22,"pl-c1"],[22,23,"pl-s"]],[],[],[],[],[[0,32,"pl-mh"],[4,32,"pl-en"]],[],[[3,5,"pl-s"],[10,12,"pl-s"],[18,20,"pl-s"],[45,47,"pl-s"],[120,122,"pl-s"],[129,130,"pl-s"],[130,142,"pl-c1"],[142,143,"pl-s"],[146,148,"pl-s"],[179,181,"pl-s"],[187,189,"pl-s"],[229,231,"pl-s"],[233,235,"pl-s"],[301,302,"pl-s"],[302,339,"pl-c1"],[339,340,"pl-s"]],[],[[52,54,"pl-s"],[54,55,"pl-s"],[55,90,"pl-c1"],[90,91,"pl-s"],[91,93,"pl-s"],[111,112,"pl-s"],[112,116,"pl-c1"],[116,117,"pl-s"],[132,133,"pl-s"],[133,163,"pl-c1"],[163,164,"pl-s"],[196,198,"pl-s"],[213,215,"pl-s"],[269,271,"pl-s"],[271,272,"pl-s"],[272,295,"pl-c1"],[295,296,"pl-s"],[296,298,"pl-s"],[371,372,"pl-s"],[372,388,"pl-c1"],[388,389,"pl-s"],[426,428,"pl-s"],[428,429,"pl-s"],[429,452,"pl-c1"],[452,453,"pl-s"],[453,455,"pl-s"],[508,509,"pl-s"],[509,514,"pl-c1"],[514,515,"pl-s"],[564,565,"pl-s"],[565,600,"pl-c1"],[600,601,"pl-s"]],[],[[0,1,"pl-ml"],[11,12,"pl-ml"],[33,34,"pl-s"],[34,42,"pl-c1"],[42,43,"pl-s"],[44,45,"pl-ml"],[52,53,"pl-ml"]],[[0,1,"pl-ml"],[11,12,"pl-ml"],[43,44,"pl-ml"],[51,52,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[29,30,"pl-s"],[30,55,"pl-c1"],[55,56,"pl-s"],[57,58,"pl-ml"],[74,76,"pl-s"],[85,87,"pl-s"],[112,113,"pl-ml"]],[[0,1,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,40,"pl-c1"],[40,41,"pl-s"],[42,43,"pl-ml"],[44,46,"pl-s"],[55,57,"pl-s"],[79,80,"pl-ml"]],[[0,1,"pl-ml"],[7,8,"pl-ml"],[9,10,"pl-s"],[10,15,"pl-c1"],[15,16,"pl-s"],[17,18,"pl-ml"],[19,21,"pl-s"],[30,32,"pl-s"],[54,55,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[29,30,"pl-s"],[30,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[39,41,"pl-s"],[50,52,"pl-s"],[74,75,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[20,21,"pl-s"],[21,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[49,50,"pl-ml"]],[[0,1,"pl-ml"],[21,22,"pl-ml"],[23,24,"pl-s"],[24,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[52,53,"pl-ml"]],[],[[4,6,"pl-s"],[6,7,"pl-s"],[7,38,"pl-c1"],[38,39,"pl-s"],[39,41,"pl-s"],[47,48,"pl-s"],[48,63,"pl-c1"],[63,64,"pl-s"],[114,116,"pl-s"],[119,121,"pl-s"],[126,127,"pl-s"],[127,158,"pl-c1"],[158,159,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[[0,74,"pl-c"],[0,1,"pl-c"]],[[0,60,"pl-c"],[0,1,"pl-c"]],[[0,72,"pl-c"],[0,1,"pl-c"]],[],[[0,59,"pl-c"],[0,1,"pl-c"]],[],[],[],[[32,49,"pl-smi"]],[[32,33,"pl-k"],[53,54,"pl-k"]],[[0,3,"pl-s"]],[],[[7,9,"pl-s"],[14,16,"pl-s"],[41,42,"pl-s"],[42,53,"pl-c1"],[53,54,"pl-s"],[64,65,"pl-s"],[65,84,"pl-c1"],[84,85,"pl-s"],[88,89,"pl-s"],[89,101,"pl-c1"],[101,102,"pl-s"],[109,111,"pl-s"],[111,112,"pl-s"],[112,133,"pl-c1"],[133,134,"pl-s"],[134,136,"pl-s"],[218,219,"pl-s"],[219,249,"pl-c1"],[249,250,"pl-s"]],[],[[0,34,"pl-mh"],[4,34,"pl-en"]],[],[[4,6,"pl-s"],[9,11,"pl-s"],[29,31,"pl-s"],[35,37,"pl-s"],[116,118,"pl-s"],[125,127,"pl-s"]],[],[[4,6,"pl-s"],[6,7,"pl-s"],[7,39,"pl-c1"],[39,40,"pl-s"],[40,42,"pl-s"],[94,96,"pl-s"],[96,97,"pl-s"],[97,121,"pl-c1"],[121,122,"pl-s"],[122,124,"pl-s"],[162,164,"pl-s"],[164,165,"pl-s"],[165,177,"pl-c1"],[177,178,"pl-s"],[178,180,"pl-s"],[190,192,"pl-s"],[192,193,"pl-s"],[193,220,"pl-c1"],[220,221,"pl-s"],[221,223,"pl-s"],[250,251,"pl-s"],[251,256,"pl-c1"],[256,257,"pl-s"],[300,301,"pl-s"],[301,359,"pl-c1"],[359,360,"pl-s"],[467,468,"pl-s"],[468,480,"pl-c1"],[480,481,"pl-s"],[496,497,"pl-s"],[497,509,"pl-c1"],[509,510,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[[0,81,"pl-c"],[0,1,"pl-c"]],[[0,62,"pl-c"],[0,1,"pl-c"]],[[0,61,"pl-c"],[0,1,"pl-c"]],[],[[0,59,"pl-c"],[0,1,"pl-c"]],[],[],[[41,51,"pl-smi"]],[[33,34,"pl-k"],[52,53,"pl-k"]],[[8,58,"pl-s"],[8,9,"pl-pds"],[57,58,"pl-pds"]],[[0,3,"pl-s"]],[],[[51,52,"pl-s"],[52,99,"pl-c1"],[99,100,"pl-s"],[176,177,"pl-s"],[216,217,"pl-s"],[217,218,"pl-s"],[218,281,"pl-corl"],[281,282,"pl-s"],[304,305,"pl-s"],[305,310,"pl-c1"],[310,311,"pl-s"]],[],[[0,10,"pl-mh"],[3,10,"pl-en"]],[],[[0,2,"pl-s"],[19,21,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[[0,3,"pl-s"]],[],[[0,2,"pl-s"],[19,21,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[[27,28,"pl-k"]],[[0,3,"pl-s"]],[],[[31,32,"pl-s"],[32,51,"pl-c1"],[51,52,"pl-s"],[68,69,"pl-s"],[69,97,"pl-c1"],[97,98,"pl-s"],[136,137,"pl-s"],[137,149,"pl-c1"],[149,150,"pl-s"],[186,187,"pl-s"],[187,193,"pl-c1"],[193,194,"pl-s"]],[],[[0,2,"pl-s"],[12,14,"pl-s"],[37,38,"pl-s"],[38,73,"pl-c1"],[73,74,"pl-s"],[138,140,"pl-s"],[140,141,"pl-s"],[141,160,"pl-c1"],[160,161,"pl-s"],[161,163,"pl-s"],[203,205,"pl-s"],[205,206,"pl-s"],[206,221,"pl-c1"],[221,222,"pl-s"],[222,224,"pl-s"],[238,239,"pl-s"],[239,288,"pl-c1"],[288,289,"pl-s"],[324,326,"pl-s"],[326,327,"pl-s"],[327,331,"pl-c1"],[331,332,"pl-s"],[332,334,"pl-s"],[350,351,"pl-s"],[351,382,"pl-c1"],[382,383,"pl-s"],[398,400,"pl-s"],[400,401,"pl-s"],[401,406,"pl-c1"],[406,407,"pl-s"],[407,409,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[[63,64,"pl-k"]],[[7,104,"pl-s"],[7,9,"pl-pds"],[53,54,"pl-k"],[80,81,"pl-k"],[90,91,"pl-k"],[103,104,"pl-pds"]],[[19,28,"pl-s"],[19,20,"pl-pds"],[20,27,"pl-smi"],[27,28,"pl-pds"],[57,82,"pl-s"],[57,58,"pl-pds"],[81,82,"pl-pds"],[83,84,"pl-k"],[95,96,"pl-k"]],[],[[0,3,"pl-s"]],[],[[29,30,"pl-s"],[30,36,"pl-c1"],[36,37,"pl-s"],[40,41,"pl-s"],[41,59,"pl-c1"],[59,60,"pl-s"],[67,68,"pl-s"],[68,80,"pl-c1"],[80,81,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[[0,4,"pl-c1"],[5,19,"pl-s"],[5,6,"pl-pds"],[18,19,"pl-pds"],[20,21,"pl-k"]],[],[],[[0,3,"pl-s"]],[],[[34,35,"pl-s"],[35,47,"pl-c1"],[47,48,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[[0,3,"pl-s"]],[],[[0,16,"pl-mh"],[3,16,"pl-en"]],[],[[8,10,"pl-s"],[10,11,"pl-s"],[11,22,"pl-c1"],[22,23,"pl-s"],[23,25,"pl-s"],[74,76,"pl-s"],[83,85,"pl-s"],[88,90,"pl-s"],[99,101,"pl-s"],[117,119,"pl-s"],[119,120,"pl-s"],[120,142,"pl-c1"],[142,143,"pl-s"],[143,145,"pl-s"],[212,213,"pl-s"],[213,215,"pl-c1"],[215,216,"pl-s"],[219,220,"pl-s"],[220,225,"pl-c1"],[225,226,"pl-s"]],[],[[0,9,"pl-mh"],[3,9,"pl-en"]],[],[[0,1,"pl-ml"],[6,7,"pl-ml"],[13,14,"pl-ml"],[23,24,"pl-ml"],[37,38,"pl-ml"]],[[0,1,"pl-ml"],[6,7,"pl-ml"],[13,14,"pl-ml"],[23,24,"pl-ml"],[37,38,"pl-ml"]],[[0,1,"pl-ml"],[14,15,"pl-ml"],[23,24,"pl-ml"],[25,26,"pl-s"],[26,28,"pl-c1"],[28,29,"pl-s"],[30,31,"pl-ml"],[89,90,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[96,97,"pl-s"],[97,110,"pl-c1"],[110,111,"pl-s"],[116,117,"pl-s"],[117,125,"pl-c1"],[125,126,"pl-s"],[129,130,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,42,"pl-c1"],[42,43,"pl-s"],[44,45,"pl-ml"],[78,79,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,94,"pl-c1"],[94,95,"pl-s"],[96,97,"pl-ml"],[129,130,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[63,64,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[90,91,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[27,28,"pl-ml"],[29,30,"pl-s"],[30,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[82,83,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[61,62,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[33,34,"pl-ml"],[35,36,"pl-s"],[36,38,"pl-c1"],[38,39,"pl-s"],[40,41,"pl-ml"],[80,81,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,28,"pl-c1"],[28,29,"pl-s"],[30,31,"pl-ml"],[76,77,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,105,"pl-c1"],[105,106,"pl-s"],[107,108,"pl-ml"],[158,159,"pl-ml"]],[[0,1,"pl-ml"],[37,38,"pl-ml"],[46,47,"pl-ml"],[48,49,"pl-s"],[49,51,"pl-c1"],[51,52,"pl-s"],[53,54,"pl-ml"],[80,81,"pl-s"],[81,96,"pl-c1"],[96,97,"pl-s"],[101,102,"pl-s"],[102,114,"pl-c1"],[114,115,"pl-s"],[117,118,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[53,54,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[27,28,"pl-ml"],[29,30,"pl-s"],[30,41,"pl-c1"],[41,42,"pl-s"],[43,44,"pl-ml"],[62,63,"pl-s"],[63,72,"pl-c1"],[72,73,"pl-s"],[77,78,"pl-s"],[78,90,"pl-c1"],[90,91,"pl-s"],[94,95,"pl-ml"]],[[0,1,"pl-ml"],[17,18,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,29,"pl-c1"],[29,30,"pl-s"],[31,32,"pl-ml"],[88,89,"pl-ml"]],[[0,1,"pl-ml"],[38,39,"pl-ml"],[47,48,"pl-ml"],[49,50,"pl-s"],[50,111,"pl-c1"],[111,112,"pl-s"],[113,114,"pl-ml"],[164,165,"pl-s"],[165,181,"pl-c1"],[181,182,"pl-s"],[198,199,"pl-ml"]],[[0,1,"pl-ml"],[35,36,"pl-ml"],[44,45,"pl-ml"],[46,47,"pl-s"],[47,54,"pl-c1"],[54,55,"pl-s"],[56,57,"pl-ml"],[92,93,"pl-s"],[93,98,"pl-c1"],[98,99,"pl-s"],[102,103,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,45,"pl-c1"],[45,46,"pl-s"],[47,48,"pl-ml"],[71,72,"pl-s"],[72,77,"pl-c1"],[77,78,"pl-s"],[82,83,"pl-s"],[83,89,"pl-c1"],[89,90,"pl-s"],[97,98,"pl-s"],[98,104,"pl-c1"],[104,105,"pl-s"],[107,108,"pl-s"],[108,119,"pl-c1"],[119,120,"pl-s"],[134,135,"pl-ml"]],[[0,1,"pl-ml"],[33,34,"pl-ml"],[42,43,"pl-ml"],[44,45,"pl-s"],[45,92,"pl-c1"],[92,93,"pl-s"],[94,95,"pl-ml"],[110,111,"pl-s"],[111,134,"pl-c1"],[134,135,"pl-s"],[139,140,"pl-s"],[140,146,"pl-c1"],[146,147,"pl-s"],[149,150,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,40,"pl-c1"],[40,41,"pl-s"],[42,43,"pl-ml"],[135,136,"pl-s"],[136,140,"pl-c1"],[140,141,"pl-s"],[143,144,"pl-s"],[144,150,"pl-c1"],[150,151,"pl-s"],[153,154,"pl-s"],[154,159,"pl-c1"],[159,160,"pl-s"],[162,163,"pl-s"],[163,168,"pl-c1"],[168,169,"pl-s"],[171,172,"pl-s"],[172,183,"pl-c1"],[183,184,"pl-s"],[223,224,"pl-s"],[224,229,"pl-c1"],[229,230,"pl-s"],[305,306,"pl-s"],[306,341,"pl-c1"],[341,342,"pl-s"],[367,368,"pl-s"],[368,391,"pl-c1"],[391,392,"pl-s"],[394,395,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,40,"pl-c1"],[40,41,"pl-s"],[42,43,"pl-ml"],[103,104,"pl-s"],[104,127,"pl-c1"],[127,128,"pl-s"],[153,154,"pl-s"],[154,177,"pl-c1"],[177,178,"pl-s"],[216,217,"pl-s"],[217,229,"pl-c1"],[229,230,"pl-s"],[232,233,"pl-ml"]],[[0,1,"pl-ml"],[35,36,"pl-ml"],[44,45,"pl-ml"],[46,47,"pl-s"],[47,49,"pl-c1"],[49,50,"pl-s"],[51,52,"pl-ml"],[173,174,"pl-s"],[174,179,"pl-c1"],[179,180,"pl-s"],[232,233,"pl-s"],[233,238,"pl-c1"],[238,239,"pl-s"],[271,272,"pl-s"],[272,330,"pl-c1"],[330,331,"pl-s"],[365,366,"pl-s"],[366,378,"pl-c1"],[378,379,"pl-s"],[389,390,"pl-s"],[390,417,"pl-c1"],[417,418,"pl-s"],[440,441,"pl-s"],[441,465,"pl-c1"],[465,466,"pl-s"],[472,473,"pl-s"],[508,509,"pl-s"],[509,510,"pl-s"],[510,573,"pl-corl"],[573,574,"pl-s"],[601,602,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[36,37,"pl-ml"],[38,39,"pl-s"],[39,41,"pl-c1"],[41,42,"pl-s"],[43,44,"pl-ml"],[97,98,"pl-s"],[98,130,"pl-c1"],[130,131,"pl-s"],[156,157,"pl-s"],[157,189,"pl-c1"],[189,190,"pl-s"],[214,215,"pl-s"],[215,227,"pl-c1"],[227,228,"pl-s"],[230,231,"pl-ml"]],[[0,1,"pl-ml"],[30,31,"pl-ml"],[37,38,"pl-ml"],[39,40,"pl-s"],[40,42,"pl-c1"],[42,43,"pl-s"],[44,45,"pl-ml"],[148,149,"pl-s"],[149,161,"pl-c1"],[161,162,"pl-s"],[224,225,"pl-s"],[225,228,"pl-c1"],[228,229,"pl-s"],[326,327,"pl-s"],[327,339,"pl-c1"],[339,340,"pl-s"],[349,350,"pl-s"],[350,374,"pl-c1"],[374,375,"pl-s"],[380,381,"pl-s"],[381,413,"pl-c1"],[413,414,"pl-s"],[496,497,"pl-ml"]],[[0,1,"pl-ml"],[23,24,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,329,"pl-c1"],[329,330,"pl-s"],[331,332,"pl-ml"],[430,431,"pl-s"],[431,469,"pl-c1"],[469,470,"pl-s"],[473,474,"pl-ml"]],[[0,1,"pl-ml"],[46,47,"pl-ml"],[55,56,"pl-ml"],[57,58,"pl-s"],[58,72,"pl-c1"],[72,73,"pl-s"],[74,75,"pl-ml"],[84,85,"pl-s"],[85,98,"pl-c1"],[98,99,"pl-s"],[119,120,"pl-ml"]],[[0,1,"pl-ml"],[46,47,"pl-ml"],[55,56,"pl-ml"],[57,58,"pl-s"],[58,74,"pl-c1"],[74,75,"pl-s"],[76,77,"pl-ml"],[86,87,"pl-s"],[87,100,"pl-c1"],[100,101,"pl-s"],[145,146,"pl-ml"]],[[0,1,"pl-ml"],[39,40,"pl-ml"],[48,49,"pl-ml"],[50,51,"pl-s"],[51,58,"pl-c1"],[58,59,"pl-s"],[60,61,"pl-ml"],[70,71,"pl-s"],[71,84,"pl-c1"],[84,85,"pl-s"],[97,98,"pl-ml"]],[[0,1,"pl-ml"],[47,48,"pl-ml"],[56,57,"pl-ml"],[58,59,"pl-s"],[59,73,"pl-c1"],[73,74,"pl-s"],[75,76,"pl-ml"],[114,115,"pl-ml"]],[[0,1,"pl-ml"],[47,48,"pl-ml"],[56,57,"pl-ml"],[58,59,"pl-s"],[59,92,"pl-c1"],[92,93,"pl-s"],[94,95,"pl-ml"],[182,183,"pl-ml"]],[[0,1,"pl-ml"],[40,41,"pl-ml"],[49,50,"pl-ml"],[51,52,"pl-s"],[52,62,"pl-c1"],[62,63,"pl-s"],[64,65,"pl-ml"],[95,96,"pl-ml"]],[[0,1,"pl-ml"],[33,34,"pl-ml"],[42,43,"pl-ml"],[44,45,"pl-s"],[45,128,"pl-c1"],[128,129,"pl-s"],[130,131,"pl-ml"],[191,192,"pl-ml"]],[[0,1,"pl-ml"],[25,26,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,40,"pl-c1"],[40,41,"pl-s"],[42,43,"pl-ml"],[49,50,"pl-s"],[50,54,"pl-c1"],[54,55,"pl-s"],[76,77,"pl-s"],[77,83,"pl-c1"],[83,84,"pl-s"],[102,103,"pl-s"],[103,112,"pl-c1"],[112,113,"pl-s"],[127,128,"pl-s"],[128,139,"pl-c1"],[139,140,"pl-s"],[174,175,"pl-s"],[175,194,"pl-c1"],[194,195,"pl-s"],[244,245,"pl-s"],[245,257,"pl-c1"],[257,258,"pl-s"],[260,261,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[28,29,"pl-ml"],[30,31,"pl-s"],[31,33,"pl-c1"],[33,34,"pl-s"],[35,36,"pl-ml"],[109,110,"pl-ml"]],[[0,1,"pl-ml"],[10,11,"pl-ml"],[19,20,"pl-ml"],[21,22,"pl-s"],[22,90,"pl-c1"],[90,91,"pl-s"],[92,93,"pl-ml"],[143,144,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[61,62,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[57,58,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,33,"pl-c1"],[33,34,"pl-s"],[35,36,"pl-ml"],[61,62,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,29,"pl-c1"],[29,30,"pl-s"],[31,32,"pl-ml"],[102,103,"pl-ml"]],[[0,1,"pl-ml"],[14,15,"pl-ml"],[21,22,"pl-ml"],[23,24,"pl-s"],[24,26,"pl-c1"],[26,27,"pl-s"],[28,29,"pl-ml"],[57,58,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,29,"pl-c1"],[29,30,"pl-s"],[31,32,"pl-ml"],[91,92,"pl-ml"]],[[0,1,"pl-ml"],[28,29,"pl-ml"],[37,38,"pl-ml"],[39,40,"pl-s"],[40,45,"pl-c1"],[45,46,"pl-s"],[47,48,"pl-ml"],[53,54,"pl-s"],[54,62,"pl-c1"],[62,63,"pl-s"],[111,112,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,53,"pl-c1"],[53,54,"pl-s"],[55,56,"pl-ml"],[61,62,"pl-s"],[62,68,"pl-c1"],[68,69,"pl-s"],[128,129,"pl-s"],[129,162,"pl-c1"],[162,163,"pl-s"],[165,166,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[33,34,"pl-ml"],[35,36,"pl-s"],[36,43,"pl-c1"],[43,44,"pl-s"],[45,46,"pl-ml"],[51,52,"pl-s"],[52,56,"pl-c1"],[56,57,"pl-s"],[77,78,"pl-s"],[78,109,"pl-c1"],[109,110,"pl-s"],[117,118,"pl-ml"]],[[0,1,"pl-ml"],[41,42,"pl-ml"],[47,48,"pl-ml"],[49,50,"pl-s"],[50,53,"pl-c1"],[53,54,"pl-s"],[55,56,"pl-ml"],[109,110,"pl-s"],[110,119,"pl-c1"],[119,120,"pl-s"],[124,125,"pl-s"],[125,155,"pl-c1"],[155,156,"pl-s"],[159,160,"pl-ml"]],[[0,1,"pl-ml"],[40,41,"pl-ml"],[46,47,"pl-ml"],[48,49,"pl-s"],[49,51,"pl-c1"],[51,52,"pl-s"],[53,54,"pl-ml"],[113,114,"pl-s"],[114,121,"pl-c1"],[121,122,"pl-s"],[126,127,"pl-s"],[127,157,"pl-c1"],[157,158,"pl-s"],[161,162,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,31,"pl-c1"],[31,32,"pl-s"],[33,34,"pl-ml"],[97,98,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[83,84,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,31,"pl-c1"],[31,32,"pl-s"],[33,34,"pl-ml"],[75,76,"pl-ml"]],[[0,1,"pl-ml"],[23,24,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,43,"pl-c1"],[43,44,"pl-s"],[45,46,"pl-ml"],[80,81,"pl-ml"]],[[0,1,"pl-ml"],[23,24,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,94,"pl-c1"],[94,95,"pl-s"],[96,97,"pl-ml"],[130,131,"pl-ml"]],[[0,1,"pl-ml"],[16,17,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[65,66,"pl-ml"]],[[0,1,"pl-ml"],[23,24,"pl-ml"],[30,31,"pl-ml"],[32,33,"pl-s"],[33,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[91,92,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[28,29,"pl-ml"],[30,31,"pl-s"],[31,33,"pl-c1"],[33,34,"pl-s"],[35,36,"pl-ml"],[84,85,"pl-ml"]],[[0,1,"pl-ml"],[21,22,"pl-ml"],[30,31,"pl-ml"],[32,33,"pl-s"],[33,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[122,123,"pl-ml"]],[[0,1,"pl-ml"],[25,26,"pl-ml"],[34,35,"pl-ml"],[36,37,"pl-s"],[37,39,"pl-c1"],[39,40,"pl-s"],[41,42,"pl-ml"],[81,82,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,29,"pl-c1"],[29,30,"pl-s"],[31,32,"pl-ml"],[61,62,"pl-ml"]],[[0,1,"pl-ml"],[25,26,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,37,"pl-c1"],[37,38,"pl-s"],[39,40,"pl-ml"],[111,112,"pl-ml"]],[[0,1,"pl-ml"],[16,17,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,108,"pl-c1"],[108,109,"pl-s"],[110,111,"pl-ml"],[162,163,"pl-ml"]],[[0,1,"pl-ml"],[33,34,"pl-ml"],[40,41,"pl-ml"],[42,43,"pl-s"],[43,48,"pl-c1"],[48,49,"pl-s"],[50,51,"pl-ml"],[57,58,"pl-s"],[58,62,"pl-c1"],[62,63,"pl-s"],[95,96,"pl-s"],[96,108,"pl-c1"],[108,109,"pl-s"],[119,120,"pl-s"],[120,137,"pl-c1"],[137,138,"pl-s"],[166,167,"pl-s"],[167,181,"pl-c1"],[181,182,"pl-s"],[203,204,"pl-s"],[204,213,"pl-c1"],[213,214,"pl-s"],[216,217,"pl-ml"]],[[0,1,"pl-ml"],[38,39,"pl-ml"],[47,48,"pl-ml"],[49,50,"pl-s"],[50,52,"pl-c1"],[52,53,"pl-s"],[54,55,"pl-ml"],[96,97,"pl-s"],[97,109,"pl-c1"],[109,110,"pl-s"],[124,125,"pl-s"],[125,148,"pl-c1"],[148,149,"pl-s"],[151,152,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[84,85,"pl-s"],[85,94,"pl-c1"],[94,95,"pl-s"],[130,131,"pl-s"],[131,143,"pl-c1"],[143,144,"pl-s"],[154,155,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,33,"pl-c1"],[33,34,"pl-s"],[35,36,"pl-ml"],[87,88,"pl-s"],[88,98,"pl-c1"],[98,99,"pl-s"],[157,158,"pl-ml"]],[[0,1,"pl-ml"],[21,22,"pl-ml"],[30,31,"pl-ml"],[32,33,"pl-s"],[33,35,"pl-c1"],[35,36,"pl-s"],[37,38,"pl-ml"],[120,121,"pl-s"],[121,133,"pl-c1"],[133,134,"pl-s"],[136,137,"pl-ml"]],[[0,1,"pl-ml"],[18,19,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[90,91,"pl-ml"]],[[0,1,"pl-ml"],[12,13,"pl-ml"],[21,22,"pl-ml"],[23,24,"pl-s"],[24,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[44,45,"pl-s"],[45,53,"pl-c1"],[53,54,"pl-s"],[78,79,"pl-s"],[79,83,"pl-c1"],[83,84,"pl-s"],[86,87,"pl-s"],[87,92,"pl-c1"],[92,93,"pl-s"],[95,96,"pl-s"],[96,100,"pl-c1"],[100,101,"pl-s"],[103,104,"pl-s"],[104,109,"pl-c1"],[109,110,"pl-s"],[113,114,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,29,"pl-c1"],[29,30,"pl-s"],[31,32,"pl-ml"],[92,93,"pl-ml"]],[[0,1,"pl-ml"],[11,12,"pl-ml"],[20,21,"pl-ml"],[22,23,"pl-s"],[23,50,"pl-c1"],[50,51,"pl-s"],[52,53,"pl-ml"],[93,94,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[73,74,"pl-ml"]],[[0,1,"pl-ml"],[16,17,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[110,111,"pl-ml"]],[[0,1,"pl-ml"],[13,14,"pl-ml"],[22,23,"pl-ml"],[24,25,"pl-s"],[25,422,"pl-c1"],[422,423,"pl-s"],[424,425,"pl-ml"],[426,427,"pl-s"],[445,446,"pl-s"],[446,447,"pl-s"],[447,502,"pl-corl"],[502,503,"pl-s"],[518,519,"pl-s"],[519,532,"pl-c1"],[532,533,"pl-s"],[569,570,"pl-s"],[570,607,"pl-c1"],[607,608,"pl-s"],[645,646,"pl-s"],[646,677,"pl-c1"],[677,678,"pl-s"],[781,782,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[36,37,"pl-ml"],[38,39,"pl-s"],[39,48,"pl-c1"],[48,49,"pl-s"],[50,51,"pl-ml"],[110,111,"pl-s"],[111,123,"pl-c1"],[123,124,"pl-s"],[134,135,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[36,37,"pl-ml"],[38,39,"pl-s"],[39,48,"pl-c1"],[48,49,"pl-s"],[50,51,"pl-ml"],[105,106,"pl-s"],[106,118,"pl-c1"],[118,119,"pl-s"],[129,130,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[36,37,"pl-ml"],[38,39,"pl-s"],[39,48,"pl-c1"],[48,49,"pl-s"],[50,51,"pl-ml"],[105,106,"pl-s"],[106,118,"pl-c1"],[118,119,"pl-s"],[129,130,"pl-ml"]],[[0,1,"pl-ml"],[21,22,"pl-ml"],[28,29,"pl-ml"],[30,31,"pl-s"],[31,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[88,89,"pl-s"],[89,93,"pl-c1"],[93,94,"pl-s"],[100,101,"pl-s"],[101,138,"pl-c1"],[138,139,"pl-s"],[174,175,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,48,"pl-c1"],[48,49,"pl-s"],[50,51,"pl-ml"],[108,109,"pl-s"],[109,132,"pl-c1"],[132,133,"pl-s"],[135,136,"pl-ml"]],[[0,1,"pl-ml"],[45,46,"pl-ml"],[54,55,"pl-ml"],[56,57,"pl-s"],[57,82,"pl-c1"],[82,83,"pl-s"],[84,85,"pl-ml"],[105,106,"pl-s"],[106,131,"pl-c1"],[131,132,"pl-s"],[137,138,"pl-s"],[138,178,"pl-c1"],[178,179,"pl-s"],[234,235,"pl-ml"]],[[0,1,"pl-ml"],[41,42,"pl-ml"],[48,49,"pl-ml"],[50,51,"pl-s"],[51,55,"pl-c1"],[55,56,"pl-s"],[57,58,"pl-ml"],[107,108,"pl-ml"]],[[0,1,"pl-ml"],[47,48,"pl-ml"],[56,57,"pl-ml"],[58,59,"pl-s"],[59,61,"pl-c1"],[61,62,"pl-s"],[63,64,"pl-ml"],[114,115,"pl-ml"]],[[0,1,"pl-ml"],[38,39,"pl-ml"],[47,48,"pl-ml"],[49,50,"pl-s"],[50,55,"pl-c1"],[55,56,"pl-s"],[57,58,"pl-ml"],[129,130,"pl-s"],[130,133,"pl-c1"],[133,134,"pl-s"],[137,138,"pl-ml"]],[[0,1,"pl-ml"],[46,47,"pl-ml"],[55,56,"pl-ml"],[57,58,"pl-s"],[58,60,"pl-c1"],[60,61,"pl-s"],[62,63,"pl-ml"],[152,153,"pl-ml"]],[[0,1,"pl-ml"],[31,32,"pl-ml"],[40,41,"pl-ml"],[42,43,"pl-s"],[43,123,"pl-c1"],[123,124,"pl-s"],[125,126,"pl-ml"],[180,181,"pl-ml"]],[[0,1,"pl-ml"],[38,39,"pl-ml"],[44,45,"pl-ml"],[46,47,"pl-s"],[47,51,"pl-c1"],[51,52,"pl-s"],[53,54,"pl-ml"],[94,95,"pl-s"],[95,107,"pl-c1"],[107,108,"pl-s"],[111,112,"pl-ml"]],[[0,1,"pl-ml"],[16,17,"pl-ml"],[25,26,"pl-ml"],[27,28,"pl-s"],[28,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[93,94,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[27,28,"pl-ml"],[29,30,"pl-s"],[30,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[100,101,"pl-s"],[101,114,"pl-c1"],[114,115,"pl-s"],[120,121,"pl-s"],[121,129,"pl-c1"],[129,130,"pl-s"],[133,134,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[33,34,"pl-ml"],[35,36,"pl-s"],[36,44,"pl-c1"],[44,45,"pl-s"],[46,47,"pl-ml"],[82,83,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[33,34,"pl-ml"],[35,36,"pl-s"],[36,88,"pl-c1"],[88,89,"pl-s"],[90,91,"pl-ml"],[125,126,"pl-ml"]],[[0,1,"pl-ml"],[17,18,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,37,"pl-c1"],[37,38,"pl-s"],[39,40,"pl-ml"],[67,68,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[92,93,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[86,87,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[63,64,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,40,"pl-c1"],[40,41,"pl-s"],[42,43,"pl-ml"],[82,83,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,30,"pl-c1"],[30,31,"pl-s"],[32,33,"pl-ml"],[63,64,"pl-ml"]],[[0,1,"pl-ml"],[17,18,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,109,"pl-c1"],[109,110,"pl-s"],[111,112,"pl-ml"],[164,165,"pl-ml"]],[[0,1,"pl-ml"],[39,40,"pl-ml"],[48,49,"pl-ml"],[50,51,"pl-s"],[51,53,"pl-c1"],[53,54,"pl-s"],[55,56,"pl-ml"],[113,114,"pl-ml"]],[[0,1,"pl-ml"],[32,33,"pl-ml"],[41,42,"pl-ml"],[43,44,"pl-s"],[44,54,"pl-c1"],[54,55,"pl-s"],[56,57,"pl-ml"],[82,83,"pl-s"],[83,100,"pl-c1"],[100,101,"pl-s"],[105,106,"pl-s"],[106,118,"pl-c1"],[118,119,"pl-s"],[121,122,"pl-s"],[122,130,"pl-c1"],[130,131,"pl-s"],[135,136,"pl-s"],[136,142,"pl-c1"],[142,143,"pl-s"],[145,146,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,34,"pl-c1"],[34,35,"pl-s"],[36,37,"pl-ml"],[57,58,"pl-ml"]],[[0,1,"pl-ml"],[45,46,"pl-ml"],[54,55,"pl-ml"],[56,57,"pl-s"],[57,59,"pl-c1"],[59,60,"pl-s"],[61,62,"pl-ml"],[121,122,"pl-s"],[122,145,"pl-c1"],[145,146,"pl-s"],[148,149,"pl-ml"]],[[0,1,"pl-ml"],[20,21,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,43,"pl-c1"],[43,44,"pl-s"],[45,46,"pl-ml"],[66,67,"pl-s"],[67,76,"pl-c1"],[76,77,"pl-s"],[81,82,"pl-s"],[82,94,"pl-c1"],[94,95,"pl-s"],[98,99,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,31,"pl-c1"],[31,32,"pl-s"],[33,34,"pl-ml"],[92,93,"pl-ml"]],[[0,1,"pl-ml"],[29,30,"pl-ml"],[38,39,"pl-ml"],[40,41,"pl-s"],[41,43,"pl-c1"],[43,44,"pl-s"],[45,46,"pl-ml"],[61,62,"pl-s"],[62,93,"pl-c1"],[93,94,"pl-s"],[116,117,"pl-s"],[117,138,"pl-c1"],[138,139,"pl-s"],[141,142,"pl-s"],[142,158,"pl-c1"],[158,159,"pl-s"],[161,162,"pl-s"],[162,190,"pl-c1"],[190,191,"pl-s"],[197,198,"pl-s"],[198,241,"pl-c1"],[241,242,"pl-s"],[263,264,"pl-s"],[264,279,"pl-c1"],[279,280,"pl-s"],[286,287,"pl-s"],[287,321,"pl-c1"],[321,322,"pl-s"],[342,343,"pl-ml"]],[[0,1,"pl-ml"],[36,37,"pl-ml"],[43,44,"pl-ml"],[45,46,"pl-s"],[46,50,"pl-c1"],[50,51,"pl-s"],[52,53,"pl-ml"],[59,60,"pl-s"],[60,64,"pl-c1"],[64,65,"pl-s"],[153,154,"pl-s"],[154,159,"pl-c1"],[159,160,"pl-s"],[199,200,"pl-s"],[200,218,"pl-c1"],[218,219,"pl-s"],[221,222,"pl-ml"]],[[0,1,"pl-ml"],[21,22,"pl-ml"],[30,31,"pl-ml"],[32,33,"pl-s"],[33,41,"pl-c1"],[41,42,"pl-s"],[43,44,"pl-ml"],[73,74,"pl-s"],[74,80,"pl-c1"],[80,81,"pl-s"],[83,84,"pl-s"],[84,93,"pl-c1"],[93,94,"pl-s"],[96,97,"pl-s"],[97,104,"pl-c1"],[104,105,"pl-s"],[107,108,"pl-s"],[108,116,"pl-c1"],[116,117,"pl-s"],[122,123,"pl-s"],[123,128,"pl-c1"],[128,129,"pl-s"],[151,152,"pl-s"],[152,171,"pl-c1"],[171,172,"pl-s"],[174,175,"pl-s"],[175,180,"pl-c1"],[180,181,"pl-s"],[296,297,"pl-ml"]],[[0,1,"pl-ml"],[17,18,"pl-ml"],[26,27,"pl-ml"],[28,29,"pl-s"],[29,371,"pl-c1"],[371,372,"pl-s"],[373,374,"pl-ml"],[422,423,"pl-s"],[423,435,"pl-c1"],[435,436,"pl-s"],[462,463,"pl-ml"]],[[0,1,"pl-ml"],[40,41,"pl-ml"],[49,50,"pl-ml"],[51,52,"pl-s"],[52,54,"pl-c1"],[54,55,"pl-s"],[56,57,"pl-ml"],[106,107,"pl-s"],[107,115,"pl-c1"],[115,116,"pl-s"],[118,119,"pl-ml"]],[[0,1,"pl-ml"],[41,42,"pl-ml"],[50,51,"pl-ml"],[52,53,"pl-s"],[53,55,"pl-c1"],[55,56,"pl-s"],[57,58,"pl-ml"],[108,109,"pl-s"],[109,117,"pl-c1"],[117,118,"pl-s"],[120,121,"pl-ml"]],[[0,1,"pl-ml"],[42,43,"pl-ml"],[51,52,"pl-ml"],[53,54,"pl-s"],[54,56,"pl-c1"],[56,57,"pl-s"],[58,59,"pl-ml"],[110,111,"pl-s"],[111,119,"pl-c1"],[119,120,"pl-s"],[122,123,"pl-ml"]],[[0,1,"pl-ml"],[42,43,"pl-ml"],[51,52,"pl-ml"],[53,54,"pl-s"],[54,56,"pl-c1"],[56,57,"pl-s"],[58,59,"pl-ml"],[113,114,"pl-s"],[114,122,"pl-c1"],[122,123,"pl-s"],[125,126,"pl-ml"]],[[0,1,"pl-ml"],[43,44,"pl-ml"],[52,53,"pl-ml"],[54,55,"pl-s"],[55,57,"pl-c1"],[57,58,"pl-s"],[59,60,"pl-ml"],[115,116,"pl-s"],[116,124,"pl-c1"],[124,125,"pl-s"],[127,128,"pl-ml"]],[[0,1,"pl-ml"],[44,45,"pl-ml"],[53,54,"pl-ml"],[55,56,"pl-s"],[56,58,"pl-c1"],[58,59,"pl-s"],[60,61,"pl-ml"],[117,118,"pl-s"],[118,126,"pl-c1"],[126,127,"pl-s"],[129,130,"pl-ml"]],[[0,1,"pl-ml"],[53,54,"pl-ml"],[62,63,"pl-ml"],[64,65,"pl-s"],[65,67,"pl-c1"],[67,68,"pl-s"],[69,70,"pl-ml"],[85,86,"pl-s"],[86,90,"pl-c1"],[90,91,"pl-s"],[95,96,"pl-s"],[96,104,"pl-c1"],[104,105,"pl-s"],[145,146,"pl-ml"]],[[0,1,"pl-ml"],[54,55,"pl-ml"],[63,64,"pl-ml"],[65,66,"pl-s"],[66,68,"pl-c1"],[68,69,"pl-s"],[70,71,"pl-ml"],[86,87,"pl-s"],[87,91,"pl-c1"],[91,92,"pl-s"],[96,97,"pl-s"],[97,105,"pl-c1"],[105,106,"pl-s"],[144,145,"pl-ml"]],[[0,1,"pl-ml"],[48,49,"pl-ml"],[55,56,"pl-ml"],[57,58,"pl-s"],[58,62,"pl-c1"],[62,63,"pl-s"],[64,65,"pl-ml"],[71,72,"pl-s"],[72,76,"pl-c1"],[76,77,"pl-s"],[106,107,"pl-s"],[107,132,"pl-c1"],[132,133,"pl-s"],[195,196,"pl-s"],[196,201,"pl-c1"],[201,202,"pl-s"],[213,214,"pl-s"],[214,256,"pl-c1"],[256,257,"pl-s"],[261,262,"pl-s"],[262,264,"pl-c1"],[264,265,"pl-s"],[267,268,"pl-ml"]],[[0,1,"pl-ml"],[31,32,"pl-ml"],[40,41,"pl-ml"],[42,43,"pl-s"],[43,53,"pl-c1"],[53,54,"pl-s"],[55,56,"pl-ml"],[74,75,"pl-s"],[75,83,"pl-c1"],[83,84,"pl-s"],[107,108,"pl-s"],[108,116,"pl-c1"],[116,117,"pl-s"],[140,141,"pl-ml"]],[[0,1,"pl-ml"],[50,51,"pl-ml"],[59,60,"pl-ml"],[61,62,"pl-s"],[62,64,"pl-c1"],[64,65,"pl-s"],[66,67,"pl-ml"],[82,83,"pl-s"],[83,87,"pl-c1"],[87,88,"pl-s"],[92,93,"pl-s"],[93,101,"pl-c1"],[101,102,"pl-s"],[139,140,"pl-ml"]],[[0,1,"pl-ml"],[51,52,"pl-ml"],[60,61,"pl-ml"],[62,63,"pl-s"],[63,65,"pl-c1"],[65,66,"pl-s"],[67,68,"pl-ml"],[83,84,"pl-s"],[84,88,"pl-c1"],[88,89,"pl-s"],[93,94,"pl-s"],[94,102,"pl-c1"],[102,103,"pl-s"],[143,144,"pl-s"],[144,184,"pl-c1"],[184,185,"pl-s"],[188,189,"pl-ml"]],[[0,1,"pl-ml"],[28,29,"pl-ml"],[37,38,"pl-ml"],[39,40,"pl-s"],[40,50,"pl-c1"],[50,51,"pl-s"],[52,53,"pl-ml"],[77,78,"pl-s"],[78,86,"pl-c1"],[86,87,"pl-s"],[117,118,"pl-s"],[118,126,"pl-c1"],[126,127,"pl-s"],[167,168,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,43,"pl-c1"],[43,44,"pl-s"],[45,46,"pl-ml"],[61,62,"pl-s"],[62,69,"pl-c1"],[69,70,"pl-s"],[72,73,"pl-s"],[73,82,"pl-c1"],[82,83,"pl-s"],[85,86,"pl-s"],[86,94,"pl-c1"],[94,95,"pl-s"],[100,101,"pl-s"],[101,107,"pl-c1"],[107,108,"pl-s"],[115,116,"pl-s"],[116,124,"pl-c1"],[124,125,"pl-s"],[130,131,"pl-s"],[131,149,"pl-c1"],[149,150,"pl-s"],[154,155,"pl-s"],[155,163,"pl-c1"],[163,164,"pl-s"],[185,186,"pl-s"],[186,198,"pl-c1"],[198,199,"pl-s"],[250,251,"pl-ml"]],[[0,1,"pl-ml"],[9,10,"pl-ml"],[18,19,"pl-ml"],[20,21,"pl-s"],[21,427,"pl-c1"],[427,428,"pl-s"],[429,430,"pl-ml"],[431,432,"pl-s"],[446,447,"pl-s"],[447,448,"pl-s"],[448,499,"pl-corl"],[499,500,"pl-s"],[562,563,"pl-s"],[563,568,"pl-c1"],[568,569,"pl-s"],[676,677,"pl-s"],[677,690,"pl-c1"],[690,691,"pl-s"],[728,729,"pl-s"],[729,763,"pl-c1"],[763,764,"pl-s"],[769,770,"pl-s"],[770,788,"pl-c1"],[788,789,"pl-s"],[793,794,"pl-s"],[794,813,"pl-c1"],[813,814,"pl-s"],[818,819,"pl-s"],[819,824,"pl-c1"],[824,825,"pl-s"],[831,832,"pl-s"],[832,862,"pl-c1"],[862,863,"pl-s"],[964,965,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,46,"pl-c1"],[46,47,"pl-s"],[48,49,"pl-ml"],[108,109,"pl-s"],[109,120,"pl-c1"],[120,121,"pl-s"],[127,128,"pl-s"],[128,137,"pl-c1"],[137,138,"pl-s"],[172,173,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[29,30,"pl-ml"],[31,32,"pl-s"],[32,36,"pl-c1"],[36,37,"pl-s"],[38,39,"pl-ml"],[109,110,"pl-s"],[110,119,"pl-c1"],[119,120,"pl-s"],[130,131,"pl-ml"]],[[0,1,"pl-ml"],[23,24,"pl-ml"],[32,33,"pl-ml"],[34,35,"pl-s"],[35,44,"pl-c1"],[44,45,"pl-s"],[46,47,"pl-ml"],[99,100,"pl-s"],[100,109,"pl-c1"],[109,110,"pl-s"],[120,121,"pl-ml"]],[[0,1,"pl-ml"],[17,18,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,32,"pl-c1"],[32,33,"pl-s"],[34,35,"pl-ml"],[80,81,"pl-s"],[81,85,"pl-c1"],[85,86,"pl-s"],[92,93,"pl-s"],[93,127,"pl-c1"],[127,128,"pl-s"],[160,161,"pl-ml"]],[[0,1,"pl-ml"],[15,16,"pl-ml"],[24,25,"pl-ml"],[26,27,"pl-s"],[27,135,"pl-c1"],[135,136,"pl-s"],[137,138,"pl-ml"],[194,195,"pl-s"],[195,204,"pl-c1"],[204,205,"pl-s"],[253,254,"pl-s"],[254,262,"pl-c1"],[262,263,"pl-s"],[264,265,"pl-s"],[265,275,"pl-c1"],[275,276,"pl-s"],[334,335,"pl-s"],[335,355,"pl-c1"],[355,356,"pl-s"],[391,392,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,52,"pl-c1"],[52,53,"pl-s"],[54,55,"pl-ml"],[82,83,"pl-ml"]],[[0,1,"pl-ml"],[24,25,"pl-ml"],[33,34,"pl-ml"],[35,36,"pl-s"],[36,58,"pl-c1"],[58,59,"pl-s"],[60,61,"pl-ml"],[140,141,"pl-ml"]],[[0,1,"pl-ml"],[26,27,"pl-ml"],[35,36,"pl-ml"],[37,38,"pl-s"],[38,54,"pl-c1"],[54,55,"pl-s"],[56,57,"pl-ml"],[83,84,"pl-ml"]],[[0,1,"pl-ml"],[19,20,"pl-ml"],[28,29,"pl-ml"],[30,31,"pl-s"],[31,39,"pl-c1"],[39,40,"pl-s"],[41,42,"pl-ml"],[61,62,"pl-ml"]],[[0,1,"pl-ml"],[22,23,"pl-ml"],[31,32,"pl-ml"],[33,34,"pl-s"],[34,42,"pl-c1"],[42,43,"pl-s"],[44,45,"pl-ml"],[98,99,"pl-s"],[99,128,"pl-c1"],[128,129,"pl-s"],[131,132,"pl-ml"]],[[0,1,"pl-ml"],[37,38,"pl-ml"],[44,45,"pl-ml"],[46,47,"pl-s"],[47,52,"pl-c1"],[52,53,"pl-s"],[54,55,"pl-ml"],[132,133,"pl-s"],[133,137,"pl-c1"],[137,138,"pl-s"],[154,155,"pl-s"],[155,167,"pl-c1"],[167,168,"pl-s"],[169,170,"pl-s"],[170,174,"pl-c1"],[174,175,"pl-s"],[218,219,"pl-ml"]],[[0,1,"pl-ml"],[27,28,"pl-ml"],[36,37,"pl-ml"],[38,39,"pl-s"],[39,121,"pl-c1"],[121,122,"pl-s"],[123,124,"pl-ml"],[188,189,"pl-ml"]],[[0,1,"pl-ml"],[38,39,"pl-ml"],[44,45,"pl-ml"],[46,47,"pl-s"],[47,51,"pl-c1"],[51,52,"pl-s"],[53,54,"pl-ml"],[92,93,"pl-s"],[93,102,"pl-c1"],[102,103,"pl-s"],[106,107,"pl-ml"]],[],[[0,18,"pl-mh"],[3,18,"pl-en"]],[],[[12,14,"pl-s"],[18,20,"pl-s"],[84,85,"pl-s"],[85,92,"pl-c1"],[92,93,"pl-s"]],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[[0,3,"pl-s"]],[],[[0,1,"pl-s"],[1,14,"pl-c1"],[14,15,"pl-s"],[24,26,"pl-s"],[41,43,"pl-s"],[104,105,"pl-s"],[136,137,"pl-s"],[137,138,"pl-s"],[138,171,"pl-corl"],[171,172,"pl-s"],[225,226,"pl-s"],[226,243,"pl-c1"],[243,244,"pl-s"]],[],[[0,1,"pl-v"],[2,4,"pl-s"],[26,28,"pl-s"],[30,31,"pl-s"],[31,48,"pl-c1"],[48,49,"pl-s"],[51,52,"pl-s"],[52,69,"pl-c1"],[69,70,"pl-s"],[81,82,"pl-s"],[82,89,"pl-c1"],[89,90,"pl-s"]],[[0,1,"pl-v"],[2,4,"pl-s"],[13,15,"pl-s"],[24,25,"pl-s"],[25,54,"pl-c1"],[54,55,"pl-s"],[61,62,"pl-s"],[62,106,"pl-c1"],[106,107,"pl-s"],[111,112,"pl-s"],[112,166,"pl-c1"],[166,167,"pl-s"]],[[0,1,"pl-v"],[2,4,"pl-s"],[11,13,"pl-s"],[44,45,"pl-s"],[45,74,"pl-c1"],[74,75,"pl-s"]],[[0,1,"pl-v"],[2,4,"pl-s"],[16,18,"pl-s"],[36,37,"pl-s"],[37,62,"pl-c1"],[62,63,"pl-s"]],[[0,1,"pl-v"],[2,4,"pl-s"],[16,18,"pl-s"]],[],[],[],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,27,"pl-c1"],[27,28,"pl-s"],[28,30,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,15,"pl-c1"],[15,16,"pl-s"],[16,18,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,21,"pl-c1"],[21,22,"pl-s"],[22,24,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,12,"pl-c1"],[12,13,"pl-s"],[13,15,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,17,"pl-c1"],[17,18,"pl-s"],[18,20,"pl-s"],[23,24,"pl-s"],[35,36,"pl-s"],[36,37,"pl-s"],[37,50,"pl-corl"],[50,51,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,15,"pl-c1"],[15,16,"pl-s"],[16,18,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[3,5,"pl-s"],[5,6,"pl-s"],[6,14,"pl-c1"],[14,15,"pl-s"],[15,17,"pl-s"]],[],[],[],[[0,3,"pl-s"],[3,7,"pl-en"]],[],[],[],[],[],[],[],[[0,3,"pl-s"]],[],[[20,21,"pl-s"],[21,37,"pl-c1"],[37,38,"pl-s"],[40,41,"pl-s"],[41,54,"pl-c1"],[54,55,"pl-s"],[57,58,"pl-s"],[58,68,"pl-c1"],[68,69,"pl-s"]],[],[[4,5,"pl-s"],[5,21,"pl-c1"],[21,22,"pl-s"],[157,158,"pl-s"],[158,168,"pl-c1"],[168,169,"pl-s"]],[],[[0,1,"pl-s"],[1,17,"pl-c1"],[17,18,"pl-s"]],[],[[0,20,"pl-mh"],[3,20,"pl-en"]],[],[[0,1,"pl-s"],[1,2,"pl-v"],[33,34,"pl-s"],[39,40,"pl-s"],[40,41,"pl-s"],[41,49,"pl-corl"],[49,50,"pl-s"],[146,147,"pl-s"],[147,157,"pl-c1"],[157,158,"pl-s"],[196,197,"pl-s"],[197,222,"pl-c1"],[222,223,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[18,19,"pl-s"],[19,29,"pl-c1"],[29,30,"pl-s"],[49,50,"pl-s"],[50,96,"pl-c1"],[96,97,"pl-s"],[109,110,"pl-s"],[110,120,"pl-c1"],[120,121,"pl-s"],[127,128,"pl-s"],[128,135,"pl-c1"],[135,136,"pl-s"]],[[0,1,"pl-s"],[1,2,"pl-v"],[18,19,"pl-s"],[19,30,"pl-c1"],[30,31,"pl-s"],[78,79,"pl-s"],[95,96,"pl-s"],[96,97,"pl-s"],[97,115,"pl-corl"],[115,116,"pl-s"],[118,119,"pl-s"],[119,133,"pl-c1"],[133,134,"pl-s"]]],"colorizedLines":null}},"title":"trustee/deployment/helm-chart/README.md at main · confidential-containers/trustee","appPayload":{},"meta":{"title":"trustee/deployment/helm-chart/README.md at main · confidential-containers/trustee"}}</script>
