Matrix Completion Audit

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

UNOFFICIAL/EXPERIMENTAL. Generated by scripts/generate-matrix-completion-audit.mjs. Do not hand-edit. Regenerate with npm run matrix-completion-audit.

One row per non-green / not-yet-run cell of the master catalog matrix. For each cell it records the lane, the state, a product-readable reason, the next action, the support artifact, and a completion class that separates needs a run from needs a model/support fix from already has a named product decision - so the matrix can be finished in the right order.

It is a read-only projection over the committed decision/queue surfaces (disposition-frontier, the live/kind decisions, the burn-down, run-blocks, base-outcomes, lifecycle-route-actions, and the matrix's own promotion/lifecycle columns). It changes no status and runs nothing.

Completion classes

657 non-green cells:

ClassCellsMeaning
needs-target-or-prereq-fix429Blocked on a target prerequisite, image, or tooling - a user/target action, not a model change.
already-decided136A watch row with a recorded product decision: evidence plus a named residue. Usable today with the caveat.
needs-run47A command exists - just run it (the burn-down / run-block surfaces have the exact command).
needs-modeling45The catalog/model has to change before this can pass.
LaneCells
promotion389
G60
P60
L51
K50
lifecycle47
StateCells
proven167
watch136
not-applicable-source110
blocked99
not-applicable-candidate67
todo47
fail18
not-applicable-derived-variant13

needs-run (47)

A command exists - just run it (the burn-down / run-block surfaces have the exact command).

ChartVariantLaneStateReasonNext action
argo-cd/argo-workflows@1.0.14controller-default-reviewedlifecycletodolifecycle route(s) defined (todo:1) but not yet observed liveobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
argo-cd/argo-workflows@1.0.14defaultlifecycletodolifecycle route(s) defined (todo:1) but not yet observed liveobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
argo-cd/argocd-image-updater@1.2.2defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
bitnami/contour@21.1.4defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
bitnami/contour@21.1.4no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
cloudnative-pg/cloudnative-pg@0.28.2defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
cloudnative-pg/cloudnative-pg@0.28.2no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
elastic/eck-operator@3.4.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
elastic/eck-operator@3.4.0halifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
elastic/eck-operator@3.4.0no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
external-dns/external-dns@1.21.1defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
external-dns/external-dns@1.21.1dry-run-txt-registrylifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
external-dns/external-dns@1.21.1no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
fairwinds-stable/goldilocks@10.3.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
gatekeeper/gatekeeper@3.22.2no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
grafana/alloy@1.8.2defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/alloy@1.8.2no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/loki@7.0.0simple-scalable-miniolifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/loki@7.0.0single-binary-filesystemlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/pyroscope@2.0.2defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/pyroscope@2.0.2halifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
grafana/pyroscope@2.0.2no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/consul@2.0.0default-control-planelifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/consul@2.0.0secure-mesh-existing-secretslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/terraform@1.1.2defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/terraform@1.1.2no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/vault@0.32.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/vault@0.32.0dev-modelifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
hashicorp/vault@0.32.0ha-raft-uilifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
ingress-nginx/ingress-nginx@4.15.1admission-disabledlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
ingress-nginx/ingress-nginx@4.15.1internal-clusteriplifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
jaegertracing/jaeger-operator@2.57.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
jaegertracing/jaeger-operator@2.57.0no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
kedacore/keda@2.19.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
kyverno/kyverno@3.8.1no-crdslifecycletodolifecycle route(s) defined (observed:6) but not yet observed liveobserve the routed lifecycle action and record a receipt (see lifecycle-route-actions)
minio-operator/operator@7.1.1defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
percona/pxc-operator@1.19.1defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
percona/pxc-operator@1.19.1no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
prometheus-community/prometheus-adapter@5.3.0apiservice-v1-capabilitylifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlylifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
prometheus-community/prometheus-adapter@5.3.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
prometheus-community/prometheus-operator-crds@29.0.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
rook-release/rook-ceph@v1.19.5defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
strimzi/strimzi-kafka-operator@1.0.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
strimzi/strimzi-kafka-operator@1.0.0no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
traefik/traefik@40.2.0defaultlifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live
traefik/traefik@40.2.0no-crdslifecycletodochart has hook/lifecycle behavior with no live observation yetdecide and record the lifecycle route, then observe it live

needs-target-or-prereq-fix (429)

Blocked on a target prerequisite, image, or tooling - a user/target action, not a model change.

