# Target-Prerequisite Action Packets

**UNOFFICIAL/EXPERIMENTAL.** Generated by
`scripts/generate-target-prerequisite-actions.mjs`. Do not hand-edit. Regenerate
with `npm run target-prerequisite-actions`.

One **action packet** per [target-prerequisite-workdown](../target-prerequisite-workdown/summary.md)
row: the concrete preflight to do **before** rerunning a non-green K/G/P row, with
the required inputs, the evidence to look for after staging, and the rerun
command. Every packet is `automatic: false` — this is a plan/preflight layer, not
proof of automated execution. See
[remote-images-and-supported-bases](../../docs/user/remote-images-and-supported-bases.md)
for the sibling image story, and
[residue-families](../../docs/reference/residue-families.md) for the vocabulary.

## 40 action packets

| Action kind | Rows |
| --- | ---: |
| `operator-review` | 20 |
| `install-crds` | 6 |
| `create-namespace` | 4 |
| `provide-external-service` | 4 |
| `stage-secret` | 3 |
| `unknown-preflight` | 2 |
| `provide-storage-or-topology` | 1 |

| Owner class | Rows |
| --- | ---: |
| `operator-review` | 27 |
| `user-stage` | 12 |
| `target-policy` | 1 |

## Packets

| Chart | Base | Lane | Action | Required inputs | Rerun after staging |
| --- | --- | --- | --- | --- | --- |
| autoscaler/cluster-autoscaler@9.57.0 | default | K | unknown-preflight | the missing Helm input value(s) | `npm run kind-parity:run -- --chart autoscaler/cluster-autoscaler --version 9.57.0 --base default` |
| aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1 | default | G/P | provide-storage-or-topology | AWS/EKS metadata + node providerID | `npm run live-parity:run -- --recipe recipes/aws-ebs-csi-driver/aws-ebs-csi-driver/2.60.1 --base default` |
| bitnami/contour@21.1.4 | legacy | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/bitnami/contour/21.1.4 --base legacy --repo-url oci://registry-1.docker.io/bitnamicharts` |
| dex/dex@0.24.0 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/dex/dex/0.24.0 --base default` |
| dex/dex@0.24.0 | default | K | operator-review | operator review of the runtime residue | `npm run kind-parity:run -- --chart dex/dex --version 0.24.0 --base default` |
| elastic/filebeat@8.5.1 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/elastic/filebeat/8.5.1 --base default` |
| elastic/filebeat@8.5.1 | default | K | stage-secret | Secret elasticsearch-master-certs | `npm run kind-parity:run -- --chart elastic/filebeat --version 8.5.1 --base default` |
| elastic/filebeat@8.5.1 | node-or-cluster-collector | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/elastic/filebeat/8.5.1 --base node-or-cluster-collector` |
| elastic/filebeat@8.5.1 | node-or-cluster-collector | K | provide-external-service | the upstream service/endpoint the workload connects to | `npm run kind-parity:run -- --chart elastic/filebeat --version 8.5.1 --base node-or-cluster-collector` |
| elastic/kibana@8.5.1 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/elastic/kibana/8.5.1 --base default` |
| elastic/kibana@8.5.1 | default | K | provide-external-service | the upstream service/endpoint the workload connects to | `npm run kind-parity:run -- --chart elastic/kibana --version 8.5.1 --base default` |
| elastic/metricbeat@8.5.1 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/elastic/metricbeat/8.5.1 --base default` |
| elastic/metricbeat@8.5.1 | default | K | stage-secret | Secret elasticsearch-master-certs | `npm run kind-parity:run -- --chart elastic/metricbeat --version 8.5.1 --base default` |
| fluent/fluentd@0.5.3 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/fluent/fluentd/0.5.3 --base default` |
| gitlab/gitlab-runner@0.89.0 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/gitlab/gitlab-runner/0.89.0 --base default` |
| gitlab/gitlab-runner@0.89.0 | default | K | provide-external-service | the upstream service/endpoint the workload connects to | `npm run kind-parity:run -- --chart gitlab/gitlab-runner --version 0.89.0 --base default` |
| grafana/pyroscope@2.0.2 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/grafana/pyroscope/2.0.2 --base default` |
| grafana/pyroscope@2.0.2 | ha | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/grafana/pyroscope/2.0.2 --base ha` |