  <div data-target="react-app.reactRoot"><meta name="github-code-view-meta-stats" id="github-code-view-meta-stats" data-hydrostats="publish"/> <!-- --> <a hidden="" id="code-view-repo-link" href="/confidential-containers/trustee" data-discover="true"></a> <div class="d-none"></div><div><div style="--spacing:var(--spacing-none)" class="prc-PageLayout-PageLayoutRoot--KH-d" data-component="SplitPageLayout" data-has-sidebar="true"><div class="prc-PageLayout-SidebarWrapper-kLG4B CopilotSidePanelSidebar-module__SidePanel__L3O0C CopilotSidePanelSidebar-module__HiddenSidePanel__TBRGn" style="--spacing-column:var(--spacing-none)" data-is-hidden="false" data-position="end" data-sticky="true" data-responsive-variant="fullscreen"><div class="prc-PageLayout-VerticalDivider-9QRmK prc-PageLayout-SidebarVerticalDivider-0Rl0V" data-component="PageLayout.VerticalDivider" data-variant="line" data-position="end" style="--spacing:var(--spacing-none)"><div class="prc-PageLayout-DraggableHandle-9s6B4" data-component="PageLayout.DragHandle" role="slider" aria-label="Draggable pane splitter" aria-valuemin="450" aria-valuemax="768" aria-valuenow="544" aria-valuetext="Pane width 544 pixels" tabindex="0"></div></div><div class="prc-PageLayout-Sidebar-iciWg" data-component="SplitPageLayout.Sidebar" data-resizable="true" style="--spacing:var(--spacing-normal);--pane-min-width:450px;--pane-max-width:768px;--pane-width-custom:544px;--pane-width-size:var(--pane-width-custom);--pane-width:544px"><div class="height-full" data-testid="copilot-code-view-side-panel"><div id="copilot-side-panel-content" class="height-full"></div></div></div></div><div class="prc-PageLayout-PageLayoutWrapper-2BhU2" data-width="full"><div class="prc-PageLayout-PageLayoutContent-BneH9"><div id="repos-file-tree-sidebar" class="CodeViewFileTreeLayout-module__sidebar__n_Aau" tabindex="0"><div class="prc-PageLayout-PaneWrapper-pHPop ReposFileTreePane-module__Pane__rBZpI ReposFileTreePane-module__HideTree__AYZnm ReposFileTreePane-module__HidePane__VHAVt" style="--offset-header:0px;--spacing-row:var(--spacing-none);--spacing-column:var(--spacing-none)" data-is-hidden="false" data-position="start" data-sticky="true"><div class="prc-PageLayout-HorizontalDivider-JLVqp prc-PageLayout-PaneHorizontalDivider-9tbnE" data-component="PageLayout.HorizontalDivider" data-variant-regular="none" data-variant-narrow="none" data-position="start" style="--spacing-divider:var(--spacing-none);--spacing:var(--spacing-none)"></div><div class="prc-PageLayout-Pane-AyzHK" data-component="SplitPageLayout.Pane" data-resizable="true" style="--spacing:var(--spacing-none);--pane-min-width:256px;--pane-max-width:calc(100vw - var(--pane-max-width-diff));--pane-width-size:var(--pane-width-large);--pane-width:320px"></div><div class="prc-PageLayout-VerticalDivider-9QRmK prc-PageLayout-PaneVerticalDivider-le57g" data-component="PageLayout.VerticalDivider" data-variant-narrow="none" data-variant-regular="line" data-variant-wide="line" data-position="start" style="--spacing:var(--spacing-none)"><div class="prc-PageLayout-DraggableHandle-9s6B4" data-component="PageLayout.DragHandle" role="slider" aria-label="Draggable pane splitter" aria-valuemin="256" aria-valuemax="600" aria-valuenow="320" aria-valuetext="Pane width 320 pixels" tabindex="0"></div></div></div></div><div data-component="SplitPageLayout.Content" class="prc-PageLayout-ContentWrapper-gR9eG"><div class="prc-PageLayout-Content-xWL-A" data-width="full" style="--spacing:var(--spacing-none)"><div class="SharedPageLayout-module__content__IwGAp" data-selector="repos-split-pane-content" id="repos-split-pane-content" tabindex="0"> <!-- --> <div class="container CodeViewHeader-module__Box__JkPOb"><div class="CodeViewHeader-module__StickyHeader__Qn7UN" id="StickyHeader"><div class="CodeViewHeader-module__Box_1__SbNDV"><div class="CodeViewHeader-module__Box_2__TB46f"><div class="react-code-view-header-wrap--narrow CodeViewHeader-module__Box_3__q1zUL"><div class="CodeViewHeader-module__treeToggleWrapper__RQ__9"><h2 class="use-tree-pane-module__Heading__s4QbZ prc-Heading-Heading-MtWFE" data-component="Heading"><button data-component="Button" type="button" aria-label="Expand file tree" data-testid="expand-file-tree-button-mobile" class="prc-Button-ButtonBase-9n-Xk ExpandFileTreeButton-module__Button_1__Svs95" data-loading="false" data-size="medium" data-variant="invisible"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-arrow-left" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M7.78 12.53a.75.75 0 0 1-1.06 0L2.47 8.28a.75.75 0 0 1 0-1.06l4.25-4.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042L4.81 7h7.44a.75.75 0 0 1 0 1.5H4.81l2.97 2.97a.75.75 0 0 1 0 1.06Z"></path></svg></span><span data-component="text" class="prc-Button-Label-FWkx3">Files</span></span></button><button data-component="IconButton" type="button" data-testid="expand-file-tree-button" aria-controls="repos-file-tree" class="prc-Button-ButtonBase-9n-Xk position-relative ExpandFileTreeButton-module__expandButton__hDOcv ExpandFileTreeButton-module__filesButtonBreakpoint__zEvz3 fgColor-muted prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="medium" data-variant="invisible" aria-labelledby="_R_4lla9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-sidebar-collapse" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M6.823 7.823a.25.25 0 0 1 0 .354l-2.396 2.396A.25.25 0 0 1 4 10.396V5.604a.25.25 0 0 1 .427-.177Z"></path><path d="M1.75 0h12.5C15.216 0 16 .784 16 1.75v12.5A1.75 1.75 0 0 1 14.25 16H1.75A1.75 1.75 0 0 1 0 14.25V1.75C0 .784.784 0 1.75 0ZM1.5 1.75v12.5c0 .138.112.25.25.25H9.5v-13H1.75a.25.25 0 0 0-.25.25ZM11 14.5h3.25a.25.25 0 0 0 .25-.25V1.75a.25.25 0 0 0-.25-.25H11Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="se" data-component="Tooltip" aria-hidden="true" id="_R_4lla9lik5_">Expand file tree</span><div class="d-none"></div></h2></div><div class="react-code-view-header-mb--narrow mr-2"><button data-component="Button" type="button" aria-haspopup="true" aria-expanded="false" tabindex="0" aria-label="main branch" data-testid="anchor-button" data-icv-name="Switch branches/tags" class="prc-Button-ButtonBase-9n-Xk ref-selector-class RefSelectorAnchoredOverlay-module__RefSelectorOverlayBtn__a3WK3" data-loading="false" data-size="medium" data-variant="default" id="ref-picker-repos-header-ref-selector-wide"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-git-branch" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M9.5 3.25a2.25 2.25 0 1 1 3 2.122V6A2.5 2.5 0 0 1 10 8.5H6a1 1 0 0 0-1 1v1.128a2.251 2.251 0 1 1-1.5 0V5.372a2.25 2.25 0 1 1 1.5 0v1.836A2.493 2.493 0 0 1 6 7h4a1 1 0 0 0 1-1v-.628A2.25 2.25 0 0 1 9.5 3.25Zm-6 0a.75.75 0 1 0 1.5 0 .75.75 0 0 0-1.5 0Zm8.25-.75a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5ZM4.25 12a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5Z"></path></svg></span><span data-component="text" class="prc-Button-Label-FWkx3"><div class="RefSelectorAnchoredOverlay-module__RefSelectorOverlayContainer__yaf4p"><div style="max-width:125px" class="ref-selector-button-text-container RefSelectorAnchoredOverlay-module__RefSelectorBtnTextContainer__Di3rk"><span class="RefSelectorAnchoredOverlay-module__RefSelectorText__w_fmP">main</span></div></div></span><span data-component="trailingVisual" class="prc-Button-Visual-YNt2F prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-down" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m4.427 7.427 3.396 3.396a.25.25 0 0 0 .354 0l3.396-3.396A.25.25 0 0 0 11.396 7H4.604a.25.25 0 0 0-.177.427Z"></path></svg></span></span></button><div class="d-none"></div></div><div class="react-code-view-header-mb--narrow CodeViewHeader-module__Box_5__MQ0hL"><div class="Breadcrumb-module__container__Vxvev Breadcrumb-module__lg__Rjz0A"><nav data-testid="breadcrumbs" aria-labelledby="repos-header-breadcrumb-heading" id="repos-header-breadcrumb" class="Breadcrumb-module__nav__rQFDj"><h2 class="sr-only ScreenReaderHeading-module__userSelectNone__rwWIk prc-Heading-Heading-MtWFE" data-component="Heading" data-testid="screen-reader-heading" id="repos-header-breadcrumb-heading">Breadcrumbs</h2><ol class="Breadcrumb-module__list__ZH6zr"><li class="Breadcrumb-module__listItem__Ib0x_"><a class="Breadcrumb-module__repoLink__O2Nbs prc-Link-Link-9ZwDx" data-component="Link" data-testid="breadcrumbs-repo-link" href="/confidential-containers/trustee/tree/main" data-discover="true">trustee</a></li><li class="Breadcrumb-module__listItem__Ib0x_"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__lg__Rjz0A" aria-hidden="true">/</span><a class="Breadcrumb-module__directoryLink__kQy_t prc-Link-Link-9ZwDx" data-component="Link" href="/confidential-containers/trustee/tree/main/deployment" data-discover="true">deployment</a></li><li class="Breadcrumb-module__listItem__Ib0x_"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__lg__Rjz0A" aria-hidden="true">/</span><a class="Breadcrumb-module__directoryLink__kQy_t prc-Link-Link-9ZwDx" data-component="Link" href="/confidential-containers/trustee/tree/main/deployment/helm-chart" data-discover="true">helm-chart</a></li></ol></nav><div data-testid="breadcrumbs-filename" class="Breadcrumb-module__filename__equZR"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__lg__Rjz0A" aria-hidden="true">/</span><h1 class="Breadcrumb-module__filenameHeading__MNMtw Breadcrumb-module__lg__Rjz0A prc-Heading-Heading-MtWFE" data-component="Heading" tabindex="-1" id="file-name-id">README.md</h1></div><button data-component="IconButton" type="button" class="prc-Button-ButtonBase-9n-Xk ml-2 prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="invisible" aria-labelledby="_R_7lla9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-copy" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z"></path><path d="M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z"></path></svg></button><span class="CopyToClipboardIconButton-module__tooltip__WyiwL prc-TooltipV2-Tooltip-tLeuB" data-direction="nw" data-component="Tooltip" aria-label="Copy path" aria-hidden="true" id="_R_7lla9lik5_">Copy path</span></div></div></div><div class="react-code-view-header-element--wide"><div class="CodeViewHeader-module__Box_7___0R6c"><div class="d-flex gap-2"><div><div class="CodeViewHeader-module__FileResultsList__JDzUy"><span class="d-flex FileResultsList-module__FilesSearchBox__ivVkc TextInput-wrapper prc-components-TextInputWrapper-Hpdqi prc-components-TextInputBaseWrapper-wY-n0" data-no-trailing-action="true" data-component="TextInput" data-leading-visual="true" data-trailing-visual="true" aria-busy="false"><span class="TextInput-icon" id="_R_1cpla9lik5_" aria-hidden="true" data-component="TextInput.LeadingVisual"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-search" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M10.68 11.74a6 6 0 0 1-7.922-8.982 6 6 0 0 1 8.982 7.922l3.04 3.04a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215ZM11.5 7a4.499 4.499 0 1 0-8.997 0A4.499 4.499 0 0 0 11.5 7Z"></path></svg></span><input type="text" aria-label="Go to file" role="combobox" aria-controls="file-results-list" aria-expanded="false" aria-haspopup="dialog" autoCorrect="off" spellCheck="false" placeholder="Go to file" aria-describedby="_R_1cpla9lik5_ _R_1cpla9lik5H1_" data-component="input" class="prc-components-Input-IwWrt" value=""/><span class="TextInput-icon" id="_R_1cpla9lik5H1_" aria-hidden="true" data-component="TextInput.TrailingVisual"></span></span></div><div class="d-none"></div></div><button data-component="Button" type="button" style="display:none" class="prc-Button-ButtonBase-9n-Xk NavigationMenu-module__Button__LpKgm" data-loading="false" data-no-visuals="true" data-size="medium" data-variant="default"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="text" class="prc-Button-Label-FWkx3">Blame</span></span></button><div class="d-none"></div><button data-component="IconButton" type="button" data-testid="more-file-actions-button-nav-menu-wide" aria-haspopup="true" aria-expanded="false" tabindex="0" class="prc-Button-ButtonBase-9n-Xk js-blob-dropdown-click NavigationMenu-module__IconButton__HpX3G prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="medium" data-variant="default" aria-labelledby="_R_7p9la9lik5_" id="_R_99la9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-kebab-horizontal" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3ZM1.5 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Zm13 0a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="nw" data-component="Tooltip" aria-hidden="true" id="_R_7p9la9lik5_">More file actions</span></div></div></div><div class="react-code-view-header-element--narrow"><div class="CodeViewHeader-module__Box_7___0R6c"><div class="d-flex gap-2"><button data-component="Button" type="button" style="display:none" class="prc-Button-ButtonBase-9n-Xk NavigationMenu-module__Button__LpKgm" data-loading="false" data-no-visuals="true" data-size="medium" data-variant="default"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="text" class="prc-Button-Label-FWkx3">Blame</span></span></button><div class="d-none"></div><button data-component="IconButton" type="button" data-testid="more-file-actions-button-nav-menu-narrow" aria-haspopup="true" aria-expanded="false" tabindex="0" class="prc-Button-ButtonBase-9n-Xk js-blob-dropdown-click NavigationMenu-module__IconButton__HpX3G prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="medium" data-variant="default" aria-labelledby="_R_7pdla9lik5_" id="_R_9dla9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-kebab-horizontal" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3ZM1.5 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Zm13 0a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="nw" data-component="Tooltip" aria-hidden="true" id="_R_7pdla9lik5_">More file actions</span></div></div></div></div></div></div></div><div class="CodeView-module__contentWrapper__cG2JH"><div class="react-code-view-bottom-padding"><div class="BlobTopBanners-module__Box__v_nvx"></div></div> <div class="d-none"></div><div class="d-flex flex-column border rounded-2 tmp-mb-3 pl-1"><div class="LatestCommit-module__Box__B25ZT"><h2 class="sr-only ScreenReaderHeading-module__userSelectNone__rwWIk prc-Heading-Heading-MtWFE" data-component="Heading" data-testid="screen-reader-heading">Latest commit</h2><div style="width:120px" class="Skeleton Skeleton--text" data-testid="loading"> </div><div class="d-flex flex-shrink-0 gap-2"><div data-testid="latest-commit-details" class="d-none d-sm-flex flex-items-center"></div><div class="d-flex gap-2"><h2 class="sr-only ScreenReaderHeading-module__userSelectNone__rwWIk prc-Heading-Heading-MtWFE" data-component="Heading" data-testid="screen-reader-heading">History</h2><a data-component="LinkButton" href="/confidential-containers/trustee/commits/main/deployment/helm-chart/README.md" class="prc-Button-ButtonBase-9n-Xk d-none d-lg-flex LinkButton-module__linkButton__nFnov flex-items-center fgColor-default" data-loading="false" data-size="small" data-variant="invisible"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-history" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m.427 1.927 1.215 1.215a8.002 8.002 0 1 1-1.6 5.685.75.75 0 1 1 1.493-.154 6.5 6.5 0 1 0 1.18-4.458l1.358 1.358A.25.25 0 0 1 3.896 6H.25A.25.25 0 0 1 0 5.75V2.104a.25.25 0 0 1 .427-.177ZM7.75 4a.75.75 0 0 1 .75.75v2.992l2.028.812a.75.75 0 0 1-.557 1.392l-2.5-1A.751.751 0 0 1 7 8.25v-3.5A.75.75 0 0 1 7.75 4Z"></path></svg></span><span data-component="text" class="prc-Button-Label-FWkx3"><span class="fgColor-default">History</span></span></span></a><div class="d-sm-none"></div><div class="d-flex d-lg-none"><a data-component="LinkButton" aria-label="View commit history for this file." href="/confidential-containers/trustee/commits/main/deployment/helm-chart/README.md" class="prc-Button-ButtonBase-9n-Xk LinkButton-module__linkButton__nFnov flex-items-center fgColor-default" data-loading="false" data-size="small" data-variant="invisible" aria-describedby="_R_4mlala9lik5_"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-history" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m.427 1.927 1.215 1.215a8.002 8.002 0 1 1-1.6 5.685.75.75 0 1 1 1.493-.154 6.5 6.5 0 1 0 1.18-4.458l1.358 1.358A.25.25 0 0 1 3.896 6H.25A.25.25 0 0 1 0 5.75V2.104a.25.25 0 0 1 .427-.177ZM7.75 4a.75.75 0 0 1 .75.75v2.992l2.028.812a.75.75 0 0 1-.557 1.392l-2.5-1A.751.751 0 0 1 7 8.25v-3.5A.75.75 0 0 1 7.75 4Z"></path></svg></span></span></a><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="s" data-component="Tooltip" role="tooltip" aria-hidden="true" id="_R_4mlala9lik5_">History</span></div></div></div></div></div><div class="d-flex flex-row"><div class="container BlobViewContent-module__blobContainer__DtH2d"><div class="react-code-size-details-banner BlobViewContent-module__codeSizeDetails__e5sUw"><div class="react-code-size-details-banner CodeSizeDetails-module__Box__VcD6l"><div class="text-mono CodeSizeDetails-module__Box_1__GVxQL"><div data-testid="blob-size" class="CodeSizeDetails-module__Truncate_1__lE93V prc-Truncate-Truncate-2G1eo" data-inline="true" title="38.9 KB" style="--truncate-max-width:100%"><span>477 lines (376 loc) · 38.9 KB</span></div></div></div></div><div class="react-blob-view-header-sticky BlobViewContent-module__stickyHeader__VwxB5" id="repos-sticky-header"><div class="BlobViewHeader-module__Box__yhm9u"><div class="react-blob-sticky-header"><div class="FileNameStickyHeader-module__outerWrapper__ZL4Xc FileNameStickyHeader-module__outerWrapperHidden__Zpynk"><div class="FileNameStickyHeader-module__Box_1__Hazu5"><div class="FileNameStickyHeader-module__Box_2__hoolP"><div class="FileNameStickyHeader-module__Box_3__MVKsk"><button data-component="Button" type="button" aria-haspopup="true" aria-expanded="false" tabindex="0" aria-label="main branch" data-testid="anchor-button" data-icv-name="Switch branches/tags" class="prc-Button-ButtonBase-9n-Xk ref-selector-class RefSelectorAnchoredOverlay-module__RefSelectorOverlayBtn__a3WK3" data-loading="false" data-size="medium" data-variant="default" id="ref-picker-repos-header-ref-selector"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-git-branch" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M9.5 3.25a2.25 2.25 0 1 1 3 2.122V6A2.5 2.5 0 0 1 10 8.5H6a1 1 0 0 0-1 1v1.128a2.251 2.251 0 1 1-1.5 0V5.372a2.25 2.25 0 1 1 1.5 0v1.836A2.493 2.493 0 0 1 6 7h4a1 1 0 0 0 1-1v-.628A2.25 2.25 0 0 1 9.5 3.25Zm-6 0a.75.75 0 1 0 1.5 0 .75.75 0 0 0-1.5 0Zm8.25-.75a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5ZM4.25 12a.75.75 0 1 0 0 1.5.75.75 0 0 0 0-1.5Z"></path></svg></span><span data-component="text" class="prc-Button-Label-FWkx3"><div class="RefSelectorAnchoredOverlay-module__RefSelectorOverlayContainer__yaf4p"><div style="max-width:125px" class="ref-selector-button-text-container RefSelectorAnchoredOverlay-module__RefSelectorBtnTextContainer__Di3rk"><span class="RefSelectorAnchoredOverlay-module__RefSelectorText__w_fmP">main</span></div></div></span><span data-component="trailingVisual" class="prc-Button-Visual-YNt2F prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-triangle-down" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="m4.427 7.427 3.396 3.396a.25.25 0 0 0 .354 0l3.396-3.396A.25.25 0 0 0 11.396 7H4.604a.25.25 0 0 0-.177.427Z"></path></svg></span></span></button><div class="d-none"></div></div><div class="FileNameStickyHeader-module__Box_4__FLhtt"><div class="Breadcrumb-module__container__Vxvev Breadcrumb-module__md__Wb1Gs"><nav data-testid="breadcrumbs" aria-labelledby="sticky-breadcrumb-heading" id="sticky-breadcrumb" class="Breadcrumb-module__nav__rQFDj"><h2 class="sr-only ScreenReaderHeading-module__userSelectNone__rwWIk prc-Heading-Heading-MtWFE" data-component="Heading" data-testid="screen-reader-heading" id="sticky-breadcrumb-heading">Breadcrumbs</h2><ol class="Breadcrumb-module__list__ZH6zr"><li class="Breadcrumb-module__listItem__Ib0x_"><a class="Breadcrumb-module__repoLink__O2Nbs prc-Link-Link-9ZwDx" data-component="Link" data-testid="breadcrumbs-repo-link" href="/confidential-containers/trustee/tree/main" data-discover="true">trustee</a></li><li class="Breadcrumb-module__listItem__Ib0x_"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__md__Wb1Gs" aria-hidden="true">/</span><a class="Breadcrumb-module__directoryLink__kQy_t prc-Link-Link-9ZwDx" data-component="Link" href="/confidential-containers/trustee/tree/main/deployment" data-discover="true">deployment</a></li><li class="Breadcrumb-module__listItem__Ib0x_"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__md__Wb1Gs" aria-hidden="true">/</span><a class="Breadcrumb-module__directoryLink__kQy_t prc-Link-Link-9ZwDx" data-component="Link" href="/confidential-containers/trustee/tree/main/deployment/helm-chart" data-discover="true">helm-chart</a></li></ol></nav><div data-testid="breadcrumbs-filename" class="Breadcrumb-module__filename__equZR"><span class="Breadcrumb-module__separator__eNwsI Breadcrumb-module__md__Wb1Gs" aria-hidden="true">/</span><h1 class="Breadcrumb-module__filenameHeading__MNMtw Breadcrumb-module__md__Wb1Gs prc-Heading-Heading-MtWFE" data-component="Heading" tabindex="-1" id="sticky-file-name-id">README.md</h1></div><button data-component="IconButton" type="button" class="prc-Button-ButtonBase-9n-Xk ml-2 prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="invisible" aria-labelledby="_R_7lcpala9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-copy" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z"></path><path d="M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z"></path></svg></button><span class="CopyToClipboardIconButton-module__tooltip__WyiwL prc-TooltipV2-Tooltip-tLeuB" data-direction="s" data-component="Tooltip" aria-label="Copy path" aria-hidden="true" id="_R_7lcpala9lik5_">Copy path</span></div></div></div><button data-component="Button" type="button" class="prc-Button-ButtonBase-9n-Xk FileNameStickyHeader-module__Button__LSEU_ FileNameStickyHeader-module__GoToTopButton__nxAFn" data-loading="false" data-size="small" data-variant="invisible"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="leadingVisual" class="prc-Button-Visual-YNt2F prc-Button-LeadingVisual-UySKu prc-Button-VisualWrap-E4cnq"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-arrow-up" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M3.47 7.78a.75.75 0 0 1 0-1.06l4.25-4.25a.75.75 0 0 1 1.06 0l4.25 4.25a.751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018L9 4.81v7.44a.75.75 0 0 1-1.5 0V4.81L4.53 7.78a.75.75 0 0 1-1.06 0Z"></path></svg></span><span data-component="text" class="prc-Button-Label-FWkx3">Top</span></span></button></div></div></div><div class="BlobViewHeader-module__Box_1__VEmuQ"><h2 class="sr-only ScreenReaderHeading-module__userSelectNone__rwWIk prc-Heading-Heading-MtWFE" data-component="Heading" data-testid="screen-reader-heading">File metadata and controls</h2><div class="BlobViewHeader-module__Box_2__icUs2"><ul aria-label="File view" class="prc-SegmentedControl-SegmentedControl-lqIXp BlobTabButtons-module__SegmentedControl__jen2u" data-variant="default" data-size="small" data-component="SegmentedControl"><li class="prc-SegmentedControl-Item-tSCQh" data-selected="" data-component="SegmentedControl.Button"><button aria-pressed="true" class="prc-SegmentedControl-Button-E48xz" type="button" style="--separator-color:transparent"><span class="prc-SegmentedControl-Content-1COlk segmentedControl-content"><div class="prc-SegmentedControl-Text-7S2y2 segmentedControl-text" data-text="Preview">Preview</div></span></button></li><li class="prc-SegmentedControl-Item-tSCQh" data-component="SegmentedControl.Button"><button aria-pressed="false" class="prc-SegmentedControl-Button-E48xz" type="button" style="--separator-color:var(--borderColor-default)"><span class="prc-SegmentedControl-Content-1COlk segmentedControl-content"><div class="prc-SegmentedControl-Text-7S2y2 segmentedControl-text" data-text="Code">Code</div></span></button></li><li class="prc-SegmentedControl-Item-tSCQh" data-component="SegmentedControl.Button"><button aria-pressed="false" class="prc-SegmentedControl-Button-E48xz" type="button" style="--separator-color:var(--borderColor-default)"><span class="prc-SegmentedControl-Content-1COlk segmentedControl-content"><div class="prc-SegmentedControl-Text-7S2y2 segmentedControl-text" data-text="Blame">Blame</div></span></button></li></ul><div class="d-none"></div><div class="react-code-size-details-in-header CodeSizeDetails-module__Box__VcD6l"><div class="text-mono CodeSizeDetails-module__Box_1__GVxQL"><div data-testid="blob-size" class="CodeSizeDetails-module__Truncate_1__lE93V prc-Truncate-Truncate-2G1eo" data-inline="true" title="38.9 KB" style="--truncate-max-width:100%"><span>477 lines (376 loc) · 38.9 KB</span></div></div></div></div><div class="BlobViewHeader-module__Box_3__ng6v2"><div class="d-none"></div><div class="react-blob-header-edit-and-raw-actions BlobViewHeader-module__Box_4__J4Y4W"><div class="d-none"></div><div class="prc-ButtonGroup-ButtonGroup-vFUrY" data-component="ButtonGroup"><div class="prc-ButtonGroup-Item-PqvDl"><a data-component="LinkButton" href="https://github.com/confidential-containers/trustee/raw/refs/heads/main/deployment/helm-chart/README.md" data-testid="raw-button" class="prc-Button-ButtonBase-9n-Xk LinkButton-module__linkButton__nFnov BlobViewHeader-module__LinkButton__X9kx2" data-loading="false" data-no-visuals="true" data-size="small" data-variant="default"><span data-component="buttonContent" data-align="center" class="prc-Button-ButtonContent-Iohp5"><span data-component="text" class="prc-Button-Label-FWkx3">Raw</span></span></a></div><div class="prc-ButtonGroup-Item-PqvDl"><button data-component="IconButton" type="button" data-testid="copy-raw-button" class="prc-Button-ButtonBase-9n-Xk prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="default" aria-labelledby="_R_qaucpala9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-copy" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z"></path><path d="M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="n" data-component="Tooltip" aria-hidden="true" id="_R_qaucpala9lik5_">Copy raw file</span></div><div class="prc-ButtonGroup-Item-PqvDl"><button data-component="IconButton" type="button" data-testid="download-raw-button" class="prc-Button-ButtonBase-9n-Xk BlobViewHeader-module__downloadButton__ef459 prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="default" aria-labelledby="_R_eaucpala9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-download" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M2.75 14A1.75 1.75 0 0 1 1 12.25v-2.5a.75.75 0 0 1 1.5 0v2.5c0 .138.112.25.25.25h10.5a.25.25 0 0 0 .25-.25v-2.5a.75.75 0 0 1 1.5 0v2.5A1.75 1.75 0 0 1 13.25 14Z"></path><path d="M7.25 7.689V2a.75.75 0 0 1 1.5 0v5.689l1.97-1.969a.749.749 0 1 1 1.06 1.06l-3.25 3.25a.749.749 0 0 1-1.06 0L4.22 6.78a.749.749 0 1 1 1.06-1.06l1.97 1.969Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="n" data-component="Tooltip" aria-hidden="true" id="_R_eaucpala9lik5_">Download raw file</span></div></div></div><button data-component="IconButton" type="button" aria-pressed="false" class="prc-Button-ButtonBase-9n-Xk tmp-mr-2 TableOfContents-module__IconButton__jrlNM prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="invisible" aria-labelledby="_R_3ucpala9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-list-unordered" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M5.75 2.5h8.5a.75.75 0 0 1 0 1.5h-8.5a.75.75 0 0 1 0-1.5Zm0 5h8.5a.75.75 0 0 1 0 1.5h-8.5a.75.75 0 0 1 0-1.5Zm0 5h8.5a.75.75 0 0 1 0 1.5h-8.5a.75.75 0 0 1 0-1.5ZM2 14a1 1 0 1 1 0-2 1 1 0 0 1 0 2Zm1-6a1 1 0 1 1-2 0 1 1 0 0 1 2 0ZM2 4a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="n" data-component="Tooltip" aria-hidden="true" id="_R_3ucpala9lik5_">Outline</span><div class="react-blob-header-edit-and-raw-actions-combined"><button data-component="IconButton" type="button" title="More file actions" data-testid="more-file-actions-button" aria-haspopup="true" aria-expanded="false" tabindex="0" class="prc-Button-ButtonBase-9n-Xk js-blob-dropdown-click BlobViewHeader-module__IconButton__XrMQY prc-Button-IconButton-fyge7" data-loading="false" data-no-visuals="true" data-size="small" data-variant="invisible" aria-labelledby="_R_fkecpala9lik5_" id="_R_kecpala9lik5_"><svg data-component="Octicon" aria-hidden="true" focusable="false" class="octicon octicon-kebab-horizontal" viewBox="0 0 16 16" width="16" height="16" fill="currentColor" display="inline-block" overflow="visible" style="vertical-align:text-bottom"><path d="M8 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3ZM1.5 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Zm13 0a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path></svg></button><span class="prc-TooltipV2-Tooltip-tLeuB" data-direction="nw" data-component="Tooltip" aria-hidden="true" id="_R_fkecpala9lik5_">Edit and raw actions</span></div></div></div></div><div></div></div><div class="BlobViewContent-module__blobContentWrapper__JS0W6"><section aria-labelledby="file-name-id-wide file-name-id-mobile" class="BlobContent-module__blobContentSection__VOgZq BlobContent-module__blobContentSectionMarkdown__mPLOK" style="margin-top:46px"><div class="js-snippet-clipboard-copy-unpositioned BlobContent-module__markdownBlob__T8jpG" data-hpc="true" containertiming="hpc"><article class="markdown-body entry-content container-lg" itemprop="text"><div class="markdown-heading" dir="auto"><h1 tabindex="-1" class="heading-element" dir="auto">Trustee Helm Chart</h1><a id="user-content-trustee-helm-chart" class="anchor" aria-label="Permalink: Trustee Helm Chart" href="#trustee-helm-chart"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">Helm chart for <a href="https://github.com/confidential-containers">Confidential Containers</a> <strong>Trustee</strong> on Kubernetes: <strong>KBS</strong>, <strong>gRPC AS</strong>, and <strong>RVPS</strong>, with optional bundled <strong>PostgreSQL</strong> (<a href="https://artifacthub.io/packages/helm/bitnami/postgresql" rel="nofollow">Bitnami chart</a>) and <strong>Valkey</strong> (<a href="https://artifacthub.io/packages/helm/bitnami/valkey" rel="nofollow">Bitnami chart</a>, a Redis-protocol store for KBS sessions). KBS is wired to remote <strong><code>coco_as_grpc</code></strong> Attestation Service.</p>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Install</h2><a id="user-content-install" class="anchor" aria-label="Permalink: Install" href="#install"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto"><strong>Requirements</strong>: Kubernetes 1.19+, Helm 3. If bundled Postgres is needed (when <strong><code>storageBackend.type: Postgres</code></strong> or <strong><code>sessionStorageType: Postgres</code></strong>), the Bitnami subchart uses PVC-backed storage, so your cluster must provide a usable <strong>StorageClass</strong> (or you must bind an existing claim).</p>
<p dir="auto">From the <strong>repository root</strong>:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace"><pre>helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace</pre></div>
<p dir="auto">Wait for workloads, then port-forward KBS (default HTTP <strong>8080</strong>). The internal ClusterIP Service is <strong><code>&lt;Helm fullname&gt;-kbs</code></strong> (with the install command below, <strong><code>trustee-kbs</code></strong>):</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl get pods -n coco-trustee -w
kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080"><pre>kubectl get pods -n coco-trustee -w
kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080</pre></div>
<p dir="auto">Uninstall the release:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm uninstall trustee -n coco-trustee"><pre>helm uninstall trustee -n coco-trustee</pre></div>
<div class="markdown-alert markdown-alert-note" dir="auto"><p class="markdown-alert-title" dir="auto"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p dir="auto">When <code>secrets.useEphemeralGeneratedKeys</code> is <code>true</code> (default), a <strong>post-delete</strong> Helm hook removes the release-scoped <code>*-bootstrap-user-keys</code> Secret automatically.</p>
</div>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Typical scenarios</h2><a id="user-content-typical-scenarios" class="anchor" aria-label="Permalink: Typical scenarios" href="#typical-scenarios"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">Default: LocalFs storage</h3><a id="user-content-default-localfs-storage" class="anchor" aria-label="Permalink: Default: LocalFs storage" href="#default-localfs-storage"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">Same as <strong>Install</strong> above. If neither <strong><code>storageBackend.type</code></strong> nor <strong><code>sessionStorageType</code></strong> is <strong><code>Postgres</code></strong>, the chart does not deploy bundled Postgres; components use the default <strong><code>storageBackend</code></strong> (e.g. <strong>LocalFs</strong>).</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">PostgreSQL as storage backend + in-memory KBS sessions</h3><a id="user-content-postgresql-as-storage-backend--in-memory-kbs-sessions" class="anchor" aria-label="Permalink: PostgreSQL as storage backend + in-memory KBS sessions" href="#postgresql-as-storage-backend--in-memory-kbs-sessions"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml"><pre>helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml</pre></div>
<p dir="auto">This enables the <strong>Bitnami PostgreSQL</strong> subchart (<code>postgresql.enabled: true</code>) and sets <strong><code>storageBackend.type: Postgres</code></strong>. KBS sessions stay in memory (<code>sessionStorageType: Memory</code>). Demo credentials default to <code>trustee</code> / <code>trustee</code> / <code>trustee</code> (override via <code>postgresql.auth.*</code>).</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">External PostgreSQL</h3><a id="user-content-external-postgresql" class="anchor" aria-label="Permalink: External PostgreSQL" href="#external-postgresql"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">When an external Postgres service is used, set <strong><code>storageBackend.postgres.mode=external</code></strong>, pre-create a Secret with a <strong><code>POSTGRES_URL</code></strong> key, and point the chart at it:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl create secret generic trustee-external-postgres -n coco-trustee \
  --from-literal=POSTGRES_URL='postgresql://user:password@postgres.example.com:5432/trustee?sslmode=require'

