Hook Route Candidate Work Orders

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

UNOFFICIAL/EXPERIMENTAL - generated work orders, 2026-06-11.

These generated work orders turn candidate hook route plans into assignable proof work. They do not execute hooks, admit charts to the maintained hook queue, or claim production readiness.

Summary

candidate charts: 10
work orders: 72
dependency-closure hook rows: 5
target/preflight rows: 9

Pattern Mix

PatternCharts
provisioning-job3
database-migration-pair2
environment-conditional-hooks1
hook-like-migration-jobs1
install-critical-crd-hook1
migration-and-sync-hooks1
vendored-traefik-lifecycle-hook1

Work Orders By Chart

kong/kong@3.2.0

Pattern: database-migration-pair<br> Phases: pre-upgrade, post-upgrade<br> Dependency source: chart-own<br> Candidate route: upgrade-action-with-receipt

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2ordered-upgrade-actionoperator reviewerThe pre-upgrade and post-upgrade actions are mapped to an ordered lifecycle route with rollback and failure-handling notes.
3target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
4maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
5gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
6runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
7maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

k8s-dashboard/kubernetes-dashboard@7.14.0

Pattern: database-migration-pair (vendored)<br> Phases: pre-upgrade, post-upgrade<br> Dependency source: vendored kong subchart<br> Candidate route: upgrade-action-with-receipt (if rendered)

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2dependency-closure-reviewcatalog reviewerThe dependency source, dependency lock, and affected bases are recorded before the route is admitted to the maintained queue.
3ordered-upgrade-actionoperator reviewerThe pre-upgrade and post-upgrade actions are mapped to an ordered lifecycle route with rollback and failure-handling notes.
4maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
5gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
6runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
7maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

gitlab/gitlab@10.0.0

Pattern: vendored-traefik-lifecycle-hook<br> Phases: post-install, post-upgrade<br> Dependency source: vendored traefik subchart<br> Candidate route: argocd-or-flux-lifecycle-hook

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2dependency-closure-reviewcatalog reviewerThe dependency source, dependency lock, and affected bases are recorded before the route is admitted to the maintained queue.
3target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
4serious-chart-base-selectioncatalog ownerA serious-chart review chooses the supported base and records which lifecycle concerns are supported, deferred, or blocked.
5maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
6gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
7runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
8maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

airflow-helm/airflow@8.9.0

Pattern: migration-and-sync-hooks<br> Phases: post-install, post-upgrade<br> Dependency source: chart-own<br> Candidate route: explicit-managed-action

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
3maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
4gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
5runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
6maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

bitnami/kafka@32.4.3

Pattern: provisioning-job<br> Phases: post-install, post-upgrade<br> Dependency source: chart-own<br> Candidate route: explicit-managed-action

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2provisioning-mode-splitcatalog reviewerThe catalog has a provisioning-off base and, if useful, a provisioning-enabled base with target facts and a managed action receipt.
3target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
4maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
5gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
6runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
7maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

bitnami/minio@17.0.21

Pattern: provisioning-job<br> Phases: post-install, post-upgrade<br> Dependency source: chart-own (also vendored into bitnami/thanos)<br> Candidate route: explicit-managed-action

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2dependency-closure-reviewcatalog reviewerThe dependency source, dependency lock, and affected bases are recorded before the route is admitted to the maintained queue.
3provisioning-mode-splitcatalog reviewerThe catalog has a provisioning-off base and, if useful, a provisioning-enabled base with target facts and a managed action receipt.
4target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
5maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
6gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
7runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
8maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

datadog/datadog@3.214.0

Pattern: environment-conditional-hooks<br> Phases: pre-install, pre-upgrade, post-install, post-upgrade<br> Dependency source: chart-own plus vendored datadog-csi-driver<br> Candidate route: target-class-preflight-and-upgrade-action

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2dependency-closure-reviewcatalog reviewerThe dependency source, dependency lock, and affected bases are recorded before the route is admitted to the maintained queue.
3target-scope-splitplatform reviewerSupported target classes are split into separate scopes with preflight checks or explicit unsupported-target blockers.
4target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
5maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
6gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
7runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
8maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

bitnami/thanos@17.3.1

Pattern: provisioning-job (vendored)<br> Phases: post-install, post-upgrade<br> Dependency source: vendored minio subchart<br> Candidate route: explicit-managed-action

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2dependency-closure-reviewcatalog reviewerThe dependency source, dependency lock, and affected bases are recorded before the route is admitted to the maintained queue.
3provisioning-mode-splitcatalog reviewerThe catalog has a provisioning-off base and, if useful, a provisioning-enabled base with target facts and a managed action receipt.
4target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
5maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
6gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
7runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
8maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

apache-airflow/airflow@1.21.0

Pattern: hook-like-migration-jobs<br> Phases: none found by static scan<br> Dependency source: chart-own lifecycle-like Jobs<br> Candidate route: recipe-time-lifecycle-verification

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2hook-free-claim-reviewcatalog reviewerThe chart records whether lifecycle jobs are normal desired state, managed actions, or blockers for the selected base.
3target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
4maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
5gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
6runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
7maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

argo-cd/argo-workflows@1.0.14

Pattern: install-critical-crd-hook<br> Phases: pre-install, pre-upgrade<br> Dependency source: chart-own<br> Candidate route: preflight-or-presync-crd-apply

OrderWork typeReviewerDone when
1base-rendering-reviewcatalog reviewerThe selected recipe/base records whether the hook renders, is intentionally inert, or requires a separate supported base.
2target-preflightplatform reviewerTarget facts or preflight checks exist for the selected route, or the target prerequisite is explicitly out of scope.
3maintained-route-receiptcatalog reviewerA HookLifecycleRouteReceipt or explicit blocker exists in the maintained hook lifecycle area for the selected base.
4gitops-lifecycle-mappingoperator reviewerThe route records whether Argo CD, Flux, a ConfigHub action, or an operator-run action owns the lifecycle step.
5runtime-observation-or-executionoperator reviewerThe selected path has an execution receipt, a fresh observation receipt, or a named reason why runtime proof is deferred.
6maintained-queue-admissioncatalog ownerThe row is admitted to the maintained hook queue or remains in candidates with the missing evidence named.

Rules

Spreadsheet

Use work-orders.csv for assignment, filtering, and status tracking.