{
  "kind": "LiveParityDecisions",
  "unofficial": true,
  "description": "Product-readable decisions for the committed NON-PASS ConfigHub OCI + live Helm-vs-ConfigHub (G/P-lane) rows. Classifies each watch/blocked row by residue, who owns the fix, and whether the chart/base is usable today. Read-only over committed evidence. Generated by scripts/generate-live-parity-decisions.mjs; do not hand-edit.",
  "source": "data/live-helm-confighub-compare/summary.csv",
  "residue_categories": [
    "gitops-runtime",
    "operate-policy",
    "target-runtime",
    "target-fit",
    "target-prerequisite",
    "crd-bootstrap",
    "render-input",
    "remote-image",
    "capability-profile",
    "semantic-model-gap"
  ],
  "note": "A watch row is known evidence with a named residue: semantic Helm-vs-ConfigHub parity passed; a GitOps/runtime/operate condition remains. It is not a pass and not a failure.",
  "decisions": [
    {
      "chart": "argo-cd/argo-cd",
      "version": "9.5.17",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: child Argo Application not materialized (parity passed)",
      "support_artifact": "recipes/argo-cd/argo-cd/9.5.17/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/argo-cd-argo-cd-default-9-5-17/receipt.yaml"
    },
    {
      "chart": "aws-ebs-csi-driver/aws-ebs-csi-driver",
      "version": "2.60.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-fit",
      "blocker_owner": "user or catalog",
      "usable_today": "watch — needs a target with the required platform shape",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed), but the selected proof target does not provide a platform behavior this base requires. Choose a target that satisfies the base, or create a separate base for the smaller proof target.",
      "next_action": "Review the target-topology support artifact, choose a target with the required platform behavior, or create a target-scoped base before rerunning.",
      "reason": "target-fit: AWS/EKS metadata or provider identity missing on vanilla kind (parity passed)",
      "support_artifact": "recipes/aws-ebs-csi-driver/aws-ebs-csi-driver/2.60.1/target-topology.yaml",
      "receipt": "runs/live-helm-confighub-compare/aws-ebs-csi-driver-aws-ebs-csi-driver-default/receipt.yaml"
    },
    {
      "chart": "bitnami/apache",
      "version": "11.4.29",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-apache-default/receipt.yaml"
    },
    {
      "chart": "bitnami/apache",
      "version": "11.4.29",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-apache-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/contour",
      "version": "21.1.4",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-contour-default/receipt.yaml"
    },
    {
      "chart": "bitnami/contour",
      "version": "21.1.4",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "watch: inspect receipt",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/bitnami-contour-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/contour",
      "version": "21.1.4",
      "variant": "no-crds",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-contour-no-crds/receipt.yaml"
    },
    {
      "chart": "bitnami/elasticsearch",
      "version": "22.1.6",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-elasticsearch-default/receipt.yaml"
    },
    {
      "chart": "bitnami/elasticsearch",
      "version": "22.1.6",
      "variant": "ha",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-elasticsearch-ha/receipt.yaml"
    },
    {
      "chart": "bitnami/elasticsearch",
      "version": "22.1.6",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-elasticsearch-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/mongodb",
      "version": "19.0.9",
      "variant": "existing-secret-replicaset",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)",
      "support_artifact": "recipes/bitnami/mongodb/19.0.9/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/bitnami-mongodb-existing-secret-replicaset-19-0-9/receipt.yaml"
    },
    {
      "chart": "bitnami/mongodb",
      "version": "19.1.0",
      "variant": "existing-secret-replicaset",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)",
      "support_artifact": "recipes/bitnami/mongodb/19.1.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/bitnami-mongodb-existing-secret-replicaset-19-1-0/receipt.yaml"
    },
    {
      "chart": "bitnami/nginx",
      "version": "24.0.4",
      "variant": "existing-tls-ingress",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/bitnami/nginx/24.0.4/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/bitnami-nginx-existing-tls-ingress-24-0-4/receipt.yaml"
    },
    {
      "chart": "bitnami/nginx",
      "version": "25.0.0",