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set storageBackend.type=Postgres \
  --set storageBackend.postgres.mode=external \
  --set storageBackend.postgres.external.existingSecretName=trustee-external-postgres \
  --set storageBackend.postgres.external.existingSecretKey=POSTGRES_URL"><pre>kubectl create secret generic trustee-external-postgres -n coco-trustee \
  --from-literal=POSTGRES_URL=<span class="pl-s"><span class="pl-pds">'</span>postgresql://user:password@postgres.example.com:5432/trustee?sslmode=require<span class="pl-pds">'</span></span>

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set storageBackend.type=Postgres \
  --set storageBackend.postgres.mode=external \
  --set storageBackend.postgres.external.existingSecretName=trustee-external-postgres \
  --set storageBackend.postgres.external.existingSecretKey=POSTGRES_URL</pre></div>
<p dir="auto">When <code>storageBackend.postgres.mode=external</code>, the chart does <strong>NOT</strong> deploy the Bitnami subchart (<code>postgresql.enabled</code> stays <code>false</code>), even if Postgres is required by <code>storageBackend.type</code> or <code>sessionStorageType</code>.</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">Valkey (Redis protocol) for KBS sessions</h3><a id="user-content-valkey-redis-protocol-for-kbs-sessions" class="anchor" aria-label="Permalink: Valkey (Redis protocol) for KBS sessions" href="#valkey-redis-protocol-for-kbs-sessions"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">The KBS <strong><code>Redis</code></strong> session backend speaks the Redis wire protocol. The chart bundles <strong>Valkey</strong> (BSD-licensed) instead of Redis, whose license is no longer OSI-approved; any Redis-protocol-compatible service works. Storing sessions outside the KBS Pod allows running several KBS replicas.</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml"><pre>helm dependency update ./deployment/helm-chart

