Top-20 Production Disposition Details

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

The top-20 catalog entries are supported for local-test. This file states exactly what must be closed before production support can be claimed.

The lifecycle columns separate retained source-hook evidence from recipe-level lifecycle policy and related CRD/webhook/controller observations.

Accepted disposition receipts recorded: 105

ChartLocal-test variantsProduction stateAcceptedOpenSource hooksLifecycle basisLive/e2e receipts
argo-cd/argo-cd@9.5.15default, no-crdsproduction-review-ready700recipe-hook-policy:no-hooks5
bitnami/mongodb@19.0.7static-passwords, existing-secret-replicasetproduction-review-ready600recipe-hook-policy:no-hooks8
bitnami/mysql@14.0.3static-passwords, existing-secretproduction-review-ready500recipe-hook-policy:no-hooks2
bitnami/nginx@24.0.2http-clusterip, existing-tls-ingressproduction-review-ready400none8
bitnami/postgresql@18.6.7static-passwords, existing-secretproduction-review-ready500recipe-hook-policy:no-hooks8
bitnami/rabbitmq@16.0.14static-passwords, existing-secretproduction-review-ready500recipe-hook-policy:no-hooks2
bitnami/redis@25.5.3default, reuse-existing-secretproduction-review-ready400recipe-hook-policy:no-hooks5
external-secrets/external-secrets@2.5.0default, no-crdsproduction-review-ready600lifecycle-observations:2/22
grafana/grafana@10.5.15static-passwords, existing-secret-ingressproduction-review-ready500none2
grafana/loki@7.0.0single-binary-filesystem, simple-scalable-minioproduction-review-ready500recipe-lifecycle-policy2
grafana/tempo@1.24.4local-persistent, s3-query-observabilityproduction-review-ready400none2
hashicorp/consul@2.0.0default-control-plane, secure-mesh-existing-secretsproduction-review-ready800recipe-lifecycle-policy2
hashicorp/vault@0.32.0dev-mode, default, ha-raft-uiproduction-review-ready600none3
ingress-nginx/ingress-nginx@4.15.1default, admission-disabled, internal-clusteripproduction-review-ready500recipe-hook-policy:no-hooks3
jetstack/cert-manager@v1.20.2default, crds-enabledproduction-blocked610recipe-hook-policy:no-hooks; lifecycle-observations:2/22
longhorn/longhorn@1.11.2default, ui-ingressproduction-review-ready500recipe-hook-policy:no-hooks2
metrics-server/metrics-server@3.13.0default, external-tls-caproduction-review-ready500recipe-hook-policy:no-hooks2
prometheus-community/kube-prometheus-stack@85.3.3default, no-crdsproduction-review-ready702source-hooks:25
prometheus-community/prometheus@29.8.0default, server-only-ephemeralproduction-review-ready300none5
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0default, sync-secret-rotationproduction-review-ready400none2

Closest Rows

These rows have accepted production-disposition receipts or three or fewer open dispositions. They are the clearest next production-review work queue. The same queue is available as next-actions.csv.

