# Model And Prerequisite Resolution Plan

**UNOFFICIAL/EXPERIMENTAL.** Generated by
`scripts/generate-model-prereq-resolution.mjs`. Do not hand-edit.
Regenerate with `npm run model-prereq-resolution`.

This is the execution bridge for current B1/B2 rows. It does not mark
anything fixed. It assigns every model gap and target-prerequisite row to
one product path: a new base variant, an existing sibling base, a derived
target variant, a target-scoped platform policy, or operator review before
any variant should be created.

## Summary

| Metric | Rows |
| --- | ---: |
| Total rows | 63 |
| Model-gap rows | 23 |
| Target-prerequisite rows | 40 |

### Rows by resolution path

| Value | Rows |
| --- | ---: |
| `operator-review-first` | 20 |
| `crd-ownership-base-or-target-action` | 7 |
| `derived-target-variant` | 7 |
| `semantic-normalization` | 7 |
| `stack-or-target-fact-variant` | 4 |
| `new-provider-base-variant` | 3 |
| `use-existing-sibling-base` | 3 |
| `new-base-variant-after-input-identification` | 2 |
| `use-existing-capability-base` | 2 |
| `external-crds-base` | 1 |
| `new-storage-base-variant` | 1 |
| `semantic-normalization-or-smaller-base` | 1 |
| `target-fact-generator-on-existing-base` | 1 |
| `target-scoped-base` | 1 |
| `target-scoped-base-or-normalization` | 1 |
| `use-existing-sibling-or-normalize-ha` | 1 |
| `use-existing-sibling-or-split-crds` | 1 |

### Rows by variant role

| Value | Rows |
| --- | ---: |
| `no variant until cause is known` | 20 |
| `CRD ownership base plus target prerequisite` | 7 |
| `target-bound derived variant` | 7 |
| `legacy image-retention base` | 6 |
| `stack-derived variant` | 4 |
| `CRD ownership off-ramp` | 3 |
| `base variant if rendered objects change` | 2 |
| `capability-profile base` | 2 |
| `provider and credential base` | 2 |
| `CRD ownership base` | 1 |
| `existing base with normalization` | 1 |
| `existing values-profile base` | 1 |
| `HA base after normalization` | 1 |
| `HA base with CRD ownership boundary` | 1 |
| `HA topology base` | 1 |
| `platform topology base` | 1 |
| `provider and credential base with external CRDs` | 1 |
| `storage target base` | 1 |
| `target-scoped platform base` | 1 |

