kubespray-helm-airgap
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the
helm-pushplugin from the ChartMuseum GitHub repository. - [EXTERNAL_DOWNLOADS]: The skill references pulling container images from well-known registries including GitHub Container Registry (
ghcr.io) and Docker Hub (docker.io). - [COMMAND_EXECUTION]: The documentation includes commands to modify system-level configuration in
/etc/containers/registries.confto allow insecure (non-TLS) communication with local registries, which is a common requirement in isolated laboratory or air-gapped environments. - [COMMAND_EXECUTION]: The skill suggests setting broad file permissions (
chmod 777) on the local data directory used by the ChartMuseum service to ensure the container process has write access.
Audit Metadata