<!-- Generated by npm run catalog:maps. Do not edit by hand. -->

# hashicorp/consul 2.0.0 Catalog Map

This page makes the artifact chain explicit:

```text
chart -> recipe -> variants -> variant revisions -> package bases -> receipts
```

## Status

| Field | Value |
| --- | --- |
| Chart | hashicorp/consul@2.0.0 |
| Catalog status | catalog-supported |
| Support level | supported-for-declared-scopes |
| Supported scopes | local-test |
| Production readiness | production-review-ready |
| Supported variants | default-control-plane, secure-mesh-existing-secrets |
| Candidate variants | none |
| Control points | admission-webhook, capability-profile, cluster-rbac, crd-ownership, dependency-lock, extension-slots, installer-support-object, lifecycle-policy, mesh-gateway-policy, namespace-references, source-lock, stateful-workload, target-facts, target-topology, ui-ingress-policy |

## Feature And Proof Summary

This is the chart-level summary. Use the variant table and receipt links below
for exact base-variant evidence.

| Field | Value |
| --- | --- |
| Adoption bucket | try-from-public-catalog |
| User status | catalog-supported-with-live-evidence |
| Strongest evidence | live-helm-vs-confighub-parity |
| Proof lanes | render parity 2/2; ConfigHub 2/2; local live 1/2; GitOps live 1/2; live parity 1/2 |
| Feature summary | webhooks;required-values;install-vs-upgrade;extension-slots |
| Hard gap | ha (curated proof lane - bespoke teaching needed) |
| Next action | image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes |

## Artifact Chain

| Stage | Artifact |
| --- | --- |
| Source chart lock | [recipes/hashicorp/consul/2.0.0/source-lock.yaml](source-lock.yaml) |
| Dependency lock | [recipes/hashicorp/consul/2.0.0/dependency-lock.yaml](dependency-lock.yaml) |
| Recipe | [recipes/hashicorp/consul/2.0.0/recipe.yaml](recipe.yaml) |
| Helm plan | [recipes/hashicorp/consul/2.0.0/helm-plan.yaml](helm-plan.yaml) |
| Chart dossier | [recipes/hashicorp/consul/2.0.0/chart-dossier.yaml](chart-dossier.yaml) |
| Control points | [recipes/hashicorp/consul/2.0.0/control-points.yaml](control-points.yaml) |
| Value model | [recipes/hashicorp/consul/2.0.0/value-model.yaml](value-model.yaml) |
| Runtime review | [recipes/hashicorp/consul/2.0.0/runtime-review.yaml](runtime-review.yaml) |
| GitOps runtime review | [recipes/hashicorp/consul/2.0.0/gitops-runtime-review.yaml](gitops-runtime-review.yaml) |
| Target topology | [recipes/hashicorp/consul/2.0.0/target-topology.yaml](target-topology.yaml) |
| Target prerequisite plan | [recipes/hashicorp/consul/2.0.0/target-prerequisite-plan.yaml](target-prerequisite-plan.yaml) |
| Weirdness and mitigations | [recipes/hashicorp/consul/2.0.0/weirdness-and-mitigations.md](weirdness-and-mitigations.md) |
| Catalog status | [recipes/hashicorp/consul/2.0.0/catalog-status.yaml](catalog-status.yaml) |
| Helm pain report | [recipes/hashicorp/consul/2.0.0/helm-pain-report.yaml](helm-pain-report.yaml) |
| Installer package OCI | `oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-consul:2.0.0` |
| Installer package source | [packages/hashicorp/consul/2.0.0](../../../../packages/hashicorp/consul/2.0.0) |
| Installer package receipt | [recipes/hashicorp/consul/2.0.0/publication/installer-package-receipt.yaml](publication/installer-package-receipt.yaml) |
| Machine index | [recipes/hashicorp/consul/2.0.0/artifact-index.yaml](artifact-index.yaml) |

