Next-Ten Waves

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated directory turns the current execution plan into small work queues. It is intentionally narrower than the full attack-plan workdown: these are the next rows to work, not the whole corpus.

Current Waves

gap-review first rows:             9
strict promotion-review rows:      31
latest-version promotion rows:     7
variant-build rows:                5
production-disposition first rows: 5
import prototype rows:             3

Files

FilePurpose
gap-review-wave.csvFirst existing-secret and CRD/no-CRDs hard gaps to review.
../top100-promotion-wave/wave.csvCurrent strict top-100 promotion-review wave: proof-grade charts with two-cluster parity.
latest-promotion-wave.csv7 latest top-20 candidates that are ready for full lane promotion work.
variant-build-wave.csvWave-2 chart variants to render and prove next.
production-disposition-wave.csvFirst five catalog-supported charts to move toward production disposition.
import-prototype-wave.csvImport examples that explain public chart, managed overlay, and post-render promotion routes.

The production-disposition wave separates accepted dispositions from open dispositions, so the queue shows only the production decisions still needing receipts before the follow-up runtime/GitOps and image-digest lanes run.

Gap Review Wave

#ChartCapabilityProof tierNext action
1bitnami/apacheexisting-secretproof-gradesource-review values; if no toggle exists, keep existing-secret unavailable and document external-secret production path
2bitnami/contourexisting-secretproof-gradesource-review values; if no toggle exists, keep existing-secret unavailable and document external-secret production path
3bitnami/elasticsearchexisting-secretproof-gradesource-review values; if no toggle exists, keep existing-secret unavailable and document external-secret production path
4bitnami/memcachedexisting-secretproof-gradesource-review values; if no toggle exists, keep existing-secret unavailable and document external-secret production path
5bitnami/nginxexisting-secretcatalog-supportedwrite production disposition for generated secret ownership and target-fact preflight
6bitnami/phpmyadminexisting-secretproof-gradesource-review values; if no toggle exists, keep existing-secret unavailable and document external-secret production path
7argo-cd/argocd-image-updaterno-crdsproof-gradesource-review CRD values, then classify as chart-toggle-found or no-crds-not-offered
8minio-operator/operatorno-crdsproof-gradesource-review CRD values, then classify as chart-toggle-found or no-crds-not-offered
9rook-release/rook-cephno-crdsproof-gradesource-review CRD values, then classify as chart-toggle-found or no-crds-not-offered

Strict Promotion Review Wave

PriorityChartVariantsScan highScan mediumNext
2aqua/trivy-operator@0.32.1default;no-crds019review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2argo-cd/argo-events@2.4.21default;no-crds05review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2argo-cd/argo-rollouts@2.40.9default;no-crds010review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2argo-cd/argo-workflows@1.0.14default;controller-default-reviewed;minimal-crds022review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2autoscaler/cluster-autoscaler@9.57.0default;controller-default-reviewed14review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2autoscaler/vertical-pod-autoscaler@0.9.0default;no-crds025review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2cloudnative-pg/cloudnative-pg@0.28.2default;no-crds016review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2elastic/eck-operator@3.4.0default;ha;no-crds018review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2elastic/logstash@8.5.1default;ha00review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2external-dns/external-dns@1.21.1default;no-crds;dry-run-txt-registry03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2fairwinds-stable/vpa@4.11.0default;no-crds021review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2gatekeeper/gatekeeper@3.22.2default;no-crds022review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2grafana/alloy@1.8.2default;no-crds03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2grafana/rollout-operator@0.49.0default;no-crds08review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2jaegertracing/jaeger-operator@2.57.0default;no-crds03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2jetstack/trust-manager@v0.22.1default;no-crds04review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2kedacore/keda@2.19.0default;no-crds017review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2nats/nack@0.34.0default;no-crds08review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2nats/nats@2.14.0default;ha01review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2open-telemetry/opentelemetry-operator@0.114.0default;no-crds09review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2percona/pg-operator@3.0.0default;no-crds08review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2percona/psmdb-operator@1.22.0default;no-crds03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2percona/pxc-operator@1.19.1default;no-crds03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2prometheus-community/alertmanager@1.37.0default;ha00review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2prometheus-community/kube-state-metrics@7.4.0default;cluster-metrics-readonly04review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2prometheus-community/prometheus-blackbox-exporter@11.10.0default;cluster-metrics-readonly00review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2prometheus-community/prometheus-node-exporter@4.55.0default;cluster-metrics-readonly02review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2sealed-secrets/sealed-secrets@2.18.6default;no-crds03review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2stakater/reloader@2.2.12default;controller-default-reviewed04review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2strimzi/strimzi-kafka-operator@1.0.0default;no-crds020review the existing variants, then write production disposition or support-decision artifacts before changing catalog status
2vm/victoria-metrics-single@0.39.0default;default-reviewed00review the existing variants, then write production disposition or support-decision artifacts before changing catalog status

Latest-Version Promotion Wave

#ChartCurrentCandidateStatus
1argo-cd/argo-cd9.5.159.5.17root-path-promoted-review-required
2bitnami/mongodb19.0.719.1.0root-path-promoted-review-required
3bitnami/nginx24.0.225.0.0root-path-promoted-review-required
4bitnami/postgresql18.6.718.7.0root-path-promoted-review-required
5bitnami/redis25.5.327.0.0root-path-promoted-review-required
6prometheus-community/kube-prometheus-stack85.3.386.1.0root-path-promoted-review-required
7prometheus-community/prometheus29.8.029.9.0root-path-promoted-review-required

Variant Build Wave

#ChartProposed variantsBlocking questions
1traefik/traefikdefault;external-crds;internal-clusterip-dashboard-off;cloud-loadbalancercatalog support still requires comparing default against the new user-shaped variants;confirm exact Traefik chart value for CRD creation versus CRD provider enablement;cloud-specific annotations must be target/variant-owned
2external-dns/external-dnsroute53-irsa;cloudflare-existing-secret;dry-run-txt-registryconfirm chart-supported secret/env shape
3vmware-tanzu/veleroaws-s3-existing-secret;azure-blob-existing-secret;filesystem-backup-node-agentproof recipe uses velero/velero source; source alias must stay clear in catalog;daemonset privileges need production disposition
4istio-official/istiodrevisioned-control-plane;external-ca;minimal-profileconfirm exact chart values and secret shape
5kyverno/kyvernodefault-admission;external-crds;ha-admission-reportsconfirm exact chart CRD ownership values;webhook rollout and disruption policy must be dispositioned

Production Disposition Wave

#ChartAcceptedOpen
1bitnami/redisgenerated fact ownership;hook and lifecycle phase policy;scan/gate warning disposition;target fact preflight-
2bitnami/nginxextension slot provenance and scan policy;generated fact ownership;scan/gate warning disposition;target fact preflight-
3metrics-server/metrics-servercluster RBAC review;generated fact ownership;hook and lifecycle phase policy;scan/gate warning disposition;target fact preflight-
4prometheus-community/prometheuscluster RBAC review;extension slot provenance and scan policy;scan/gate warning disposition-
5bitnami/postgresqlgenerated fact ownership;hook and lifecycle phase policy;scan/gate warning disposition;storage backup restore and rollback policy;target fact preflight-

Import Prototype Wave

#CaseRouteStatus
1public-chart-rediscub helm install can inspect quickly; recipe import creates maintained cub installer packagecomplete
2managed-overlay-external-dnsmanaged overlay import; user choices are classified before rendercomplete
3post-render-promotioncub variant create over cloned Spaces and Unitscomplete