Production Disposition And Live/E2E Lane

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

The top-20 are mandatory catalog entries because their upstream Helm charts are too popular to omit. This lane records the work needed to move those supported top-20 entries from local-test support toward production support.

It does not claim production support itself. Production support is recorded in the target-scoped decision artifacts under data/production-support-decisions/.

Summary

catalog-supported local-test charts: 20
ConfigHub proof receipts passing: 20
live/e2e observed charts: 20
production-review-ready disposition rows: 19
production-blocked pending disposition: 1
target-scoped support decision artifacts: 20
target-scoped supported decisions: 17
target-scoped superseded decisions: 2
target-scoped rejected decisions: 1
target-scoped draft decisions: 0
source Helm-hook rows: 1
hook/lifecycle disposition rows: 12
related lifecycle observation rows: 2
accepted production disposition receipts: 105
charts with accepted dispositions: 20

The hook/lifecycle disposition is a production-review item. It does not always mean the retained source scan found Helm hooks. Use the evidence fields in top20.csv:

Use data/top20-base-readiness/base-readiness.csv for base-by-base live readiness. A chart can be production-review-ready at the disposition level while a non-default base still needs target runtime review. The target-scoped production support decision chooses the supported base, target scope, accepted risk boundary, and required runtime checks.

How To Read The Production State

StateMeaning
catalog-supportedThe chart is in the public catalog with maintained bases and local-test proof.
production-review-readyThe required pre-review disposition receipts exist for the chart.
blockedOne or more required pre-review disposition receipts are missing.
production-supportedNot set by this lane. It requires a separate target-scoped support decision.

production-review-ready is not the same as production support. It means the chart has enough accepted disposition evidence to make or audit a target-scoped production support decision.

Use these generated files as follows:

FileUse
data/production-support-decisions/summary.mdCurrent target-scoped support decisions: supported, superseded, rejected, or draft.
data/production-disposition/next-actions.csvHistorical pre-decision action per top-20 chart.
data/production-disposition/support-decision-contract.mdPre-decision contract and queue used to create the current support decisions.
data/production-disposition/support-decision-queue.csvHistorical one-row-per-chart support-decision queue.
data/production-disposition/dispositions.mdAccepted receipts, evidence, owners, and unblock rules.
data/scan-disposition-workdown/summary.mdWhether scan findings need fixes, hardened bases, explicit acceptance, runtime review, or policy decisions.

Typical support work includes choosing the production base, naming the target scope, accepting or patching scan findings, confirming lifecycle and target-fact requirements, refreshing live/e2e evidence for that scope, and recording or updating the support decision.

Pre-Decision Workstreams

This historical queue shows the decision that was needed before the current target-scoped decisions were closed. Use the current decision artifacts for the active support state.

WorkstreamChartsNext action
Image digest resolution10Pin images by digest or record an explicit exception before production OCI support.<br>argo-cd/argo-cd@9.5.15 (default)<br>bitnami/mysql@14.0.3 (static-passwords)<br>bitnami/rabbitmq@16.0.14 (static-passwords)<br>external-secrets/external-secrets@2.5.0 (default)<br>grafana/grafana@10.5.15 (existing-secret-ingress)<br>and 5 more
Lifecycle support boundary4Record which lifecycle behavior is supported, observed, excluded, or operator-owned.<br>bitnami/mongodb@19.0.7 (static-passwords)<br>bitnami/postgresql@18.6.7 (static-passwords)<br>bitnami/redis@25.5.3 (default)<br>ingress-nginx/ingress-nginx@4.15.1 (internal-clusterip)
Security acceptance or hardened base4Accept current security findings for the target scope or create a hardened base variant.<br>longhorn/longhorn@1.11.2 (default)<br>prometheus-community/kube-prometheus-stack@85.3.3 (default)<br>prometheus-community/prometheus@29.8.0 (server-only-ephemeral)<br>secrets-store-csi-driver/secrets-store-csi-driver@1.6.0 (default)
Close open dispositions1Write or fix missing disposition receipts before making a support decision.<br>jetstack/cert-manager@v1.20.2 (crds-enabled)
Scope decision1Write the missing target-scoped support boundary.<br>bitnami/nginx@24.0.2 (http-clusterip)

For the full per-chart contract, use data/production-disposition/support-decision-contract.md. For the spreadsheet form, use data/production-disposition/support-decision-queue.csv.

Top-20 Disposition Table

ChartVariantsConfigHub proofLive/e2eProduction statusAcceptedOpen dispositions
argo-cd/argo-cd@9.5.15default, no-crdspasslocal-kind-observedproduction-review-ready7
bitnami/mongodb@19.0.7static-passwords, existing-secret-replicasetpasslocal-kind-observedproduction-review-ready6
bitnami/mysql@14.0.3static-passwords, existing-secretpasslocal-kind-observedproduction-review-ready5
bitnami/nginx@24.0.2http-clusterip, existing-tls-ingresspasslocal-kind-observedproduction-review-ready4
bitnami/postgresql@18.6.7static-passwords, existing-secretpasslocal-kind-observedproduction-review-ready5
bitnami/rabbitmq@16.0.14static-passwords, existing-secretpasslocal-kind-observedproduction-review-ready5
bitnami/redis@25.5.3default, reuse-existing-secretpasslocal-kind-observedproduction-review-ready4
external-secrets/external-secrets@2.5.0default, no-crdspasslocal-kind-observedproduction-review-ready6
grafana/grafana@10.5.15static-passwords, existing-secret-ingresspasslocal-kind-observedproduction-review-ready5
grafana/loki@7.0.0single-binary-filesystem, simple-scalable-miniopasslocal-kind-observedproduction-review-ready5
grafana/tempo@1.24.4local-persistent, s3-query-observabilitypasslocal-kind-observedproduction-review-ready4
hashicorp/consul@2.0.0default-control-plane, secure-mesh-existing-secretspasslocal-kind-observedproduction-review-ready8
hashicorp/vault@0.32.0dev-mode, default, ha-raft-uipasslocal-kind-observedproduction-review-ready6
ingress-nginx/ingress-nginx@4.15.1default, admission-disabled, internal-clusterippasslocal-kind-observedproduction-review-ready5
jetstack/cert-manager@v1.20.2default, crds-enabledpasslocal-kind-observedblocked6target fact preflight
longhorn/longhorn@1.11.2default, ui-ingresspasslocal-kind-observedproduction-review-ready5
metrics-server/metrics-server@3.13.0default, external-tls-capasslocal-kind-observedproduction-review-ready5
prometheus-community/kube-prometheus-stack@85.3.3default, no-crdspasslocal-kind-observedproduction-review-ready7
prometheus-community/prometheus@29.8.0default, server-only-ephemeralpasslocal-kind-observedproduction-review-ready3
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0default, sync-secret-rotationpasslocal-kind-observedproduction-review-ready4

Doctrine

The top-20 must be in the catalog. Their local-test paths are easy to try because they have passing ConfigHub/cub installer receipts. They are not production-supported until their scan/gate warnings, lifecycle risks, target facts, and live/e2e observation requirements have explicit dispositions and a separate production support decision records the target scope.