      "variant": "existing-tls-ingress",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/bitnami/nginx/25.0.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/bitnami-nginx-existing-tls-ingress-25-0-0/receipt.yaml"
    },
    {
      "chart": "bitnami/opensearch",
      "version": "2.0.10",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-opensearch-default/receipt.yaml"
    },
    {
      "chart": "bitnami/opensearch",
      "version": "2.0.10",
      "variant": "ha",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-opensearch-ha/receipt.yaml"
    },
    {
      "chart": "bitnami/opensearch",
      "version": "2.0.10",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-opensearch-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/phpmyadmin",
      "version": "20.0.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-phpmyadmin-default/receipt.yaml"
    },
    {
      "chart": "bitnami/phpmyadmin",
      "version": "20.0.0",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-phpmyadmin-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/spark",
      "version": "10.0.3",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-spark-default/receipt.yaml"
    },
    {
      "chart": "bitnami/spark",
      "version": "10.0.3",
      "variant": "ha",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-spark-ha/receipt.yaml"
    },
    {
      "chart": "bitnami/spark",
      "version": "10.0.3",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-spark-legacy/receipt.yaml"
    },
    {
      "chart": "bitnami/zookeeper",
      "version": "13.8.7",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-zookeeper-default/receipt.yaml"
    },
    {
      "chart": "bitnami/zookeeper",
      "version": "13.8.7",
      "variant": "ha",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-zookeeper-ha/receipt.yaml"
    },
    {
      "chart": "bitnami/zookeeper",
      "version": "13.8.7",
      "variant": "legacy",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/bitnami-zookeeper-legacy/receipt.yaml"
    },
    {
      "chart": "dex/dex",
      "version": "0.24.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod config/runtime errors (parity passed)",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/dex-dex-default/receipt.yaml"
    },
    {
      "chart": "elastic/filebeat",
      "version": "8.5.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/elastic-filebeat-default/receipt.yaml"
    },
    {
      "chart": "elastic/filebeat",
      "version": "8.5.1",
      "variant": "node-or-cluster-collector",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
    },
    {
      "chart": "elastic/kibana",
      "version": "8.5.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/elastic-kibana-default/receipt.yaml"
    },
    {
      "chart": "elastic/metricbeat",
      "version": "8.5.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/elastic-metricbeat-default/receipt.yaml"
    },
    {
      "chart": "fluent/fluentd",
      "version": "0.5.3",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod config/runtime errors (parity passed)",
      "support_artifact": "recipes/fluent/fluentd/0.5.3/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/fluent-fluentd-default/receipt.yaml"
    },
    {
      "chart": "gitlab/gitlab-runner",
      "version": "0.89.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: ConfigHub workload not ready (parity passed)",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/gitlab-gitlab-runner-default/receipt.yaml"
    },
    {
      "chart": "grafana/pyroscope",
      "version": "2.0.2",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: ConfigHub workload not ready (parity passed)",
      "support_artifact": "recipes/grafana/pyroscope/2.0.2/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/grafana-pyroscope-default/receipt.yaml"
    },
    {
      "chart": "grafana/pyroscope",
      "version": "2.0.2",
      "variant": "ha",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: ConfigHub workload not ready (parity passed)",
      "support_artifact": "recipes/grafana/pyroscope/2.0.2/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/grafana-pyroscope-ha/receipt.yaml"
    },
    {
      "chart": "grafana/pyroscope",
      "version": "2.0.2",
      "variant": "no-crds",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: ConfigHub workload not ready (parity passed)",
      "support_artifact": "recipes/grafana/pyroscope/2.0.2/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/grafana-pyroscope-no-crds/receipt.yaml"
    },
    {
      "chart": "grafana/tempo",
      "version": "1.24.4",
