Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can install SafeLine on Kubernetes using either a third-party preview Helm chart or a separate third-party chart labeled stable LTS. Neither repository, by itself, establishes that Chaitin endorses the chart for production. SafeLine is a self-hosted web application firewall and reverse proxy, and the official project repository names an Ingress-NGINX integration for protecting Kubernetes ingress traffic. The chart’s optional management-console ingress is a separate feature from routing application traffic through the WAF.

Choose a chart track before installing

The available Helm instructions are in two separate GitHub repositories. Their labels describe the chart branches; they are not independent evidence of vendor support or production suitability.

Track Chart reference International image note Documented operational warning
Preview yaencn/safeline — repository branch labels it preview. The README documents global.image.registry=chaitin and global.image.region="-g" for international image deployment from appVersion 8.8.2 on x86_64. Deployments should run one pod replica; multiple replicas can cause WAF errors.
LTS yaencn/safeline-lts — repository branch labels it stable LTS. The README documents the corresponding international image settings from appVersion 8.8.0; the cited note does not specify an architecture. Deployments should run one pod replica; multiple replicas can cause WAF errors.

These details come from the third-party preview and LTS chart READMEs (preview chart repository; LTS chart repository). Check the current chart version, values, appVersion, and architecture support before installing: README commands and defaults can change. The official project repository identifies an Ingress-NGINX integration, but that does not establish that Chaitin maintains or endorses either Helm chart for production (SafeLine project repository).

Check your cluster and chart values

Before installation, confirm that your cluster has a working Helm and Kubernetes setup, a DNS name for the console if you plan to expose it, a suitable storage class, and access to the required container image registry. The chart examples do not establish universal platform prerequisites, so verify requirements for your cluster and the chart release you select.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect and pin a specific chart version and review its values rather than deploying mutable defaults. Pay particular attention to database credentials, persistence, service exposure, ingress class, and TLS. The preview README documents default service exposure that includes Tengine as a LoadBalancer, management web as NodePort 31443, and internal PostgreSQL as a database option. These are chart defaults, not recommendations for every cluster.

Install the chart in a dedicated namespace

The following is the preview repository’s example with console ingress enabled and a hostname supplied. It is a repository example, not an independently tested command; review the current chart version and values before using it on a real cluster.

helm repo add yaencn https://helm.yaencn.com/charts
helm install safeline --namespace safeline 
  --set global.ingress.enabled=true 
  --set global.ingress.hostname="waf.example.com" 
  yaencn/safeline

The preview README also shows local-chart installation and a repository-based example that configures the console hostname. For the LTS track, the repository example uses yaencn/safeline-lts instead of yaencn/safeline. Both chart repositories document console ingress as disabled by default; their examples use the nginx ingress class. If you configure a TLS Secret for that ingress, create the Secret before installing the chart.

Set security-sensitive values

  • Replace the documented internal PostgreSQL password default, changeit, before deployment.
  • The preview chart README advises replacing the default EC private key for production.
  • Review persistent storage and service exposure settings against your cluster’s requirements; do not assume the documented defaults are appropriate.

Choose how traffic reaches SafeLine

The chart’s service exposure and console ingress settings are not interchangeable. In the preview chart, global.exposeServicesAsPorts.enabled is documented as true by default, and the README recommends port exposure by default. For a chart configuration that uses Ingress mode for the services, the preview README says to set this value to false.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Console ingress exposes the management interface at its configured hostname. It does not, by itself, mean that application requests pass through SafeLine. The official SafeLine repository describes the product as a reverse proxy and names an Ingress-NGINX integration for protecting Kubernetes ingress traffic. The sources cited here do not establish the exact application onboarding steps for that integration, so follow its current configuration documentation before routing a website through it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the release and test before production

After installing, use your normal Kubernetes procedures to check Helm release status, pod readiness, services, ingress resources, logs, and persistent storage. These are operational checks, not a checklist prescribed by the cited chart excerpts.

Begin with benign application traffic and controlled security test cases in a non-production environment. Watch application behavior and logs for false positives, and have a rollback path before changing production routing. Do not plan on horizontal scaling or high availability from these charts based on the documented setup: both repositories warn that multiple pod replicas can cause WAF errors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.