hashicorp/vault@0.32.0 Production Packet

A repository document, rendered for the site. View source markdown.

What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated packet summarizes the current support story for a hard chart. It is a navigation surface over existing evidence, not a new support decision.

Current Answer

FieldValue
Supported basedefault
Support decisionrejected
Production dispositionproduction-review-ready
Target scopekind-vanilla; namespace=vault; delivery=confighub-oci; controller=argo
Delivery pathconfighub-oci
Evidence count9
Strongest user-facing evidencelive-helm-vs-confighub-parity
Live summarylocal:2/3 gitops:2/3 live-parity:2/3 two-cluster:3/3

Why This Chart Is Hard

Security-sensitive stateful system where dev-mode is useful for parity but not a production support claim.

What A User Can Safely Do Today

Use dev-mode only for local/demo proof. A production Vault base must cover init/unseal, storage, TLS, backup/restore, and operator runbook evidence.

What Remains Before Broader Production Use

Keep the default base as a ready-to-try parity example. Create a separate TLS-enabled, digest-pinned, persistent-storage base with explicit init, unseal, recovery, backup, and upgrade procedures before reconsidering production support.

Bases

BaseUser readinessLane summaryTarget factsCommand
defaultstart-hererender=pass; confighub=pass; local=pass; gitops=pass; live-parity=pass; two-cluster=passnonecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-vault:0.32.0 --base default --work-dir <tmp> --non-interactive --namespace vault
dev-modestart-hererender=pass; confighub=pass; local=pass; gitops=pass; live-parity=pass; two-cluster=passnonecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-vault:0.32.0 --base dev-mode --work-dir <tmp> --non-interactive --namespace vault
ha-raft-uiruntime-watchrender=pass; confighub=pass; local=blocked; gitops=watch; live-parity=watch; two-cluster=passtopology minSchedulableNodes=3cub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-vault:0.32.0 --base ha-raft-ui --work-dir <tmp> --non-interactive --namespace vault

Quirks And Inputs

FieldValue
Quirks surfacedwebhooks;extension-slots;required-values;tpl;capabilities;rbac;storage
User must providea StorageClass / storage decision; webhook/cert readiness at delivery time; mandatory chart inputs
ConfigHub / installer absorbsexact rendered objects with render parity and receipts; extension slots routed to reviewed bases
Extension slot routenone recorded

Decision Details

DecisionState
Image policymutable-tags-prevent-production-support
Scan policydefault-security-posture-not-accepted-for-production
Lifecycle policymanual-vault-operations-not-production-supported
Target factsproduction-target-contract-not-defined
Live evidenceparity-passed-production-support-rejected

Regenerate:

npm run hard-charts:packets
npm run hard-charts:packets:verify