## Rows

| Queue | Chart | Base | Lane | Resolution | Variant role | First step |
| --- | --- | --- | --- | --- | --- | --- |
| model-gap | `autoscaler/cluster-autoscaler@9.57.0` | controller-default-reviewed | K | target-fact-generator-on-existing-base | existing values-profile base | teach the recipe how the cluster name and AWS region are supplied for this target profile |
| model-gap | `aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1` | default | K | target-scoped-base-or-normalization | target-scoped platform base | separate vanilla-kind parity from the AWS/EKS topology claim recorded in target-topology.yaml |
| model-gap | `bitnami/apache@11.4.29` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `bitnami/contour@21.1.4` | no-crds | K | external-crds-base | CRD ownership base | make the CRD ownership choice visible in the base name and target-prerequisite action packet |
| model-gap | `bitnami/elasticsearch@22.1.6` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `bitnami/opensearch@2.0.10` | default | K | semantic-normalization | existing base with normalization | inspect the K receipt diffs and add only justified semantic normalization, not a blind variant |
| model-gap | `bitnami/opensearch@2.0.10` | ha | K | semantic-normalization-or-smaller-base | HA base after normalization | inspect the HA K receipt diffs and split target topology from semantic noise |
| model-gap | `bitnami/opensearch@2.0.10` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `bitnami/phpmyadmin@20.0.0` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `bitnami/spark@10.0.3` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `bitnami/zookeeper@13.8.7` | legacy | K | semantic-normalization | legacy image-retention base | record the Namespace support object as expected installer scaffolding rather than a Helm semantic difference |
| model-gap | `grafana/pyroscope@2.0.2` | ha | K | use-existing-sibling-or-split-crds | HA base with CRD ownership boundary | route HA users to the existing K-pass siblings unless the HA topology itself is needed |
| model-gap | `hashicorp/terraform@1.1.2` | default | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | separate Terraform Workspace CRD ownership from the Secret prerequisites needed by the controller |
| model-gap | `nats/nack@0.34.0` | default | K | use-existing-sibling-base | CRD ownership off-ramp | mark no-crds as the first K-safe base and keep default scoped to CRD-owning targets |
| model-gap | `nats/nats@2.14.0` | ha | K | use-existing-sibling-or-normalize-ha | HA topology base | decide whether HA is a supported public base for this chart or a target-scoped advanced base |
| model-gap | `nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18` | default | G/P | new-storage-base-variant | storage target base | replace the implicit default with a base that names the NFS server contract before render and before delivery |
| model-gap | `prometheus-community/kube-prometheus-stack@86.1.0` | default | K | use-existing-sibling-base | CRD ownership off-ramp | make no-crds the first K-safe base for 86.1.0 and leave default scoped to CRD-owning targets |
| model-gap | `prometheus-community/prometheus-adapter@5.3.0` | cluster-metrics-readonly | G/P | use-existing-capability-base | capability-profile base | route users from cluster-metrics-readonly to apiservice-v1-capability when APIService v1 is required |
| model-gap | `prometheus-community/prometheus-adapter@5.3.0` | default | G/P | use-existing-capability-base | capability-profile base | route users from default to apiservice-v1-capability when APIService v1 is required |
| model-gap | `traefik/traefik@40.2.0` | default | K | use-existing-sibling-base | CRD ownership off-ramp | align the Traefik CRD ownership vocabulary with the wave-2 real variant work order |
| model-gap | `velero/velero@12.0.1` | default | G/P | new-provider-base-variant | provider and credential base | implement the first Velero provider base from catalog-promotion-wave2 and bind backup credentials as target facts |
| model-gap | `velero/velero@12.0.1` | default | K | new-provider-base-variant | provider and credential base | implement the first Velero provider base from catalog-promotion-wave2 and bind backup credentials as target facts |
| model-gap | `velero/velero@12.0.1` | no-crds | G/P | new-provider-base-variant | provider and credential base with external CRDs | start with a provider base, then split CRD ownership if the target supplies Velero CRDs |
| target-prerequisite | `autoscaler/cluster-autoscaler@9.57.0` | default | K | new-base-variant-after-input-identification | base variant if rendered objects change | replace the unknown prerequisite with a named chart value, Secret, namespace, CRD, or external dependency |
| target-prerequisite | `aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1` | default | G/P | target-scoped-base | platform topology base | record the platform target shape and do not treat vanilla kind as the authoritative target for this base |
| target-prerequisite | `bitnami/contour@21.1.4` | legacy | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `dex/dex@0.24.0` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `dex/dex@0.24.0` | default | K | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `elastic/filebeat@8.5.1` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `elastic/filebeat@8.5.1` | default | K | derived-target-variant | target-bound derived variant | create or reference the Secret in the target, then bind it through the target-prerequisite action packet |
