Generated. Do not edit by hand.
This survey separates two kinds of Secret handling that Helm often mixes together:
- user or application credential material, such as passwords, tokens, TLS keys, object-store credentials, and existing Secret references;
- Kubernetes lifecycle state, such as webhook serving certificates and service-account token Secrets.
The survey is built from committed top-100 artifact indexes, rendered object sets, target facts, hook lifecycle receipts, and webhook certificate lifecycle receipts. It does not run live lanes.
Summary
variants surveyed: 179
secret rows: 91
variant dispositions: not-applicable=118, staged=26, delivered=21, needs-lane-support=6, delivered-and-staged=4, observed=4
secret dispositions: staged=47, delivered=31, needs-lane-support=8, observed=5
secret roles: user-credential-material=52, kubernetes-lifecycle-state=25, secret-material-review=14
lifecycle secrets still needing lane support: 8
Reading Rule
deliveredmeans the rendered artifact contains the Secret and the recipe or installer package records how it is handled.stagedmeans the selected base requires a target Secret before apply.observedmeans committed lifecycle evidence records the Secret staging or controller behavior for that base.needs-lane-supportmeans the Secret is visible, but the repo should add a staging receipt, lifecycle observation, or explicit refusal before stronger live or production claims.not-applicablemeans the base has no rendered Secret and no required target Secret in the committed artifact index.
Lifecycle Secrets Needing Lane Support
Machine-readable forms:
Regenerate:
npm run secrets:lifecycle
npm run secrets:lifecycle:verify