Per-variant hook lifecycle routes

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

UNOFFICIAL/EXPERIMENTAL. Generated by scripts/generate-lifecycle-routes-by-variant.mjs; do not hand-edit. Regenerate with npm run lifecycle:routes-by-variant.

Plain-English answer to "what must happen before or after deployment, and who handles it?" for each chart and built preset config. Every lifecycle step is named, assigned to an executor, and linked to evidence or remaining work. Derived from committed inputs only (the chart-level and exact-base routes in data/lifecycle-route-actions/, each base's variant.yaml, and the matrix's per-base disposition). The product does not auto-execute these routes yet (automatic: false); that, with a receipt, is the roadmap (#688).

Charts: 17 · with a real per-variant delta: 6 (argo-cd/argo-workflows, bitnami/contour, gatekeeper/gatekeeper, kedacore/keda, kyverno/kyverno, prometheus-community/kube-prometheus-stack).

argo-cd/argo-workflows

BaseHook (route)After deploy, who runs it?Per-base change
controller-default-reviewed@1.0.14 (package applies 8 CRDs first)crd-install → preflight-or-presync-crd-applyPrerequisite - run the generated package script before the workloadspackaged-action (the package carries the 8 CRDs and its generated script applies them before the workload; this base still needs its own live route receipt)
default@1.0.14 (package applies 8 CRDs first)crd-install → preflight-or-presync-crd-applyHandled - the generated package script applies the CRDs firstresolved (the package carries and applies the 8 CRDs before the workload (observed live))
minimal-crds@1.0.14crd-install → self-contained-crd-baseYour applier - must apply CRDs before dependent objectsresolved (this base installs the required CRDs (observed live))

bitnami/contour

BaseHook (route)After deploy, who runs it?Per-base change
legacy@21.1.4hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-

gatekeeper/gatekeeper

BaseHook (route)After deploy, who runs it?Per-base change
default@3.22.2hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-
default@3.22.2hook-phase → upgrade-action-with-receiptYour delivery - a GitOps PreSync/PostSync or cub action (receipted)-

kedacore/keda

BaseHook (route)After deploy, who runs it?Per-base change
no-crds@2.19.0 (package applies 6 CRDs first)webhook-readiness → webhook-readiness-observationYour delivery waits for the controller-created or operator-supplied certificate, then checks webhook readiness-

kyverno/kyverno

BaseHook (route)After deploy, who runs it?Per-base change
default@3.8.1hook-delete-policy → delete-cleanup-policyYour cluster - at uninstall, automatically-
default@3.8.1hook-phase → upgrade-action-with-receiptYour delivery - a GitOps PreSync/PostSync or cub action (receipted)-
default@3.8.1hook-test → explicit-test-checkOpt-in check - run from CI or on demand (tests are explicit by design)-
default@3.8.1hook-weight-ordering → preserve-orderingYour applier - must apply CRDs before dependent objects-
default@3.8.1target-facts → target-facts-or-preflightPrerequisite - supply once (Secret / CRD / storage), like values-
no-crds@3.8.1 (needs 22 CRDs)hook-delete-policy → delete-cleanup-policyYour cluster - at uninstall, automatically-
no-crds@3.8.1 (needs 22 CRDs)hook-delete-policy → preserve-cleanup-policyYour cluster - at uninstall, automatically-
no-crds@3.8.1 (needs 22 CRDs)hook-phase → upgrade-action-with-receiptYour delivery - a GitOps PreSync/PostSync or cub action (receipted)-
no-crds@3.8.1 (needs 22 CRDs)hook-test → explicit-test-checkOpt-in check - run from CI or on demand (tests are explicit by design)-
no-crds@3.8.1 (needs 22 CRDs)hook-weight-ordering → preserve-orderingYour applier - must apply CRDs before dependent objectsreduced (CRD-first ordering is not needed in a base that installs no CRDs)
no-crds@3.8.1 (needs 22 CRDs)target-facts → target-facts-or-preflightPrerequisite - supply once (Secret / CRD / storage), like valuesstrengthened (this base needs 22 CRDs supplied before deploy (the default base installs them for you))

