Local Live Non-Pass Triage

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated report explains the local Kubernetes rows that did not pass. It starts from base-outcomes.csv and the committed observation receipts. The purpose is to make the next action clear without turning every non-pass row into a product defect.

Snapshot

chart/base rows:          199
local live observed rows: 199
local live pass rows:     148
local live non-pass rows: 51
classified non-pass rows: 50
needs manual inspection:  1

Route Classes

Route classRowsMeaningNext action
runtime-readiness22The objects applied, but a controller or workload did not become healthy in the observation budget.Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
target-prerequisite10The workload reached Kubernetes but one or more pods were waiting for target-provided config, mounts, certificates, or setup.Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
image-dependency6The target could not pull at least one rendered image, so the row is testing image availability rather than ConfigHub parity.Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
webhook-cert-lifecycle4A webhook or admission controller needs certificate material or a cert-generation lifecycle step before the workload can become ready.Model the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
admission-or-rbac3Kubernetes rejected an object because of permissions, admission, immutability, or API validation.Decide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.
api-version-unsupported2The rendered objects use a Kubernetes API version that the tested target no longer serves.Use a supported chart version, compatibility base, or target Kubernetes profile before rerun.
cloud-or-provider-prerequisite2The chart expects provider credentials, cloud APIs, buckets, DNS, volumes, or another external system.Model the provider dependency as target facts or an external managed prerequisite before rerun.
inspect-receipt1The receipt has useful failure evidence, but the automatic classifier does not yet have a precise route.Read the receipt and add a classifier rule only after the product route is clear.
lifecycle-ordering1The rendered objects are valid, but the target needs a staged lifecycle sequence instead of one bulk apply.Use the lifecycle route for this chart, then observe the staged apply or cleanup sequence with a receipt.

First Rows To Inspect

ChartBaseResultRoute classNext actionReceipt
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultfailadmission-or-rbacDecide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.receipt
velero/velero@12.0.1defaultblockedadmission-or-rbacDecide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.receipt
velero/velero@12.0.1no-crdsblockedadmission-or-rbacDecide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.receipt
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedapi-version-unsupportedUse a supported chart version, compatibility base, or target Kubernetes profile before rerun.receipt
prometheus-community/prometheus-adapter@5.3.0defaultblockedapi-version-unsupportedUse a supported chart version, compatibility base, or target Kubernetes profile before rerun.receipt
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultfailcloud-or-provider-prerequisiteModel the provider dependency as target facts or an external managed prerequisite before rerun.receipt
grafana/tempo@1.24.4s3-query-observabilityblockedcloud-or-provider-prerequisiteModel the provider dependency as target facts or an external managed prerequisite before rerun.receipt
bitnami/spark@10.0.3defaultblockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
bitnami/spark@10.0.3hablockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
bitnami/zookeeper@13.8.7defaultblockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
bitnami/zookeeper@13.8.7hablockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
istio/gateway@1.30.0controller-default-reviewedblockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
istio/gateway@1.30.0defaultblockedimage-dependencyPin, mirror, override, or document the image dependency, then rerun against a target that can pull it.receipt
open-telemetry/opentelemetry-operator@0.114.0defaultblockedinspect-receiptRead the receipt and add a classifier rule only after the product route is clear.receipt
projectcalico/tigera-operator@v3.32.0defaultblockedlifecycle-orderingUse the lifecycle route for this chart, then observe the staged apply or cleanup sequence with a receipt.receipt
argo-cd/argo-workflows@1.0.14controller-default-reviewedblockedruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
argo-cd/argo-workflows@1.0.14defaultblockedruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
bitnami/contour@21.1.4no-crdsblockedruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
bitnami/elasticsearch@22.1.6defaultfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
bitnami/elasticsearch@22.1.6hafailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
bitnami/opensearch@2.0.10defaultfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
bitnami/opensearch@2.0.10hafailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
cloudnative-pg/cloudnative-pg@0.28.2no-crdsfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
dex/dex@0.24.0defaultfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
elastic/logstash@8.5.1hafailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
gitlab/gitlab-runner@0.89.0defaultfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
grafana/pyroscope@2.0.2hafailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
grafana/rollout-operator@0.49.0no-crdsfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
hashicorp/terraform@1.1.2no-crdsblockedruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt
istio/istiod@1.30.0defaultfailruntime-readinessInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.receipt

How To Use This

These rows are live evidence, not shame stickers. A non-pass row can be a useful result: it may prove that a base needs a target fact, a CRD policy, an image mirror, a larger target profile, a provider prerequisite, or a clean rerun. The route class tells the next useful action before making stronger support claims.

Machine-readable files:

data/local-live-triage/triage.csv
data/local-live-triage/classes.csv

Regenerate and verify:

npm run local-live:triage
npm run local-live:triage:verify