Top-100 APIService Coverage

A repository document, rendered for the site. View source markdown.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated report joins the source-scan APIService signal to maintained recipe/package rows and committed runtime evidence.

APIService objects need a stricter runtime contract than ordinary rendered objects. The desired object can match while Kubernetes API aggregation, CA trust, or backing service readiness still fails. This report therefore keeps four facts separate:

rendered APIService object observed
backing workload observed
Helm-vs-ConfigHub live parity observed
aggregated API availability observed

Current Reading

source top-100 APIService rows:          5
maintained APIService recipe rows:       5
maintained rows outside source top-100:  3
catalog-supported APIService rows:       1
rows with API aggregation observation:   2
rows with object/workload observation:   2
rows with two-cluster parity only:       0
rows still source-detected only:         3
aggregated API availability receipts:    2
compatible capability bases created:     1
capability-profile candidates observed:  1
active proof/import work orders:          5

Only rows with both an Available=True APIService condition and a successful aggregated API query receipt claim aggregated API availability. Today that evidence exists for Metrics Server and KEDA.

Prometheus Adapter also has a live-tested capability-profile route. Adding apiregistration.k8s.io/v1 to the render profile changes the chart's APIService from the refused apiregistration.k8s.io/v1beta1 object to a target-supported apiregistration.k8s.io/v1 object. That route is now a maintained proof base, apiservice-v1-capability; it still needs the normal ConfigHub, live, GitOps, and APIService runtime proof lanes before catalog promotion.

Coverage Status

StatusRows
api-aggregation-observed2
source-detected-needs-recipe3

Source Top-100 Rows

RankChartSource versionStatusObject observedWorkload observedLive parityAggregation observedNext action
9k8s-dashboard/kubernetes-dashboard7.14.0source-detected-needs-recipenonononocreate recipe/import candidate, then model APIService readiness and aggregation observation before catalog claims
11metrics-server/metrics-server3.13.0api-aggregation-observedyesyesyesyeskeep the runtime/GitOps APIService receipt fresh; use this pattern for the next APIService chart
43datadog/datadog3.214.0source-detected-needs-recipenonononocreate recipe/import candidate, then model APIService readiness and aggregation observation before catalog claims
53kedacore/keda2.19.0api-aggregation-observedyesyesnoyesdecide whether KEDA enters a catalog promotion wave using the two-cluster parity and ConfigHub OCI APIService receipts
71bitnami/metrics-server7.4.12source-detected-needs-recipenonononocreate recipe/import candidate, then model APIService readiness and aggregation observation before catalog claims

Maintained APIService Rows

This appendix includes maintained recipe/package rows with APIService source signals even when the source chart sits outside the source top-100 slice. It keeps target compatibility blockers visible without changing the source-top-100 counts above.

RankChartSource versionRendered APIService objectsStatusConfigHub proofTarget blockTarget decisionNext action
11metrics-server/metrics-server3.13.02api-aggregation-observedyes--keep the runtime/GitOps APIService receipt fresh; use this pattern for the next APIService chart
53kedacore/keda2.19.02api-aggregation-observedyes--decide whether KEDA enters a catalog promotion wave using the two-cluster parity and ConfigHub OCI APIService receipts
118prometheus-community/prometheus-adapter5.3.03compatible-base-created-needs-standard-lanesyesapi-version-unsupporteddo-not-promote-for-this-target-profileRun ConfigHub proof, local live, live Helm-vs-ConfigHub parity, and the APIService runtime contract for the maintained apiservice-v1-capability base before catalog promotion.
130fairwinds-stable/goldilocks10.3.00source-signal-not-rendered-in-maintained-basesno--render path recorded: current maintained bases do not render APIService objects; require runtime aggregation evidence only for a future APIService-enabled base
148fairwinds-stable/vpa4.11.00source-signal-not-rendered-in-maintained-basesno--render path recorded: current maintained bases do not render APIService objects; require runtime aggregation evidence only for a future APIService-enabled base

Maintained status counts:

StatusRows
api-aggregation-observed2
compatible-base-created-needs-standard-lanes1
source-signal-not-rendered-in-maintained-bases2

Capability Profile Candidates

These rows are live-tested routes from a refused current base to a possible future maintained base. They are not current catalog support claims.

