Status Dashboard

A repository document, rendered for the site. View source markdown.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated dashboard is the short front door for current project status. It joins the top100 readiness, top500 evidence map, proof lane, graph bridge, quirk, hook, GitOps, and live-parity tables without replacing them.

Use this page to answer:

What is working now?
Which claims are only partial?
Where are the main residues?
Which detailed CSV should I open next?

Current State

SectionMetricValueStatusSource
outcome coveragemaintained chart rows with model support108/110gooddata/outcome-coverage/chart-outcomes.csv
top100catalog-supported charts20/100partialdata/top100-readiness/readiness.csv
top100proof-grade non-catalog charts80/100partialdata/top100-readiness/readiness.csv
outcome coveragevariant-rich maintained chart rows77/110partialdata/outcome-coverage/chart-outcomes.csv
chart usepublic catalog answers20/100partialdata/chart-use-guide/chart-use-guide.csv
chart useproof-ready but not public catalog answers37/100partialdata/chart-use-guide/chart-use-guide.csv
chart usebetter base variant needed answers33/100gapdata/chart-use-guide/chart-use-guide.csv
chart uselimitation decision needed answers9/100gapdata/chart-use-guide/chart-use-guide.csv
top100covered by top100 contract20/100partialdata/top100-coverage/coverage.csv
top100partial by top100 contract80/100partialdata/top100-coverage/coverage.csv
top100average top100 coverage89/100partialdata/top100-coverage/coverage.csv
top100top100 promotion-review queue37/80partialdata/top100-coverage/work-queue.csv
top100first strict top100 promotion wave31/37partialdata/top100-promotion-wave/wave.csv
top100fast-track top100 promotion candidates0/31partialdata/top100-promotion-wave/fast-track.csv
top100fast-track promotion review packets0/0partialdata/top100-promotion-wave/fast-track-reviews/review-packets.csv
top100fast-track storage rollback reviews0/0partialdata/top100-promotion-wave/fast-track-reviews/storage-rollback/storage-reviews.csv
top100top100 user-shaped variant queue33/80partialdata/top100-coverage/work-queue.csv
top100useful-base proposal rows43partialdata/useful-base-design-queue/queue.csv
top100useful-base realized rows10/43partialdata/useful-base-realization-wave/wave.csv
top100useful-base proposal families7/7partialdata/useful-base-design-queue/families.csv
top100useful-base proposals not yet built33/43gapdata/useful-base-design-queue/queue.csv
top100top100 limitation-decision queue9/80partialdata/top100-coverage/work-queue.csv
refreshtop20 proofs still current13/20partialdata/refresh-survival/refreshes.csv
refreshtop20 upstream update candidates7/20partialdata/refresh-survival/refreshes.csv
refreshupdate candidates with proof-complete root paths7/7partialdata/refresh-survival/refreshes.csv
refreshlatest refresh p0 action rows0/7partialdata/latest-top20-refresh/action-queue/queue.csv
top500source rows scanned495/500partialdata/top500-catalog-analysis/review.csv
top500rows with current recipe proof91/500partialdata/top500-catalog-analysis/review.csv
top500catalog-supported rows20/500partialdata/top500-catalog-analysis/review.csv
top500proof-grade rows71/500partialdata/top500-catalog-analysis/review.csv
top500rows with no current recipe proof409/500gapdata/top500-catalog-analysis/review.csv
top500version-drift review rows21/500partialdata/top500-catalog-analysis/review.csv
proof lanesrender parity rows199/199gooddata/outcome-coverage/base-outcomes.csv
proof lanesin-ConfigHub proof rows198/199partialdata/outcome-coverage/base-outcomes.csv
proof laneslocal live rows148/199partialdata/outcome-coverage/base-outcomes.csv
proof lanesexplicit lifecycle observation rows20/20gooddata/outcome-coverage/base-outcomes.csv
proof laneslocal live non-pass rows classified51/51gooddata/local-live-triage/triage.csv
proof lanesGitOps/OCI live pass rows139/199partialdata/outcome-coverage/base-outcomes.csv
proof laneslive Helm-vs-ConfigHub parity pass rows139/199partialdata/outcome-coverage/base-outcomes.csv
proof lanestwo-cluster kind parity pass rows130/179partialdata/live-kind-parity/summary.csv
proof lanestwo-cluster semantic parity pass rows155/179gooddata/live-kind-parity/summary.csv
proof lanescomplete core lane rows126/199gapdata/outcome-coverage/base-outcomes.csv
proof lanestop20 start-here base variants26/42partialdata/top20-base-readiness/base-readiness.csv
proof lanestop20 bases needing unresolved prerequisite or runtime review3/42partialdata/top20-base-readiness/base-readiness.csv
derived variantsderived variant golden rows10/10gooddata/variant-goldens/derived-expansion-wave/work-orders.csv
derived variantsderived variant live create receipts10/10goodruns/derived-variant-execution
derived variantstarget-bound derived variant receipts6/10partialruns/derived-variant-target-bound
graph bridgecharts with recovered graph fragments20/110partialdata/edge-recovery/edges.csv
graph bridgerecovered graph edge rows118/118gooddata/edge-recovery/edges.csv
graph bridgetarget-fact graph edges75/118partialdata/edge-recovery/edges.csv
graph bridgegenerated-fact graph edges1/118partialdata/edge-recovery/edges.csv
graph bridgerows with field reachability4/118partialdata/edge-recovery/edges.csv
live evidenceruntime/GitOps wave rows11/11partialdata/runtime-gitops/wave1.csv
live evidenceselected live Helm-vs-ConfigHub parity receipts139/199partialdata/live-helm-confighub-compare/summary.csv