| grafana/pyroscope@2.0.2 | no-crds | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/grafana/pyroscope/2.0.2 --base no-crds` |
| hashicorp/terraform@1.1.2 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/hashicorp/terraform/1.1.2 --base default` |
| hashicorp/terraform@1.1.2 | no-crds | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/hashicorp/terraform/1.1.2 --base no-crds` |
| hashicorp/terraform@1.1.2 | no-crds | K | stage-secret | Secret workspacesecrets; Secret terraformrc | `npm run kind-parity:run -- --chart hashicorp/terraform --version 1.1.2 --base no-crds` |
| hashicorp/vault@0.32.0 | ha-raft-ui | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/hashicorp/vault/0.32.0 --base ha-raft-ui` |
| istio/istiod@1.30.0 | default | G/P | create-namespace | the target Namespace named by the chart | `npm run live-parity:run -- --recipe recipes/istio/istiod/1.30.0 --base default` |
| istio/istiod@1.30.0 | default | K | create-namespace | Namespace istio-system | `npm run kind-parity:run -- --chart istio/istiod --version 1.30.0 --base default` |
| jaegertracing/jaeger-operator@2.57.0 | default | G/P | install-crds | cert-manager CRDs | `npm run live-parity:run -- --recipe recipes/jaegertracing/jaeger-operator/2.57.0 --base default` |
| jaegertracing/jaeger-operator@2.57.0 | default | K | install-crds | cert-manager CRDs | `npm run kind-parity:run -- --chart jaegertracing/jaeger-operator --version 2.57.0 --base default` |
| jaegertracing/jaeger-operator@2.57.0 | no-crds | K | install-crds | cert-manager CRDs | `npm run kind-parity:run -- --chart jaegertracing/jaeger-operator --version 2.57.0 --base no-crds` |
| nats/surveyor@0.20.9 | default-reviewed | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/nats/surveyor/0.20.9 --base default-reviewed` |
| nats/surveyor@0.20.9 | default-reviewed | K | provide-external-service | the upstream service/endpoint the workload connects to | `npm run kind-parity:run -- --chart nats/surveyor --version 0.20.9 --base default-reviewed` |
| nats/surveyor@0.20.9 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/nats/surveyor/0.20.9 --base default` |
| nats/surveyor@0.20.9 | default | K | operator-review | operator review of the runtime residue | `npm run kind-parity:run -- --chart nats/surveyor --version 0.20.9 --base default` |
| nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18 | default | K | unknown-preflight | value nfs.server | `npm run kind-parity:run -- --chart nfs-subdir-external-provisioner/nfs-subdir-external-provisioner --version 4.0.18 --base default` |
| opencost/opencost@2.5.21 | default | G/P | operator-review | operator review of the runtime residue | `npm run live-parity:run -- --recipe recipes/opencost/opencost/2.5.21 --base default` |
| opencost/opencost@2.5.21 | default | K | operator-review | operator review of the runtime residue | `npm run kind-parity:run -- --chart opencost/opencost --version 2.5.21 --base default` |
| prometheus-community/prometheus-adapter@5.3.0 | cluster-metrics-readonly | K | install-crds | the chart's CRDs | `npm run kind-parity:run -- --chart prometheus-community/prometheus-adapter --version 5.3.0 --base cluster-metrics-readonly` |
| prometheus-community/prometheus-adapter@5.3.0 | default | K | install-crds | the chart's CRDs | `npm run kind-parity:run -- --chart prometheus-community/prometheus-adapter --version 5.3.0 --base default` |
| rook-release/rook-ceph-cluster@v1.19.5 | default | G/P | create-namespace | Namespace rook-ceph | `npm run live-parity:run -- --recipe recipes/rook-release/rook-ceph-cluster/v1.19.5 --base default` |
| rook-release/rook-ceph-cluster@v1.19.5 | default | K | create-namespace | Namespace rook-ceph | `npm run kind-parity:run -- --chart rook-release/rook-ceph-cluster --version v1.19.5 --base default` |
| velero/velero@12.0.1 | no-crds | K | install-crds | the chart's CRDs | `npm run kind-parity:run -- --chart velero/velero --version 12.0.1 --base no-crds` |

## Boundaries

- Read-only projection over the target-prerequisite workdown. No live run, no
  cluster, no `runs/` edit, and nothing marked fixed or automated.
- `automatic: false` on every packet; staging and the rerun are deliberate steps.
- The rerun command is what to run *after* the prerequisite is staged, not now.