ChartAcceptedOpenOpen dispositionsNext receiptExternal scan reading
hashicorp/consul@2.0.080-default-control-plane: warn, 5 finding(s) (liveness-port:1;readiness-port:1;startup-port:1;unset-cpu-requirements:1;unset-memory-requirements:1); secure-mesh-existing-secrets: warn, 6 finding(s) (job-ttl-seconds-after-finished:1;liveness-port:1;readiness-port:1;startup-port:1;unset-cpu-requirements:1)
argo-cd/argo-cd@9.5.1570-default: warn, 18 finding(s) (unset-cpu-requirements:9;unset-memory-requirements:9); no-crds: warn, 18 finding(s) (unset-cpu-requirements:9;unset-memory-requirements:9)
prometheus-community/kube-prometheus-stack@85.3.370-default: warn, 27 finding(s) (dangling-service:7;unset-cpu-requirements:6;unset-memory-requirements:6;no-read-only-root-fs:3;sensitive-host-mounts:3); no-crds: warn, 27 finding(s) (dangling-service:7;unset-cpu-requirements:6;unset-memory-requirements:6;no-read-only-root-fs:3;sensitive-host-mounts:3)
bitnami/mongodb@19.0.760-existing-secret-replicaset: warn, 2 finding(s) (pdb-unhealthy-pod-eviction-policy:2); static-passwords: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1)
external-secrets/external-secrets@2.5.060-default: warn, 6 finding(s) (unset-cpu-requirements:3;unset-memory-requirements:3); no-crds: warn, 6 finding(s) (unset-cpu-requirements:3;unset-memory-requirements:3)
hashicorp/vault@0.32.060-default: warn, 9 finding(s) (no-read-only-root-fs:2;unset-cpu-requirements:2;unset-memory-requirements:2;liveness-port:1;readiness-port:1); dev-mode: warn, 9 finding(s) (no-read-only-root-fs:2;unset-cpu-requirements:2;unset-memory-requirements:2;liveness-port:1;readiness-port:1); ha-raft-ui: warn, 12 finding(s) (dangling-service:2;no-read-only-root-fs:2;unset-cpu-requirements:2;unset-memory-requirements:2;liveness-port:1)
bitnami/mysql@14.0.350-existing-secret: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1); static-passwords: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1)
bitnami/postgresql@18.6.750-existing-secret: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1); static-passwords: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1)
bitnami/rabbitmq@16.0.1450-existing-secret: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1); static-passwords: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1)
grafana/grafana@10.5.1550-existing-secret-ingress: warn, 3 finding(s) (no-read-only-root-fs:1;unset-cpu-requirements:1;unset-memory-requirements:1); static-passwords: warn, 3 finding(s) (no-read-only-root-fs:1;unset-cpu-requirements:1;unset-memory-requirements:1)
grafana/loki@7.0.050-simple-scalable-minio: warn, 18 finding(s) (unset-memory-requirements:9;unset-cpu-requirements:8;no-read-only-root-fs:1); single-binary-filesystem: warn, 12 finding(s) (unset-cpu-requirements:6;unset-memory-requirements:6)
ingress-nginx/ingress-nginx@4.15.150-admission-disabled: warn, 4 finding(s) (liveness-port:1;no-read-only-root-fs:1;readiness-port:1;unset-memory-requirements:1); default: warn, 4 finding(s) (liveness-port:1;no-read-only-root-fs:1;readiness-port:1;unset-memory-requirements:1); internal-clusterip: warn, 4 finding(s) (liveness-port:1;no-read-only-root-fs:1;readiness-port:1;unset-memory-requirements:1)
longhorn/longhorn@1.11.250-default: warn, 24 finding(s) (no-read-only-root-fs:5;run-as-non-root:5;unset-cpu-requirements:5;unset-memory-requirements:5;dangling-service:2); ui-ingress: warn, 24 finding(s) (no-read-only-root-fs:5;run-as-non-root:5;unset-cpu-requirements:5;unset-memory-requirements:5;dangling-service:2)
metrics-server/metrics-server@3.13.050-default: warn, 1 finding(s) (unset-memory-requirements:1); external-tls-ca: warn, 1 finding(s) (unset-memory-requirements:1)
bitnami/nginx@24.0.240-existing-tls-ingress: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1); http-clusterip: warn, 1 finding(s) (pdb-unhealthy-pod-eviction-policy:1)
bitnami/redis@25.5.340-default: warn, 2 finding(s) (pdb-unhealthy-pod-eviction-policy:2); reuse-existing-secret: warn, 2 finding(s) (pdb-unhealthy-pod-eviction-policy:2)
grafana/tempo@1.24.440-local-persistent: warn, 3 finding(s) (no-read-only-root-fs:1;unset-cpu-requirements:1;unset-memory-requirements:1); s3-query-observability: warn, 6 finding(s) (no-read-only-root-fs:2;unset-cpu-requirements:2;unset-memory-requirements:2)
secrets-store-csi-driver/secrets-store-csi-driver@1.6.040-default: warn, 8 finding(s) (no-read-only-root-fs:3;run-as-non-root:3;privilege-escalation-container:1;privileged-container:1); sync-secret-rotation: warn, 8 finding(s) (no-read-only-root-fs:3;run-as-non-root:3;privilege-escalation-container:1;privileged-container:1)
prometheus-community/prometheus@29.8.030-default: warn, 21 finding(s) (unset-cpu-requirements:6;unset-memory-requirements:6;no-read-only-root-fs:4;sensitive-host-mounts:3;host-network:1); server-only-ephemeral: warn, 6 finding(s) (no-read-only-root-fs:2;unset-cpu-requirements:2;unset-memory-requirements:2)
jetstack/cert-manager@v1.20.261target fact preflightdata/production-disposition/receipts/jetstack-cert-manager/target-fact-preflight.yamlcrds-enabled: warn, 6 finding(s) (unset-cpu-requirements:3;unset-memory-requirements:3); default: warn, 6 finding(s) (unset-cpu-requirements:3;unset-memory-requirements:3)