live evidencetwo-cluster kind parity receipts179/179partialdata/live-kind-parity/summary.csv
live evidencelive parity rerun rows needing decisions108/108partialdata/live-parity-rerun-plan/rerun-plan.csv
live evidencelive parity rows needing model or staging first51/108partialdata/live-parity-rerun-plan/rerun-plan.csv
live evidencelive parity rows needing target review first39/108partialdata/live-parity-rerun-plan/rerun-plan.csv
live evidencelive matrix commands remaining142gapdata/live-matrix-burndown/work-items.csv
live evidencelive matrix GitOps/OCI parity commands remaining73gapdata/live-matrix-burndown/work-items.csv
live evidencelive matrix two-cluster kind commands remaining69gapdata/live-matrix-burndown/work-items.csv
live evidenceGitOps aggregate health residue rows49/199partialdata/gitops-health-residue/residue.csv
live evidenceConfigHub/OCI semantic parity defect receipts0/199gooddata/live-helm-confighub-compare/summary.csv
live evidencetwo-cluster semantic parity defect receipts16/179gooddata/live-kind-parity/summary.csv
production dispositiontop20 production-review-ready charts19/20partialdata/production-disposition/top20.csv
production dispositiontop20 production-blocked charts1/20partialdata/production-disposition/top20.csv
production dispositioncharts with accepted production dispositions20/20partialdata/production-disposition/top20.csv
production support decisionstarget-scoped decision artifacts20/20partialdata/production-support-decisions/decisions.csv
production support decisionssupported decision artifacts17/20partialdata/production-support-decisions/decisions.csv
production support decisionssuperseded decision artifacts2/20partialdata/production-support-decisions/decisions.csv
production support decisionsrejected decision artifacts1/20partialdata/production-support-decisions/decisions.csv
production support decisionsdraft decision artifacts0/20gooddata/production-support-decisions/decisions.csv
scan dispositionhigh-priority scan rows4/20partialdata/scan-disposition-workdown/workdown.csv
scan dispositionremaining mutable-image rows0/20gooddata/scan-disposition-workdown/workdown.csv
scan dispositionprivileged infrastructure review rows4/20partialdata/scan-disposition-workdown/workdown.csv
quirkstracked-and-surfaced axes9/26gooddata/quirk-coverage/coverage.csv
quirkspartly tracked axes3/26partialdata/quirk-coverage/coverage.csv
quirkssource-scanned but not surfaced axes5/26gapdata/quirk-coverage/coverage.csv
quirksnot-scanned axes6/26gapdata/quirk-coverage/coverage.csv
quirksP0 source quirk work queue rows51/95gapdata/quirk-work-queue/top100-queue.csv
quirkshard proof gap shortlist rows25/51gapdata/hard-proof-gaps/shortlist.csv
remote dependenciestop100 dependency-risk rows with maintained locks19/49partialdata/remote-dependency-closure/top100.csv
remote dependenciesactive P0 dependency closure work rows21/49gapdata/remote-dependency-closure/top100.csv
extension slotstop20 charts with extension slots13/20partialdata/extension-slots/extension-slots.csv
extension slotstop100 charts with extension slots82/100partialdata/extension-slots/extension-slots.csv
extension slotstop500 source rows using tpl362/500partialdata/quirk-coverage/coverage.csv
secretstop100 variants with explicit Secret disposition179/179gooddata/secret-lifecycle/variant-summary.csv
secretsSecret rows needing lifecycle lane support8/91gapdata/secret-lifecycle/secrets.csv
secretstarget-fact Secret rows47/91partialdata/secret-lifecycle/secrets.csv
hookstop100 source-scan hook charts11/100partialdata/hook-lifecycle/source-top100-hooks.csv
hookstop100 source hook rows still uncovered0/11gooddata/hook-coverage/top100-hook-coverage.csv
hooksmaintained hook queue rows5/11partialdata/hook-lifecycle/maintained-hook-queue.csv
hookssource-reviewed hook rows not yet maintained8/11gapdata/hook-lifecycle-review/top100-source-hook-route-review.csv
hookssource hook rows with candidate route plans8/11partialdata/hook-coverage/top100-hook-coverage.csv
hookshook-like candidate rows outside source inventory2/10partialdata/hook-route-candidates/candidates.csv
hookshook candidate route work orders72/72partialdata/hook-route-candidates/work-orders.csv
hookshook route receipts present5/5partialdata/hook-lifecycle/maintained-hook-queue.csv
hookshook lifecycle observations present5/5gooddata/hook-lifecycle/maintained-hook-queue.csv
hookshook partial lifecycle observations present0/5gooddata/hook-lifecycle/maintained-hook-queue.csv
hookshook/lifecycle boundary rows13/13partialdata/lifecycle-boundary/lifecycle-boundary.csv
hookshook queue rows still needing route receipts0/5gooddata/lifecycle-boundary/lifecycle-boundary.csv
hookshook routes still needing execution or observation0/5gooddata/lifecycle-boundary/lifecycle-boundary.csv
hooksrelated lifecycle observation receipts passing4/4gooddata/lifecycle-observations/cert-manager-eso/summary.csv
apiservicetop100 source APIService charts5/100partialdata/apiservice-coverage/top100-apiservice-coverage.csv
apiserviceAPIService rows with object/workload observation2/5partialdata/apiservice-coverage/top100-apiservice-coverage.csv
apiserviceAPIService rows with aggregation availability receipts2/5partialdata/apiservice-coverage/top100-apiservice-coverage.csv
apiserviceAPIService rows still source-detected only3/5gapdata/apiservice-coverage/top100-apiservice-coverage.csv