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml</pre></div>
<p dir="auto">This enables the <strong>Bitnami Valkey</strong> subchart (<code>valkey.enabled: true</code>) and sets <strong><code>sessionStorageType: Redis</code></strong>. The chart writes the connection URL into a release-scoped Secret and injects it into KBS as <strong><code>REDIS_URL</code></strong>. The demo password defaults to <code>trustee</code> (override via <code>valkey.auth.password</code>). Sessions are short-lived, so the bundled Valkey runs <code>standalone</code> without a PVC by default (<code>valkey.primary.persistence.enabled: false</code>).</p>
<p dir="auto">The default Valkey image is pulled from <strong>docker.io</strong>, where anonymous pulls are rate-limited. Override the image source to use a private mirror:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm upgrade --install trustee ./deployment/helm-chart ... \
  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml \
  --set valkey.image.registry=mirror.example.com \
  --set valkey.image.repository=bitnami/valkey \
  --set valkey.image.tag=9.1.0"><pre>helm upgrade --install trustee ./deployment/helm-chart ... \
  -f ./deployment/helm-chart/scenarios/valkey-sessions.yaml \
  --set valkey.image.registry=mirror.example.com \
  --set valkey.image.repository=bitnami/valkey \
  --set valkey.image.tag=9.1.0</pre></div>
<p dir="auto">(A chart-wide <code>global.imageRegistry</code> is also honored by the Bitnami subcharts.)</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">External Redis-compatible service</h3><a id="user-content-external-redis-compatible-service" class="anchor" aria-label="Permalink: External Redis-compatible service" href="#external-redis-compatible-service"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">When an external Redis-compatible service is used, set <strong><code>storageBackend.redis.mode=external</code></strong>, pre-create a Secret with the connection URL, and point the chart at it:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl create secret generic trustee-external-redis -n coco-trustee \
  --from-literal=REDIS_URL='redis://:password@redis.example.com:6379'