ChartVariantLaneStateReasonNext action
aqua/trivy-operator@0.32.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
aqua/trivy-operator@0.32.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
aqua/trivy-operator@0.32.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-cd@9.5.15(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argo-cd@9.5.15no-crdsLblockedlocal-live blocked: webhook-cert-lifecycle: deployment/argo-cd-argocd-applicationset-controller: prerequisite-blocked (stuck creating: missing mount/secret/config) (argo-cd-argocd-application-controller-0[CreateContainerConfigError ready=false restarts=0;] argo-cd-argocd-applicationset-controller-d7b845Model the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
argo-cd/argo-cd@9.5.15no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-cd@9.5.17(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argo-cd@9.5.17defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-cd@9.5.17no-crdspromotionblockedpromotion depends on upstream and downstream ConfigHub Spaces; the ConfigHub proof lane is missingrun the ConfigHub proof lane first
argo-cd/argo-events@2.4.21(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argo-events@2.4.21defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-events@2.4.21no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-rollouts@2.40.9(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argo-rollouts@2.40.9defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-rollouts@2.40.9no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-workflows@1.0.14(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argo-workflows@1.0.14controller-default-reviewedLblockedlocal-live blocked: runtime-readiness: target fact: required CRD clusterworkflowtemplates.argoproj.io missingInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
argo-cd/argo-workflows@1.0.14controller-default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-workflows@1.0.14defaultLblockedlocal-live blocked: runtime-readiness: target fact: required CRD clusterworkflowtemplates.argoproj.io missingInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
argo-cd/argo-workflows@1.0.14defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argo-workflows@1.0.14minimal-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
argo-cd/argocd-image-updater@1.2.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
argo-cd/argocd-image-updater@1.2.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
autoscaler/cluster-autoscaler@9.57.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
autoscaler/cluster-autoscaler@9.57.0controller-default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
autoscaler/cluster-autoscaler@9.57.0default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
autoscaler/cluster-autoscaler@9.57.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
autoscaler/vertical-pod-autoscaler@0.9.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
autoscaler/vertical-pod-autoscaler@0.9.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
autoscaler/vertical-pod-autoscaler@0.9.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1default + topologypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultLfaillocal-live fail: cloud-or-provider-prerequisite: daemonset/ebs-csi-node: not-ready (ebs-csi-controller-8d8878fb7-24jf4[ ready=true restarts=3;Error ready=false restarts=3; ready=true restarts=3;CrashLoopBackOff ready=false restarts=4; ready=tru)Model the provider dependency as target facts or an external managed prerequisite before rerun.
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/apache@11.4.29(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/apache@11.4.29defaultLblockedlocal-live blocked: target-prerequisite: deployment/apache: prerequisite-blocked (stuck creating: missing mount/secret/config) (apache-5fdf47cb6-f4p8z[PodInitializing ready=false restarts=0;] node-collector-66b46f8d9-qnkc6[Completed ready=false restarts=0;] scan-vulnerabilityreport-56d95)Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
bitnami/apache@11.4.29defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/apache@11.4.29legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/contour@21.1.4(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/contour@21.1.4defaultLblockedlocal-live blocked: target-prerequisite: daemonset/contour-envoy: prerequisite-blocked (stuck creating: missing mount/secret/config) (contour-contour-6f88fd5fc6-67kb6[ContainerCreating ready=false restarts=0;] contour-envoy-jtk4r[PodInitializing ready=false restarts=0;PodInitializing ready=fal)Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
bitnami/contour@21.1.4defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/contour@21.1.4legacy + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
bitnami/contour@21.1.4legacyLblockedlocal-live blocked: target-prerequisite: daemonset/contour-envoy: prerequisite-blocked (stuck creating: missing mount/secret/config) (contour-contour-9c9cb9d47-rxs4w[ContainerCreating ready=false restarts=0;] contour-envoy-9sfdn[PodInitializing ready=false restarts=0;PodInitializing ready=fals)Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
bitnami/contour@21.1.4legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/contour@21.1.4no-crdsLblockedlocal-live blocked: runtime-readiness: daemonset/contour-envoy: prerequisite-blocked (stuck creating: missing mount/secret/config) (contour-contour-6f88fd5fc6-2bhll[ContainerCreating ready=false restarts=0;] contour-envoy-tgr65[PodInitializing ready=false restarts=0;PodInitializing ready=fal)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
bitnami/contour@21.1.4no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/elasticsearch@22.1.6(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/elasticsearch@22.1.6defaultLfaillocal-live fail: runtime-readiness: statefulset/elasticsearch-coordinating: not-ready (elasticsearch-coordinating-0[PodInitializing ready=false restarts=0;] elasticsearch-coordinating-1[PodInitializing ready=false restarts=0;] elasticsearch-data-0)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
bitnami/elasticsearch@22.1.6defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/elasticsearch@22.1.6haLfaillocal-live fail: runtime-readiness: statefulset/elasticsearch-coordinating: not-ready (elasticsearch-coordinating-0[PodInitializing ready=false restarts=0;] elasticsearch-coordinating-1[PodInitializing ready=false restarts=0;] elasticsearch-data-0)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
bitnami/elasticsearch@22.1.6hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/elasticsearch@22.1.6legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/memcached@8.5.5(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/memcached@8.5.5defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/memcached@8.5.5storage-default-reviewedpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
bitnami/mongodb@19.0.7(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/mongodb@19.0.7existing-secret-replicasetpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/mongodb@19.0.9(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/mongodb@19.0.9static-passwordspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/mongodb@19.1.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/mysql@14.0.3(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/mysql@14.0.3existing-secretpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/nginx@24.0.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/nginx@24.0.2customer-acme-prodpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
bitnami/nginx@24.0.2existing-tls-ingresspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/nginx@24.0.2http-clusterippromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/nginx@24.0.2prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
bitnami/nginx@24.0.4(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/nginx@25.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/opensearch@2.0.10(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/opensearch@2.0.10defaultLfaillocal-live fail: runtime-readiness: statefulset/opensearch-coordinating: not-ready (opensearch-coordinating-0[PodInitializing ready=false restarts=0;] opensearch-coordinating-1[PodInitializing ready=false restarts=0;] opensearch-data-0[PodIniti)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
bitnami/opensearch@2.0.10defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/opensearch@2.0.10haLfaillocal-live fail: runtime-readiness: statefulset/opensearch-coordinating: not-ready (opensearch-coordinating-0[PodInitializing ready=false restarts=0;] opensearch-coordinating-1[PodInitializing ready=false restarts=0;] opensearch-data-0[PodIniti)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
bitnami/opensearch@2.0.10hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/opensearch@2.0.10legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/phpmyadmin@20.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/phpmyadmin@20.0.0defaultLblockedlocal-live blocked: target-prerequisite: deployment/phpmyadmin: prerequisite-blocked (stuck creating: missing mount/secret/config) (node-collector-66b46f8d9-qnkc6[Completed ready=false restarts=0;] phpmyadmin-f67d9cfd6-8hv8z[PodInitializing ready=false restarts=0;] scan-vulnerabilityreport-5)Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
bitnami/phpmyadmin@20.0.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/phpmyadmin@20.0.0legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/phpmyadmin@20.0.0web-ui-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