Next Work Queues

Use this section when the question is what should move next, not when the question is whether a specific receipt passed. Workstreams can overlap: one chart can need image, scan, lifecycle, and fresh evidence work before it becomes production-supported for a target scope.

Top100 Catalog Work

QueueChartsNext action
Use public catalog now20Open CATALOG.md and top20 base readiness; choose a base with the lane you need.
Promote proof-grade charts37Run catalog promotion review, select realistic bases, and add selected live lanes.
Fast-track low-residue promotion rows0Open the storage/rollback reviews, choose the target boundaries, complete any proof lanes listed in fast-track.csv, then record target-scoped support decisions.
Design useful base variants33Build the proposed recipe/package bases, then rerun render parity and promotion review before treating them as catalog offers.
Resolve limitation decisions9Decide whether the named gap is supported, disclosed, deferred, or blocked.

Hard Proof Gap Work

These rows are the top assignment queue for public charts where source-scan quirks, dependency closure, or hook routing could damage trust if overclaimed.

QueueRowsNext action
Shortlist25Assign the first rows to modeled facts, route receipts, runtime observations, better bases, or explicit blockers.
Catalog-visible hard gaps3Handle visible catalog rows first so public claims stay narrow and backed.
Hook-route hard gaps9Promote candidate routes into maintained receipts, runtime observations, or explicit blockers.
Remote dependency hard gaps20Close dependency range policy, refresh-survival, and recipe-import gaps before stronger catalog claims.
APIService hard gaps4Add APIService readiness modeling and runtime observation routes.

Remote Dependency Closure Work

These rows close provenance and refresh-survival gaps for public charts that pull remote, vendored, or non-exact dependencies.

WorkstreamRowsNext action
Create recipe/import candidates30Create recipe/import candidates with source locks, dependency locks, first bases, render parity, and catalog decisions.
Add dependency locks0Add dependency-lock.yaml or record that the dependency closure is intentionally empty.
Record dependency range policy5Record non-exact dependency policy and refresh-survival evidence before promotion or upgrade.
Backfill dependency provenance0Record a Chart.lock digest or source-derived dependency provenance.
Promote closure facts0Expose dependency closure facts in chart facts and status surfaces.

Top20 Production Support Work

WorkstreamChartsNext action
Supported scope evidence17Keep target-scoped evidence fresh before using the supported scope as a production example.

Latest Refresh Work

These rows are the current upstream-update queue for the supported top-20 catalog. A row here does not replace the supported catalog version by itself. It identifies the next proof or review action before a replacement can be considered.

ActionChartsNext action
Write replacement decisions0Review the latest-aligned candidate against the supported version and record a target-scoped replacement decision.
Refresh superseded retained candidates0Regenerate candidate proof/package roots for the newer upstream version, then rerun the refresh surfaces.
Create missing retained candidates0Make the needed generator support version/output overrides, then create the missing candidate proof.
Promote render candidates and complete live lanes0Promote the candidate root paths, then run ConfigHub proof, local live, and live parity lanes before replacement.

Live Parity Work

QueueRowsNext action
inspect-diff-first16Inspect the semantic diff before another rerun.
model-or-stage-first51Stage the prerequisite, choose the lifecycle route, or record the operating policy before rerunning.
review-target-first39Review runtime, storage, controller health, or wait conditions before rerunning.
inspect-receipt-first2Read the receipt and classify the row before rerunning.

Active Proof Queue

These are the current live parity rows where another run is not the first useful step. When a support artifact exists, it is linked here; otherwise the row still needs a support artifact or a direct receipt review before rerun.

