hashicorp/consul@2.0.0 Production Packet

A repository document, rendered for the site. View source markdown.

What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated packet summarizes the current support story for a hard chart. It is a navigation surface over existing evidence, not a new support decision.

Current Answer

FieldValue
Supported basedefault-control-plane
Support decisionsupported
Production dispositionproduction-review-ready
Target scopecub-lk-kind-vanilla; namespace=consul; delivery=confighub-oci; controller=argo
Delivery pathconfighub-oci
Evidence count17
Strongest user-facing evidencelive-helm-vs-confighub-parity
Live summarylocal:1/2 gitops:1/2 live-parity:1/2 two-cluster:2/2

Why This Chart Is Hard

Service-mesh control plane with TLS, ACL, gateway/UI options, storage/quorum choices, webhooks, and secret prerequisites.

What A User Can Safely Do Today

Use default-control-plane for the declared proof scope. Secure mesh, TLS, ACL, gateway, UI, production quorum, and digest-pinned paths need separate bases.

What Remains Before Broader Production Use

Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate secure-mesh, TLS, ACL, gateway, UI, external-CRD, production-quorum, hardening, and digest-pinned bases for real customer Consul workloads.

Bases

BaseUser readinessLane summaryTarget factsCommand
default-control-planestart-hererender=pass; confighub=pass; local=pass; gitops=pass; live-parity=pass; two-cluster=passnonecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-consul:2.0.0 --base default-control-plane --work-dir <tmp> --non-interactive --namespace consul
secure-mesh-existing-secretsruntime-watchrender=pass; confighub=pass; local=fail; gitops=watch; live-parity=watch; two-cluster=passrequired Secret consul/consul-ca-cert keys tls.crt; required Secret consul/consul-server-cert keys tls.crt,tls.key; required Secret consul/consul-gossip-encryption-key keys key; required Secret consul/consul-bootstrap-acl-token keys token; topology minSchedulableNodes=3cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-consul:2.0.0 --base secure-mesh-existing-secrets --work-dir <tmp> --non-interactive --namespace consul

Quirks And Inputs

FieldValue
Quirks surfacedwebhooks;extension-slots;install-vs-upgrade-divergence;required-values;tpl;capabilities;rbac;storage
User must providea StorageClass / storage decision; webhook/cert readiness at delivery time; mandatory chart inputs
ConfigHub / installer absorbsexact rendered objects with render parity and receipts; extension slots routed to reviewed bases; install-vs-upgrade render divergence captured per revision
Extension slot routenone recorded

Decision Details

DecisionState
Image policymutable-image-exception-accepted-for-target-scope
Scan policydefault-control-plane-resource-policy-accepted-for-target-scope
Lifecycle policylifecycle-observed-for-proof-scope
Target factsno-unresolved-target-prerequisite-in-candidate-base
Live evidencefresh-target-evidence-passed

Regenerate:

npm run hard-charts:packets
npm run hard-charts:packets:verify