bitnami/postgresql@18.6.10(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/postgresql@18.6.10static-passwordspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/postgresql@18.6.7(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/postgresql@18.6.7existing-secretpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/postgresql@18.7.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/rabbitmq@16.0.14(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/rabbitmq@16.0.14existing-secretpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/redis@25.5.3(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/redis@25.5.3defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/redis@25.5.3prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
bitnami/redis@25.5.3reuse-existing-secretpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/redis@25.5.3staging-eu-westpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
bitnami/redis@27.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/spark@10.0.3(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/spark@10.0.3defaultLblockedlocal-live blocked: image-dependency: statefulset/spark-master: image-pull-blocked (spark-master-0[ImagePullBackOff ready=false restarts=0;] spark-worker-0[ImagePullBackOff ready=false restarts=0;])Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
bitnami/spark@10.0.3defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/spark@10.0.3haLblockedlocal-live blocked: image-dependency: statefulset/spark-master: image-pull-blocked (rollout-operator-5f688cdb68-pc7sz[ ready=false restarts=0;] spark-master-0[ImagePullBackOff ready=false restarts=0;] spark-worker-0[ImagePullBackOff ready=false)Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
bitnami/spark@10.0.3hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/spark@10.0.3legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/zookeeper@13.8.7(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
bitnami/zookeeper@13.8.7defaultLblockedlocal-live blocked: image-dependency: statefulset/zookeeper: image-pull-blocked (zookeeper-0[ImagePullBackOff ready=false restarts=0;])Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
bitnami/zookeeper@13.8.7defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/zookeeper@13.8.7haLblockedlocal-live blocked: image-dependency: statefulset/zookeeper: image-pull-blocked (zookeeper-0[ImagePullBackOff ready=false restarts=0;] zookeeper-1[ImagePullBackOff ready=false restarts=0;] zookeeper-2[ImagePullBackOff ready=false restarts=0;)Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
bitnami/zookeeper@13.8.7hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
bitnami/zookeeper@13.8.7legacypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
cloudnative-pg/cloudnative-pg@0.28.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
cloudnative-pg/cloudnative-pg@0.28.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
cloudnative-pg/cloudnative-pg@0.28.2no-crdsLfaillocal-live fail: runtime-readiness: deployment/cloudnative-pg: not-ready (cloudnative-pg-d8f4779dd-wjsfg[CrashLoopBackOff ready=false restarts=5;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
cloudnative-pg/cloudnative-pg@0.28.2no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
coredns/coredns@1.45.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
coredns/coredns@1.45.2controller-default-reviewedpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
coredns/coredns@1.45.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
crossplane-stable/crossplane@2.3.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
crossplane-stable/crossplane@2.3.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
descheduler/descheduler@0.36.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
descheduler/descheduler@0.36.0cluster-metrics-readonlypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
descheduler/descheduler@0.36.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
dex/dex@0.24.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
dex/dex@0.24.0default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
dex/dex@0.24.0defaultKblockedtarget-runtime: pod crash loop (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
dex/dex@0.24.0defaultLfaillocal-live fail: runtime-readiness: deployment/dex: not-ready (dex-854b786b7-w67bg[CrashLoopBackOff ready=false restarts=4;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
dex/dex@0.24.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
dex/dex@0.24.0web-ui-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/eck-operator@3.4.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
elastic/eck-operator@3.4.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/eck-operator@3.4.0hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/eck-operator@3.4.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/filebeat@8.5.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
elastic/filebeat@8.5.1default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/filebeat@8.5.1default + secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/filebeat@8.5.1defaultKblockedtarget-prerequisite: required Secret missing (parity passed)Stage the named Secret as a target fact, then the row can move to pass.
elastic/filebeat@8.5.1defaultLblockedlocal-live blocked: target-prerequisite: daemonset/filebeat-filebeat: prerequisite-blocked (stuck creating: missing mount/secret/config) (filebeat-filebeat-z6hc6[ContainerCreating ready=false restarts=0;])Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
elastic/filebeat@8.5.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/filebeat@8.5.1node-or-cluster-collector + external-apipromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/filebeat@8.5.1node-or-cluster-collector + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/filebeat@8.5.1node-or-cluster-collectorKblockedhelm-runtime: upstream not ready (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
elastic/filebeat@8.5.1node-or-cluster-collectorLblockedlocal-live blocked: target-prerequisite: daemonset/filebeat-filebeat: prerequisite-blocked (stuck creating: missing mount/secret/config) (filebeat-filebeat-s9zzq[ContainerCreating ready=false restarts=0;])Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
elastic/filebeat@8.5.1node-or-cluster-collectorpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/kibana@8.5.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
elastic/kibana@8.5.1default + external-apipromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/kibana@8.5.1default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/kibana@8.5.1defaultKblockedhelm-runtime: upstream not ready (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
elastic/kibana@8.5.1defaultLblockedlocal-live blocked: target-prerequisite: deployment/kibana-kibana: prerequisite-blocked (stuck creating: missing mount/secret/config) (kibana-kibana-9bf64bc55-8fpng[ContainerCreating ready=false restarts=0;])Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
elastic/kibana@8.5.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/kibana@8.5.1web-ui-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/logstash@8.5.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
elastic/logstash@8.5.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/logstash@8.5.1haLfaillocal-live fail: runtime-readiness: statefulset/logstash-logstash: not-ready (logstash-logstash-0[ ready=true restarts=0;] logstash-logstash-1[] logstash-logstash-2[])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
elastic/logstash@8.5.1hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
elastic/metricbeat@8.5.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
elastic/metricbeat@8.5.1default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/metricbeat@8.5.1default + secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
elastic/metricbeat@8.5.1defaultKblockedtarget-prerequisite: required Secret missing (parity passed)Stage the named Secret as a target fact, then the row can move to pass.
elastic/metricbeat@8.5.1defaultLblockedlocal-live blocked: target-prerequisite: daemonset/metricbeat-metricbeat: prerequisite-blocked (stuck creating: missing mount/secret/config) (metricbeat-kube-state-metrics-658dd9bbbc-ngcqr[ ready=true restarts=0;] metricbeat-metricbeat-68rfr[ContainerCreating ready=false restarts=0;] metricbeat-metriTurn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
elastic/metricbeat@8.5.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
external-dns/external-dns@1.21.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
external-dns/external-dns@1.21.1cloudflare-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
external-dns/external-dns@1.21.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
external-dns/external-dns@1.21.1dry-run-txt-registrypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
external-dns/external-dns@1.21.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
external-dns/external-dns@1.21.1route53-irsapromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
external-secrets/external-secrets@2.5.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
external-secrets/external-secrets@2.5.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fairwinds-stable/goldilocks@10.3.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
fairwinds-stable/goldilocks@10.3.0cluster-metrics-readonlypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
fairwinds-stable/goldilocks@10.3.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fairwinds-stable/vpa@4.11.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
fairwinds-stable/vpa@4.11.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fairwinds-stable/vpa@4.11.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
falcosecurity/falco@9.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
falcosecurity/falco@9.0.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