ChartBaseResultNext stepSupport artifact
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultblockedruntime-review-
argo-cd/argo-cd@9.5.17defaultwatchgitops-runtime-reviewrecipes/argo-cd/argo-cd/9.5.17/gitops-runtime-review.yaml
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultwatchtarget-fit-reviewrecipes/aws-ebs-csi-driver/aws-ebs-csi-driver/2.60.1/target-topology.yaml
bitnami/apache@11.4.29defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/apache@11.4.29legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/contour@21.1.4defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/contour@21.1.4legacywatchruntime-review-
bitnami/contour@21.1.4no-crdswatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/elasticsearch@22.1.6defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/elasticsearch@22.1.6hawatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/elasticsearch@22.1.6legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/mongodb@19.0.9existing-secret-replicasetwatchgitops-runtime-reviewrecipes/bitnami/mongodb/19.0.9/gitops-runtime-review.yaml
bitnami/mongodb@19.1.0existing-secret-replicasetwatchgitops-runtime-reviewrecipes/bitnami/mongodb/19.1.0/gitops-runtime-review.yaml
bitnami/nginx@24.0.4existing-tls-ingresswatchgitops-runtime-reviewrecipes/bitnami/nginx/24.0.4/gitops-runtime-review.yaml
bitnami/nginx@25.0.0existing-tls-ingresswatchgitops-runtime-reviewrecipes/bitnami/nginx/25.0.0/gitops-runtime-review.yaml
bitnami/opensearch@2.0.10defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/opensearch@2.0.10hawatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/opensearch@2.0.10legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/phpmyadmin@20.0.0defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/phpmyadmin@20.0.0legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/spark@10.0.3defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/spark@10.0.3hawatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/spark@10.0.3legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/zookeeper@13.8.7defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/zookeeper@13.8.7hawatchimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/zookeeper@13.8.7legacywatchimage-retention-reviewdata/image-digest-workdown/summary.md
dex/dex@0.24.0defaultwatchruntime-review-
elastic/filebeat@8.5.1defaultwatchruntime-reviewrecipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml
elastic/filebeat@8.5.1node-or-cluster-collectorwatchruntime-reviewrecipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml
elastic/kibana@8.5.1defaultwatchruntime-review-
elastic/metricbeat@8.5.1defaultwatchruntime-review-
fluent/fluentd@0.5.3defaultwatchruntime-reviewrecipes/fluent/fluentd/0.5.3/runtime-review.yaml
gitlab/gitlab-runner@0.89.0defaultwatchruntime-review-
grafana/pyroscope@2.0.2defaultwatchruntime-reviewrecipes/grafana/pyroscope/2.0.2/runtime-review.yaml
grafana/pyroscope@2.0.2hawatchruntime-reviewrecipes/grafana/pyroscope/2.0.2/runtime-review.yaml
grafana/pyroscope@2.0.2no-crdswatchruntime-reviewrecipes/grafana/pyroscope/2.0.2/runtime-review.yaml
grafana/tempo@1.24.4s3-query-observabilitywatchgitops-runtime-reviewrecipes/grafana/tempo/1.24.4/gitops-runtime-review.yaml
hashicorp/consul@2.0.0secure-mesh-existing-secretswatchgitops-runtime-reviewrecipes/hashicorp/consul/2.0.0/gitops-runtime-review.yaml
hashicorp/terraform@1.1.2defaultwatchruntime-reviewrecipes/hashicorp/terraform/1.1.2/target-prerequisite-plan.yaml
hashicorp/terraform@1.1.2no-crdswatchruntime-reviewrecipes/hashicorp/terraform/1.1.2/target-prerequisite-plan.yaml
hashicorp/vault@0.32.0ha-raft-uiwatchoperating-policyrecipes/hashicorp/vault/0.32.0/operating-policy.yaml
istio/gateway@1.30.0controller-default-reviewedwatchimage-retention-reviewdata/image-digest-workdown/summary.md
istio/gateway@1.30.0defaultwatchimage-retention-reviewdata/image-digest-workdown/summary.md
jetstack/trust-manager@v0.22.1defaultwatchgitops-runtime-reviewrecipes/jetstack/trust-manager/v0.22.1/gitops-runtime-review.yaml
kyverno/kyverno-policies@3.8.0defaultwatchgitops-runtime-reviewrecipes/kyverno/kyverno-policies/3.8.0/gitops-runtime-review.yaml
linkerd/linkerd-crds@1.8.0defaultwatchgitops-runtime-reviewrecipes/linkerd/linkerd-crds/1.8.0/gitops-runtime-review.yaml
minio-operator/tenant@7.1.1defaultwatchgitops-runtime-reviewrecipes/minio-operator/tenant/7.1.1/gitops-runtime-review.yaml
nats/surveyor@0.20.9defaultwatchruntime-reviewrecipes/nats/surveyor/0.20.9/runtime-review.yaml
nats/surveyor@0.20.9default-reviewedwatchruntime-reviewrecipes/nats/surveyor/0.20.9/runtime-review.yaml
open-telemetry/opentelemetry-operator@0.114.0defaultwatchgitops-runtime-reviewrecipes/open-telemetry/opentelemetry-operator/0.114.0/gitops-runtime-review.yaml
opencost/opencost@2.5.21defaultwatchruntime-review-
prometheus-community/prometheus@29.9.0defaultwatchgitops-runtime-reviewrecipes/prometheus-community/prometheus/29.9.0/gitops-runtime-review.yaml
traefik/traefik@40.2.0no-crdswatchgitops-runtime-reviewrecipes/traefik/traefik/40.2.0/gitops-runtime-review.yaml
istio/istiod@1.30.0defaultblockedstage-prerequisiterecipes/istio/istiod/1.30.0/target-prerequisite-plan.yaml
jaegertracing/jaeger-operator@2.57.0defaultblockedstage-prerequisiterecipes/jaegertracing/jaeger-operator/2.57.0/target-prerequisite-plan.yaml
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedcapability-profile-baserecipes/prometheus-community/prometheus-adapter/5.3.0/CATALOG.md
prometheus-community/prometheus-adapter@5.3.0defaultblockedcapability-profile-baserecipes/prometheus-community/prometheus-adapter/5.3.0/CATALOG.md
rook-release/rook-ceph-cluster@v1.19.5defaultblockedstage-prerequisiterecipes/rook-release/rook-ceph-cluster/v1.19.5/target-prerequisite-plan.yaml
velero/velero@12.0.1defaultblockedrender-input-modelrecipes/velero/velero/12.0.1/value-model.yaml
velero/velero@12.0.1no-crdsblockedrender-input-modelrecipes/velero/velero/12.0.1/value-model.yaml
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultblockedinspect-parity-diff-
bitnami/apache@11.4.29legacyblockedinspect-parity-diff-
bitnami/contour@21.1.4no-crdsblockedinspect-parity-diff-
bitnami/elasticsearch@22.1.6legacyblockedinspect-parity-diff-
bitnami/opensearch@2.0.10defaultblockedinspect-parity-diff-
bitnami/opensearch@2.0.10hablockedinspect-parity-diff-
bitnami/opensearch@2.0.10legacyblockedinspect-parity-diff-
bitnami/phpmyadmin@20.0.0legacyblockedinspect-parity-diff-
bitnami/spark@10.0.3legacyblockedinspect-parity-diff-
bitnami/zookeeper@13.8.7legacyblockedinspect-parity-diff-
grafana/pyroscope@2.0.2hablockedinspect-parity-diff-
hashicorp/terraform@1.1.2defaultblockedinspect-parity-diff-
nats/nack@0.34.0defaultblockedinspect-parity-diff-
nats/nats@2.14.0hablockedinspect-parity-diff-
prometheus-community/kube-prometheus-stack@86.1.0defaultblockedinspect-parity-diff-
traefik/traefik@40.2.0defaultblockedinspect-parity-diff-
autoscaler/cluster-autoscaler@9.57.0controller-default-reviewedblockedinspect-receipt-
bitnami/apache@11.4.29defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/elasticsearch@22.1.6defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/elasticsearch@22.1.6hablockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/phpmyadmin@20.0.0defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/spark@10.0.3defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/spark@10.0.3hablockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/zookeeper@13.8.7defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
bitnami/zookeeper@13.8.7hablockedimage-retention-reviewdata/image-digest-workdown/summary.md
elastic/filebeat@8.5.1defaultblockedstage-prerequisiterecipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml
elastic/metricbeat@8.5.1defaultblockedstage-prerequisite-
hashicorp/terraform@1.1.2no-crdsblockedstage-prerequisiterecipes/hashicorp/terraform/1.1.2/target-prerequisite-plan.yaml
istio/gateway@1.30.0controller-default-reviewedblockedimage-retention-reviewdata/image-digest-workdown/summary.md
istio/gateway@1.30.0defaultblockedimage-retention-reviewdata/image-digest-workdown/summary.md
istio/istiod@1.30.0defaultblockedstage-prerequisiterecipes/istio/istiod/1.30.0/target-prerequisite-plan.yaml
jaegertracing/jaeger-operator@2.57.0defaultblockedstage-prerequisiterecipes/jaegertracing/jaeger-operator/2.57.0/target-prerequisite-plan.yaml
jaegertracing/jaeger-operator@2.57.0no-crdsblockedstage-prerequisiterecipes/jaegertracing/jaeger-operator/2.57.0/target-prerequisite-plan.yaml
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultblockedrender-input-modelrecipes/nfs-subdir-external-provisioner/nfs-subdir-external-provisioner/4.0.18/value-model.yaml
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedstage-prerequisite-
prometheus-community/prometheus-adapter@5.3.0defaultblockedstage-prerequisite-
rook-release/rook-ceph-cluster@v1.19.5defaultblockedstage-prerequisiterecipes/rook-release/rook-ceph-cluster/v1.19.5/target-prerequisite-plan.yaml
velero/velero@12.0.1defaultblockedinspect-receipt-
velero/velero@12.0.1no-crdsblockedstage-prerequisite-
bitnami/contour@21.1.4defaultblockedlifecycle-route-
dex/dex@0.24.0defaultblockedruntime-review-
elastic/filebeat@8.5.1node-or-cluster-collectorblockedruntime-reviewrecipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml
elastic/kibana@8.5.1defaultblockedruntime-review-
gitlab/gitlab-runner@0.89.0defaultwatchruntime-review-
kyverno/kyverno-policies@3.8.0defaultwatchruntime-review-
nats/surveyor@0.20.9defaultblockedruntime-reviewrecipes/nats/surveyor/0.20.9/runtime-review.yaml
nats/surveyor@0.20.9default-reviewedblockedruntime-reviewrecipes/nats/surveyor/0.20.9/runtime-review.yaml
opencost/opencost@2.5.21defaultblockedruntime-review-