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set sessionStorageType=Redis \
  --set storageBackend.redis.mode=external \
  --set storageBackend.redis.external.existingSecretName=trustee-external-redis \
  --set storageBackend.redis.external.existingSecretKey=REDIS_URL"><pre>kubectl create secret generic trustee-external-redis -n coco-trustee \
  --from-literal=REDIS_URL=<span class="pl-s"><span class="pl-pds">'</span>redis://:password@redis.example.com:6379<span class="pl-pds">'</span></span>

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set sessionStorageType=Redis \
  --set storageBackend.redis.mode=external \
  --set storageBackend.redis.external.existingSecretName=trustee-external-redis \
  --set storageBackend.redis.external.existingSecretKey=REDIS_URL</pre></div>
<p dir="auto">When <code>storageBackend.redis.mode=external</code>, the chart does <strong>NOT</strong> deploy the Valkey subchart (<code>valkey.enabled</code> stays <code>false</code>).</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">Bring your own keys (BYOK)</h3><a id="user-content-bring-your-own-keys-byok" class="anchor" aria-label="Permalink: Bring your own keys (BYOK)" href="#bring-your-own-keys-byok"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">Key material is controlled only by <strong><code>secrets.useEphemeralGeneratedKeys</code></strong>:</p>
<ul dir="auto">
<li><strong><code>true</code> (default):</strong> a Helm <strong>pre-install / pre-upgrade hook</strong> Job generates ephemeral demo keys into a release-scoped Secret (name ends with <strong><code>bootstrap-user-keys</code></strong>). <strong><code>helm uninstall</code></strong> runs a <strong>post-delete</strong> hook that removes that Secret.</li>
<li><strong><code>false</code>:</strong> you must <strong>pre-create</strong> a Kubernetes <strong><code>Secret</code></strong> in the target namespace, then set <strong><code>secrets.existingSecretName</code></strong> to that name. The bootstrap hook is <strong>not</strong> rendered.</li>
</ul>
<p dir="auto">When ephemeral generation is enabled, the hook uses:</p>
<ul dir="auto">
<li>an <code>initContainer</code> (OpenSSL image) to generate keys into an <code>emptyDir</code></li>
<li>a <code>quay.io/kata-containers/kubectl</code> container to create the Secret from generated files</li>
</ul>
<p dir="auto">Both images are overridable via <code>bootstrapUserKeysJob.keygenImage.*</code> and <code>bootstrapUserKeysJob.kubectlImage.*</code>.</p>
<p dir="auto">When ephemeral generation is disabled, the Secret must define these <strong>data keys</strong> (values are PEM text or base64-encoded PEM, same as any <code>kubectl create secret generic --from-file=...</code>):</p>
<markdown-accessiblity-table><table>
<thead>
<tr>
<th>Secret key</th>
<th>Role</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong><code>KBS_ADMIN_PRIVATE_KEY</code></strong> / <strong><code>KBS_ADMIN_PUBKEY</code></strong></td>
<td>KBS admin API Ed25519 keypair (used to sign admin JWTs).</td>
</tr>
<tr>
<td><strong><code>KBS_ADMIN_TOKEN</code></strong></td>
<td>Pre-signed admin bearer JWT for <code>kbs-client --admin-token-file</code> (generated by the bootstrap hook when ephemeral keys are enabled).</td>
</tr>
<tr>
<td><strong><code>AS_TOKEN_SIGNING_PRIVATE_KEY</code></strong></td>
<td>Attestation Service: sign attestation tokens.</td>
</tr>
<tr>
<td><strong><code>AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN</code></strong></td>
<td>AS: <code>x5c</code> / cert chain; KBS: trust anchor for token verification.</td>
</tr>
</tbody>
</table></markdown-accessiblity-table>
<p dir="auto">The chart mounts that Secret on KBS and gRPC AS and <strong>maps</strong> those keys to in-container paths <strong><code>private.key</code></strong>, <strong><code>public.pub</code></strong>, <strong><code>token.key</code></strong>, <strong><code>token-cert-chain.pem</code></strong> under <strong><code>/opt/confidential-containers/kbs/user-keys</code></strong>.</p>
<p dir="auto">Example (create Secret, then install):</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl create secret generic trustee-byok-keys -n coco-trustee \
  --from-file=KBS_ADMIN_PRIVATE_KEY=./admin.key.pem \
  --from-file=KBS_ADMIN_PUBKEY=./admin.pub.pem \
  --from-file=AS_TOKEN_SIGNING_PRIVATE_KEY=./token.key.pem \
  --from-file=AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN=./token-chain.pem

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set secrets.useEphemeralGeneratedKeys=false \
  --set secrets.existingSecretName=trustee-byok-keys"><pre>kubectl create secret generic trustee-byok-keys -n coco-trustee \
  --from-file=KBS_ADMIN_PRIVATE_KEY=./admin.key.pem \
  --from-file=KBS_ADMIN_PUBKEY=./admin.pub.pem \
  --from-file=AS_TOKEN_SIGNING_PRIVATE_KEY=./token.key.pem \
  --from-file=AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN=./token-chain.pem

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set secrets.useEphemeralGeneratedKeys=false \
  --set secrets.existingSecretName=trustee-byok-keys</pre></div>
<p dir="auto">Or use <strong><code>scenarios/bring-your-own-keys.yaml</code></strong> (adjust Secret name / file paths in the comments there).</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">Native KBS HTTPS</h3><a id="user-content-native-kbs-https" class="anchor" aria-label="Permalink: Native KBS HTTPS" href="#native-kbs-https"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">The default KBS listener uses plaintext HTTP. For a KBS endpoint that clients or
confidential guests reach directly, enable native HTTPS and provide an existing
Secret containing the endpoint private key and certificate chain. The chart does
not generate this identity material because its certificate SAN must match the
address used by KBS clients.</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl create namespace coco-trustee
kubectl create secret tls trustee-kbs-tls \
  --namespace coco-trustee \
  --key ./kbs.key \
  --cert ./kbs.crt