falcosecurity/falco@9.0.0node-or-cluster-collectorpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
falcosecurity/falcosidekick@0.13.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
falcosecurity/falcosidekick@0.13.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fluent/fluent-bit@0.57.6(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
fluent/fluent-bit@0.57.6defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fluent/fluent-bit@0.57.6node-or-cluster-collectorpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
fluent/fluentd@0.5.3(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
fluent/fluentd@0.5.3default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
fluent/fluentd@0.5.3defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
fluent/fluentd@0.5.3node-or-cluster-collectorpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
gatekeeper/gatekeeper@3.22.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
gatekeeper/gatekeeper@3.22.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
gatekeeper/gatekeeper@3.22.2no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
gitlab/gitlab-runner@0.89.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
gitlab/gitlab-runner@0.89.0default + external-apipromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
gitlab/gitlab-runner@0.89.0default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
gitlab/gitlab-runner@0.89.0defaultLfaillocal-live fail: runtime-readiness: deployment/gitlab-runner: not-ready (gitlab-runner-844d54c8cc-x6rtt[ ready=false restarts=1;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
gitlab/gitlab-runner@0.89.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
gitlab/gitlab-runner@0.89.0runner-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
grafana/alloy@1.8.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/alloy@1.8.2defaultpromotionblockedserver-side promotion did not prove changed-unit catch-up and added-unit cloninginspect the promotion receipt and resolve the recorded blocker
grafana/alloy@1.8.2no-crdspromotionblockedserver-side promotion did not prove changed-unit catch-up and added-unit cloninginspect the promotion receipt and resolve the recorded blocker
grafana/grafana@10.5.15(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/grafana@10.5.15customer-acme-prodpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
grafana/grafana@10.5.15existing-secret-ingresspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/grafana@10.5.15prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
grafana/loki@7.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/loki@7.0.0simple-scalable-miniopromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/promtail@6.17.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/promtail@6.17.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/pyroscope@2.0.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/pyroscope@2.0.2default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
grafana/pyroscope@2.0.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/pyroscope@2.0.2ha + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
grafana/pyroscope@2.0.2haLfaillocal-live fail: runtime-readiness: statefulset/pyroscope: not-ready (pyroscope-0[ ready=false restarts=1;] pyroscope-1[ ready=false restarts=1;] pyroscope-alloy-0[ ready=true restarts=0; ready=true restarts=0;] surveyor-c4759d87-)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
grafana/pyroscope@2.0.2hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/pyroscope@2.0.2no-crds + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
grafana/pyroscope@2.0.2no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/rollout-operator@0.49.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/rollout-operator@0.49.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/rollout-operator@0.49.0no-crdsLfaillocal-live fail: runtime-readiness: deployment/rollout-operator: not-ready (rollout-operator-5f688cdb68-psdjv[ ready=false restarts=0;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
grafana/rollout-operator@0.49.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
grafana/tempo@1.24.4(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
grafana/tempo@1.24.4s3-query-observabilityLblockedlocal-live blocked: cloud-or-provider-prerequisite: statefulset/tempo: prerequisite-blocked (stuck creating: missing mount/secret/config) (tempo-0[CreateContainerConfigError ready=false restarts=0; ready=true restarts=0;])Model the provider dependency as target facts or an external managed prerequisite before rerun.
grafana/tempo@1.24.4s3-query-observabilitypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
haproxytech/kubernetes-ingress@1.52.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
haproxytech/kubernetes-ingress@1.52.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/consul@2.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
hashicorp/consul@2.0.0secure-mesh-existing-secretsLfaillocal-live fail: webhook-cert-lifecycle: deployment/consul-consul-connect-injector: not-ready (consul-consul-connect-injector-5f47dfbd9-knxmc[CrashLoopBackOff ready=false restarts=6;] consul-consul-ingress-gateway-7c9f6b86f8-v484m[PodInitializing ready=fa)Model the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
hashicorp/consul@2.0.0secure-mesh-existing-secretspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/terraform@1.1.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
hashicorp/terraform@1.1.2default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
hashicorp/terraform@1.1.2defaultLblockedlocal-live blocked: target-prerequisite: deployment/terraform-terraform-sync-workspace: prerequisite-blocked (stuck creating: missing mount/secret/config) (terraform-terraform-sync-workspace-67688dd4fd-tk52q[ContainerCreating ready=false restarts=0;])Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
hashicorp/terraform@1.1.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/terraform@1.1.2no-crds + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
hashicorp/terraform@1.1.2no-crds + secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
hashicorp/terraform@1.1.2no-crdsKblockedtarget-prerequisite: required Secret missing (parity passed)Stage the named Secret as a target fact, then the row can move to pass.
hashicorp/terraform@1.1.2no-crdsLblockedlocal-live blocked: runtime-readiness: deployment/terraform-terraform-sync-workspace: prerequisite-blocked (stuck creating: missing mount/secret/config) (kibana-kibana-9bf64bc55-qm87r[ContainerCreating ready=false restarts=0;] rollout-operator-5f688cdb68-pc7sz[ ready=false restarts=0;] surveyor-c47Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
hashicorp/terraform@1.1.2no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/vault@0.32.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
hashicorp/vault@0.32.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/vault@0.32.0ha-raft-ui + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
hashicorp/vault@0.32.0ha-raft-uiLblockedlocal-live blocked: target-prerequisite: statefulset/vault: prerequisite-blocked (stuck creating: missing mount/secret/config) (vault-0[ContainerCreating ready=false restarts=0;] vault-1[] vault-2[] vault-agent-injector-8c76487db-r7vcn[ ready=true restarts=0;])Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
hashicorp/vault@0.32.0ha-raft-uipromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
hashicorp/vault@0.32.0regulated-prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
hashicorp/vault@0.32.0staging-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
ingress-nginx/ingress-nginx@4.15.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
ingress-nginx/ingress-nginx@4.15.1admission-disabledpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
ingress-nginx/ingress-nginx@4.15.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
istio/gateway@1.30.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
istio/gateway@1.30.0controller-default-reviewedLblockedlocal-live blocked: image-dependency: deployment/gateway: image-pull-blocked (gateway-7c598dffd4-w4m4g[ImagePullBackOff ready=false restarts=0;] kibana-kibana-9bf64bc55-qm87r[ContainerCreating ready=false restarts=0;] rollout-operator-5f6)Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
istio/gateway@1.30.0controller-default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
istio/gateway@1.30.0defaultLblockedlocal-live blocked: image-dependency: deployment/gateway: image-pull-blocked (gateway-7c598dffd4-jlxxc[ImagePullBackOff ready=false restarts=0;])Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
istio/gateway@1.30.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
istio/istiod@1.30.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
istio/istiod@1.30.0default + namespacepromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
istio/istiod@1.30.0defaultGblockedtarget-prerequisite: namespace missing (parity passed)Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
istio/istiod@1.30.0defaultKblockedtarget-prerequisite: required Namespace missing (parity passed)Declare and stage the required Namespace as a target fact, then the row can move to pass.
istio/istiod@1.30.0defaultLfaillocal-live fail: runtime-readiness: deployment/istiod: not-ready ()Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
istio/istiod@1.30.0defaultPblockedtarget-prerequisite: namespace missing (parity passed)Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
istio/istiod@1.30.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
istio/istiod@1.30.0external-capromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
istio/istiod@1.30.0minimal-profilepromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