| target-prerequisite | `elastic/filebeat@8.5.1` | node-or-cluster-collector | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `elastic/filebeat@8.5.1` | node-or-cluster-collector | K | stack-or-target-fact-variant | stack-derived variant | identify the upstream service or API the workload expects, then encode it as a target fact or stack dependency |
| target-prerequisite | `elastic/kibana@8.5.1` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `elastic/kibana@8.5.1` | default | K | stack-or-target-fact-variant | stack-derived variant | identify the upstream service or API the workload expects, then encode it as a target fact or stack dependency |
| target-prerequisite | `elastic/metricbeat@8.5.1` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `elastic/metricbeat@8.5.1` | default | K | derived-target-variant | target-bound derived variant | create or reference the Secret in the target, then bind it through the target-prerequisite action packet |
| target-prerequisite | `fluent/fluentd@0.5.3` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `gitlab/gitlab-runner@0.89.0` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `gitlab/gitlab-runner@0.89.0` | default | K | stack-or-target-fact-variant | stack-derived variant | identify the upstream service or API the workload expects, then encode it as a target fact or stack dependency |
| target-prerequisite | `grafana/pyroscope@2.0.2` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `grafana/pyroscope@2.0.2` | ha | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `grafana/pyroscope@2.0.2` | no-crds | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `hashicorp/terraform@1.1.2` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `hashicorp/terraform@1.1.2` | no-crds | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `hashicorp/terraform@1.1.2` | no-crds | K | derived-target-variant | target-bound derived variant | create or reference the Secret in the target, then bind it through the target-prerequisite action packet |
| target-prerequisite | `hashicorp/vault@0.32.0` | ha-raft-ui | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `istio/istiod@1.30.0` | default | G/P | derived-target-variant | target-bound derived variant | create the Namespace or make namespace creation an explicit preflight step for this target |
| target-prerequisite | `istio/istiod@1.30.0` | default | K | derived-target-variant | target-bound derived variant | create the Namespace or make namespace creation an explicit preflight step for this target |
| target-prerequisite | `jaegertracing/jaeger-operator@2.57.0` | default | G/P | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |
| target-prerequisite | `jaegertracing/jaeger-operator@2.57.0` | default | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |
| target-prerequisite | `jaegertracing/jaeger-operator@2.57.0` | no-crds | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |
| target-prerequisite | `nats/surveyor@0.20.9` | default-reviewed | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `nats/surveyor@0.20.9` | default-reviewed | K | stack-or-target-fact-variant | stack-derived variant | identify the upstream service or API the workload expects, then encode it as a target fact or stack dependency |
| target-prerequisite | `nats/surveyor@0.20.9` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `nats/surveyor@0.20.9` | default | K | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18` | default | K | new-base-variant-after-input-identification | base variant if rendered objects change | replace the unknown prerequisite with a named chart value, Secret, namespace, CRD, or external dependency |
| target-prerequisite | `opencost/opencost@2.5.21` | default | G/P | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `opencost/opencost@2.5.21` | default | K | operator-review-first | no variant until cause is known | inspect pod events/logs and classify the missing condition before modeling a base or target fact |
| target-prerequisite | `prometheus-community/prometheus-adapter@5.3.0` | cluster-metrics-readonly | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |
| target-prerequisite | `prometheus-community/prometheus-adapter@5.3.0` | default | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |
| target-prerequisite | `rook-release/rook-ceph-cluster@v1.19.5` | default | G/P | derived-target-variant | target-bound derived variant | create the Namespace or make namespace creation an explicit preflight step for this target |
| target-prerequisite | `rook-release/rook-ceph-cluster@v1.19.5` | default | K | derived-target-variant | target-bound derived variant | create the Namespace or make namespace creation an explicit preflight step for this target |
| target-prerequisite | `velero/velero@12.0.1` | no-crds | K | crd-ownership-base-or-target-action | CRD ownership base plus target prerequisite | choose whether this target owns CRDs through the base or through an external prerequisite |

## Boundaries

- A row here is not fixed until its required evidence is recorded and the
  source matrix cell changes through the normal generated surfaces.
- A new base variant is recommended only when the Helm-rendered object shape
  changes or the catalog needs a clear render-time fork.
- A derived target variant is recommended only when the object shape is already
  correct and the remaining work is target binding, such as a Secret,
  Namespace, external endpoint, approval, or target profile.
- Operator-review rows deliberately do not name a variant yet.

Machine-readable form:

- [resolution.csv](./resolution.csv)
- [resolution.json](./resolution.json)