## Variants

| Variant | Variant file | Package base | Revision | Helm objects | cub installer objects | Match | Helm equivalence | Scan | Gate | Target facts |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| default-control-plane | [recipes/hashicorp/consul/2.0.0/variants/default-control-plane/variant.yaml](variants/default-control-plane/variant.yaml) | [packages/hashicorp/consul/2.0.0/bases/default-control-plane](../../../../packages/hashicorp/consul/2.0.0/bases/default-control-plane) | [recipes/hashicorp/consul/2.0.0/revisions/default-control-plane/r001/variant-revision.yaml](revisions/default-control-plane/r001/variant-revision.yaml) | 68 | 69 | 68/68 | pass | warn | warn | none |
| secure-mesh-existing-secrets | [recipes/hashicorp/consul/2.0.0/variants/secure-mesh-existing-secrets/variant.yaml](variants/secure-mesh-existing-secrets/variant.yaml) | [packages/hashicorp/consul/2.0.0/bases/secure-mesh-existing-secrets](../../../../packages/hashicorp/consul/2.0.0/bases/secure-mesh-existing-secrets) | [recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/variant-revision.yaml](revisions/secure-mesh-existing-secrets/r001/variant-revision.yaml) | 97 | 98 | 97/97 | pass | warn | warn | required Secret consul/consul-ca-cert keys tls.crt; required Secret consul/consul-server-cert keys tls.crt,tls.key; required Secret consul/consul-gossip-encryption-key keys key; required Secret consul/consul-bootstrap-acl-token keys token; topology minSchedulableNodes=3 |

## Package Bases

| Base | Path | Default | Description |
| --- | --- | --- | --- |
| default-control-plane | [packages/hashicorp/consul/2.0.0/bases/default-control-plane](../../../../packages/hashicorp/consul/2.0.0/bases/default-control-plane) | yes | consul default control plane variant rendered from hashicorp/consul@2.0.0 |
| secure-mesh-existing-secrets | [packages/hashicorp/consul/2.0.0/bases/secure-mesh-existing-secrets](../../../../packages/hashicorp/consul/2.0.0/bases/secure-mesh-existing-secrets) | no | consul secure mesh with existing Secrets variant rendered from hashicorp/consul@2.0.0 |

## Receipts

| Variant | Revision | Receipt | Kind | Result | Path |
| --- | --- | --- | --- | --- | --- |
| default-control-plane | r001 | render | RenderReceipt | recorded | [recipes/hashicorp/consul/2.0.0/revisions/default-control-plane/r001/receipts/render-receipt.yaml](revisions/default-control-plane/r001/receipts/render-receipt.yaml) |
| default-control-plane | r001 | helmEquivalence | HelmEquivalenceReceipt | pass | [recipes/hashicorp/consul/2.0.0/revisions/default-control-plane/r001/receipts/helm-equivalence-receipt.yaml](revisions/default-control-plane/r001/receipts/helm-equivalence-receipt.yaml) |
| default-control-plane | r001 | scan | ScanReceipt | warn | [recipes/hashicorp/consul/2.0.0/revisions/default-control-plane/r001/receipts/scan-receipt.yaml](revisions/default-control-plane/r001/receipts/scan-receipt.yaml) |
| default-control-plane | r001 | installGate | InstallGate | warn | [recipes/hashicorp/consul/2.0.0/revisions/default-control-plane/r001/receipts/install-gate.yaml](revisions/default-control-plane/r001/receipts/install-gate.yaml) |
| secure-mesh-existing-secrets | r001 | render | RenderReceipt | recorded | [recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/receipts/render-receipt.yaml](revisions/secure-mesh-existing-secrets/r001/receipts/render-receipt.yaml) |
| secure-mesh-existing-secrets | r001 | helmEquivalence | HelmEquivalenceReceipt | pass | [recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/receipts/helm-equivalence-receipt.yaml](revisions/secure-mesh-existing-secrets/r001/receipts/helm-equivalence-receipt.yaml) |
| secure-mesh-existing-secrets | r001 | scan | ScanReceipt | warn | [recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/receipts/scan-receipt.yaml](revisions/secure-mesh-existing-secrets/r001/receipts/scan-receipt.yaml) |
| secure-mesh-existing-secrets | r001 | installGate | InstallGate | warn | [recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/receipts/install-gate.yaml](revisions/secure-mesh-existing-secrets/r001/receipts/install-gate.yaml) |

## Current Install Shape

```sh
cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-consul:2.0.0 --base <variant> --work-dir <tmp> --non-interactive --namespace <namespace>
```

Use the variant table above to choose the package base. The `oci://` ref is
the public package users pull; the `packages/...` path is the repo source path
used by maintainers and proof scripts. The proof path compares regular Helm
output with real `cub installer setup` output and explains every intentional
difference, such as the Namespace support object or separated Secrets.