istio/istiod@1.30.0revisioned-control-planepromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
jaegertracing/jaeger-operator@2.57.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
jaegertracing/jaeger-operator@2.57.0default + crdpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
jaegertracing/jaeger-operator@2.57.0defaultGblockedtarget-prerequisite: cert-manager CRDs missingStage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
jaegertracing/jaeger-operator@2.57.0defaultKblockedtarget-prerequisite: cert-manager CRDs missingStage the chart's CRDs as target facts (or pick a CRD-rendering base), then the row can move to pass.
jaegertracing/jaeger-operator@2.57.0defaultPblockedtarget-prerequisite: cert-manager CRDs missingStage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
jaegertracing/jaeger-operator@2.57.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jaegertracing/jaeger-operator@2.57.0no-crds + crdpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
jaegertracing/jaeger-operator@2.57.0no-crdsKblockedtarget-prerequisite: cert-manager CRDs missingStage the chart's CRDs as target facts (or pick a CRD-rendering base), then the row can move to pass.
jaegertracing/jaeger-operator@2.57.0no-crdsLblockedlocal-live blocked: webhook-cert-lifecycle: deployment/jaeger-operator: prerequisite-blocked (stuck creating: missing mount/secret/config) (jaeger-operator-b44465548-7jfbn[ContainerCreating ready=false restarts=0;] node-collector-df9b9bcd9-nnjs4[Completed ready=false restarts=0;] scan-vulnerabilityr)Model the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
jaegertracing/jaeger-operator@2.57.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jaegertracing/jaeger@4.8.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
jaegertracing/jaeger@4.8.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jaegertracing/jaeger@4.8.0node-or-cluster-collectorpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
jetstack/cert-manager-csi-driver@v0.14.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
jetstack/cert-manager-csi-driver@v0.14.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jetstack/cert-manager@v1.20.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
jetstack/cert-manager@v1.20.2defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jetstack/trust-manager@v0.22.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
jetstack/trust-manager@v0.22.1defaultLfaillocal-live fail: runtime-readiness: deployment/trust-manager: not-ready (node-collector-df9b9bcd9-nnjs4[Completed ready=false restarts=0;] scan-vulnerabilityreport-578fc5b667-79lfn[Completed ready=false restarts=0;] scan-vulnerabilit)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
jetstack/trust-manager@v0.22.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
jetstack/trust-manager@v0.22.1no-crdsLfaillocal-live fail: runtime-readiness: deployment/trust-manager: not-ready (trust-manager-6db9f66446-c44df[PodInitializing ready=false restarts=0;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
jetstack/trust-manager@v0.22.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
kedacore/keda@2.19.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
kedacore/keda@2.19.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
kedacore/keda@2.19.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
kyverno/kyverno-policies@3.8.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
kyverno/kyverno-policies@3.8.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
kyverno/kyverno@3.8.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
kyverno/kyverno@3.8.1default-admissionpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
kyverno/kyverno@3.8.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
kyverno/kyverno@3.8.1external-crdspromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
kyverno/kyverno@3.8.1ha-admission-reportspromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
kyverno/kyverno@3.8.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
linkerd/linkerd-crds@1.8.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
linkerd/linkerd-crds@1.8.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
longhorn/longhorn@1.11.2(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
longhorn/longhorn@1.11.2ui-ingresspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
metrics-server/metrics-server@3.13.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
metrics-server/metrics-server@3.13.0external-tls-capromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
metrics-server/metrics-server@3.13.0prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
minio-operator/operator@7.1.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
minio-operator/operator@7.1.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
minio-operator/operator@7.1.1storage-default-reviewedpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
minio-operator/tenant@7.1.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
minio-operator/tenant@7.1.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/nack@0.34.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
nats/nack@0.34.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/nack@0.34.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/nats@2.14.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
nats/nats@2.14.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/nats@2.14.0hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/surveyor@0.20.9(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
nats/surveyor@0.20.9default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
nats/surveyor@0.20.9default-reviewed + external-apipromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
nats/surveyor@0.20.9default-reviewed + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
nats/surveyor@0.20.9default-reviewedKblockedhelm-runtime: upstream not ready (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
nats/surveyor@0.20.9default-reviewedLblockedlocal-live blocked: runtime-readiness: deployment/surveyor: prerequisite-blocked (stuck creating: missing mount/secret/config) (kibana-kibana-9bf64bc55-qm87r[ContainerCreating ready=false restarts=0;] nats-0[ ready=true restarts=0; ready=true restarts=0;] nats-1[ ready=true restarts=0; r)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
nats/surveyor@0.20.9default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nats/surveyor@0.20.9defaultKblockedtarget-runtime: pod crash loop (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
nats/surveyor@0.20.9defaultLfaillocal-live fail: runtime-readiness: deployment/surveyor: not-ready (surveyor-c4759d87-fx675[CrashLoopBackOff ready=false restarts=5;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
nats/surveyor@0.20.9defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18storage-default-reviewedpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
open-telemetry/opentelemetry-operator@0.114.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
open-telemetry/opentelemetry-operator@0.114.0defaultLblockedlocal-live blocked: inspect-receipt: target fact CRDs: source variant jetstack/cert-manager@v1.20.2/crds-enabled render missingRead the receipt and add a classifier rule only after the product route is clear.
open-telemetry/opentelemetry-operator@0.114.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
open-telemetry/opentelemetry-operator@0.114.0no-crdsLblockedlocal-live blocked: webhook-cert-lifecycle: deployment/opentelemetry-operator: prerequisite-blocked (stuck creating: missing mount/secret/config) (node-collector-df9b9bcd9-nnjs4[Completed ready=false restarts=0;] opentelemetry-operator-7b79f764b-kfcxt[ContainerCreating ready=false restarts=0;] scan-vulnModel the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
open-telemetry/opentelemetry-operator@0.114.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
opencost/opencost@2.5.21(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
opencost/opencost@2.5.21cluster-metrics-readonlypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
opencost/opencost@2.5.21default + reviewpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
opencost/opencost@2.5.21defaultKblockedtarget-runtime: pod crash loop (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
opencost/opencost@2.5.21defaultLfaillocal-live fail: runtime-readiness: deployment/opencost: not-ready (opencost-6545848947-wcs2m[CrashLoopBackOff ready=false restarts=4; ready=true restarts=0;])Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
opencost/opencost@2.5.21defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/pg-operator@3.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
percona/pg-operator@3.0.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/pg-operator@3.0.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/psmdb-operator@1.22.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
percona/psmdb-operator@1.22.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/psmdb-operator@1.22.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/pxc-operator@1.19.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
percona/pxc-operator@1.19.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
percona/pxc-operator@1.19.1no-crdsLblockedlocal-live blocked: runtime-readiness: deployment/pxc-operator: prerequisite-blocked (stuck creating: missing mount/secret/config) (kibana-kibana-9bf64bc55-qm87r[ContainerCreating ready=false restarts=0;] pxc-operator-5f59645bd-ctt85[CrashLoopBackOff ready=false restarts=4;] rollout-operator)Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
percona/pxc-operator@1.19.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
projectcalico/tigera-operator@v3.32.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