      "variant": "s3-query-observability",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/grafana/tempo/1.24.4/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/grafana-tempo-s3-query-observability/receipt.yaml"
    },
    {
      "chart": "hashicorp/consul",
      "version": "2.0.0",
      "variant": "secure-mesh-existing-secrets",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/hashicorp/consul/2.0.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/receipt.yaml"
    },
    {
      "chart": "hashicorp/terraform",
      "version": "1.1.2",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "recipes/hashicorp/terraform/1.1.2/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/hashicorp-terraform-default/receipt.yaml"
    },
    {
      "chart": "hashicorp/terraform",
      "version": "1.1.2",
      "variant": "no-crds",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod ContainerCreating (parity passed)",
      "support_artifact": "recipes/hashicorp/terraform/1.1.2/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/hashicorp-terraform-no-crds/receipt.yaml"
    },
    {
      "chart": "hashicorp/vault",
      "version": "0.32.0",
      "variant": "ha-raft-ui",
      "result": "watch",
      "residue_category": "operate-policy",
      "blocker_owner": "needs operate review",
      "usable_today": "watch — needs an operational readiness step",
      "user_decision": "Semantic parity passed, but an operational policy/readiness step (for example init/unseal) is required before the workload is fully ready. Not a parity defect.",
      "next_action": "Perform and record the operational step (e.g. Vault init/unseal) for the target scope; see the operating-policy artifact.",
      "reason": "operate-policy: Vault init/unseal readiness (parity passed)",
      "support_artifact": "recipes/hashicorp/vault/0.32.0/operating-policy.yaml",
      "receipt": "runs/live-helm-confighub-compare/hashicorp-vault-ha-raft-ui/receipt.yaml"
    },
    {
      "chart": "istio/gateway",
      "version": "1.30.0",
      "variant": "controller-default-reviewed",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/istio-gateway-controller-default-reviewed/receipt.yaml"
    },
    {
      "chart": "istio/gateway",
      "version": "1.30.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "remote-image",
      "blocker_owner": "catalog or image publisher",
      "usable_today": "watch — image reference must be resolved",
      "user_decision": "The rendered objects matched regular Helm, but at least one image reference was not pullable on the target. This is image retention, registry access, or image override work, not a ConfigHub object-model defect.",
      "next_action": "Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.",
      "reason": "remote-image: image pull failed or pinned image is unavailable (parity passed)",
      "support_artifact": "data/image-digest-workdown/summary.md",
      "receipt": "runs/live-helm-confighub-compare/istio-gateway-default/receipt.yaml"
    },
    {
      "chart": "istio/istiod",
      "version": "1.30.0",
      "variant": "default",
      "result": "blocked",
      "residue_category": "target-prerequisite",
      "blocker_owner": "user",
      "usable_today": "yes, after staging the prerequisite",
      "user_decision": "Usable once you stage the named prerequisite (for example a namespace, Secret, or CRD) on the target; the rendered objects matched regular Helm (semantic parity passed). The prerequisite is missing, not the configuration.",
      "next_action": "Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.",
      "reason": "target-prerequisite: namespace missing (parity passed)",
      "support_artifact": "recipes/istio/istiod/1.30.0/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/istio-istiod-default/receipt.yaml"
    },
    {
      "chart": "jaegertracing/jaeger-operator",
      "version": "2.57.0",
      "variant": "default",
      "result": "blocked",
      "residue_category": "target-prerequisite",
      "blocker_owner": "user",
      "usable_today": "yes, after staging the prerequisite",
      "user_decision": "Usable once you stage the named prerequisite (for example a namespace, Secret, or CRD) on the target; the rendered objects matched regular Helm (semantic parity passed). The prerequisite is missing, not the configuration.",
      "next_action": "Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.",
      "reason": "target-prerequisite: cert-manager CRDs missing",
      "support_artifact": "recipes/jaegertracing/jaeger-operator/2.57.0/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/jaegertracing-jaeger-operator-default/receipt.yaml"
    },
    {
      "chart": "jetstack/trust-manager",