Local Live Non-Pass Triage

Every chart/base row now has local-kind observation evidence. Passing rows prove that the rendered objects converged on the tested target. Non-pass rows are classified here so they become next actions rather than vague failures.

Route classRowsNext action
runtime-readiness22Inspect pod logs/events, decide whether the issue is target policy, lifecycle, chart configuration, or a better base, then rerun.
target-prerequisite10Turn the missing target condition into a target fact, preflight, lifecycle route, or better base variant.
image-dependency6Pin, mirror, override, or document the image dependency, then rerun against a target that can pull it.
webhook-cert-lifecycle4Model the serving certificate as a generated fact, target fact, cert-manager dependency, preflight, or explicit lifecycle action, then rerun.
admission-or-rbac3Decide whether the base needs a permission/admission preflight, a different target scope, or a rejected support boundary.
api-version-unsupported2Use a supported chart version, compatibility base, or target Kubernetes profile before rerun.
cloud-or-provider-prerequisite2Model the provider dependency as target facts or an external managed prerequisite before rerun.
inspect-receipt1Read the receipt and add a classifier rule only after the product route is clear.
lifecycle-ordering1Use the lifecycle route for this chart, then observe the staged apply or cleanup sequence with a receipt.
ChartBaseResultRoute class
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultfailadmission-or-rbac
velero/velero@12.0.1defaultblockedadmission-or-rbac
velero/velero@12.0.1no-crdsblockedadmission-or-rbac
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedapi-version-unsupported
prometheus-community/prometheus-adapter@5.3.0defaultblockedapi-version-unsupported
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultfailcloud-or-provider-prerequisite
grafana/tempo@1.24.4s3-query-observabilityblockedcloud-or-provider-prerequisite
bitnami/spark@10.0.3defaultblockedimage-dependency
bitnami/spark@10.0.3hablockedimage-dependency
bitnami/zookeeper@13.8.7defaultblockedimage-dependency
bitnami/zookeeper@13.8.7hablockedimage-dependency
istio/gateway@1.30.0controller-default-reviewedblockedimage-dependency

Use local-live-triage/summary.md for the full table with receipts and per-row next actions.

Hook And Lifecycle Work

QueueRowsNext action
Hook candidate route plans10Use these as reviewed inputs; do not treat them as maintained receipts or runtime proof.
Hook candidate work orders72Assign base rendering, dependency closure, target preflight, GitOps mapping, receipt, and observation tasks from the generated work-order list.
Hook candidates not yet maintained8Promote each candidate into a maintained lifecycle receipt, runtime observation path, or explicit blocker before support claims.
Hook route selected, observation pending0Run the selected lifecycle path and commit execution or observation receipts.
Hook install lifecycle observed, remaining phase pending0Run the remaining lifecycle phase, such as upgrade, and commit the execution or observation receipt.
Hook-bearing rows observed5Keep receipt freshness current when the supported target changes.
Related CRD/webhook/controller observations4Use these as examples for hook-like lifecycle proof, not as universal hook support.

Spreadsheet forms: next-work-queues.csv and active-proof-queue.csv.

Chart Use Answers

The Chart Use Guide is the user-facing route into the top-100 data. It answers whether a chart is ready to try from the public catalog, needs promotion review, needs a better base variant, or needs a limitation decision first.

AnswerChartsMeaning
yes-public-catalog20Public catalog entry exists. Choose a base and check the proof lane you need.
not-yet-public-catalog-proof-ready37Proof exists and variants look useful, but catalog promotion review is not done.
not-yet-user-ready33The current proof is too default-shaped; design a useful base variant first.
decision-needed-first9A named gap must be supported, disclosed, deferred, or blocked before promotion.

Use chart-use-guide/summary.md for one row per top-100 chart and the next command or file to open.

Top100 Readiness

Adoption bucketCharts
promote-after-review37
needs-useful-variant33
try-from-public-catalog20
limitation-decision-first9
not-ready1
Strongest evidenceCharts
live-helm-vs-confighub-parity74
in-confighub-proof13
local-kubernetes-live8
two-cluster-kind-parity5

The top100 is model-supported, but not uniformly live-proven. Use top100-readiness/readiness.csv for one row per chart, and outcome-coverage/base-outcomes.csv for exact chart/base lane status.

Top500 Evidence Map

The top500 table is retained source reconnaissance joined to the current recipe/package corpus. It shows which retained source-scan rows now have current proof, which rows only have source facts, and where the retained source version differs from the maintained recipe version.

Catalog statusRows
not-in-catalog409
proof-grade71
catalog-supported20
Recipe statusRows
no-current-recipe409
current-recipe-exact-version70
current-recipe-different-version21

Use top500-catalog-analysis/summary.md for the narrative and top500-catalog-analysis/review.csv for one row per retained source-scan chart.

Top20 Catalog Status

This is the compact chart-by-chart view for the public catalog. It shows the supported base variants, current evidence strength, and lane counts. The CSV also includes each chart's feature summary for hooks, CRDs, generated Secrets, webhooks, values schemas, and other tracked quirks. Use top20-status.csv when you want the same data in a spreadsheet.