projectcalico/tigera-operator@v3.32.0controller-default-reviewedpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
projectcalico/tigera-operator@v3.32.0defaultLblockedlocal-live blocked: lifecycle-ordering: apply: resource mapping not found for name: "default" namespace: "" from "STDIN": no matches for kind "APIServer" in version "operator.tigera.io/v1" ensure CRDs are installed first resource mapping not foundUse the lifecycle route for this chart, then observe the staged apply or cleanup sequence with a receipt.
projectcalico/tigera-operator@v3.32.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/alertmanager@1.37.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/alertmanager@1.37.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/alertmanager@1.37.0hapromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-prometheus-stack@85.3.3(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/kube-prometheus-stack@85.3.3defaultKblockedvariant-keyed K rig: the chart-variant's only two-cluster kind parity receipt is on 86.1.0 and is blocked (parity: semantic object diff), so no version has a passing K proof - runs/live-kind-parity/prometheus-community-kube-prometheus-stack-default/receipt.yamlresolve the variant's K blocker on 86.1.0; the K rig keys receipts by chart-variant, so re-running this version would overwrite that receipt
prometheus-community/kube-prometheus-stack@85.3.3defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-prometheus-stack@85.3.3no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-prometheus-stack@86.1.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/kube-prometheus-stack@86.1.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-prometheus-stack@86.1.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-state-metrics@7.4.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/kube-state-metrics@7.4.0cluster-metrics-readonlypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/kube-state-metrics@7.4.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-adapter@5.3.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus-adapter@5.3.0apiservice-v1-capabilitypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonly + crdpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-adapter@5.3.0default + crdpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
prometheus-community/prometheus-adapter@5.3.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-blackbox-exporter@11.10.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus-blackbox-exporter@11.10.0cluster-metrics-readonlypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-blackbox-exporter@11.10.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-node-exporter@4.55.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus-node-exporter@4.55.0cluster-metrics-readonlypromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-node-exporter@4.55.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-operator-crds@29.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus-operator-crds@29.0.0cluster-metrics-readonlypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
prometheus-community/prometheus-operator-crds@29.0.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus-pushgateway@3.6.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus-pushgateway@3.6.0cluster-metrics-readonlypromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
prometheus-community/prometheus-pushgateway@3.6.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus@29.8.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus@29.8.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus@29.8.0prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
prometheus-community/prometheus@29.8.0prod-us-eastpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
prometheus-community/prometheus@29.8.0staging-eu-westpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
prometheus-community/prometheus@29.8.0staging-eu-westpromotionnot-applicable-derived-variantderived ConfigHub variant creation is not the base-variant promotion laneuse the derived variant receipts and target-bound lane for this downstream variant
prometheus-community/prometheus@29.9.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
prometheus-community/prometheus@29.9.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
prometheus-community/prometheus@29.9.0server-only-ephemeralpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
rook-release/rook-ceph-cluster@v1.19.5(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
rook-release/rook-ceph-cluster@v1.19.5default + namespacepromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
rook-release/rook-ceph-cluster@v1.19.5defaultGblockedtarget-prerequisite: namespace missing (parity passed)Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
rook-release/rook-ceph-cluster@v1.19.5defaultKblockedtarget-prerequisite: required Namespace missing (parity passed)Declare and stage the required Namespace as a target fact, then the row can move to pass.
rook-release/rook-ceph-cluster@v1.19.5defaultPblockedtarget-prerequisite: namespace missing (parity passed)Stage the named prerequisite as a target fact (see the target-prerequisite-plan), then the row can move to pass.
rook-release/rook-ceph-cluster@v1.19.5defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
rook-release/rook-ceph@v1.19.5(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
rook-release/rook-ceph@v1.19.5defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
runix/pgadmin4@1.62.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
runix/pgadmin4@1.62.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
runix/pgadmin4@1.62.0web-ui-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
sealed-secrets/sealed-secrets@2.18.6(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
sealed-secrets/sealed-secrets@2.18.6defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
sealed-secrets/sealed-secrets@2.18.6no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0sync-secret-rotationpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
stakater/reloader@2.2.12(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
stakater/reloader@2.2.12controller-default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
stakater/reloader@2.2.12defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
strimzi/strimzi-kafka-operator@1.0.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
strimzi/strimzi-kafka-operator@1.0.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
strimzi/strimzi-kafka-operator@1.0.0no-crdsLblockedlocal-live blocked: runtime-readiness: deployment/strimzi-cluster-operator: prerequisite-blocked (stuck creating: missing mount/secret/config) (kibana-kibana-9bf64bc55-qm87r[ContainerCreating ready=false restarts=0;] rollout-operator-5f688cdb68-pc7sz[ ready=false restarts=0;] strimzi-cluster-operatInspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
strimzi/strimzi-kafka-operator@1.0.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
traefik/traefik@40.2.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
traefik/traefik@40.2.0cloud-loadbalancerpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
traefik/traefik@40.2.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
traefik/traefik@40.2.0external-crdspromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
traefik/traefik@40.2.0internal-clusterip-dashboard-offpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
traefik/traefik@40.2.0no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
velero/velero@12.0.1(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
velero/velero@12.0.1aws-s3-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
velero/velero@12.0.1azure-blob-existing-secretpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
velero/velero@12.0.1defaultLblockedlocal-live blocked: admission-or-rbac: apply: Error from server (Invalid): error when creating "STDIN": BackupStorageLocation.velero.io "default" is invalid: spec.provider: Required value Error from server (Invalid): error when creating "STDIN":Decide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.
velero/velero@12.0.1defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
velero/velero@12.0.1filesystem-backup-node-agentpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
velero/velero@12.0.1no-crds + crdpromotionnot-applicable-candidatecandidate rows are planning rows, not server-side promotion evidenceturn this candidate into a real base or derived variant before server-side promotion applies
velero/velero@12.0.1no-crdsKblockedtarget-prerequisite: CRDs missingStage the chart's CRDs as target facts (or pick a CRD-rendering base), then the row can move to pass.
velero/velero@12.0.1no-crdsLblockedlocal-live blocked: admission-or-rbac: apply: Error from server (Invalid): error when creating "STDIN": BackupStorageLocation.velero.io "default" is invalid: spec.provider: Required value Error from server (Invalid): error when creating "STDIN":Decide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.
velero/velero@12.0.1no-crdspromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
vm/victoria-logs-single@0.12.5(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
vm/victoria-logs-single@0.12.5defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
vm/victoria-metrics-single@0.39.0(source)promotionnot-applicable-sourcesource rows are upstream chart inputs, not server-side promotion evidencechoose or create an F2 base before server-side variant promotion applies
vm/victoria-metrics-single@0.39.0default-reviewedpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes
vm/victoria-metrics-single@0.39.0defaultpromotionprovenserver-side promotion receipt passedkeep receipt fresh when the upstream base changes

