Production Support Decision Contract

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

The top-20 catalog entries have local-test proof and accepted production disposition receipts. They are not production-supported until a target-scoped support decision is recorded.

A support decision names the exact base variant, target scope, delivery path, runtime expectations, accepted risks, and evidence refresh required for a production claim.

Required Decision Fields

FieldMeaning
chart and versionThe maintained chart entry.
supported baseThe base variant that is in production scope. Other bases stay local-test or review-only unless separately approved.
target scopeCluster type, namespace, GitOps controller, storage assumptions, CRD ownership, required Secrets, and other target prerequisites.
delivery pathConfigHub OCI, Argo, Flux, direct apply, or another declared route.
scan decisionFindings fixed, accepted, blocked, or moved into a hardened base.
image decisionDigest-pinned images or an explicit exception for the supported scope.
lifecycle decisionHooks, CRDs, webhooks, generated facts, controller-populated fields, and observation freshness policy.
live evidenceThe receipt or command that refreshes live/e2e evidence for the selected scope.
support boundaryWhat the catalog promises, and what remains operator-owned.

Current Queue

Decision stateCharts
close-dispositions-first1
lifecycle-support-scope-decision4
resolve-images-before-production-oci10
scope-decision-needed1
security-acceptance-or-hardened-base4

Workstreams

The queue is easier to work by decision state. Each row below groups charts with the same remaining production-support decision.

WorkstreamChartsNext action
Image digest resolution10Pin images by digest or record the explicit exception before claiming production OCI support.<br>argo-cd/argo-cd@9.5.15 (default)<br>bitnami/mysql@14.0.3 (static-passwords)<br>bitnami/rabbitmq@16.0.14 (static-passwords)<br>external-secrets/external-secrets@2.5.0 (default)<br>grafana/grafana@10.5.15 (existing-secret-ingress)<br>and 5 more
Lifecycle support boundary4Record which lifecycle behavior is supported, observed, excluded, or operator-owned.<br>bitnami/mongodb@19.0.7 (static-passwords)<br>bitnami/postgresql@18.6.7 (static-passwords)<br>bitnami/redis@25.5.3 (default)<br>ingress-nginx/ingress-nginx@4.15.1 (internal-clusterip)
Security acceptance or hardened base4Accept the current security findings for the target scope or create a hardened base variant.<br>longhorn/longhorn@1.11.2 (default)<br>prometheus-community/kube-prometheus-stack@85.3.3 (default)<br>prometheus-community/prometheus@29.8.0 (server-only-ephemeral)<br>secrets-store-csi-driver/secrets-store-csi-driver@1.6.0 (default)
Close open dispositions1Write or fix the missing disposition receipts before making a support decision.<br>jetstack/cert-manager@v1.20.2 (crds-enabled)
Scope decision1Write the missing target-scoped support boundary.<br>bitnami/nginx@24.0.2 (http-clusterip)
ChartCandidate baseBase readinessDecision stateNext action
jetstack/cert-manager@v1.20.2crds-enabledstart-hereclose-dispositions-firstwrite or fix the receipt for target fact preflight
bitnami/mongodb@19.0.7static-passwordsrender-onlylifecycle-support-scope-decisionchoose whether static-passwords is in production scope; close or document its render-only live-readiness issue first
bitnami/postgresql@18.6.7static-passwordsrender-onlylifecycle-support-scope-decisionchoose whether static-passwords is in production scope; close or document its render-only live-readiness issue first
bitnami/redis@25.5.3defaultrender-onlylifecycle-support-scope-decisionchoose whether default is in production scope; close or document its render-only live-readiness issue first
ingress-nginx/ingress-nginx@4.15.1internal-clusteripstart-herelifecycle-support-scope-decisionrecord the target-scoped lifecycle support decision, then refresh live/e2e evidence for that scope
argo-cd/argo-cd@9.5.15defaultstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/mysql@14.0.3static-passwordsstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/rabbitmq@16.0.14static-passwordsstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
external-secrets/external-secrets@2.5.0defaultstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
grafana/grafana@10.5.15existing-secret-ingressstart-hereresolve-images-before-production-ociresolve image digests for each affected variant before production OCI support
grafana/loki@7.0.0single-binary-filesystemstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
grafana/tempo@1.24.4local-persistentstart-hereresolve-images-before-production-ociresolve image digests for each affected variant before production OCI support
hashicorp/consul@2.0.0default-control-planestart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
hashicorp/vault@0.32.0defaultstart-hereresolve-images-before-production-ociresolve image digests for each affected variant before production OCI support
metrics-server/metrics-server@3.13.0defaultstart-hereresolve-images-before-production-ociimage policy decision recorded for a target scope; create digest-pinned bases or overrides for stricter scopes
bitnami/nginx@24.0.2http-clusteriprender-onlyscope-decision-neededchoose whether http-clusterip is in production scope; close or document its render-only live-readiness issue first
longhorn/longhorn@1.11.2defaultstart-heresecurity-acceptance-or-hardened-basechoose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
prometheus-community/kube-prometheus-stack@85.3.3defaultrender-onlysecurity-acceptance-or-hardened-basechoose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
prometheus-community/prometheus@29.8.0server-only-ephemeralrender-onlysecurity-acceptance-or-hardened-basechoose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0defaultstart-heresecurity-acceptance-or-hardened-basechoose the supported production base, then record explicit security acceptance or create a hardened base before claiming production support

Rule

This file describes the contract. It does not create production support. A chart becomes production-supported only after its proposed decision artifact is written, reviewed, and backed by fresh evidence for the selected target scope.