prometheus-community/kube-prometheus-stack

BaseHook (route)After deploy, who runs it?Per-base change
default@85.3.3 (package applies 10 CRDs first)crd-install → preflight-or-presync-crd-applyHandled - the generated package script applies the CRDs firstresolved (the package carries and applies the 10 CRDs before the workload (observed live))
default@85.3.3 (package applies 10 CRDs first)hook-delete-policy → preserve-cleanup-policyYour delivery - an explicit, receipted step-
default@85.3.3 (package applies 10 CRDs first)hook-phase → postsync-check-or-observationYour delivery - a post-apply check (receipted)-
default@85.3.3 (package applies 10 CRDs first)hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-
default@85.3.3 (package applies 10 CRDs first)hook-phase → upgrade-action-with-receiptNot tested for this path-
default@85.3.3 (package applies 10 CRDs first)hook-weight-ordering → preserve-orderingYour delivery - an explicit, receipted step-
default@85.3.3 (package applies 10 CRDs first)target-facts → target-facts-or-preflightHandled - the recorded package script creates or checks this prerequisite-
default@85.3.3 (package applies 10 CRDs first)webhook-readiness → webhook-readiness-observationYour delivery - an explicit, receipted step-
no-crds@85.3.3 (package applies 10 CRDs first)crd-install → preflight-or-presync-crd-applyHandled - the generated package script applies the CRDs firstresolved (the package carries and applies the 10 CRDs before the workload (observed live))
no-crds@85.3.3 (package applies 10 CRDs first)hook-delete-policy → preserve-cleanup-policyYour delivery - an explicit, receipted step-
no-crds@85.3.3 (package applies 10 CRDs first)hook-phase → postsync-check-or-observationYour delivery - a post-apply check (receipted)-
no-crds@85.3.3 (package applies 10 CRDs first)hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-
no-crds@85.3.3 (package applies 10 CRDs first)hook-phase → upgrade-action-with-receiptYour delivery - a GitOps PreSync/PostSync or cub action (receipted)-
no-crds@85.3.3 (package applies 10 CRDs first)hook-weight-ordering → preserve-orderingYour delivery - an explicit, receipted step-
no-crds@85.3.3 (package applies 10 CRDs first)target-facts → target-facts-or-preflightHandled - the recorded package script creates or checks this prerequisite-
no-crds@85.3.3 (package applies 10 CRDs first)webhook-readiness → webhook-readiness-observationYour delivery - an explicit, receipted step-
default@86.1.0 (package applies 10 CRDs first)crd-install → preflight-or-presync-crd-applyHandled - the generated package script applies the CRDs firstresolved (the package carries and applies the 10 CRDs before the workload (observed live))
default@86.1.0 (package applies 10 CRDs first)hook-delete-policy → preserve-cleanup-policyYour delivery - an explicit, receipted step-
default@86.1.0 (package applies 10 CRDs first)hook-phase → postsync-check-or-observationYour delivery - a post-apply check (receipted)-
default@86.1.0 (package applies 10 CRDs first)hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-
default@86.1.0 (package applies 10 CRDs first)hook-phase → upgrade-action-with-receiptNot tested for this path-
default@86.1.0 (package applies 10 CRDs first)hook-weight-ordering → preserve-orderingYour delivery - an explicit, receipted step-
default@86.1.0 (package applies 10 CRDs first)target-facts → target-facts-or-preflightHandled - the recorded package script creates or checks this prerequisite-
default@86.1.0 (package applies 10 CRDs first)webhook-readiness → webhook-readiness-observationYour delivery - an explicit, receipted step-
no-crds@86.1.0 (package applies 10 CRDs first)crd-install → preflight-or-presync-crd-applyHandled - the generated package script applies the CRDs firstresolved (the package carries and applies the 10 CRDs before the workload (observed live))
no-crds@86.1.0 (package applies 10 CRDs first)hook-delete-policy → preserve-cleanup-policyYour delivery - an explicit, receipted step-
no-crds@86.1.0 (package applies 10 CRDs first)hook-phase → postsync-check-or-observationYour delivery - a post-apply check (receipted)-
no-crds@86.1.0 (package applies 10 CRDs first)hook-phase → preflight-or-presyncYour delivery - a preflight step before apply (receipted)-
no-crds@86.1.0 (package applies 10 CRDs first)hook-phase → upgrade-action-with-receiptYour delivery - a GitOps PreSync/PostSync or cub action (receipted)-
no-crds@86.1.0 (package applies 10 CRDs first)hook-weight-ordering → preserve-orderingYour delivery - an explicit, receipted step-
no-crds@86.1.0 (package applies 10 CRDs first)target-facts → target-facts-or-preflightHandled - the recorded package script creates or checks this prerequisite-
no-crds@86.1.0 (package applies 10 CRDs first)webhook-readiness → webhook-readiness-observationYour delivery - an explicit, receipted step-

Charts without a per-variant delta yet

These charts have hook routes but no built variant set that changes the hook behavior (single base, or candidate/blocked with no built variants). Routes are chart-level.