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee \
  -f ./deployment/helm-chart/scenarios/native-tls.yaml"><pre>kubectl create namespace coco-trustee
kubectl create secret tls trustee-kbs-tls \
  --namespace coco-trustee \
  --key ./kbs.key \
  --cert ./kbs.crt

helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee \
  -f ./deployment/helm-chart/scenarios/native-tls.yaml</pre></div>
<p dir="auto">With <code>kbs.tls.enabled=true</code>, the chart leaves <code>insecure_http</code> at its secure
default (<code>false</code>), mounts the standard <code>tls.key</code> and <code>tls.crt</code> data keys from the
selected Kubernetes TLS Secret, and changes the KBS health probes to HTTPS.</p>
<p dir="auto">KBS does not reload endpoint identity material dynamically, so restart the KBS
Deployment after replacing the TLS Secret contents.</p>
<p dir="auto">Ingress TLS termination is a separate mode: leave native KBS TLS disabled and
configure <code>ingress.tls</code> when the Ingress controller should serve HTTPS and
forward plaintext HTTP to KBS. Do not combine native KBS TLS with Ingress unless
the chosen Ingress controller is explicitly configured to use HTTPS for its
backend connection.</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">IBM Secure Execution (s390x)</h3><a id="user-content-ibm-secure-execution-s390x" class="anchor" aria-label="Permalink: IBM Secure Execution (s390x)" href="#ibm-secure-execution-s390x"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">On <strong>s390x</strong>, the <strong>IBM Secure Execution (SE)</strong> verifier needs attestation materials at runtime. Because KBS talks to a <strong>remote <code>coco_as_grpc</code> AS</strong>, the verifier runs inside the <strong>AS Pod</strong>, so these materials must be mounted on <strong>AS</strong>, not KBS. (This differs from the builtin-AS kustomize overlay in <code>kbs/config/kubernetes/overlays/ibm-se</code>, which mounts them on KBS.)</p>
<p dir="auto">The verifier reads materials from fixed paths under <strong><code>/run/confidential-containers/ibmse/</code></strong> (overridable via <code>SE_*</code> env vars; see <code>deps/verifier/src/se/README.md</code>). The chart mounts them from a <strong>local node path</strong> via a PersistentVolume / PersistentVolumeClaim — set <strong><code>as.verifier.se.credsDir</code></strong> to the directory on the node that contains the materials (equivalent to <code>IBM_SE_CREDS_DIR</code> used in the kustomize overlay), and <strong><code>as.verifier.se.nodeName</code></strong> to the name of that node.  The chart then creates a <code>local</code>-type PV + PVC and mounts the whole directory at <code>/run/confidential-containers/ibmse/</code> on the AS Pod.</p>
<markdown-accessiblity-table><table>
<thead>
<tr>
<th>Material</th>
<th>Expected path under <code>credsDir</code></th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>RSA measurement key pair</td>
<td><code>rsa/encrypt_key.{pem,pub}</code></td>
<td>Private key is <strong>sensitive</strong> — restrict node access.</td>
</tr>
<tr>
<td>Signing / intermediate certs</td>
<td><code>certs/</code></td>
<td><strong>Directory</strong>; all files are read.</td>
</tr>
<tr>
<td>CRLs</td>
<td><code>crls/</code></td>
<td><strong>Directory</strong>; all files are read.</td>
</tr>
<tr>
<td>Host Key Documents (HKD)</td>
<td><code>hkds/</code></td>
<td><strong>Directory</strong>; all files are read.</td>
</tr>
<tr>
<td>SE image header</td>
<td><code>hdr/hdr.bin</code></td>
<td>Binary file.</td>
</tr>
<tr>
<td>Root CA (optional)</td>
<td><code>root_ca.crt</code></td>
<td>Single file.</td>
</tr>
</tbody>
</table></markdown-accessiblity-table>
<p dir="auto">Set <strong><code>CERTS_OFFLINE_VERIFICATION=true</code></strong> (via <code>as.extraEnvVars</code>) to verify the HKD certificate chain offline. Do <strong>not</strong> set <code>SE_SKIP_CERTS_VERIFICATION=true</code> outside development — it disables HKD certificate chain verification.</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="# 1. Place all materials under a directory on the target s390x node, e.g.:
#    $IBM_SE_CREDS_DIR/{rsa/,certs/,crls/,hkds/,hdr/hdr.bin}
#    See deps/verifier/src/se/README.md for how to obtain the materials.

# 2. Install, pointing the chart at the node and directory:
helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/ibm-se.yaml \
  --set as.verifier.se.credsDir=$IBM_SE_CREDS_DIR \
  --set as.verifier.se.nodeName=&lt;your-s390x-node-name&gt;"><pre><span class="pl-c"><span class="pl-c">#</span> 1. Place all materials under a directory on the target s390x node, e.g.:</span>
<span class="pl-c"><span class="pl-c">#</span>    $IBM_SE_CREDS_DIR/{rsa/,certs/,crls/,hkds/,hdr/hdr.bin}</span>
<span class="pl-c"><span class="pl-c">#</span>    See deps/verifier/src/se/README.md for how to obtain the materials.</span>

<span class="pl-c"><span class="pl-c">#</span> 2. Install, pointing the chart at the node and directory:</span>
helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  -f ./deployment/helm-chart/scenarios/ibm-se.yaml \
  --set as.verifier.se.credsDir=<span class="pl-smi">$IBM_SE_CREDS_DIR</span> \
  --set as.verifier.se.nodeName=<span class="pl-k">&lt;</span>your-s390x-node-name<span class="pl-k">&gt;</span></pre></div>
<p dir="auto">Use an <strong>s390x</strong> AS image built with the <code>se-verifier</code> feature (<code>as.image.repository</code> / <code>as.image.tag</code>). See <strong><code>scenarios/ibm-se.yaml</code></strong> for the full override. Set the SE attestation policy afterwards as documented in <code>deps/verifier/src/se/README.md</code>.</p>
<div class="markdown-heading" dir="auto"><h3 tabindex="-1" class="heading-element" dir="auto">AMD SEV-SNP offline VCEK store</h3><a id="user-content-amd-sev-snp-offline-vcek-store" class="anchor" aria-label="Permalink: AMD SEV-SNP offline VCEK store" href="#amd-sev-snp-offline-vcek-store"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">The <strong>SNP</strong> verifier needs a <strong>VCEK</strong> certificate to validate an attestation report. By default it fetches one from <strong>AMD KDS</strong>, which requires outbound connectivity from the AS Pod. Air-gapped clusters can instead stage the certificates on the node and have the verifier read them locally.</p>
<p dir="auto">Set <strong><code>as.verifier.snp.kdsStoreHostPath</code></strong> to the directory on the node that holds the store, <strong><code>as.verifier.snp.nodeName</code></strong> to the name of that node, and add an <strong><code>OfflineStore</code></strong> entry to <strong><code>as.verifier.snp.vcekSources</code></strong>. The chart then creates a <code>local</code>-type PV + PVC and mounts the directory at <code>/opt/confidential-containers/attestation-service/kds-store</code> on the AS Pod. The three values are required together: rendering fails if the store is mounted without an <code>OfflineStore</code> source, or an <code>OfflineStore</code> source is configured without the mount, so a misconfiguration cannot silently fall back to KDS.</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="# 1. Place the certificates under a directory on the target SNP node, laid out as
#    $KDS_STORE/vcek/{hwid}/{tcb_prefix}_vcek.der  (preferred)
#    $KDS_STORE/vcek/{hwid}/vcek.der               (fallback)

# 2. Install, pointing the chart at the node and directory:
helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set as.verifier.snp.kdsStoreHostPath=$KDS_STORE \
  --set as.verifier.snp.nodeName=&lt;your-snp-node-name&gt; \
  --set 'as.verifier.snp.vcekSources[0].type=OfflineStore'"><pre><span class="pl-c"><span class="pl-c">#</span> 1. Place the certificates under a directory on the target SNP node, laid out as</span>
<span class="pl-c"><span class="pl-c">#</span>    $KDS_STORE/vcek/{hwid}/{tcb_prefix}_vcek.der  (preferred)</span>
<span class="pl-c"><span class="pl-c">#</span>    $KDS_STORE/vcek/{hwid}/vcek.der               (fallback)</span>

<span class="pl-c"><span class="pl-c">#</span> 2. Install, pointing the chart at the node and directory:</span>
helm upgrade --install trustee ./deployment/helm-chart \
  --namespace coco-trustee --create-namespace \
  --set as.verifier.snp.kdsStoreHostPath=<span class="pl-smi">$KDS_STORE</span> \
  --set as.verifier.snp.nodeName=<span class="pl-k">&lt;</span>your-snp-node-name<span class="pl-k">&gt;</span> \
  --set <span class="pl-s"><span class="pl-pds">'</span>as.verifier.snp.vcekSources[0].type=OfflineStore<span class="pl-pds">'</span></span></pre></div>
<p dir="auto">Sources are tried in the order given, so appending <code>--set 'as.verifier.snp.vcekSources[1].type=KDS'</code> keeps AMD KDS as a fallback for certificates that are missing locally. See <a href="/confidential-containers/trustee/blob/main/attestation-service/docs/amd-offline-certificate-cache.md">the AMD offline certificate cache guide</a> for how to build the <code>vcek/</code> directory and when it has to be refreshed.</p>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Testing</h2><a id="user-content-testing" class="anchor" aria-label="Permalink: Testing" href="#testing"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto"><strong>Inspect resources</strong>:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl get deploy,pods,svc -n coco-trustee
helm status trustee -n coco-trustee"><pre>kubectl get deploy,pods,svc -n coco-trustee
helm status trustee -n coco-trustee</pre></div>
<p dir="auto"><strong>Render-only check</strong> (no install):</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="helm dependency update ./deployment/helm-chart

helm template trustee ./deployment/helm-chart \
  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml \
  --namespace coco-trustee &gt; /tmp/trustee-render.yaml"><pre>helm dependency update ./deployment/helm-chart