      "version": "v0.22.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/jetstack/trust-manager/v0.22.1/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/jetstack-trust-manager-default/receipt.yaml"
    },
    {
      "chart": "kyverno/kyverno-policies",
      "version": "3.8.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: ClusterPolicy OutOfSync health Healthy (parity passed)",
      "support_artifact": "recipes/kyverno/kyverno-policies/3.8.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/kyverno-kyverno-policies-default/receipt.yaml"
    },
    {
      "chart": "linkerd/linkerd-crds",
      "version": "1.8.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: CustomResourceDefinition OutOfSync health Healthy (parity passed)",
      "support_artifact": "recipes/linkerd/linkerd-crds/1.8.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/linkerd-linkerd-crds-default/receipt.yaml"
    },
    {
      "chart": "minio-operator/tenant",
      "version": "7.1.1",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/minio-operator/tenant/7.1.1/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/minio-operator-tenant-default/receipt.yaml"
    },
    {
      "chart": "nats/surveyor",
      "version": "0.20.9",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod config/runtime errors (parity passed)",
      "support_artifact": "recipes/nats/surveyor/0.20.9/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/nats-surveyor-default/receipt.yaml"
    },
    {
      "chart": "nats/surveyor",
      "version": "0.20.9",
      "variant": "default-reviewed",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod config/runtime errors (parity passed)",
      "support_artifact": "recipes/nats/surveyor/0.20.9/runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/nats-surveyor-default-reviewed/receipt.yaml"
    },
    {
      "chart": "nfs-subdir-external-provisioner/nfs-subdir-external-provisioner",
      "version": "4.0.18",
      "variant": "default",
      "result": "blocked",
      "residue_category": "semantic-model-gap",
      "blocker_owner": "catalog",
      "usable_today": "no — needs catalog work",
      "user_decision": "Not usable on this base yet, and not a user action: the ConfigHub delivery did not match the live Helm result (a semantic/model difference), so the row did not pass. Catalog/model work.",
      "next_action": "Catalog work: reconcile the base, render context, target facts, or semantic contract with the live Helm result, then rerun.",
      "reason": "helm-runtime: upstream leg blocked",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/nfs-subdir-external-provisioner-nfs-subdir-external-provisioner-default/receipt.yaml"
    },
    {
      "chart": "open-telemetry/opentelemetry-operator",
      "version": "0.114.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/open-telemetry/opentelemetry-operator/0.114.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/open-telemetry-opentelemetry-operator-default/receipt.yaml"
    },
    {
      "chart": "opencost/opencost",
      "version": "2.5.21",
      "variant": "default",
      "result": "watch",
      "residue_category": "target-runtime",
      "blocker_owner": "needs runtime review",
      "usable_today": "watch — config correct, runtime unconfirmed",
      "user_decision": "The rendered config matched regular Helm (semantic parity passed) but the workload did not reach the expected runtime state on the target. Runtime residue to review, not a parity defect.",
      "next_action": "Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.",
      "reason": "target-runtime: pod config/runtime errors (parity passed)",
      "support_artifact": "",
      "receipt": "runs/live-helm-confighub-compare/opencost-opencost-default/receipt.yaml"
    },
    {
      "chart": "prometheus-community/prometheus-adapter",
      "version": "5.3.0",
      "variant": "cluster-metrics-readonly",
      "result": "blocked",
      "residue_category": "capability-profile",
      "blocker_owner": "catalog",
      "usable_today": "yes, use the capability-profile base",
      "user_decision": "The selected base rendered a Kubernetes API version that the target no longer serves. This is a render-profile/base selection issue, not a runtime prerequisite and not a semantic ConfigHub-vs-Helm diff.",
      "next_action": "Use or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.",
      "reason": "capability-profile: rendered APIService version is not served by target Kubernetes",
      "support_artifact": "recipes/prometheus-community/prometheus-adapter/5.3.0/CATALOG.md",
      "receipt": "runs/live-helm-confighub-compare/prometheus-community-prometheus-adapter-cluster-metrics-readonly/receipt.yaml"
    },
    {
      "chart": "prometheus-community/prometheus-adapter",