needs-modeling (45)

The catalog/model has to change before this can pass.

ChartVariantLaneStateReasonNext action
autoscaler/cluster-autoscaler@9.57.0controller-default-reviewedKblockedno target fact value generator for autoDiscovery.clusterNameCatalog work: add the missing target-fact value generator, then rerun.
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultKblockedsemantic object parity issue: missing=0 extra=1 diffs=2; extra=v1Namespacedefault; objects=apps/v1Deploymentdefaultebs-csi-controller; storage.k8s.io/v1CSIDriverebs.csi.aws.comCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/apache@11.4.29defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/apache@11.4.29legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=1; extra=v1Namespacedefault; objects=apps/v1Deploymentdefaultapache; runtime also fails to pull docker.io/bitnami/apache:2.4.65-debian-12-r2Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/contour@21.1.4defaultKblockedhelm-hook: pre-install certificate generation failed (parity passed)Catalog work: add a lifecycle route for the hook action or provide the hook-produced object as a target prerequisite, then rerun.
bitnami/contour@21.1.4no-crdsKblockedsemantic object parity issue: missing=5 extra=1 diffs=0; missing=apiextensions.k8s.io/v1CustomResourceDefinitioncontourconfigurations.projectcontour.io; apiextensions.k8s.io/v1CustomResourceDefinitioncontourdeployments.projectcontour.io; apiextensions.k8s.io/v1CustomResourceDefinitionextensionservices.projectcontour.io; apiextensions.k8s.io/v1CustomResourceDefinitionhttpproxies.projectcontour.io; apiextensions.k8s.io/v1CustomResourceDefinitiontlscertificatedelegations.projectcontour.io; extra=v1Namespacedefault; runtime also fails to pull docker.io/bitnami/contour:1.32.1-debian-12-r0; lifecycle also hits pre-install certificate-generation hook failure; runtime also requires hook/target Secret(s): envoycertCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/elasticsearch@22.1.6defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/elasticsearch@22.1.6haKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/elasticsearch@22.1.6legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=4; extra=v1Namespacedefault; objects=apps/v1StatefulSetdefaultelasticsearch-coordinating; apps/v1StatefulSetdefaultelasticsearch-data; apps/v1StatefulSetdefaultelasticsearch-ingest; apps/v1StatefulSetdefaultelasticsearch-master; runtime also fails to pull docker.io/bitnami/os-shell:12-debian-12-r50Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/opensearch@2.0.10defaultKblockedsemantic object parity issue: missing=0 extra=1 diffs=4; extra=v1Namespacedefault; objects=v1Servicedefaultopensearch-coordinating-hl; v1Servicedefaultopensearch-data-hl; v1Servicedefaultopensearch-ingest-hl; v1Servicedefaultopensearch-master-hl; live Helm includes Service spec.trafficDistribution=PreferClose for this cluster capability profile; runtime also fails to pull docker.io/bitnami/os-shell:12-debian-12-r51Catalog work: model the required Kubernetes capability/profile field, update the base or semantic contract, then rerun.
bitnami/opensearch@2.0.10haKblockedsemantic object parity issue: missing=0 extra=1 diffs=8; extra=v1Namespacedefault; objects=apps/v1StatefulSetdefaultopensearch-coordinating; apps/v1StatefulSetdefaultopensearch-data; apps/v1StatefulSetdefaultopensearch-ingest; apps/v1StatefulSetdefaultopensearch-master; v1Servicedefaultopensearch-coordinating-hl; v1Servicedefaultopensearch-data-hl; live Helm includes Service spec.trafficDistribution=PreferClose for this cluster capability profile; runtime also fails to pull docker.io/bitnami/os-shell:12-debian-12-r51Catalog work: model the required Kubernetes capability/profile field, update the base or semantic contract, then rerun.
bitnami/opensearch@2.0.10legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=8; extra=v1Namespacedefault; objects=apps/v1StatefulSetdefaultopensearch-coordinating; apps/v1StatefulSetdefaultopensearch-data; apps/v1StatefulSetdefaultopensearch-ingest; apps/v1StatefulSetdefaultopensearch-master; v1Servicedefaultopensearch-coordinating-hl; v1Servicedefaultopensearch-data-hl; live Helm includes Service spec.trafficDistribution=PreferClose for this cluster capability profile; runtime also fails to pull docker.io/bitnami/os-shell:12-debian-12-r51Catalog work: model the required Kubernetes capability/profile field, update the base or semantic contract, then rerun.
bitnami/phpmyadmin@20.0.0defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/phpmyadmin@20.0.0legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=1; extra=v1Namespacedefault; objects=apps/v1Deploymentdefaultphpmyadmin; runtime also fails to pull docker.io/bitnami/phpmyadmin:5.2.2-debian-12-r22Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/spark@10.0.3defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/spark@10.0.3haKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/spark@10.0.3legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=2; extra=v1Namespacedefault; objects=apps/v1StatefulSetdefaultspark-master; apps/v1StatefulSetdefaultspark-worker; runtime also fails to pull docker.io/bitnami/spark:4.0.0-debian-12-r20Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
bitnami/zookeeper@13.8.7defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/zookeeper@13.8.7haKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
bitnami/zookeeper@13.8.7legacyKblockedsemantic object parity issue: missing=0 extra=1 diffs=1; extra=v1Namespacedefault; objects=apps/v1StatefulSetdefaultzookeeper; runtime also fails to pull docker.io/bitnami/zookeeper:3.9.3-debian-12-r21Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
grafana/pyroscope@2.0.2haKblockedsemantic object parity issue: missing=0 extra=2 diffs=0; extra=apiextensions.k8s.io/v1CustomResourceDefinitionpodlogs.monitoring.grafana.com; v1NamespacedefaultCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
hashicorp/terraform@1.1.2defaultKblockedsemantic object parity issue: missing=0 extra=2 diffs=0; extra=apiextensions.k8s.io/v1CustomResourceDefinitionworkspaces.app.terraform.io; v1Namespacedefault; runtime also requires hook/target Secret(s): terraformrc, workspacesecretsCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
istio/gateway@1.30.0controller-default-reviewedKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
istio/gateway@1.30.0defaultKblockedremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun.
nats/nack@0.34.0defaultKblockedsemantic object parity issue: missing=0 extra=7 diffs=0; extra=apiextensions.k8s.io/v1CustomResourceDefinitionaccounts.jetstream.nats.io; apiextensions.k8s.io/v1CustomResourceDefinitionconsumers.jetstream.nats.io; apiextensions.k8s.io/v1CustomResourceDefinitionkeyvalues.jetstream.nats.io; apiextensions.k8s.io/v1CustomResourceDefinitionobjectstores.jetstream.nats.io; apiextensions.k8s.io/v1CustomResourceDefinitionstreams.jetstream.nats.io; apiextensions.k8s.io/v1CustomResourceDefinitionstreamtemplates.jetstream.nats.ioCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
nats/nats@2.14.0haKblockedsemantic object parity issue: missing=0 extra=1 diffs=3; extra=v1Namespacedefault; objects=apps/v1StatefulSetnats; v1ConfigMapnats-config; v1Servicenats-headlessCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultGblockedhelm-runtime: upstream leg blockedCatalog work: reconcile the base, render context, target facts, or semantic contract with the live Helm result, then rerun.
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultKblockedrender-input: required Helm values missingProvide the required values in the base/variant, then the row can move to pass.
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultLfaillocal-live fail: admission-or-rbac: apply: The Deployment "nfs-subdir-external-provisioner" is invalid: * spec.template.spec.volumes[0].nfs.server: Required value * spec.template.spec.containers[0].volumeMounts[0].name: Not found: "nfs-subdirDecide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultPblockedhelm-runtime: upstream leg blockedCatalog work: reconcile the base, render context, target facts, or semantic contract with the live Helm result, then rerun.
prometheus-community/kube-prometheus-stack@86.1.0defaultKblockedsemantic object parity issue: missing=0 extra=11 diffs=0; extra=apiextensions.k8s.io/v1CustomResourceDefinitionalertmanagerconfigs.monitoring.coreos.com; apiextensions.k8s.io/v1CustomResourceDefinitionalertmanagers.monitoring.coreos.com; apiextensions.k8s.io/v1CustomResourceDefinitionpodmonitors.monitoring.coreos.com; apiextensions.k8s.io/v1CustomResourceDefinitionprobes.monitoring.coreos.com; apiextensions.k8s.io/v1CustomResourceDefinitionprometheusagents.monitoring.coreos.com; apiextensions.k8s.io/v1CustomResourceDefinitionprometheuses.monitoring.coreos.comCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyGblockedcapability-profile: rendered APIService version is not served by target KubernetesUse or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyKblockedtarget-prerequisite: CRDs missingStage the chart's CRDs as target facts (or pick a CRD-rendering base), then the row can move to pass.
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyLblockedlocal-live blocked: api-version-unsupported: apply: error: resource mapping not found for name: "v1beta1.custom.metrics.k8s.io" namespace: "" from "STDIN": no matches for kind "APIService" in version "apiregistration.k8s.io/v1beta1" ensure CRDs are insUse a supported chart version, compatibility base, or target Kubernetes profile before rerun.
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyPblockedcapability-profile: rendered APIService version is not served by target KubernetesUse or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.
prometheus-community/prometheus-adapter@5.3.0defaultGblockedcapability-profile: rendered APIService version is not served by target KubernetesUse or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.
prometheus-community/prometheus-adapter@5.3.0defaultKblockedtarget-prerequisite: CRDs missingStage the chart's CRDs as target facts (or pick a CRD-rendering base), then the row can move to pass.
prometheus-community/prometheus-adapter@5.3.0defaultLblockedlocal-live blocked: api-version-unsupported: apply: error: resource mapping not found for name: "v1beta1.custom.metrics.k8s.io" namespace: "" from "STDIN": no matches for kind "APIService" in version "apiregistration.k8s.io/v1beta1" ensure CRDs are insUse a supported chart version, compatibility base, or target Kubernetes profile before rerun.
prometheus-community/prometheus-adapter@5.3.0defaultPblockedcapability-profile: rendered APIService version is not served by target KubernetesUse or promote the base rendered for the target API set, then rerun live parity. For prometheus-adapter on modern Kubernetes, use the apiservice-v1-capability base.
traefik/traefik@40.2.0defaultKblockedsemantic object parity issue: missing=0 extra=26 diffs=0; extra=apiextensions.k8s.io/v1CustomResourceDefinitionaccesscontrolpolicies.hub.traefik.io; apiextensions.k8s.io/v1CustomResourceDefinitionaiservices.hub.traefik.io; apiextensions.k8s.io/v1CustomResourceDefinitionapiauths.hub.traefik.io; apiextensions.k8s.io/v1CustomResourceDefinitionapibundles.hub.traefik.io; apiextensions.k8s.io/v1CustomResourceDefinitionapicatalogitems.hub.traefik.io; apiextensions.k8s.io/v1CustomResourceDefinitionapiplans.hub.traefik.ioCatalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
velero/velero@12.0.1defaultGblockedrender-input: required Velero provider values missingCreate a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.
velero/velero@12.0.1defaultKblockedmanifest apply failed: Error from server (Invalid): BackupStorageLocation.velero.io "default" is invalid: [spec.credential: Invalid value: "null": spec.credential in body must be of type object: "null", spec.provider: Invalid value: "null": spec.provider in body must be of type string: "null"] Error from server (Invalid): VolumeSnapshotLocation.velero.io "default" is invalid: [spec.credential: Invalid value: "null": spec.credential in body must be of type object: "null", spec.provider: Invalid value: "null": spec.provider in body must be of type string: "null"]Catalog work: update the base, render context, target facts, or semantic contract so the installer package matches the live Helm result, then rerun.
velero/velero@12.0.1defaultPblockedrender-input: required Velero provider values missingCreate a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.
velero/velero@12.0.1no-crdsGblockedrender-input: required Velero provider values missingCreate a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.
velero/velero@12.0.1no-crdsPblockedrender-input: required Velero provider values missingCreate a non-alias base with the required Helm values, value schema, target facts, and receipts, then rerun the live lane.