ChartCandidate baseMaintained proof baseAdded API versionsRender resultLive resultReceiptNext action
prometheus-community/prometheus-adapter@5.3.0apiservice-v1-capabilityapiservice-v1-capability (maintained-base-created)apiregistration.k8s.io/v1passpassreceiptRun ConfigHub proof, local live, live Helm-vs-ConfigHub parity, and the APIService runtime contract for the maintained apiservice-v1-capability base before catalog promotion.

Runtime Contract

APIService rows become trusted runtime evidence only when one committed receipt records all of these facts for the selected chart/base:

FactWhy it matters
rendered APIService object observedproves the desired aggregation object is present in the object set
backing workload observedproves the APIService has a real server behind it
APIService Available=True observedproves Kubernetes API aggregation accepted the route and trust chain
aggregated API query observedproves a client can use the aggregated API, not only read the object
freshness timestamp recordedlets support decide whether the observation is still usable

Current contract rows:

ChartReceiptConditionQueryFreshnessGaps
k8s-dashboard/kubernetes-dashboard@7.14.0-nononono maintained recipe/import row; no rendered APIService object observation
metrics-server/metrics-server@3.13.0data/runtime-gitops/receipts/metrics-server-metrics-server/default/latest.yamlyesyesyesnone
datadog/datadog@3.214.0-nononono maintained recipe/import row; no rendered APIService object observation
kedacore/keda@2.19.0data/runtime-gitops/receipts/kedacore-keda/default/latest.yamlyesyesyesnone
bitnami/metrics-server@7.4.12-nononono maintained recipe/import row; no rendered APIService object observation

How To Use This

Files

FilePurpose
top100-apiservice-coverage.csvOne row per source top-100 chart that renders APIService objects.
maintained-apiservice-coverage.csvMaintained recipe/package rows with APIService source signals, including rows outside the source top-100 slice.
render-path-notes.mdMaintained rows where APIService source signals are conditional or vendored but not rendered by current bases.
render-path-notes.csvSpreadsheet-ready render-path decisions.
target-compatibility-decisions.mdTarget-scoped compatibility decisions for maintained rows that render unsupported APIService versions.
target-compatibility-decisions.csvSpreadsheet-ready target compatibility decisions.
capability-profile-candidates.mdLive-tested capability-profile candidates that can become future maintained bases.
capability-profile-candidates.csvSpreadsheet-ready capability-profile candidate index.
capability-profile-candidates/*.yamlCandidate receipts with render and live rehearsal evidence.
promotion-reviews/README.mdAPIService promotion-review packets for rows with enough runtime evidence to review catalog scope.
promotion-reviews/promotion-reviews.csvSpreadsheet-ready APIService promotion-review packet index.
work-orders.mdHuman next-proof queue for APIService charts.
work-orders.csvSpreadsheet-ready next-proof queue for assignment and reruns.
data/quirk-work-queue/top100-queue.csvSource quirk queue that currently carries the APIService hard gap.
runs/top20-local-kind/metrics-server-default/observation-receipt.jsonMetrics Server object/workload observation evidence.
data/runtime-gitops/receipts/metrics-server-metrics-server/default/latest.yamlMetrics Server APIService Available=True and kubectl top nodes evidence.
data/runtime-gitops/receipts/kedacore-keda/default/latest.yamlKEDA ConfigHub OCI/Argo runtime evidence: workloads ready, APIService Available=True, and aggregated API query pass.
runs/live-kind-parity/*/receipt.yamlTwo-cluster Helm-vs-cub installer parity evidence.

Regenerate:

npm run apiservice:coverage
npm run apiservice:coverage:verify