      "version": "5.3.0",
      "variant": "default",
      "result": "blocked",
      "residue_category": "capability-profile",
      "blocker_owner": "catalog",
      "usable_today": "yes, use the capability-profile base",
      "user_decision": "The selected base rendered a Kubernetes API version that the target no longer serves. This is a render-profile/base selection issue, not a runtime prerequisite and not a semantic ConfigHub-vs-Helm diff.",
      "next_action": "Use or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.",
      "reason": "capability-profile: rendered APIService version is not served by target Kubernetes",
      "support_artifact": "recipes/prometheus-community/prometheus-adapter/5.3.0/CATALOG.md",
      "receipt": "runs/live-helm-confighub-compare/prometheus-community-prometheus-adapter-default/receipt.yaml"
    },
    {
      "chart": "prometheus-community/prometheus",
      "version": "29.9.0",
      "variant": "default",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)",
      "support_artifact": "recipes/prometheus-community/prometheus/29.9.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/prometheus-community-prometheus-default-29-9-0/receipt.yaml"
    },
    {
      "chart": "rook-release/rook-ceph-cluster",
      "version": "v1.19.5",
      "variant": "default",
      "result": "blocked",
      "residue_category": "target-prerequisite",
      "blocker_owner": "user",
      "usable_today": "yes, after staging the prerequisite",
      "user_decision": "Usable once you stage the named prerequisite (for example a namespace, Secret, or CRD) on the target; the rendered objects matched regular Helm (semantic parity passed). The prerequisite is missing, not the configuration.",
      "next_action": "Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.",
      "reason": "target-prerequisite: namespace missing (parity passed)",
      "support_artifact": "recipes/rook-release/rook-ceph-cluster/v1.19.5/target-prerequisite-plan.yaml",
      "receipt": "runs/live-helm-confighub-compare/rook-release-rook-ceph-cluster-default/receipt.yaml"
    },
    {
      "chart": "traefik/traefik",
      "version": "40.2.0",
      "variant": "no-crds",
      "result": "watch",
      "residue_category": "gitops-runtime",
      "blocker_owner": "needs GitOps controller-health review",
      "usable_today": "watch — synced and converged; aggregate health needs explanation",
      "user_decision": "Desired state synced through ConfigHub OCI/Argo and the workloads converged, and semantic Helm-vs-ConfigHub parity passed — but Argo's aggregate health is Progressing, or a resource reads OutOfSync while Healthy. Known GitOps controller-health residue, not a parity defect.",
      "next_action": "Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.",
      "reason": "gitops-runtime: Argo health Progressing (parity passed)",
      "support_artifact": "recipes/traefik/traefik/40.2.0/gitops-runtime-review.yaml",
      "receipt": "runs/live-helm-confighub-compare/traefik-traefik-no-crds/receipt.yaml"
    },
    {
      "chart": "velero/velero",
      "version": "12.0.1",
      "variant": "default",
      "result": "blocked",
      "residue_category": "render-input",
      "blocker_owner": "catalog",
      "usable_today": "no — needs a better base",
      "user_decision": "The selected base renders incomplete or invalid chart configuration because required Helm inputs are not modeled. This is not a user target prerequisite; the catalog needs a useful base that asks for or supplies the required inputs.",
      "next_action": "Create a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.",
      "reason": "render-input: required Velero provider values missing",
      "support_artifact": "recipes/velero/velero/12.0.1/value-model.yaml",
      "receipt": "runs/live-helm-confighub-compare/velero-velero-default/receipt.yaml"
    },
    {
      "chart": "velero/velero",
      "version": "12.0.1",
      "variant": "no-crds",
      "result": "blocked",
      "residue_category": "render-input",
      "blocker_owner": "catalog",
      "usable_today": "no — needs a better base",
      "user_decision": "The selected base renders incomplete or invalid chart configuration because required Helm inputs are not modeled. This is not a user target prerequisite; the catalog needs a useful base that asks for or supplies the required inputs.",
      "next_action": "Create a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.",
      "reason": "render-input: required Velero provider values missing",
      "support_artifact": "recipes/velero/velero/12.0.1/value-model.yaml",
      "receipt": "runs/live-helm-confighub-compare/velero-velero-no-crds/receipt.yaml"
    }
  ]
}