helm template trustee ./deployment/helm-chart \
  -f ./deployment/helm-chart/scenarios/postgres-backend.yaml \
  --namespace coco-trustee <span class="pl-k">&gt;</span> /tmp/trustee-render.yaml</pre></div>
<p dir="auto">If your cluster cannot resolve <code>*.svc.cluster.local</code> from Pods, set <code>dnsHostAliasWorkaround: true</code> in your override values and then run <code>helm upgrade</code> again after Services exist so Helm <code>lookup</code> can resolve ClusterIPs.</p>
<p dir="auto"><strong>kbs-client</strong> (build from the repo: <code>cargo build -p kbs-client --release</code>): with ephemeral keys, the hook-created Secret (name ends with <strong><code>bootstrap-user-keys</code></strong>) includes a pre-signed admin JWT under <strong><code>KBS_ADMIN_TOKEN</code></strong>. KBS expects <code>authorization_mode = "AuthenticatedAuthorization"</code> with a bearer JWT that includes a <strong><code>role</code></strong> claim matching <code>[admin.authorization.regex_acl]</code> (default role <strong><code>admin</code></strong>).</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080 &amp;
SECRET=$(kubectl get secrets -n coco-trustee -o name | grep bootstrap-user-keys | head -1 | cut -d/ -f2)
kubectl get secret &quot;$SECRET&quot; -n coco-trustee -o jsonpath='{.data.KBS_ADMIN_TOKEN}' | base64 -d &gt;/tmp/admin-token
kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource-policy --allow-all"><pre>kubectl port-forward -n coco-trustee svc/trustee-kbs 8080:8080 <span class="pl-k">&amp;</span>
SECRET=<span class="pl-s"><span class="pl-pds">$(</span>kubectl get secrets -n coco-trustee -o name <span class="pl-k">|</span> grep bootstrap-user-keys <span class="pl-k">|</span> head -1 <span class="pl-k">|</span> cut -d/ -f2<span class="pl-pds">)</span></span>
kubectl get secret <span class="pl-s"><span class="pl-pds">"</span><span class="pl-smi">$SECRET</span><span class="pl-pds">"</span></span> -n coco-trustee -o jsonpath=<span class="pl-s"><span class="pl-pds">'</span>{.data.KBS_ADMIN_TOKEN}<span class="pl-pds">'</span></span> <span class="pl-k">|</span> base64 -d <span class="pl-k">&gt;</span>/tmp/admin-token
kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource-policy --allow-all</pre></div>
<p dir="auto">Set a confidential resource (<code>config</code> + <code>--admin-token-file</code>, then <code>set-resource</code>):</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="echo 'demo-payload' &gt;/tmp/demo-resource.txt
kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource \
  --path my_repo/resource_type/demo --resource-file /tmp/demo-resource.txt"><pre><span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">'</span>demo-payload<span class="pl-pds">'</span></span> <span class="pl-k">&gt;</span>/tmp/demo-resource.txt
kbs-client --url http://127.0.0.1:8080 config --admin-token-file /tmp/admin-token set-resource \
  --path my_repo/resource_type/demo --resource-file /tmp/demo-resource.txt</pre></div>
<p dir="auto">Fetch a resource by KBS URI path (<code>get-resource</code> is a top-level subcommand; it follows the normal attestation / token flow for your client build and policy):</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kbs-client --url http://127.0.0.1:8080 get-resource --path my_repo/resource_type/demo"><pre>kbs-client --url http://127.0.0.1:8080 get-resource --path my_repo/resource_type/demo</pre></div>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Configuration</h2><a id="user-content-configuration" class="anchor" aria-label="Permalink: Configuration" href="#configuration"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">Default <strong><code>values.yaml</code></strong> is intentionally small. Fixed on-disk paths for <strong>LocalFs</strong> / <strong>LocalJson</strong> are defined in <strong><code>templates/_helpers.tpl</code></strong> (not overridable via values). You can still merge extra keys with <code>-f</code> / <code>--set</code> (Helm merges arbitrary values).</p>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Values</h2><a id="user-content-values" class="anchor" aria-label="Permalink: Values" href="#values"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<markdown-accessiblity-table><table>
<thead>
<tr>
<th>Key</th>
<th>Type</th>
<th>Default</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>as.affinity</td>
<td>object</td>
<td><code>{}</code></td>
<td>Affinity and anti-affinity scheduling rules for AS Pods.</td>
</tr>
<tr>
<td>as.extraEnvVars</td>
<td>list</td>
<td><code>[]</code></td>
<td>Extra environment variables for the AS container (for example <code>HTTP(S)_PROXY</code> and <code>NO_PROXY</code>).</td>
</tr>
<tr>
<td>as.image.pullPolicy</td>
<td>string</td>
<td><code>"Always"</code></td>
<td>AS container image pull policy.</td>
</tr>
<tr>
<td>as.image.repository</td>
<td>string</td>
<td><code>"ghcr.io/confidential-containers/staged-images/coco-as-grpc"</code></td>
<td>AS container image repository.</td>
</tr>
<tr>
<td>as.image.tag</td>
<td>string</td>
<td><code>"latest"</code></td>
<td>AS container image tag.</td>
</tr>
<tr>
<td>as.imagePullSecrets</td>
<td>list</td>
<td><code>[]</code></td>
<td>Optional image pull secrets for private registries.</td>
</tr>
<tr>
<td>as.nodeSelector</td>
<td>object</td>
<td><code>{}</code></td>
<td>Node label selection constraints for AS Pods.</td>
</tr>
<tr>
<td>as.podAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Extra Pod annotations.</td>
</tr>
<tr>
<td>as.podSecurityContext</td>
<td>object</td>
<td><code>{}</code></td>
<td>Pod-level security context overrides.</td>
</tr>
<tr>
<td>as.replicaCount</td>
<td>int</td>
<td><code>1</code></td>
<td>Number of Attestation Service Pod replicas.</td>
</tr>
<tr>
<td>as.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"4","memory":"4Gi"},"requests":{"cpu":"500m","memory":"1Gi"}}</code></td>
<td>Container CPU/memory requests and limits for AS.</td>
</tr>
<tr>
<td>as.service.loadBalancerAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Annotations applied when <code>as.service.type</code> is <code>LoadBalancer</code>.</td>
</tr>
<tr>
<td>as.service.port</td>
<td>int</td>
<td><code>50004</code></td>
<td>AS Service port.</td>
</tr>
<tr>
<td>as.service.type</td>
<td>string</td>
<td><code>"ClusterIP"</code></td>
<td>AS Service type (<code>ClusterIP</code> or <code>LoadBalancer</code>).</td>
</tr>
<tr>
<td>as.tolerations</td>
<td>list</td>
<td><code>[]</code></td>
<td>Tolerations for scheduling AS Pods onto tainted nodes.</td>
</tr>
<tr>
<td>as.verifier.dcap.collateral_service</td>
<td>string</td>
<td><code>"https://api.trustedservices.intel.com/sgx/certification/v4/"</code></td>
<td>Intel DCAP collateral service URL. Required when <code>as.verifier.dcap</code> is configured.</td>
</tr>
<tr>
<td>as.verifier.dcap.tcb_update_type</td>
<td>string</td>
<td><code>"early"</code></td>
<td>DCAP TCB update type (for example <code>early</code>).</td>
</tr>
<tr>
<td>as.verifier.nvidia.type</td>
<td>string</td>
<td><code>"Local"</code></td>
<td>NVIDIA verifier type: <code>Local</code> or <code>Remote</code>. When <code>Remote</code>, <code>verifierUrl</code> must be set.</td>
</tr>
<tr>
<td>as.verifier.nvidia.verifierUrl</td>
<td>string</td>
<td><code>"https://nras.attestation.nvidia.com/v4/attest"</code></td>
<td>NRAS URL when <code>as.verifier.nvidia.type</code> is <code>Remote</code>.</td>
</tr>
<tr>
<td>as.verifier.se.credsDir</td>
<td>string</td>
<td><code>""</code></td>
<td>Absolute path on the target node to the directory containing IBM SE attestation materials (<code>rsa/</code>, <code>certs/</code>, <code>crls/</code>, <code>hkds/</code>, <code>hdr/hdr.bin</code>). When non-empty, the chart creates a <code>local</code>-type PersistentVolume + PersistentVolumeClaim and mounts the directory at <code>/run/confidential-containers/ibmse/</code> on the AS Pod. Requires <code>as.verifier.se.nodeName</code>.</td>
</tr>
<tr>
<td>as.verifier.se.nodeName</td>
<td>string</td>
<td><code>""</code></td>
<td>Kubernetes node name where the IBM SE materials directory (<code>as.verifier.se.credsDir</code>) resides. Required when <code>as.verifier.se.credsDir</code> is set; used in the PersistentVolume <code>nodeAffinity</code>.</td>
</tr>
<tr>
<td>as.verifier.snp.kdsStoreHostPath</td>
<td>string</td>
<td><code>""</code></td>
<td>Absolute path on the target node to the directory containing the AMD SNP offline VCEK certificate store (must contain a <code>vcek/</code> subdirectory). When non-empty, the chart creates a <code>local</code>-type PV + PVC and mounts it at <code>/opt/confidential-containers/attestation-service/kds-store</code> on the AS Pod, which is where an <code>OfflineStore</code> entry in <code>as.verifier.snp.vcekSources</code> reads from. Requires <code>as.verifier.snp.nodeName</code>. See <a href="/confidential-containers/trustee/blob/main/attestation-service/docs/amd-offline-certificate-cache.md">the offline certificate cache guide</a> for the directory layout.</td>
</tr>
<tr>
<td>as.verifier.snp.nodeName</td>
<td>string</td>
<td><code>""</code></td>
<td>Kubernetes node name where the kds-store directory (<code>as.verifier.snp.kdsStoreHostPath</code>) resides. Required when <code>as.verifier.snp.kdsStoreHostPath</code> is set; used in the PV <code>nodeAffinity</code>.</td>
</tr>
<tr>
<td>as.verifier.snp.vcekSources</td>
<td>list</td>
<td><code>[]</code></td>
<td>VCEK certificate sources for the SNP verifier, tried in the order given. When empty (the default), no <code>snp_verifier</code> block is emitted and the AS uses its built-in default (KDS). <code>KDS</code> fetches from AMD's Key Distribution Service and requires outbound connectivity. To configure an <code>OfflineStore</code> source, <code>as.verifier.snp.nodeName</code> and <code>as.verifier.snp.kdsStoreHostPath</code> must be provided as well, so the certificate store gets mounted into the AS Pod.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob</td>
<td>object</td>
<td><code>{"keygenImage":{"pullPolicy":"IfNotPresent","repository":"alpine/openssl","tag":"3.5.6"},"kubectlImage":{"pullPolicy":"IfNotPresent","repository":"quay.io/kata-containers/kubectl","tag":"20260112"},"resources":{"limits":{"cpu":"200m","memory":"256Mi"},"requests":{"cpu":"50m","memory":"64Mi"}}}</code></td>
<td>Bootstrap hook Job settings (pre-install/pre-upgrade key generation and post-delete cleanup when <code>secrets.useEphemeralGeneratedKeys=true</code>).</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.keygenImage.pullPolicy</td>
<td>string</td>
<td><code>"IfNotPresent"</code></td>
<td>OpenSSL <code>initContainer</code> image pull policy.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.keygenImage.repository</td>
<td>string</td>
<td><code>"alpine/openssl"</code></td>
<td>OpenSSL <code>initContainer</code> image repository that generates demo keys.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.keygenImage.tag</td>
<td>string</td>
<td><code>"3.5.6"</code></td>
<td>OpenSSL <code>initContainer</code> image tag.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.kubectlImage.pullPolicy</td>
<td>string</td>
<td><code>"IfNotPresent"</code></td>
<td>kubectl container image pull policy.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.kubectlImage.repository</td>
<td>string</td>
<td><code>"quay.io/kata-containers/kubectl"</code></td>
<td>kubectl container image repository that creates or updates the release-scoped Secret.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.kubectlImage.tag</td>
<td>string</td>
<td><code>"20260112"</code></td>
<td>kubectl container image tag.</td>
</tr>
<tr>
<td>bootstrapUserKeysJob.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"200m","memory":"256Mi"},"requests":{"cpu":"50m","memory":"64Mi"}}</code></td>
<td>CPU/memory requests and limits for the bootstrap hook Job.</td>
</tr>
<tr>
<td>dnsHostAliasWorkaround</td>
<td>bool</td>
<td><code>false</code></td>
<td>When <code>true</code>, templates use Helm <code>lookup</code> to write Service <code>clusterIP</code> entries into <code>hostAliases</code> for clusters that cannot resolve <code>*.svc.cluster.local</code>. If Services are missing on first render, rerun <code>helm upgrade</code>.</td>
</tr>
<tr>
<td>fullnameOverride</td>
<td>string</td>
<td><code>""</code></td>
<td>Override the fully qualified release name (truncated to 63 characters).</td>
</tr>
<tr>
<td>ingress</td>
<td>object</td>
<td><code>{"annotations":{},"className":"","enabled":false,"host":"","tls":[]}</code></td>
<td>Optional Kubernetes Ingress for the KBS Service.</td>
</tr>
<tr>
<td>ingress.annotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Ingress annotations.</td>
</tr>
<tr>
<td>ingress.className</td>
<td>string</td>
<td><code>""</code></td>
<td>IngressClass name.</td>
</tr>
<tr>
<td>ingress.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>Enable Ingress for KBS.</td>
</tr>
<tr>
<td>ingress.host</td>
<td>string</td>
<td><code>""</code></td>
<td>Host-based routing. Leave empty to match all hosts (IP-only access).</td>
</tr>
<tr>
<td>ingress.tls</td>
<td>list</td>
<td><code>[]</code></td>
<td>TLS configuration entries.</td>
</tr>
<tr>
<td>kbs.affinity</td>
<td>object</td>
<td><code>{}</code></td>
<td>Affinity and anti-affinity scheduling rules for KBS Pods.</td>
</tr>
<tr>
<td>kbs.config.admin.audience</td>
<td>string</td>
<td><code>"KBS"</code></td>
<td>JWT <code>audience</code> claim for the bootstrap-generated admin token.</td>
</tr>
<tr>
<td>kbs.config.admin.issuer</td>
<td>string</td>
<td><code>"TrusteeInHelm"</code></td>
<td>JWT <code>issuer</code> claim for the bootstrap-generated admin token; must match <code>[admin.authentication.bearer_jwt]</code>.</td>
</tr>
<tr>
<td>kbs.config.admin.role</td>
<td>string</td>
<td><code>"admin"</code></td>
<td>JWT <code>role</code> claim and matching <code>[admin.authorization.regex_acl]</code> role.</td>
</tr>
<tr>
<td>kbs.config.attestationService.poolSize</td>
<td>int</td>
<td><code>200</code></td>
<td>Connection pool size for the KBS -&gt; gRPC AS client (<code>pool_size</code> in <code>files/kbs-config.toml.template</code>).</td>
</tr>
<tr>
<td>kbs.config.attestationService.timeout</td>
<td>int</td>
<td><code>30</code></td>
<td>Request timeout in seconds for the KBS -&gt; gRPC AS client (<code>timeout</code> in <code>files/kbs-config.toml.template</code>).</td>
</tr>
<tr>
<td>kbs.extraEnvVars</td>
<td>list</td>
<td><code>[]</code></td>
<td>Extra environment variables to inject into the KBS container.</td>
</tr>
<tr>
<td>kbs.extraVolumeMounts</td>
<td>list</td>
<td><code>[]</code></td>
<td>Extra volume mounts for the KBS container.</td>
</tr>
<tr>
<td>kbs.extraVolumes</td>
<td>list</td>
<td><code>[]</code></td>
<td>Extra volumes to attach to the KBS Pod.</td>
</tr>
<tr>
<td>kbs.image.pullPolicy</td>
<td>string</td>
<td><code>"Always"</code></td>
<td>KBS container image pull policy.</td>
</tr>
<tr>
<td>kbs.image.repository</td>
<td>string</td>
<td><code>"ghcr.io/confidential-containers/staged-images/kbs-grpc-as"</code></td>
<td>KBS container image repository.</td>
</tr>
<tr>
<td>kbs.image.tag</td>
<td>string</td>
<td><code>"latest"</code></td>
<td>KBS container image tag.</td>
</tr>
<tr>
<td>kbs.imagePullSecrets</td>
<td>list</td>
<td><code>[]</code></td>
<td>Optional image pull secrets for private registries.</td>
</tr>
<tr>
<td>kbs.nodeSelector</td>
<td>object</td>
<td><code>{}</code></td>
<td>Node label selection constraints for KBS Pods.</td>
</tr>
<tr>
<td>kbs.podAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Extra Pod annotations (for example Prometheus scrape or service mesh integration).</td>
</tr>
<tr>
<td>kbs.podSecurityContext</td>
<td>object</td>
<td><code>{}</code></td>
<td>Pod-level security context overrides.</td>
</tr>
<tr>
<td>kbs.replicaCount</td>
<td>int</td>
<td><code>1</code></td>
<td>Number of KBS Pod replicas.</td>
</tr>
<tr>
<td>kbs.resourceRepository</td>
<td>list</td>
<td><code>[]</code></td>
<td>KBS resource repository configuration (passed through to KBS config).</td>
</tr>
<tr>
<td>kbs.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"2","memory":"2Gi"},"requests":{"cpu":"250m","memory":"256Mi"}}</code></td>
<td>Container CPU/memory requests and limits for KBS.</td>
</tr>
<tr>
<td>kbs.service.exposeLoadBalancer</td>
<td>bool</td>
<td><code>false</code></td>
<td>When <code>true</code>, create an additional external <code>LoadBalancer</code> Service (<code>&lt;fullname&gt;-kbs-lb</code>). The primary KBS Service (<code>&lt;fullname&gt;-kbs</code>) is always internal <code>ClusterIP</code>.</td>
</tr>
<tr>
<td>kbs.service.loadBalancerAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Annotations applied to the optional KBS <code>LoadBalancer</code> Service when <code>exposeLoadBalancer=true</code>.</td>
</tr>
<tr>
<td>kbs.service.port</td>
<td>int</td>
<td><code>8080</code></td>
<td>Service port for KBS; used by both the internal <code>ClusterIP</code> Service and the optional external <code>LoadBalancer</code> Service.</td>
</tr>
<tr>
<td>kbs.tls.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>Enable native HTTPS on the KBS listener. Requires <code>secretName</code>; the chart does not generate endpoint identity material.</td>
</tr>
<tr>
<td>kbs.tls.secretName</td>
<td>string</td>
<td><code>""</code></td>
<td>Secret containing the KBS HTTPS private key and certificate chain. Required when <code>enabled=true</code>.</td>
</tr>
<tr>
<td>kbs.tolerations</td>
<td>list</td>
<td><code>[]</code></td>
<td>Tolerations for scheduling KBS Pods onto tainted nodes.</td>
</tr>
<tr>
<td>log_level</td>
<td>string</td>
<td><code>"info"</code></td>
<td>Container <code>RUST_LOG</code> for KBS, AS, and RVPS (<code>info</code>, <code>debug</code>, <code>warn</code>, <code>error</code>).</td>
</tr>
<tr>
<td>nameOverride</td>
<td>string</td>
<td><code>""</code></td>
<td>Override the chart name used in labels and resource names.</td>
</tr>
<tr>
<td>nodePort</td>
<td>object</td>
<td><code>{"enabled":false,"port":""}</code></td>
<td>Expose the KBS Service via a NodePort.</td>
</tr>
<tr>
<td>nodePort.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>Enable a NodePort Service for KBS.</td>
</tr>
<tr>
<td>nodePort.port</td>
<td>string</td>
<td><code>""</code></td>
<td>Fixed NodePort number; empty assigns a random port from the NodePort range.</td>
</tr>
<tr>
<td>postgresql</td>
<td>object</td>
<td><code>{"auth":{"database":"trustee","password":"trustee","username":"trustee"},"enabled":false,"nameOverride":"postgres","primary":{"initdb":{"scriptsConfigMap":"trustee-postgres-initdb"},"persistence":{"enabled":true,"existingClaim":"","size":"8Gi","storageClass":""},"resources":{"limits":{"cpu":"1","memory":"1Gi"},"requests":{"cpu":"250m","memory":"256Mi"}}},"service":{"ports":{"postgresql":5432}}}</code></td>
<td><a href="https://artifacthub.io/packages/helm/bitnami/postgresql" rel="nofollow">Bitnami PostgreSQL</a> subchart. Set <code>enabled: true</code> when bundled Postgres is required (<code>storageBackend.postgres.mode=internal</code> and Postgres storage is needed; see <code>scenarios/postgres-backend.yaml</code>). Additional subchart keys (image, metrics, replication, and so on) are supported; see upstream docs.</td>
</tr>
<tr>
<td>postgresql.auth.database</td>
<td>string</td>
<td><code>"trustee"</code></td>
<td>Bundled Postgres database name (also used for the Trustee <code>POSTGRES_URL</code> Secret).</td>
</tr>
<tr>
<td>postgresql.auth.password</td>
<td>string</td>
<td><code>"trustee"</code></td>
<td>Bundled Postgres password (also used for the Trustee <code>POSTGRES_URL</code> Secret).</td>
</tr>
<tr>
<td>postgresql.auth.username</td>
<td>string</td>
<td><code>"trustee"</code></td>
<td>Bundled Postgres username (also used for the Trustee <code>POSTGRES_URL</code> Secret).</td>
</tr>
<tr>
<td>postgresql.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>Enable the Bitnami PostgreSQL subchart. Must be <code>true</code> when <code>storageBackend.postgres.mode=internal</code> and Postgres storage is required.</td>
</tr>
<tr>
<td>postgresql.nameOverride</td>
<td>string</td>
<td><code>"postgres"</code></td>
<td>Subchart service name override; release Service becomes <code>{Helm release}-postgres</code>.</td>
</tr>
<tr>
<td>postgresql.primary.initdb.scriptsConfigMap</td>
<td>string</td>
<td><code>"trustee-postgres-initdb"</code></td>
<td>ConfigMap wired to <code>files/postgres-initkv.sql</code> via <code>templates/postgres-initdb-configmap.yaml</code> (do not override unless you know what you are doing).</td>
</tr>
<tr>
<td>postgresql.primary.persistence.enabled</td>
<td>bool</td>
<td><code>true</code></td>
<td>Enable PVC-backed storage for bundled Postgres.</td>
</tr>
<tr>
<td>postgresql.primary.persistence.existingClaim</td>
<td>string</td>
<td><code>""</code></td>
<td>Existing PVC name to reuse for bundled Postgres.</td>
</tr>
<tr>
<td>postgresql.primary.persistence.size</td>
<td>string</td>
<td><code>"8Gi"</code></td>
<td>Requested size for the auto-created bundled Postgres PVC (for example <code>8Gi</code>).</td>
</tr>
<tr>
<td>postgresql.primary.persistence.storageClass</td>
<td>string</td>
<td><code>""</code></td>
<td>StorageClass for the auto-created bundled Postgres PVC; empty uses the cluster default.</td>
</tr>
<tr>
<td>postgresql.primary.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"1","memory":"1Gi"},"requests":{"cpu":"250m","memory":"256Mi"}}</code></td>
<td>CPU/memory requests and limits for bundled Postgres.</td>
</tr>
<tr>
<td>postgresql.service.ports.postgresql</td>
<td>int</td>
<td><code>5432</code></td>
<td>Bundled Postgres Service port (used in <code>POSTGRES_URL</code>).</td>
</tr>
<tr>
<td>rvps.affinity</td>
<td>object</td>
<td><code>{}</code></td>
<td>Affinity and anti-affinity scheduling rules for RVPS Pods.</td>
</tr>
<tr>
<td>rvps.extraEnvVars</td>
<td>list</td>
<td><code>[]</code></td>
<td>Extra environment variables for the RVPS container (for example <code>HTTP(S)_PROXY</code> and <code>NO_PROXY</code>).</td>
</tr>
<tr>
<td>rvps.image.pullPolicy</td>
<td>string</td>
<td><code>"Always"</code></td>
<td>RVPS container image pull policy.</td>
</tr>
<tr>
<td>rvps.image.repository</td>
<td>string</td>
<td><code>"ghcr.io/confidential-containers/staged-images/rvps"</code></td>
<td>RVPS container image repository.</td>
</tr>
<tr>
<td>rvps.image.tag</td>
<td>string</td>
<td><code>"latest"</code></td>
<td>RVPS container image tag.</td>
</tr>
<tr>
<td>rvps.imagePullSecrets</td>
<td>list</td>
<td><code>[]</code></td>
<td>Optional image pull secrets for private registries.</td>
</tr>
<tr>
<td>rvps.nodeSelector</td>
<td>object</td>
<td><code>{}</code></td>
<td>Node label selection constraints for RVPS Pods.</td>
</tr>
<tr>
<td>rvps.podAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Extra Pod annotations.</td>
</tr>
<tr>
<td>rvps.podSecurityContext</td>
<td>object</td>
<td><code>{}</code></td>
<td>Pod-level security context overrides.</td>
</tr>
<tr>
<td>rvps.replicaCount</td>
<td>int</td>
<td><code>1</code></td>
<td>Number of RVPS Pod replicas.</td>
</tr>
<tr>
<td>rvps.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"1","memory":"1Gi"},"requests":{"cpu":"100m","memory":"128Mi"}}</code></td>
<td>Container CPU/memory requests and limits for RVPS.</td>
</tr>
<tr>
<td>rvps.service.loadBalancerAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Annotations for the internal RVPS LoadBalancer Service.</td>
</tr>
<tr>
<td>rvps.service.loadBalancerType</td>
<td>string</td>
<td><code>"internal"</code></td>
<td>Load balancer kind when <code>rvps.service.type</code> is <code>LoadBalancer</code>: <code>internal</code> or <code>public</code>.</td>
</tr>
<tr>
<td>rvps.service.port</td>
<td>int</td>
<td><code>50003</code></td>
<td>RVPS Service port.</td>
</tr>
<tr>
<td>rvps.service.publicLoadBalancerAnnotations</td>
<td>object</td>
<td><code>{}</code></td>
<td>Annotations for the public RVPS LoadBalancer Service when <code>loadBalancerType=public</code>.</td>
</tr>
<tr>
<td>rvps.service.type</td>
<td>string</td>
<td><code>"ClusterIP"</code></td>
<td>RVPS Service type (<code>ClusterIP</code> or <code>LoadBalancer</code>).</td>
</tr>
<tr>
<td>rvps.tolerations</td>
<td>list</td>
<td><code>[]</code></td>
<td>Tolerations for scheduling RVPS Pods onto tainted nodes.</td>
</tr>
<tr>
<td>secrets.existingSecretName</td>
<td>string</td>
<td><code>""</code></td>
<td>Required when <code>useEphemeralGeneratedKeys=false</code>. Secret must contain <code>KBS_ADMIN_PRIVATE_KEY</code>, <code>KBS_ADMIN_PUBKEY</code>, <code>AS_TOKEN_SIGNING_PRIVATE_KEY</code>, and <code>AS_TOKEN_VERIFICATION_PUBLIC_KEY_CERT_CHAIN</code>. Optionally include <code>KBS_ADMIN_TOKEN</code> (see <code>kbs/config/docker-compose/setup.sh</code> for claim layout).</td>
</tr>
<tr>
<td>secrets.useEphemeralGeneratedKeys</td>
<td>bool</td>
<td><code>true</code></td>
<td>When <code>true</code>, a pre-install/pre-upgrade hook generates demo keys into a release-scoped Secret; when <code>false</code>, you must pre-create a Secret and set <code>existingSecretName</code>.</td>
</tr>
<tr>
<td>sessionStorageType</td>
<td>string</td>
<td><code>"Memory"</code></td>
<td>KBS protocol session store: <code>Memory</code>, <code>LocalJson</code>, <code>LocalFs</code>, <code>Postgres</code>, or <code>Redis</code>. When empty, follows <code>storageBackend.type</code>. <code>Redis</code> speaks the Redis protocol and is served by the bundled Valkey subchart (or an external Redis-compatible service).</td>
</tr>
<tr>
<td>storageBackend</td>
<td>object</td>
<td><code>{"localFs":{"persistence":{"as":"","kbs":"","rvps":""}},"localJson":{"persistence":{"as":"","kbs":"","rvps":""}},"postgres":{"external":{"existingSecretKey":"","existingSecretName":""},"internal":{"initKvTables":true},"mode":"internal"},"redis":{"external":{"existingSecretKey":"","existingSecretName":""},"mode":"internal"},"type":"LocalFs"}</code></td>
<td>Unified KV backend for KBS, AS, and RVPS (same <code>storage_type</code> in each service config).</td>
</tr>
<tr>
<td>storageBackend.localFs.persistence.as</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for AS local storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.localFs.persistence.kbs</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for KBS local storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.localFs.persistence.rvps</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for RVPS local storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.localJson.persistence.as</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for AS local JSON storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.localJson.persistence.kbs</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for KBS local JSON storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.localJson.persistence.rvps</td>
<td>string</td>
<td><code>""</code></td>
<td>PVC claim name for RVPS local JSON storage; empty uses <code>emptyDir</code>.</td>
</tr>
<tr>
<td>storageBackend.postgres.external.existingSecretKey</td>
<td>string</td>
<td><code>""</code></td>
<td>Required when <code>mode</code> is <code>external</code>: Secret key name for the Postgres URL.</td>
</tr>
<tr>
<td>storageBackend.postgres.external.existingSecretName</td>
<td>string</td>
<td><code>""</code></td>
<td>Required when <code>mode</code> is <code>external</code>: Secret containing the Postgres URL.</td>
</tr>
<tr>
<td>storageBackend.postgres.internal.initKvTables</td>
<td>bool</td>
<td><code>true</code></td>
<td>When <code>true</code>, run KV table init SQL from <code>files/postgres-initkv.sql</code> on first database init (via a chart-managed ConfigMap). When <code>false</code>, also set <code>postgresql.primary.initdb.scriptsConfigMap</code> to <code>""</code>.</td>
</tr>
<tr>
<td>storageBackend.postgres.mode</td>
<td>string</td>
<td><code>"internal"</code></td>
<td>Postgres source: <code>internal</code> (Bitnami subchart) or <code>external</code> (pre-created Secret).</td>
</tr>
<tr>
<td>storageBackend.redis.external.existingSecretKey</td>
<td>string</td>
<td><code>""</code></td>
<td>Required when <code>mode</code> is <code>external</code>: Secret key name for the Redis URL.</td>
</tr>
<tr>
<td>storageBackend.redis.external.existingSecretName</td>
<td>string</td>
<td><code>""</code></td>
<td>Required when <code>mode</code> is <code>external</code>: Secret containing the Redis URL (e.g. <code>redis://:password@redis.example.com:6379</code>).</td>
</tr>
<tr>
<td>storageBackend.redis.mode</td>
<td>string</td>
<td><code>"internal"</code></td>
<td>Redis-protocol source: <code>internal</code> (Bitnami Valkey subchart) or <code>external</code> (pre-created Secret with a Redis URL).</td>
</tr>
<tr>
<td>storageBackend.type</td>
<td>string</td>
<td><code>"LocalFs"</code></td>
<td>Backend type: <code>LocalFs</code>, <code>LocalJson</code>, <code>Postgres</code>, or <code>Memory</code>. When <code>Postgres</code> (or <code>sessionStorageType</code> is <code>Postgres</code>), the chart injects <code>POSTGRES_URL</code>. Only settings for the selected type take effect.</td>
</tr>
<tr>
<td>valkey</td>
<td>object</td>
<td><code>{"architecture":"standalone","auth":{"enabled":true,"password":"trustee"},"enabled":false,"image":{"pullPolicy":"IfNotPresent","registry":"registry-1.docker.io","repository":"bitnami/valkey","tag":"latest"},"nameOverride":"valkey","primary":{"persistence":{"enabled":false},"resources":{"limits":{"cpu":"1","memory":"512Mi"},"requests":{"cpu":"100m","memory":"128Mi"}},"service":{"ports":{"valkey":6379}}}}</code></td>
<td><a href="https://artifacthub.io/packages/helm/bitnami/valkey" rel="nofollow">Bitnami Valkey</a> subchart, a Redis-protocol-compatible store used for the KBS <code>Redis</code> session backend (Valkey is BSD-licensed; it replaces Redis, whose license is no longer OSI-approved). Set <code>enabled: true</code> when the bundled store is required (<code>storageBackend.redis.mode=internal</code> and <code>sessionStorageType</code> or <code>storageBackend.type</code> is <code>Redis</code>; see <code>scenarios/valkey-sessions.yaml</code>). Additional subchart keys (metrics, replication, TLS, and so on) are supported; see upstream docs.</td>
</tr>
<tr>
<td>valkey.architecture</td>
<td>string</td>
<td><code>"standalone"</code></td>
<td>Single Valkey primary; sessions do not need replicas. Set <code>replication</code> plus <code>replica.*</code> keys for HA (see upstream docs).</td>
</tr>
<tr>
<td>valkey.auth.enabled</td>
<td>bool</td>
<td><code>true</code></td>
<td>Require a password for the bundled Valkey (also used for the Trustee <code>REDIS_URL</code> Secret).</td>
</tr>
<tr>
<td>valkey.auth.password</td>
<td>string</td>
<td><code>"trustee"</code></td>
<td>Bundled Valkey password (also used for the Trustee <code>REDIS_URL</code> Secret).</td>
</tr>
<tr>
<td>valkey.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>Enable the Bitnami Valkey subchart. Must be <code>true</code> when <code>storageBackend.redis.mode=internal</code> and Redis storage is required.</td>
</tr>
<tr>
<td>valkey.image</td>
<td>object</td>
<td><code>{"pullPolicy":"IfNotPresent","registry":"registry-1.docker.io","repository":"bitnami/valkey","tag":"latest"}</code></td>
<td>Bundled Valkey container image. The default comes from <code>docker.io</code>, where anonymous pulls are rate-limited; point <code>registry</code>/<code>repository</code> at a private mirror to avoid pull failures (a chart-wide <code>global.imageRegistry</code> is also honored by the subchart).</td>
</tr>
<tr>
<td>valkey.image.pullPolicy</td>
<td>string</td>
<td><code>"IfNotPresent"</code></td>
<td>Valkey image pull policy.</td>
</tr>
<tr>
<td>valkey.image.registry</td>
<td>string</td>
<td><code>"registry-1.docker.io"</code></td>
<td>Valkey image registry; override with a mirror to avoid docker.io rate limits.</td>
</tr>
<tr>
<td>valkey.image.repository</td>
<td>string</td>
<td><code>"bitnami/valkey"</code></td>
<td>Valkey image repository.</td>
</tr>
<tr>
<td>valkey.image.tag</td>
<td>string</td>
<td><code>"latest"</code></td>
<td>Valkey image tag.</td>
</tr>
<tr>
<td>valkey.nameOverride</td>
<td>string</td>
<td><code>"valkey"</code></td>
<td>Subchart name override; the primary Service becomes <code>{Helm release}-valkey-primary</code>.</td>
</tr>
<tr>
<td>valkey.primary.persistence.enabled</td>
<td>bool</td>
<td><code>false</code></td>
<td>KBS sessions are short-lived, so the bundled Valkey defaults to no PVC; set <code>true</code> (plus optional <code>storageClass</code>/<code>size</code>) to persist sessions across Pod restarts.</td>
</tr>
<tr>
<td>valkey.primary.resources</td>
<td>object</td>
<td><code>{"limits":{"cpu":"1","memory":"512Mi"},"requests":{"cpu":"100m","memory":"128Mi"}}</code></td>
<td>CPU/memory requests and limits for the bundled Valkey primary.</td>
</tr>
<tr>
<td>valkey.primary.service.ports.valkey</td>
<td>int</td>
<td><code>6379</code></td>
<td>Bundled Valkey Service port (used in <code>REDIS_URL</code>).</td>
</tr>
</tbody>
</table></markdown-accessiblity-table>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">End-to-end test</h2><a id="user-content-end-to-end-test" class="anchor" aria-label="Permalink: End-to-end test" href="#end-to-end-test"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<p dir="auto">Provision a <strong>kind</strong> cluster out of band, preload the Trustee images into it, point <code>kubectl</code> at it, then from the repository root:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="kind create cluster --name kind --wait 5m
make -C deployment/helm-chart load-e2e-images-into-kind
make test-helm-e2e"><pre>kind create cluster --name kind --wait 5m
make -C deployment/helm-chart load-e2e-images-into-kind
make test-helm-e2e</pre></div>
<p dir="auto"><code>make e2e-test</code> assumes <strong>KBS / AS / RVPS</strong> images are already loaded into the cluster and deploys with <a href="/confidential-containers/trustee/blob/main/deployment/helm-chart/scenarios/e2e-local-images.yaml">scenarios/e2e-local-images.yaml</a>. The Makefile injects image repositories, tags, and <code>pullPolicy: Never</code> at install time so local runs and CI can use different preloaded image names without changing the scenario file.</p>
<ul dir="auto">
<li><strong>Local preloaded images</strong>: <code>trustee-e2e/*:e2e</code>, <code>pullPolicy: Never</code> (not GHCR <code>:latest</code>)</li>
<li><strong>CI images</strong>: reuses <code>docker-e2e-images-linux-amd64</code> from <code>workflow-call-build-docker-e2e-materials.yml</code> as <code>ghcr.io/confidential-containers/staged-images/*:latest</code></li>
<li><strong>Storage</strong>: bundled Postgres KV backend (<code>storageBackend.type: Postgres</code>)</li>
<li><strong>KBS sessions</strong>: bundled Valkey (<code>sessionStorageType: Redis</code>)</li>
<li><strong>KBS endpoint</strong>: native HTTPS using an ephemeral, test-only certificate</li>
</ul>
<p dir="auto">Steps:</p>
<ol dir="auto">
<li><strong><code>helm-dependency-build</code></strong></li>
<li><strong><code>helm-lint</code></strong> — validates the default HTTP, e2e, and native-HTTPS configurations</li>
<li><strong><code>prepare-e2e-tls</code></strong> — creates a test Kubernetes TLS Secret</li>
<li><strong><code>deploy</code></strong></li>
<li><strong><code>test-client</code></strong> — <a href="/confidential-containers/trustee/blob/main/deployment/helm-chart/e2e/test.sh">e2e/test.sh</a> validates the certificate and exercises KBS over HTTPS</li>
<li><strong><code>dump-logs</code></strong> — on failure only: pod status, events, describe, and container logs (current + previous), while the namespace still exists</li>
<li><strong><code>undeploy</code></strong> — always attempted, even after failures</li>
</ol>
<p dir="auto">Debug individually:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" dir="auto" data-snippet-clipboard-copy-content="make -C deployment/helm-chart load-e2e-images-into-kind
make -C deployment/helm-chart helm-lint
make -C deployment/helm-chart prepare-e2e-tls
make -C deployment/helm-chart deploy
make -C deployment/helm-chart test-client
make -C deployment/helm-chart dump-logs
make -C deployment/helm-chart undeploy"><pre>make -C deployment/helm-chart load-e2e-images-into-kind
make -C deployment/helm-chart helm-lint
make -C deployment/helm-chart prepare-e2e-tls
make -C deployment/helm-chart deploy
make -C deployment/helm-chart test-client
make -C deployment/helm-chart dump-logs
make -C deployment/helm-chart undeploy</pre></div>
<p dir="auto">Optional variables: <code>E2E_IMAGE_PREFIX</code>, <code>E2E_IMAGE_TAG</code>, <code>KBS_CLIENT</code>.</p>
<p dir="auto">CI (<code>test-e2e-kbs.yml</code>) reuses the Docker Compose e2e image build workflow artifacts: it loads the pre-built Trustee images into kind and uses the pre-built <code>kbs-client</code> binary before running Helm e2e.</p>
<p dir="auto"><code>make test-client</code> alone does not build images or undeploy.</p>
<div class="markdown-heading" dir="auto"><h2 tabindex="-1" class="heading-element" dir="auto">Development notes</h2><a id="user-content-development-notes" class="anchor" aria-label="Permalink: Development notes" href="#development-notes"><svg data-component="Octicon" class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"></path></svg></a></div>
<ol dir="auto">
<li>Do not change the files under <a href="/confidential-containers/trustee/blob/main/deployment/helm-chart/files">files</a> unless you are updating the corresponding Helm template logic. Service config is rendered from <code>*.template</code> files; Postgres KV init SQL lives in <code>files/postgres-initkv.sql</code>.</li>
<li>After changing <code>Chart.yaml</code> dependencies, run <code>helm dependency update ./deployment/helm-chart</code> and commit <code>Chart.lock</code> plus <code>charts/</code> if your packaging workflow vendors subcharts.</li>
<li>After changing <code>values.yaml</code> comments or keys, regenerate this README from <a href="/confidential-containers/trustee/blob/main/deployment/helm-chart/README.md.gotmpl">README.md.gotmpl</a>: <code>helm-docs -c .</code> (run from this directory).</li>
</ol>
</article></div><div class="d-none"></div></section></div></div></div> </div> <!-- --> </div></div></div></div></div></div><div class="ScrollMarksContainer-module__scrollMarksContainer__Eu7uU" id="find-result-marks-container"></div><div class="d-none"></div><div class="d-none"></div></div> <!-- --> <!-- --> </div>
</react-app>




