<!-- Generated by npm run catalog:maps. Do not edit by hand. -->

# bitnami/contour 21.1.4 Catalog Map

This page makes the artifact chain explicit:

```text
chart -> recipe -> variants -> variant revisions -> package bases -> receipts
```

## Status

| Field | Value |
| --- | --- |
| Chart | bitnami/contour@21.1.4 |
| Catalog status | proof-grade |
| Support level | machine-proof-only |
| Supported scopes | none |
| Production readiness | not-reviewed-for-production |
| Supported variants | none |
| Candidate variants | default, no-crds, legacy |
| Control points | capability-profile, cluster-rbac, crds, dependency-lock, extension-slots, generated-facts, helm-equivalence, lifecycle-policy, rendered-manifest-scan, source-lock, target-facts, tpl-extension-slots, variant-revision |

## Feature And Proof Summary

This is the chart-level summary. Use the variant table and receipt links below
for exact base-variant evidence.

| Field | Value |
| --- | --- |
| Adoption bucket | limitation-decision-first |
| User status | proof-grade-with-named-limitation |
| Strongest evidence | two-cluster-kind-parity |
| Proof lanes | render parity 3/3; ConfigHub 3/3; local live 0/3; GitOps live 0/3; live parity 0/3 |
| Feature summary | generated-secrets;crds;install-vs-upgrade;extension-slots |
| Hard gap | existing-secret (chart ships no Secret toggle) |
| Next action | review limitation before promotion: existing-secret (chart ships no Secret toggle) |

## Artifact Chain

| Stage | Artifact |
| --- | --- |
| Source chart lock | [recipes/bitnami/contour/21.1.4/source-lock.yaml](source-lock.yaml) |
| Dependency lock | [recipes/bitnami/contour/21.1.4/dependency-lock.yaml](dependency-lock.yaml) |
| Recipe | [recipes/bitnami/contour/21.1.4/recipe.yaml](recipe.yaml) |
| Helm plan | [recipes/bitnami/contour/21.1.4/helm-plan.yaml](helm-plan.yaml) |
| Chart dossier | [recipes/bitnami/contour/21.1.4/chart-dossier.yaml](chart-dossier.yaml) |
| Control points | [recipes/bitnami/contour/21.1.4/control-points.yaml](control-points.yaml) |
| Value model | [recipes/bitnami/contour/21.1.4/value-model.yaml](value-model.yaml) |
| Catalog status | [recipes/bitnami/contour/21.1.4/catalog-status.yaml](catalog-status.yaml) |
| Helm pain report | [recipes/bitnami/contour/21.1.4/helm-pain-report.yaml](helm-pain-report.yaml) |
| Installer package OCI | `oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-contour:21.1.4` |
| Installer package source | [packages/bitnami/contour/21.1.4](../../../../packages/bitnami/contour/21.1.4) |
| Installer package receipt | [recipes/bitnami/contour/21.1.4/publication/installer-package-receipt.yaml](publication/installer-package-receipt.yaml) |
| Machine index | [recipes/bitnami/contour/21.1.4/artifact-index.yaml](artifact-index.yaml) |

## Variants

| Variant | Variant file | Package base | Revision | Helm objects | cub installer objects | Match | Helm equivalence | Scan | Gate | Target facts |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| default | [recipes/bitnami/contour/21.1.4/variants/default/variant.yaml](variants/default/variant.yaml) | [packages/bitnami/contour/21.1.4/bases/default](../../../../packages/bitnami/contour/21.1.4/bases/default) | [recipes/bitnami/contour/21.1.4/revisions/default/r001/variant-revision.yaml](revisions/default/r001/variant-revision.yaml) | 20 | 21 | 20/20 | pass | warn | warn | required Secret default/contourcert keys ca.crt,tls.crt,tls.key; required Secret default/envoycert keys ca.crt,tls.crt,tls.key |
| no-crds | [recipes/bitnami/contour/21.1.4/variants/no-crds/variant.yaml](variants/no-crds/variant.yaml) | [packages/bitnami/contour/21.1.4/bases/no-crds](../../../../packages/bitnami/contour/21.1.4/bases/no-crds) | [recipes/bitnami/contour/21.1.4/revisions/no-crds/r001/variant-revision.yaml](revisions/no-crds/r001/variant-revision.yaml) | 15 |  | 15/15 | pass |  | allow | required Secret default/contourcert keys ca.crt,tls.crt,tls.key; required Secret default/envoycert keys ca.crt,tls.crt,tls.key |
| legacy | [recipes/bitnami/contour/21.1.4/variants/legacy/variant.yaml](variants/legacy/variant.yaml) | [packages/bitnami/contour/21.1.4/bases/legacy](../../../../packages/bitnami/contour/21.1.4/bases/legacy) | [recipes/bitnami/contour/21.1.4/revisions/legacy/r001/variant-revision.yaml](revisions/legacy/r001/variant-revision.yaml) | 20 | 21 | 20/20 | pass | pass | allow | required Secret default/contourcert keys ca.crt,tls.crt,tls.key; required Secret default/envoycert keys ca.crt,tls.crt,tls.key |

