Project reference ↗

Conjur manages secrets such as passwords and service credentials that applications need but should not keep in source code. A workload proves its identity, and Conjur applies policy to decide which secrets it may retrieve. This is useful when many applications need controlled access and credential rotation rather than shared, long-lived configuration files. Running Conjur also creates a recovery responsibility: its database and encryption material must remain available and protected.

Deployment and operating notes

The recovered chart points to CyberArk’s Conjur Open Source Helm repository. Its current README recommends choosing chart and integration versions from a compatible Conjur OSS suite release and specifies Helm 3 or later. That recommendation is more useful than selecting the newest component independently. It does not imply that the OSS chart implements every commercial CyberArk deployment or support feature.

Before adoption, define how workloads authenticate and which policies authorize each secret path. Separate Kubernetes service-account identity, Conjur policy and application consumption; successful secret retrieval by an administrator proves little about workload least privilege. Back up the database and protect the encryption material required for recovery. During migration, test allowed and denied identities, credential rotation and startup when Conjur is unavailable. Keep an audited emergency recovery path and avoid embedding secrets in version-controlled chart values. Validate the suite compatibility and Kubernetes authentication method against the chosen releases; this review did not perform a live Conjur installation or secret-store migration.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub does not mark cyberark/conjur-oss-helm-chart archived or disabled; this does not establish active maintenance, support or compatibility. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Preserved for context. Commands, versions, prices and results below reflect the original research.

Control access to your critical systems.

Conjur is an open source security service that integrates with popular tools to provide data encryption, identity management for humans and machines, and role-based access control for sensitive secrets like passwords, SSH keys, and web services.

Machine Identity

Machine Identity is the heart of Conjur. Conjur was designed from the ground up to support security automation workflows of all kinds – secrets management, SSH, traffic authorization, container environments, configuration management, and custom access control scenarios.

Secrets Management

Conjur provides a policy framework to manage access to secrets. The policy definitions contain no secret themselves, making them safe and easy to share, review, and edit among a group of people without exposing confidential information. With secrets abstraction, even the users of secrets need not know their values.

Authorization Model

Conjur’s machine identity capabilities are built on the foundation of RBAC, ensuring that the automated workloads managed by Conjur are running with proven and scalable security properties. Conjur’s policy management can be managed strictly, ensuring that security rules at scale is both tightly managed and scalable.

Scalability

Conjur has collected extensive benchmarks of the scale-out performance of Conjur, and can demonstrate linear scaling from clusters of 1 machine to 10 or more. Conjur can demonstrate the fully authenticated, authorized, retrieval of up to 4 million secrets per minute.

Built for Containers

Containers come with their own security challenges and Conjur is specifically built with those in mind. Conjur uniquely identifies containers where each container has its own unique permissions (RBAC) managed by a Conjur root policy. Applications and services running on those containers are also uniquely authenticated and authorized, making sure secrets are shared securely only with their intended recipients.

Integrations

CyberArk officially provides and supports integration libraries between Conjur and external tools such as Puppet, Ansible, and Summon, as well as API libraries for Ruby, Go, Java, and .NET. CyberArk has officially partnered with Puppet to provide joint support for the Conjur Puppet Module. CyberArk is extending this partnering relationship to other major tool vendors in the DevOps space.

Sources & further reading

  1. Conjur OSS chart requirements
  2. Conjur OSS chart configuration
  3. Recovered historical source (Common Crawl index)

Spotted something that needs another look?

Help improve this page →