Production Decision Queue

These rows are ready for a target-scoped production support decision, not already production-supported. The queue separates the first base a user should try from production evidence still needed for image pinning, scan acceptance, runtime fit, and final support scope.

ChartFirst baseBase readinessDecision focusImage subjects needing resolutionNext action
argo-cd/argo-cd@9.5.15defaultstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/mongodb@19.0.7static-passwordsrender-onlyruntime-or-prerequisite-scope0choose whether static-passwords is in production scope; close or document its render-only live-readiness issue first
bitnami/mysql@14.0.3static-passwordsstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/nginx@24.0.2http-clusteriprender-onlyruntime-or-prerequisite-scope0choose whether http-clusterip is in production scope; close or document its render-only live-readiness issue first
bitnami/postgresql@18.6.7static-passwordsrender-onlyruntime-or-prerequisite-scope0choose whether static-passwords is in production scope; close or document its render-only live-readiness issue first
bitnami/rabbitmq@16.0.14static-passwordsstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/redis@25.5.3defaultrender-onlyruntime-or-prerequisite-scope0choose whether default is in production scope; close or document its render-only live-readiness issue first
external-secrets/external-secrets@2.5.0defaultstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
grafana/grafana@10.5.15existing-secret-ingressstart-hereimage-digest-resolution2resolve image digests for each affected variant before production OCI support
grafana/loki@7.0.0single-binary-filesystemstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
grafana/tempo@1.24.4local-persistentstart-hereimage-digest-resolution2resolve image digests for each affected variant before production OCI support
hashicorp/consul@2.0.0default-control-planestart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
hashicorp/vault@0.32.0defaultstart-hereimage-digest-resolution3resolve image digests for each affected variant before production OCI support
ingress-nginx/ingress-nginx@4.15.1internal-clusteripstart-herelifecycle-support-scope0record the target-scoped lifecycle support decision, then refresh live/e2e evidence for that scope
jetstack/cert-manager@v1.20.2crds-enabledstart-heremissing-disposition2write or fix the receipt for target fact preflight
longhorn/longhorn@1.11.2defaultstart-heresecurity-acceptance-or-hardened-base2choose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
metrics-server/metrics-server@3.13.0defaultstart-hereimage-digest-resolution2image policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
prometheus-community/kube-prometheus-stack@85.3.3defaultrender-onlysecurity-acceptance-or-hardened-base2choose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
prometheus-community/prometheus@29.8.0server-only-ephemeralrender-onlysecurity-acceptance-or-hardened-base2choose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0defaultstart-heresecurity-acceptance-or-hardened-base2choose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support

Standard Disposition Types

CRD lifecycle and upgrade policy

webhook readiness and failure policy

cluster RBAC review

storage backup restore and rollback policy

generated fact ownership

target fact preflight

hook and lifecycle phase policy

extension slot provenance and scan policy

scan/gate warning disposition

Rule

A chart becomes production-review-ready when each required disposition is accepted, fixed, or turned into an explicit variant blocker, and the result is backed by rendered-digest-bound scan and live/e2e receipts. Production support still requires a separate target-scoped support decision.