## Package Bases

| Base | Path | Default | Description |
| --- | --- | --- | --- |
| legacy | [packages/bitnami/contour/21.1.4/bases/legacy](../../../../packages/bitnami/contour/21.1.4/bases/legacy) | no | bitnami/contour legacy variant (docker.io/bitnami -> docker.io/bitnamilegacy image remap) rendered from bitnami/contour@21.1.4 |
| default | [packages/bitnami/contour/21.1.4/bases/default](../../../../packages/bitnami/contour/21.1.4/bases/default) | yes | bitnami/contour default variant rendered from bitnami/contour@21.1.4 |
| no-crds | [packages/bitnami/contour/21.1.4/bases/no-crds](../../../../packages/bitnami/contour/21.1.4/bases/no-crds) | no | bitnami/contour no-crds variant rendered from bitnami/contour@21.1.4 |

## Receipts

| Variant | Revision | Receipt | Kind | Result | Path |
| --- | --- | --- | --- | --- | --- |
| default | r001 | render | RenderReceipt | recorded | [recipes/bitnami/contour/21.1.4/revisions/default/r001/receipts/render-receipt.yaml](revisions/default/r001/receipts/render-receipt.yaml) |
| default | r001 | helmEquivalence | HelmEquivalenceReceipt | pass | [recipes/bitnami/contour/21.1.4/revisions/default/r001/receipts/helm-equivalence-receipt.yaml](revisions/default/r001/receipts/helm-equivalence-receipt.yaml) |
| default | r001 | scan | ScanReceipt | warn | [recipes/bitnami/contour/21.1.4/revisions/default/r001/receipts/scan-receipt.yaml](revisions/default/r001/receipts/scan-receipt.yaml) |
| default | r001 | installGate | InstallGate | warn | [recipes/bitnami/contour/21.1.4/revisions/default/r001/receipts/install-gate.yaml](revisions/default/r001/receipts/install-gate.yaml) |
| no-crds | r001 | render | RenderReceipt | recorded | [recipes/bitnami/contour/21.1.4/revisions/no-crds/r001/receipts/render-receipt.yaml](revisions/no-crds/r001/receipts/render-receipt.yaml) |
| no-crds | r001 | helmEquivalence | HelmEquivalenceReceipt | pass | [recipes/bitnami/contour/21.1.4/revisions/no-crds/r001/receipts/helm-equivalence-receipt.yaml](revisions/no-crds/r001/receipts/helm-equivalence-receipt.yaml) |
| no-crds | r001 | scan | ScanReceipt |  | [recipes/bitnami/contour/21.1.4/revisions/no-crds/r001/receipts/scan-receipt.yaml](revisions/no-crds/r001/receipts/scan-receipt.yaml) |
| no-crds | r001 | installGate | InstallGate | allow | [recipes/bitnami/contour/21.1.4/revisions/no-crds/r001/receipts/install-gate.yaml](revisions/no-crds/r001/receipts/install-gate.yaml) |
| legacy | r001 | render | RenderReceipt | recorded | [recipes/bitnami/contour/21.1.4/revisions/legacy/r001/receipts/render-receipt.yaml](revisions/legacy/r001/receipts/render-receipt.yaml) |
| legacy | r001 | helmEquivalence | HelmEquivalenceReceipt | pass | [recipes/bitnami/contour/21.1.4/revisions/legacy/r001/receipts/helm-equivalence-receipt.yaml](revisions/legacy/r001/receipts/helm-equivalence-receipt.yaml) |
| legacy | r001 | scan | ScanReceipt | pass | [recipes/bitnami/contour/21.1.4/revisions/legacy/r001/receipts/scan-receipt.yaml](revisions/legacy/r001/receipts/scan-receipt.yaml) |
| legacy | r001 | installGate | InstallGate | allow | [recipes/bitnami/contour/21.1.4/revisions/legacy/r001/receipts/install-gate.yaml](revisions/legacy/r001/receipts/install-gate.yaml) |

## Current Install Shape

```sh
cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-contour:21.1.4 --base <variant> --work-dir <tmp> --non-interactive --namespace <namespace>
```

Use the variant table above to choose the package base. The `oci://` ref is
the public package users pull; the `packages/...` path is the repo source path
used by maintainers and proof scripts. The proof path compares regular Helm
output with real `cub installer setup` output and explains every intentional
difference, such as the Namespace support object or separated Secrets.
