# Live-Parity (G/P-lane) Decisions

**UNOFFICIAL/EXPERIMENTAL.** Generated by
`scripts/generate-live-parity-decisions.mjs`. Do not hand-edit. Regenerate with
`npm run live-parity:decisions`.

The G/P-lane companion to [kind-parity-decisions](../kind-parity-decisions/summary.md).
It classifies the committed **non-pass** ConfigHub OCI + live Helm-vs-ConfigHub
(G/P-lane) rows into product-readable decisions: per `watch`/`blocked` row, what
it means for a Helm user, **who has to fix it**, whether the chart/base is
**usable today**, the next action, and the recipe support artifact that records
the decision.

Source: [data/live-helm-confighub-compare/summary.csv](../live-helm-confighub-compare/summary.md) (read-only).
Forms: [decisions.csv](./decisions.csv), [decisions.json](./decisions.json).

## What watch and blocked mean here

- **watch** — known evidence with a named residue. The semantic Helm-vs-ConfigHub
  parity passed (the delivered objects match regular Helm); a GitOps
  controller-health, runtime, or operational condition still needs review.
  **Not a pass, not a failure.**
- **blocked** — the row did not reach the lane result. The decision names why and
  who owns the fix.

## This batch

60 non-pass rows: 52 watch, 8 blocked.
3 are resolved by the **user** (stage a prerequisite); 5
need **catalog/model** work; the rest are GitOps controller-health, runtime, or
operational residues to review. In every watch row, semantic parity already
passed — the residue is operational, not a config mismatch.

| Residue category | Rows |
| --- | ---: |
| `remote-image` | 20 |
| `target-runtime` | 16 |
| `gitops-runtime` | 14 |
| `target-prerequisite` | 3 |
| `capability-profile` | 2 |
| `render-input` | 2 |
| `operate-policy` | 1 |
| `semantic-model-gap` | 1 |
| `target-fit` | 1 |

| Who fixes it | Rows |
| --- | ---: |
| `catalog or image publisher` | 20 |
| `needs runtime review` | 16 |
| `needs GitOps controller-health review` | 14 |
| `catalog` | 5 |
| `user` | 3 |
| `needs operate review` | 1 |
| `user or catalog` | 1 |

## Rows

| Chart | Variant | Result | Residue | Who fixes it | Usable today |
| --- | --- | --- | --- | --- | --- |
| argo-cd/argo-cd@9.5.17 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1 | default | watch | target-fit | user or catalog | watch — needs a target with the required platform shape |
| bitnami/apache@11.4.29 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/apache@11.4.29 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/contour@21.1.4 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/contour@21.1.4 | legacy | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| bitnami/contour@21.1.4 | no-crds | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/elasticsearch@22.1.6 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/elasticsearch@22.1.6 | ha | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/elasticsearch@22.1.6 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/mongodb@19.0.9 | existing-secret-replicaset | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| bitnami/mongodb@19.1.0 | existing-secret-replicaset | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| bitnami/nginx@24.0.4 | existing-tls-ingress | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| bitnami/nginx@25.0.0 | existing-tls-ingress | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| bitnami/opensearch@2.0.10 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/opensearch@2.0.10 | ha | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/opensearch@2.0.10 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/phpmyadmin@20.0.0 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/phpmyadmin@20.0.0 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/spark@10.0.3 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/spark@10.0.3 | ha | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/spark@10.0.3 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/zookeeper@13.8.7 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/zookeeper@13.8.7 | ha | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| bitnami/zookeeper@13.8.7 | legacy | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| dex/dex@0.24.0 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| elastic/filebeat@8.5.1 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| elastic/filebeat@8.5.1 | node-or-cluster-collector | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| elastic/kibana@8.5.1 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| elastic/metricbeat@8.5.1 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| fluent/fluentd@0.5.3 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| gitlab/gitlab-runner@0.89.0 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| grafana/pyroscope@2.0.2 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| grafana/pyroscope@2.0.2 | ha | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| grafana/pyroscope@2.0.2 | no-crds | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| grafana/tempo@1.24.4 | s3-query-observability | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| hashicorp/consul@2.0.0 | secure-mesh-existing-secrets | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| hashicorp/terraform@1.1.2 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| hashicorp/terraform@1.1.2 | no-crds | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| hashicorp/vault@0.32.0 | ha-raft-ui | watch | operate-policy | needs operate review | watch — needs an operational readiness step |
| istio/gateway@1.30.0 | controller-default-reviewed | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| istio/gateway@1.30.0 | default | watch | remote-image | catalog or image publisher | watch — image reference must be resolved |
| istio/istiod@1.30.0 | default | blocked | target-prerequisite | user | yes, after staging the prerequisite |
| jaegertracing/jaeger-operator@2.57.0 | default | blocked | target-prerequisite | user | yes, after staging the prerequisite |
| jetstack/trust-manager@v0.22.1 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| kyverno/kyverno-policies@3.8.0 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| linkerd/linkerd-crds@1.8.0 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| minio-operator/tenant@7.1.1 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| nats/surveyor@0.20.9 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| nats/surveyor@0.20.9 | default-reviewed | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18 | default | blocked | semantic-model-gap | catalog | no — needs catalog work |
| open-telemetry/opentelemetry-operator@0.114.0 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| opencost/opencost@2.5.21 | default | watch | target-runtime | needs runtime review | watch — config correct, runtime unconfirmed |
| prometheus-community/prometheus-adapter@5.3.0 | cluster-metrics-readonly | blocked | capability-profile | catalog | yes, use the capability-profile base |
| prometheus-community/prometheus-adapter@5.3.0 | default | blocked | capability-profile | catalog | yes, use the capability-profile base |
| prometheus-community/prometheus@29.9.0 | default | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| rook-release/rook-ceph-cluster@v1.19.5 | default | blocked | target-prerequisite | user | yes, after staging the prerequisite |
| traefik/traefik@40.2.0 | no-crds | watch | gitops-runtime | needs GitOps controller-health review | watch — synced and converged; aggregate health needs explanation |
| velero/velero@12.0.1 | default | blocked | render-input | catalog | no — needs a better base |
| velero/velero@12.0.1 | no-crds | blocked | render-input | catalog | no — needs a better base |

## How To Read One Decision

`residue_category` is the kind of gap (`gitops-runtime`, `operate-policy`,
`target-runtime`, `target-prerequisite`, `semantic-model-gap`);
`blocker_owner` is who acts; `usable_today` is the honest answer for a Helm
user; `user_decision` is the plain explanation; `next_action` is the concrete
step; `support_artifact` is the recipe file that records the decision;
`receipt` is the committed evidence.

## Boundaries

- Read-only classification of committed G/P-lane evidence. No live run, no
  cluster, no `runs/` receipt edited, nothing written into
  `data/live-helm-confighub-compare/`, and no change to the master-matrix or
  status-dashboard generators.
- A decision never turns a `watch` into a `pass` or a `failure`; it explains
  the residue and routes the fix.
