This guide explains the journey from a public Helm chart to a ConfigHub Space. Use it when you want to know why this preset exists, what problem it solves, how to repeat it, and what still needs care.
It is generated from the same records that build the package, chart page, render intent, scripts, and receipts. The proof links are lower down.
Why this preset exists
Helm charts often expose many settings, but a values file alone does not tell the whole operations story. A team still needs to know what Kubernetes objects will be created, which Secrets or CRDs must already exist, whether hooks or setup jobs need special handling, and what evidence backs the result.
This preset is a named answer for one useful operating choice. It keeps the upstream chart, records the inputs and rendered YAML, and gives the team a repeatable starting point instead of a private values-file guess.
What this is
This is the default preset config for kyverno/kyverno@3.8.1. The repo also calls this a base variant. Use this when you want to start from the chart author's normal path, with the inputs recorded.
The matching catalog page is kyverno/kyverno@3.8.1.
The chart journey
We keep the Helm chart. We lock kyverno/kyverno@3.8.1, choose the default preset config, render it with the recorded values, namespace, release name, and Kubernetes capabilities, then save the output as files.
That captured output is the render variant: recipes/kyverno/kyverno/3.8.1/revisions/default/r001/rendered/release-objects.yaml. It contains 69 Kubernetes object(s): CustomResourceDefinition x22, ClusterRole x16, ClusterRoleBinding x7, Service x6, Deployment x4, Role x4, RoleBinding x4, ServiceAccount x4.
The public package is oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/kyverno-kyverno:3.8.1. Users can pull it without cloning this repo. When someone runs cub installer upload, ConfigHub stores the rendered Kubernetes YAML in a Space so it can be searched, compared, reviewed, changed, and delivered. The example script defaults to Space helm-kyverno-default, but users can choose another name with CUB_SPACE=....
What to check
This preset needs a setup step before Kubernetes can accept all of the rendered objects. The step is described below and is part of the tested install path.
The catalog records 5 extra steps for this preset. We call these lifecycle routes because they say what must happen before, during, or after Kubernetes applies the main set of files.
- Before install: preserve-ordering.
- Before install: target-facts-or-preflight.
- After install: Test hooks become checks, not hidden install behavior.
- During upgrade: Resource migration after upgrade must be recorded as an upgrade operation.
- When uninstalling: Webhook and APIService cleanup belongs to delete or rollback policy.
Hooks, setup jobs, and other install or upgrade steps are listed separately, so you can see what must run and when. Known limitation: existing-secret (chart ships no Secret toggle).
Why you can trust it
- The chart version, source, namespace, release name, values, and capability profile are recorded in the render intent.
- The render variant is committed as YAML and contains 69 Kubernetes object(s).
- The installer package OCI ref points to the package users pull for this chart version.
- Render parity is recorded as passing for this preset config.
- Hook and lifecycle work is counted and linked to the route record.
This is a claim about this recorded preset config. It is not a claim that every possible values file for this chart has been checked.
Repeat it
Fast path with no ConfigHub account:
bash <(curl -fsSL https://confighub.github.io/helm-expt/site/sh/kyverno-kyverno-3-8-1/default/try.sh)
Fast path with a ConfigHub account:
bash <(curl -fsSL https://confighub.github.io/helm-expt/site/sh/kyverno-kyverno-3-8-1/default/confighub.sh)
The core render command is:
New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.
What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.
cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/kyverno-kyverno:3.8.1 --base default --work-dir ./kyverno-kyverno-3-8-1-default --non-interactive --namespace default
After upload, create environment versions with cub variant create and move reviewed changes with cub variant promote. The walkthrough is After Upload: Create A Variant And Promote Changes.
Preset details
| Item | Value |
|---|---|
| Chart | kyverno/kyverno@3.8.1 |
| Preset config | default |
| Namespace | default |
| Release name | kyverno |
| Values | recipes/kyverno/kyverno/3.8.1/effective-values.yaml |
| Render intent | data/helm-render-intents/intents/kyverno-kyverno-3-8-1-default.yaml |
| Render variant | recipes/kyverno/kyverno/3.8.1/revisions/default/r001/rendered/release-objects.yaml |
| Package base | packages/kyverno/kyverno/3.8.1/bases/default |
| Scripts | try.sh · confighub.sh |
Prerequisites and lifecycle steps
| When | What | How it is handled |
|---|---|---|
| Before install | Keep the required apply order | preserve-ordering. |
| Before install | Prepare the target | target-facts-or-preflight. |
| After install | Run the chart check | Test hooks become checks, not hidden install behavior. |
| During upgrade | Run the upgrade step | Resource migration after upgrade must be recorded as an upgrade operation. |
| When uninstalling | Use the chart's cleanup policy | Webhook and APIService cleanup belongs to delete or rollback policy. |
Evidence
| Check | Status |
|---|---|
| Render parity | yes |
| ConfigHub scan/upload proof | yes |
| Earlier local-cluster test | yes |
| GitOps OCI live run | yes |
| Live Helm vs ConfigHub comparison | yes |
| Lifecycle routes | 5 |
Limits
- Known gap for this row: existing-secret (chart ships no Secret toggle).
- Resolve the named gap first: existing-secret (chart ships no Secret toggle).
Source files
- Chart page: https://confighub.github.io/helm-expt/site/charts/kyverno-kyverno-3-8-1.html
- Render intent:
data/helm-render-intents/intents/kyverno-kyverno-3-8-1-default.yaml - Rendered YAML:
recipes/kyverno/kyverno/3.8.1/revisions/default/r001/rendered/release-objects.yaml - Package source:
packages/kyverno/kyverno/3.8.1/bases/default - Generated scripts:
site/sh/kyverno-kyverno-3-8-1/default - Preset doctrine: Helm Chart Presets And Values