  </div>

</turbo-frame>

    </main>
  </div>

  </div>

          <footer class="footer f6 color-fg-muted color-border-subtle tmp-pt-7 tmp-pb-6 p-responsive" role="contentinfo"  >
  <h2 class='sr-only'>Footer</h2>

  


  <div class="d-flex flex-justify-center flex-items-center flex-column-reverse flex-lg-row flex-wrap flex-lg-nowrap">
    <div class="d-flex flex-items-center flex-shrink-0 mx-2">
      <a aria-label="GitHub Homepage" class="footer-octicon mr-2" href="https://github.com">
        <svg aria-hidden="true" data-component="Octicon" height="24" viewBox="0 0 24 24" version="1.1" width="24" data-view-component="true" class="octicon octicon-mark-github">
    <path d="M10.226 17.284c-2.965-.36-5.054-2.493-5.054-5.256 0-1.123.404-2.336 1.078-3.144-.292-.741-.247-2.314.09-2.965.898-.112 2.111.36 2.83 1.01.853-.269 1.752-.404 2.853-.404 1.1 0 1.999.135 2.807.382.696-.629 1.932-1.1 2.83-.988.315.606.36 2.179.067 2.942.72.854 1.101 2 1.101 3.167 0 2.763-2.089 4.852-5.098 5.234.763.494 1.28 1.572 1.28 2.807v2.336c0 .674.561 1.056 1.235.786 4.066-1.55 7.255-5.615 7.255-10.646C23.5 6.188 18.334 1 11.978 1 5.62 1 .5 6.188.5 12.545c0 4.986 3.167 9.12 7.435 10.669.606.225 1.19-.18 1.19-.786V20.63a2.9 2.9 0 0 1-1.078.224c-1.483 0-2.359-.808-2.987-2.313-.247-.607-.517-.966-1.034-1.033-.27-.023-.359-.135-.359-.27 0-.27.45-.471.898-.471.652 0 1.213.404 1.797 1.235.45.651.921.943 1.483.943.561 0 .92-.202 1.437-.719.382-.381.674-.718.944-.943"></path>
</svg>
</a>
      <span>
        &copy; 2026 GitHub,&nbsp;Inc.
      </span>
    </div>

    <nav aria-label="Footer">
      <h3 class="sr-only" id="sr-footer-heading">Footer navigation</h3>

      <ul class="list-style-none d-flex flex-justify-center flex-wrap mb-2 mb-lg-0" aria-labelledby="sr-footer-heading">


          <li class="mx-2">
            <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to Terms&quot;,&quot;label&quot;:&quot;text:terms&quot;}" href="https://docs.github.com/site-policy/github-terms/github-terms-of-service" data-view-component="true" class="Link--secondary Link">Terms</a>
          </li>

          <li class="mx-2">
            <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to privacy&quot;,&quot;label&quot;:&quot;text:privacy&quot;}" href="https://docs.github.com/site-policy/privacy-policies/github-privacy-statement" data-view-component="true" class="Link--secondary Link">Privacy</a>
          </li>


            <li class="mx-2">
              <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to security&quot;,&quot;label&quot;:&quot;text:security&quot;}" href="https://github.com/security" data-view-component="true" class="Link--secondary Link">Security</a>
            </li>

            <li class="mx-2">
              <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to status&quot;,&quot;label&quot;:&quot;text:status&quot;}" href="https://www.githubstatus.com/" data-view-component="true" class="Link--secondary Link">Status</a>
            </li>

          <li class="mx-2">
            <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to community&quot;,&quot;label&quot;:&quot;text:community&quot;}" href="https://github.community/" data-view-component="true" class="Link--secondary Link">Community</a>
          </li>

          <li class="mx-2">
            <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to docs&quot;,&quot;label&quot;:&quot;text:docs&quot;}" href="https://docs.github.com/" data-view-component="true" class="Link--secondary Link">Docs</a>
          </li>

          <li class="mx-2">
            <a data-analytics-event="{&quot;category&quot;:&quot;Footer&quot;,&quot;action&quot;:&quot;go to contact&quot;,&quot;label&quot;:&quot;text:contact&quot;}" href="https://support.github.com?tags=dotcom-footer" data-view-component="true" class="Link--secondary Link">Contact</a>
          </li>

          
<li class="mx-2" >
  <cookie-consent-link>
    <button
      type="button"
      class="Link--secondary underline-on-hover border-0 p-0 color-bg-transparent"
      data-action="click:cookie-consent-link#showConsentManagement"
      data-analytics-event="{&quot;location&quot;:&quot;footer&quot;,&quot;action&quot;:&quot;cookies&quot;,&quot;context&quot;:&quot;subfooter&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;label&quot;:&quot;cookies_link_subfooter_footer&quot;}"
    >
      Manage cookies
    </button>
  </cookie-consent-link>
</li>

  <li class="mx-2">
    <cookie-consent-link>
      <button
        type="button"
        class="Link--secondary underline-on-hover border-0 p-0 color-bg-transparent text-left"
        data-action="click:cookie-consent-link#showConsentManagement"
        data-analytics-event="{&quot;location&quot;:&quot;footer&quot;,&quot;action&quot;:&quot;dont_share_info&quot;,&quot;context&quot;:&quot;subfooter&quot;,&quot;tag&quot;:&quot;link&quot;,&quot;label&quot;:&quot;dont_share_info_link_subfooter_footer&quot;}"
      >
        Do not share my personal information
      </button>
    </cookie-consent-link>
  </li>

      </ul>
    </nav>
  </div>
</footer>



    <ghcc-consent id="ghcc" class="position-fixed bottom-0 left-0" style="z-index: 999999"
      data-locale="en"
      data-initial-cookie-consent-allowed=""
      data-cookie-consent-required="true"
    ></ghcc-consent>




  <div id="ajax-error-message" class="ajax-error-message flash flash-error" hidden>
    <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-alert">
    <path d="M6.457 1.047c.659-1.234 2.427-1.234 3.086 0l6.082 11.378A1.75 1.75 0 0 1 14.082 15H1.918a1.75 1.75 0 0 1-1.543-2.575Zm1.763.707a.25.25 0 0 0-.44 0L1.698 13.132a.25.25 0 0 0 .22.368h12.164a.25.25 0 0 0 .22-.368Zm.53 3.996v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 11a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path>
</svg>
    <button type="button" class="flash-close js-ajax-error-dismiss" aria-label="Dismiss error">
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-x">
    <path d="M3.72 3.72a.75.75 0 0 1 1.06 0L8 6.94l3.22-3.22a.749.749 0 0 1 1.275.326.749.749 0 0 1-.215.734L9.06 8l3.22 3.22a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L8 9.06l-3.22 3.22a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L6.94 8 3.72 4.78a.75.75 0 0 1 0-1.06Z"></path>
</svg>
    </button>
    You can’t perform that action at this time.
  </div>

    <template id="site-details-dialog">
  <details class="details-reset details-overlay details-overlay-dark lh-default color-fg-default hx_rsm" open>
    <summary role="button" aria-label="Close dialog"></summary>
    <details-dialog class="Box Box--overlay d-flex flex-column anim-fade-in fast hx_rsm-dialog hx_rsm-modal">
      <button class="Box-btn-octicon m-0 btn-octicon position-absolute right-0 top-0" type="button" aria-label="Close dialog" data-close-dialog>
        <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-x">
    <path d="M3.72 3.72a.75.75 0 0 1 1.06 0L8 6.94l3.22-3.22a.749.749 0 0 1 1.275.326.749.749 0 0 1-.215.734L9.06 8l3.22 3.22a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L8 9.06l-3.22 3.22a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L6.94 8 3.72 4.78a.75.75 0 0 1 0-1.06Z"></path>
</svg>
      </button>
      <div class="octocat-spinner tmp-my-6 js-details-dialog-spinner"></div>
    </details-dialog>
  </details>
</template>

    <div class="Popover js-hovercard-content position-absolute" style="display: none; outline: none;">
  <div class="Popover-message Popover-message--bottom-left Popover-message--large Box color-shadow-large" style="width:360px;">
  </div>
</div>

    <template id="snippet-clipboard-copy-button">
  <div class="zeroclipboard-container position-absolute right-0 top-0">
    <clipboard-copy aria-label="Copy code to clipboard" class="ClipboardButton btn js-clipboard-copy m-2 p-0" data-copy-feedback="Copied!" data-tooltip-direction="w">
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-copy js-clipboard-copy-icon m-2 tmp-m-2">
    <path d="M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z"></path><path d="M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z"></path>
</svg>
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-check js-clipboard-check-icon color-fg-success d-none m-2 tmp-m-2">
    <path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path>
</svg>
    </clipboard-copy>
  </div>
</template>
<template id="snippet-clipboard-copy-button-unpositioned">
  <div class="zeroclipboard-container">
    <clipboard-copy aria-label="Copy code to clipboard" class="ClipboardButton btn btn-invisible js-clipboard-copy m-2 p-0 d-flex flex-justify-center flex-items-center" data-copy-feedback="Copied!" data-tooltip-direction="w">
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-copy js-clipboard-copy-icon">
    <path d="M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z"></path><path d="M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z"></path>
</svg>
      <svg aria-hidden="true" data-component="Octicon" height="16" viewBox="0 0 16 16" version="1.1" width="16" data-view-component="true" class="octicon octicon-check js-clipboard-check-icon color-fg-success d-none">
    <path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path>
</svg>
    </clipboard-copy>
  </div>
</template>




    </div>
    <div id="js-global-screen-reader-notice" class="sr-only mt-n1" aria-live="polite" aria-atomic="true" ></div>
    <div id="js-global-screen-reader-notice-assertive" class="sr-only mt-n1" aria-live="assertive" aria-atomic="true"></div>
  </body>
</html>