already-decided (136)

A watch row with a recorded product decision: evidence plus a named residue. Usable today with the caveat.

ChartVariantLaneStateReasonNext action
argo-cd/argo-cd@9.5.15defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
argo-cd/argo-cd@9.5.17defaultGwatchgitops-runtime: child Argo Application not materialized (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
argo-cd/argo-cd@9.5.17defaultPwatchgitops-runtime: child Argo Application not materialized (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
autoscaler/cluster-autoscaler@9.57.0defaultKwatchrender-input: required Helm values missing (parity passed)Provide the required values in the base/variant, then the row can move to pass.
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultGwatchtarget-fit: AWS/EKS metadata or provider identity missing on vanilla kind (parity passed)Review the target-topology support artifact, choose a target with the required platform behavior, or create a target-scoped base before rerunning.
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultPwatchtarget-fit: AWS/EKS metadata or provider identity missing on vanilla kind (parity passed)Review the target-topology support artifact, choose a target with the required platform behavior, or create a target-scoped base before rerunning.
bitnami/apache@11.4.29defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/apache@11.4.29defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/apache@11.4.29legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/apache@11.4.29legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/contour@21.1.4defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/contour@21.1.4defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/contour@21.1.4legacyGwatchwatch: inspect receiptReview the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
bitnami/contour@21.1.4legacyPwatchwatch: inspect receiptReview the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
bitnami/contour@21.1.4no-crdsGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/contour@21.1.4no-crdsPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6haGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6haPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/elasticsearch@22.1.6legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/mongodb@19.0.7static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/mongodb@19.0.9existing-secret-replicasetGwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/mongodb@19.0.9existing-secret-replicasetPwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/mongodb@19.0.9existing-secret-replicasetpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/mongodb@19.1.0existing-secret-replicasetGwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/mongodb@19.1.0existing-secret-replicasetPwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/mongodb@19.1.0existing-secret-replicasetpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/mongodb@19.1.0static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/mysql@14.0.3static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/nginx@24.0.4existing-tls-ingressGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/nginx@24.0.4existing-tls-ingressPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/nginx@24.0.4existing-tls-ingresspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/nginx@24.0.4http-clusterippromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/nginx@25.0.0existing-tls-ingressGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/nginx@25.0.0existing-tls-ingressPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
bitnami/nginx@25.0.0existing-tls-ingresspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/nginx@25.0.0http-clusterippromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/opensearch@2.0.10defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/opensearch@2.0.10defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/opensearch@2.0.10haGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/opensearch@2.0.10haPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/opensearch@2.0.10legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/opensearch@2.0.10legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/phpmyadmin@20.0.0defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/phpmyadmin@20.0.0defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/phpmyadmin@20.0.0legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/phpmyadmin@20.0.0legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/postgresql@18.6.10existing-secretpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/postgresql@18.6.7static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/postgresql@18.7.0existing-secretpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/postgresql@18.7.0static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/rabbitmq@16.0.14static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/redis@27.0.0defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/redis@27.0.0reuse-existing-secretpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
bitnami/spark@10.0.3defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/spark@10.0.3defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/spark@10.0.3haGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/spark@10.0.3haPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/spark@10.0.3legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/spark@10.0.3legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7haGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7haPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7legacyGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
bitnami/zookeeper@13.8.7legacyPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
dex/dex@0.24.0defaultGwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
dex/dex@0.24.0defaultPwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/filebeat@8.5.1defaultGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/filebeat@8.5.1defaultPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/filebeat@8.5.1node-or-cluster-collectorGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/filebeat@8.5.1node-or-cluster-collectorPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/kibana@8.5.1defaultGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/kibana@8.5.1defaultPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/metricbeat@8.5.1defaultGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
elastic/metricbeat@8.5.1defaultPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
external-secrets/external-secrets@2.5.0defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
fluent/fluentd@0.5.3defaultGwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
fluent/fluentd@0.5.3defaultPwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
gitlab/gitlab-runner@0.89.0defaultGwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
gitlab/gitlab-runner@0.89.0defaultKwatchhelm-runtime: upstream not ready (parity passed)Review the runtime residue (crash loop / readiness) on the target and record a runtime-review support artifact.
gitlab/gitlab-runner@0.89.0defaultPwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/grafana@10.5.15static-passwordspromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
grafana/loki@7.0.0single-binary-filesystempromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
grafana/pyroscope@2.0.2defaultGwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/pyroscope@2.0.2defaultPwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/pyroscope@2.0.2haGwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/pyroscope@2.0.2haPwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/pyroscope@2.0.2no-crdsGwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/pyroscope@2.0.2no-crdsPwatchtarget-runtime: ConfigHub workload not ready (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
grafana/tempo@1.24.4local-persistentpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
grafana/tempo@1.24.4s3-query-observabilityGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
grafana/tempo@1.24.4s3-query-observabilityPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
hashicorp/consul@2.0.0default-control-planepromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
hashicorp/consul@2.0.0secure-mesh-existing-secretsGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
hashicorp/consul@2.0.0secure-mesh-existing-secretsPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
hashicorp/terraform@1.1.2defaultGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
hashicorp/terraform@1.1.2defaultPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
hashicorp/terraform@1.1.2no-crdsGwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
hashicorp/terraform@1.1.2no-crdsPwatchtarget-runtime: pod ContainerCreating (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
hashicorp/vault@0.32.0dev-modepromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
hashicorp/vault@0.32.0ha-raft-uiGwatchoperate-policy: Vault init/unseal readiness (parity passed)Perform and record the operational step (e.g. Vault init/unseal) for the target scope; see the operating-policy artifact.
hashicorp/vault@0.32.0ha-raft-uiPwatchoperate-policy: Vault init/unseal readiness (parity passed)Perform and record the operational step (e.g. Vault init/unseal) for the target scope; see the operating-policy artifact.
ingress-nginx/ingress-nginx@4.15.1internal-clusterippromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
istio/gateway@1.30.0controller-default-reviewedGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
istio/gateway@1.30.0controller-default-reviewedPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
istio/gateway@1.30.0defaultGwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
istio/gateway@1.30.0defaultPwatchremote-image: image pull failed or pinned image is unavailable (parity passed)Resolve the image by digest, override to a maintained image, or refresh the catalog base with a pullable image, then rerun the live lane.
jetstack/cert-manager@v1.20.2crds-enabledpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
jetstack/trust-manager@v0.22.1defaultGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
jetstack/trust-manager@v0.22.1defaultPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
kyverno/kyverno-policies@3.8.0defaultGwatchgitops-runtime: ClusterPolicy OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
kyverno/kyverno-policies@3.8.0defaultKwatchwatch: object parity passed; readiness needs reviewConfirm workload readiness on the target and record the result.
kyverno/kyverno-policies@3.8.0defaultPwatchgitops-runtime: ClusterPolicy OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
linkerd/linkerd-crds@1.8.0defaultGwatchgitops-runtime: CustomResourceDefinition OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
linkerd/linkerd-crds@1.8.0defaultPwatchgitops-runtime: CustomResourceDefinition OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
longhorn/longhorn@1.11.2defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
metrics-server/metrics-server@3.13.0defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
minio-operator/tenant@7.1.1defaultGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
minio-operator/tenant@7.1.1defaultPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
nats/surveyor@0.20.9default-reviewedGwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
nats/surveyor@0.20.9default-reviewedPwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
nats/surveyor@0.20.9defaultGwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
nats/surveyor@0.20.9defaultPwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
open-telemetry/opentelemetry-operator@0.114.0defaultGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
open-telemetry/opentelemetry-operator@0.114.0defaultPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
opencost/opencost@2.5.21defaultGwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
opencost/opencost@2.5.21defaultPwatchtarget-runtime: pod config/runtime errors (parity passed)Review the runtime residue (pod errors / not ready) on the target and record a runtime-review support artifact.
prometheus-community/prometheus@29.8.0server-only-ephemeralpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
prometheus-community/prometheus@29.9.0defaultGwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
prometheus-community/prometheus@29.9.0defaultPwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0defaultpromotionwatchserver-side promotion mechanics passed, but changeset-bound promote failed and required the no-changeset fallbackConfigHub v0.1.80 includes the changeset-bound add-new-units fix; rerun this promotion proof to replace the old fallback receipt with a full pass
traefik/traefik@40.2.0no-crdsGwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.
traefik/traefik@40.2.0no-crdsPwatchgitops-runtime: Argo health Progressing (parity passed)Review the controller-health residue (aggregate vs per-resource health, sync state) and refresh the gitops-runtime-review support artifact.

Boundaries