prometheus-community/kube-prometheus-stack Production-Readiness Packet

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

Generated. Do not edit by hand. This packet answers the reviewer questions in one place and links the generated evidence; it makes no new claims. Companion navigation packet: hard-chart packet.

Why this chart matters

CRDs, admission webhooks with hook-driven cert patching, cluster RBAC, generated facts, large fanout, dependency-locked subcharts, and real image/security surface in one install.

What should a serious user try first?

Base default - support decision supported, disposition production-review-ready, bounded to target scope: cub-lk-kind-vanilla; namespace=monitoring; delivery=confighub-oci; controller=argo.

Support decision evidence: fresh-target-evidence-passed (decision).

Quirks

hooks;crds;generated-secrets;existing-secret;webhooks;extension-slots;install-vs-upgrade-divergence;required-values;lookup;generated-facts;tpl;capabilities;rbac;storage

You provide: an existing Secret for some bases (NOT built - chart ships no Secret toggle); a StorageClass / storage decision; a CRD ownership choice (crds vs no-crds base); webhook/cert readiness at delivery time; target facts at variant time; mandatory chart inputs. Absorbed for you: exact rendered objects with render parity and receipts; generated Secrets separated out of the published artifact; CRD handling split into explicit bases; hooks classified and routed (not silently executed); extension slots routed to reviewed bases; install-vs-upgrade render divergence captured per revision; cluster lookups lifted into declared target facts.

Hook disposition: observed (post-install, post-upgrade, pre-install, pre-upgrade; dependency source: chart-own) - hook dispositions.

What is at render parity?

Current lane status is derived from committed receipts and generated matrix rows. Authoritative per-lane rows: outcome coverage.

What is at live parity?

What is only watch, per-target, or manual?

What production support work remains?

The target-scoped support decision is supported. Keep the target-scoped evidence fresh before using this supported scope as a production-support example.

Current work item: supported-scope-evidence - work items.

Claims we must not make yet

The exact next test

a ConfigHub-managed upgrade or a target-scoped no-crds production-support decision that applies the proven target-fact OCI path to the chosen production target.