external-secrets/external-secrets Production-Readiness Packet

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

Generated. Do not edit by hand. This packet answers the reviewer questions in one place and links the generated evidence; it makes no new claims. Companion navigation packet: hard-chart packet.

Why this chart matters

CRDs plus webhooks plus an external-system dependency by design: the chart's whole job is reconciling secrets from providers the cluster cannot prove locally.

What should a serious user try first?

Base default - support decision supported, disposition production-review-ready, bounded to target scope: cub-lk-kind-vanilla; namespace=external-secrets; delivery=confighub-oci; controller=argo.

Support decision evidence: fresh-target-evidence-passed (decision).

Quirks

crds;existing-secret;extension-slots

You provide: an existing Secret for some bases (buildable - not yet run); a CRD ownership choice (crds vs no-crds base). Absorbed for you: exact rendered objects with render parity and receipts; CRD handling split into explicit bases; extension slots routed to reviewed bases.

What is at render parity?

Current lane status is derived from committed receipts and generated matrix rows. Authoritative per-lane rows: outcome coverage.

What is at live parity?

What is only watch, per-target, or manual?

What production support work remains?

The target-scoped support decision is supported. Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate provider-specific, credential, resource-hardened, or profile-specific bases for real customer External Secrets workloads.

Current work item: supported-scope-evidence - work items.

Claims we must not make yet

The exact next test

keep the target-scoped evidence fresh; create separate provider-specific, credential, resource-hardened, or profile-specific bases for real customer External Secrets workloads.