ChartRecommended baseBase readinessStrongest evidenceRenderConfigHubLocal liveGitOps liveLive parityHard gap
argo-cd/argo-cd@9.5.15default (start-here)start-here:1; render-only:1live-helm-vs-confighub-parity2/22/21/22/22/2ha (curated proof lane - bespoke teaching needed)
bitnami/mongodb@19.0.7existing-secret-replicaset (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2-
bitnami/mysql@14.0.3existing-secret (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2ha (curated proof lane - bespoke teaching needed)
bitnami/nginx@24.0.2http-clusterip (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2existing-secret (chart ships no Secret toggle)
bitnami/postgresql@18.6.7existing-secret (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2ha (curated proof lane - bespoke teaching needed)
bitnami/rabbitmq@16.0.14existing-secret (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2ha (curated proof lane - bespoke teaching needed)
bitnami/redis@25.5.3reuse-existing-secret (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2-
external-secrets/external-secrets@2.5.0default (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-
grafana/grafana@10.5.15existing-secret-ingress (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-
grafana/loki@7.0.0single-binary-filesystem (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-
grafana/tempo@1.24.4local-persistent (start-here)start-here:1; runtime-watch:1live-helm-vs-confighub-parity2/22/21/21/21/2ha (tempo single-binary chart; HA is the separate tempo-distributed chart)
hashicorp/consul@2.0.0default-control-plane (start-here)start-here:1; runtime-watch:1live-helm-vs-confighub-parity2/22/21/21/21/2ha (curated proof lane - bespoke teaching needed)
hashicorp/vault@0.32.0default (start-here)start-here:2; runtime-watch:1live-helm-vs-confighub-parity3/33/32/32/32/3-
ingress-nginx/ingress-nginx@4.15.1internal-clusterip (start-here)start-here:3live-helm-vs-confighub-parity3/33/33/33/33/3-
jetstack/cert-manager@v1.20.2crds-enabled (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-
longhorn/longhorn@1.11.2default (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-
metrics-server/metrics-server@3.13.0default (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2existing-secret (chart ships no Secret toggle)
prometheus-community/kube-prometheus-stack@85.3.3default (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2existing-secret (chart ships no Secret toggle)
prometheus-community/prometheus@29.8.0server-only-ephemeral (render-only)render-only:2live-helm-vs-confighub-parity2/22/22/22/22/2ha (curated proof lane - bespoke teaching needed)
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0default (start-here)start-here:2live-helm-vs-confighub-parity2/22/22/22/22/2-

The table is deliberately lane-specific. A chart can be useful today without every lane passing for every base variant. The exact per-base rows are in outcome-coverage/base-outcomes.csv. The Base readiness column is generated from top20-base-readiness/base-readiness.csv, which is the better source when the question is which base variant to try first.

Live And Parity Residue

LanePassNon-passMissingTotal
in-ConfigHub19801199
local live148510199
GitOps/OCI live139600199
live Helm-vs-ConfigHub parity139600199
two-cluster kind parity130490179

Non-pass live receipts are useful evidence. They usually identify a target prerequisite, runtime behavior, or provisioning boundary rather than a render parity failure.

Current semantic parity defect receipts:

ConfigHub/OCI live comparison: 0/199
two-cluster kind parity:       16/179

The two-cluster kind parity lane is the cleanest live comparison for chart/base rows: regular Helm is applied to one vanilla kind cluster and the cub installer rendered objects are applied to another vanilla kind cluster. The receipts then compare the live outcomes. Use live-kind-parity/summary.csv for those rows.

Live Parity Next Actions

The rerun plan groups non-pass rows by the work needed before another rerun is useful.

Rerun readinessRowsMeaning
inspect-diff-first16Inspect the semantic diff before another rerun.
model-or-stage-first51Stage the prerequisite, choose the lifecycle route, or record the operating policy before rerunning.
review-target-first39Review runtime, storage, controller health, or wait conditions before rerunning.
inspect-receipt-first2Read the receipt and classify the row before rerunning.
Next stepRowsMeaning
inspect-parity-diff16Inspect the semantic object diff before changing waits, target provisioning, or the recipe.
stage-prerequisite13Stage or model CRDs, APIs, Secrets, storage, or another target prerequisite before rerunning.
lifecycle-route1Choose the hook or lifecycle observation route before rerunning strict parity.
operating-policy1Record the operating policy decision, then rerun only if expected readiness changes.
target-fit-review1Choose a target that provides the required platform behavior, or create a base that fits the target.
gitops-runtime-review14Inspect GitOps/controller health and rerun after target conditions or controller waits are corrected.
runtime-review25Inspect runtime readiness, waits, storage, capacity, or app initialization before rerunning.
inspect-receipt2Read the receipt and classify the row before rerunning.
capability-profile-base2Read the receipt and classify the row before rerunning.
image-retention-review30Read the receipt and classify the row before rerunning.
render-input-model3Model the required Helm values as a real base before rerunning.

Use live-parity-rerun-plan/summary.md for the exact row, command, receipt, diagnosis, and follow-up.

Current ConfigHub/OCI live parity non-pass receipts:

ChartVariantResultReason
argo-cd/argo-cd@9.5.17defaultwatchgitops-runtime: child Argo Application not materialized (parity passed)
hashicorp/vault@0.32.0ha-raft-uiwatchoperate-policy: Vault init/unseal readiness (parity passed)
prometheus-community/prometheus@29.9.0defaultwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)
bitnami/mongodb@19.0.9existing-secret-replicasetwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)
bitnami/mongodb@19.1.0existing-secret-replicasetwatchgitops-runtime: StatefulSet OutOfSync health Healthy (parity passed)
bitnami/nginx@24.0.4existing-tls-ingresswatchgitops-runtime: Argo health Progressing (parity passed)
bitnami/nginx@25.0.0existing-tls-ingresswatchgitops-runtime: Argo health Progressing (parity passed)
grafana/tempo@1.24.4s3-query-observabilitywatchgitops-runtime: Argo health Progressing (parity passed)
hashicorp/consul@2.0.0secure-mesh-existing-secretswatchgitops-runtime: Argo health Progressing (parity passed)
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultwatchtarget-fit: AWS/EKS metadata or provider identity missing on vanilla kind (parity passed)
bitnami/apache@11.4.29defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/apache@11.4.29legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/contour@21.1.4defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/contour@21.1.4legacywatchwatch: inspect receipt
bitnami/contour@21.1.4no-crdswatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/elasticsearch@22.1.6defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/elasticsearch@22.1.6hawatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/elasticsearch@22.1.6legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/opensearch@2.0.10defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/opensearch@2.0.10hawatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/opensearch@2.0.10legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/phpmyadmin@20.0.0defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/phpmyadmin@20.0.0legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/spark@10.0.3defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/spark@10.0.3hawatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/spark@10.0.3legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/zookeeper@13.8.7defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/zookeeper@13.8.7hawatchremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/zookeeper@13.8.7legacywatchremote-image: image pull failed or pinned image is unavailable (parity passed)
dex/dex@0.24.0defaultwatchtarget-runtime: pod config/runtime errors (parity passed)
elastic/filebeat@8.5.1defaultwatchtarget-runtime: pod ContainerCreating (parity passed)
elastic/filebeat@8.5.1node-or-cluster-collectorwatchtarget-runtime: pod ContainerCreating (parity passed)
elastic/kibana@8.5.1defaultwatchtarget-runtime: pod ContainerCreating (parity passed)
elastic/metricbeat@8.5.1defaultwatchtarget-runtime: pod ContainerCreating (parity passed)
fluent/fluentd@0.5.3defaultwatchtarget-runtime: pod config/runtime errors (parity passed)
gitlab/gitlab-runner@0.89.0defaultwatchtarget-runtime: ConfigHub workload not ready (parity passed)
grafana/pyroscope@2.0.2defaultwatchtarget-runtime: ConfigHub workload not ready (parity passed)
grafana/pyroscope@2.0.2hawatchtarget-runtime: ConfigHub workload not ready (parity passed)
grafana/pyroscope@2.0.2no-crdswatchtarget-runtime: ConfigHub workload not ready (parity passed)
hashicorp/terraform@1.1.2defaultwatchtarget-runtime: pod ContainerCreating (parity passed)
hashicorp/terraform@1.1.2no-crdswatchtarget-runtime: pod ContainerCreating (parity passed)
istio/gateway@1.30.0controller-default-reviewedwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
istio/gateway@1.30.0defaultwatchremote-image: image pull failed or pinned image is unavailable (parity passed)
istio/istiod@1.30.0defaultblockedtarget-prerequisite: namespace missing (parity passed)
jaegertracing/jaeger-operator@2.57.0defaultblockedtarget-prerequisite: cert-manager CRDs missing
jetstack/trust-manager@v0.22.1defaultwatchgitops-runtime: Argo health Progressing (parity passed)
kyverno/kyverno-policies@3.8.0defaultwatchgitops-runtime: ClusterPolicy OutOfSync health Healthy (parity passed)
linkerd/linkerd-crds@1.8.0defaultwatchgitops-runtime: CustomResourceDefinition OutOfSync health Healthy (parity passed)
minio-operator/tenant@7.1.1defaultwatchgitops-runtime: Argo health Progressing (parity passed)
nats/surveyor@0.20.9defaultwatchtarget-runtime: pod config/runtime errors (parity passed)
nats/surveyor@0.20.9default-reviewedwatchtarget-runtime: pod config/runtime errors (parity passed)
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultblockedhelm-runtime: upstream leg blocked
open-telemetry/opentelemetry-operator@0.114.0defaultwatchgitops-runtime: Argo health Progressing (parity passed)
opencost/opencost@2.5.21defaultwatchtarget-runtime: pod config/runtime errors (parity passed)
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedcapability-profile: rendered APIService version is not served by target Kubernetes
prometheus-community/prometheus-adapter@5.3.0defaultblockedcapability-profile: rendered APIService version is not served by target Kubernetes
rook-release/rook-ceph-cluster@v1.19.5defaultblockedtarget-prerequisite: namespace missing (parity passed)
traefik/traefik@40.2.0no-crdswatchgitops-runtime: Argo health Progressing (parity passed)
velero/velero@12.0.1defaultblockedrender-input: required Velero provider values missing
velero/velero@12.0.1no-crdsblockedrender-input: required Velero provider values missing

Current two-cluster kind parity non-pass receipts:

ChartBaseResultReason
autoscaler/cluster-autoscaler@9.57.0controller-default-reviewedblockedblocked: inspect receipt
autoscaler/cluster-autoscaler@9.57.0defaultwatchrender-input: required Helm values missing (parity passed)
aws-ebs-csi-driver/aws-ebs-csi-driver@2.60.1defaultblockedparity: semantic object diff
bitnami/apache@11.4.29defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/apache@11.4.29legacyblockedparity: semantic object diff
bitnami/contour@21.1.4defaultblockedhelm-hook: pre-install certificate generation failed (parity passed)
bitnami/contour@21.1.4no-crdsblockedparity: semantic object diff
bitnami/elasticsearch@22.1.6defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/elasticsearch@22.1.6hablockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/elasticsearch@22.1.6legacyblockedparity: semantic object diff
bitnami/opensearch@2.0.10defaultblockedparity: semantic object diff
bitnami/opensearch@2.0.10hablockedparity: semantic object diff
bitnami/opensearch@2.0.10legacyblockedparity: semantic object diff
bitnami/phpmyadmin@20.0.0defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/phpmyadmin@20.0.0legacyblockedparity: semantic object diff
bitnami/spark@10.0.3defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/spark@10.0.3hablockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/spark@10.0.3legacyblockedparity: semantic object diff
bitnami/zookeeper@13.8.7defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/zookeeper@13.8.7hablockedremote-image: image pull failed or pinned image is unavailable (parity passed)
bitnami/zookeeper@13.8.7legacyblockedparity: semantic object diff
dex/dex@0.24.0defaultblockedtarget-runtime: pod crash loop (parity passed)
elastic/filebeat@8.5.1defaultblockedtarget-prerequisite: required Secret missing (parity passed)
elastic/filebeat@8.5.1node-or-cluster-collectorblockedhelm-runtime: upstream not ready (parity passed)
elastic/kibana@8.5.1defaultblockedhelm-runtime: upstream not ready (parity passed)
elastic/metricbeat@8.5.1defaultblockedtarget-prerequisite: required Secret missing (parity passed)
gitlab/gitlab-runner@0.89.0defaultwatchhelm-runtime: upstream not ready (parity passed)
grafana/pyroscope@2.0.2hablockedparity: semantic object diff
hashicorp/terraform@1.1.2defaultblockedparity: semantic object diff
hashicorp/terraform@1.1.2no-crdsblockedtarget-prerequisite: required Secret missing (parity passed)
istio/gateway@1.30.0controller-default-reviewedblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
istio/gateway@1.30.0defaultblockedremote-image: image pull failed or pinned image is unavailable (parity passed)
istio/istiod@1.30.0defaultblockedtarget-prerequisite: required Namespace missing (parity passed)
jaegertracing/jaeger-operator@2.57.0defaultblockedtarget-prerequisite: cert-manager CRDs missing
jaegertracing/jaeger-operator@2.57.0no-crdsblockedtarget-prerequisite: cert-manager CRDs missing
kyverno/kyverno-policies@3.8.0defaultwatchwatch: object parity passed; readiness needs review
nats/nack@0.34.0defaultblockedparity: semantic object diff
nats/nats@2.14.0hablockedparity: semantic object diff
nats/surveyor@0.20.9defaultblockedtarget-runtime: pod crash loop (parity passed)
nats/surveyor@0.20.9default-reviewedblockedhelm-runtime: upstream not ready (parity passed)
nfs-subdir-external-provisioner/nfs-subdir-external-provisioner@4.0.18defaultblockedrender-input: required Helm values missing
opencost/opencost@2.5.21defaultblockedtarget-runtime: pod crash loop (parity passed)
prometheus-community/kube-prometheus-stack@86.1.0defaultblockedparity: semantic object diff
prometheus-community/prometheus-adapter@5.3.0cluster-metrics-readonlyblockedtarget-prerequisite: CRDs missing
prometheus-community/prometheus-adapter@5.3.0defaultblockedtarget-prerequisite: CRDs missing
rook-release/rook-ceph-cluster@v1.19.5defaultblockedtarget-prerequisite: required Namespace missing (parity passed)
traefik/traefik@40.2.0defaultblockedparity: semantic object diff
velero/velero@12.0.1defaultblockedblocked: inspect receipt
velero/velero@12.0.1no-crdsblockedtarget-prerequisite: CRDs missing

Production Disposition Boundary

The top-20 catalog entries are currently supported for the declared local-test scope. Production support is tracked separately. A review-ready row has accepted dispositions for scan/gate warnings, lifecycle risks, target facts, storage policy, RBAC, webhook behavior, and extension slots. Final production support is recorded only in the target-scoped support decision artifacts.

MetricValue
production-review-ready disposition rows19/20
production-blocked pending disposition1/20
charts with accepted dispositions20/20
target-scoped support decision artifacts20/20
supported decision artifacts17/20
superseded decision artifacts2/20
rejected decision artifacts1/20
draft decision artifacts0/20
high-priority scan rows4/20
mutable-image rows still needing fixes0/20
Open dispositionCharts
target fact preflight1
Scan routeCharts
accept-or-patch-pdb-policy6
add-resource-policy5
harden-security-context5
accept-or-split-privileged-infrastructure4
ChartProductionAcceptedOpenNext action
argo-cd/argo-cd@9.5.15production-review-ready70record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/mongodb@19.0.7production-review-ready60record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/mysql@14.0.3production-review-ready50record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/nginx@24.0.2production-review-ready40record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/postgresql@18.6.7production-review-ready50record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/rabbitmq@16.0.14production-review-ready50record final target-scoped support decision and refresh live/e2e evidence for that scope
bitnami/redis@25.5.3production-review-ready40record final target-scoped support decision and refresh live/e2e evidence for that scope
external-secrets/external-secrets@2.5.0production-review-ready60record final target-scoped support decision and refresh live/e2e evidence for that scope
grafana/grafana@10.5.15production-review-ready50record final target-scoped support decision and refresh live/e2e evidence for that scope
grafana/loki@7.0.0production-review-ready50record final target-scoped support decision and refresh live/e2e evidence for that scope

Use production-disposition/summary.md for the full top-20 disposition table and scan-disposition-workdown/summary.md for the scan warning routes. Use production-support-decisions/summary.md for target-scoped support decision artifacts.

Derived Variant Evidence

Derived ConfigHub variants are the post-render half of the model. They start from reviewed uploaded bases and use cub variant create plus ConfigHub metadata, targets, gates, links, checks, and receipts. They do not rerender Helm.

MetricValue
derived variant golden rows10/10
live cub variant create receipts10/10
target-bound derived variant receipts6/10

The golden rows are in variant-goldens/derived-expansion-wave/work-orders.csv. Live create receipts are in runs/derived-variant-execution, and target-bound receipts are in runs/derived-variant-target-bound.

Quirk And Hook Residue

Quirk coverage tierAxes
tracked-and-surfaced9
not-scanned6
source-scanned-not-surfaced5
partly-tracked3
tracked-by-lock-not-front-door2
disclosed-not-complete1

Extension Slot Coverage

Extension slots are Helm inputs that can inject raw manifests, templated snippets, config blocks, sidecars, extra volumes, or chart-specific config files. They are useful, but a populated slot changes the install shape. The supported catalog route is to keep them empty or controlled in the first base, then create a reviewed cub installer base when a slot is populated.

ScopeCharts
top-20 catalog charts with extension slots13/20
top-100 chart facts with extension slots82/100
top-500 source rows using tpl362/500
Top-20 chartExample surfacesRoute
argo-cd/argo-cd@9.5.15raw/extra manifests; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
bitnami/mongodb@19.0.7tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
bitnami/nginx@24.0.2NGINX config blocks; raw/extra manifests; sidecarskeep empty in supported bases, or make a reviewed installer base when populated
external-secrets/external-secrets@2.5.0raw/extra manifests; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
grafana/grafana@10.5.15sidecars; monitoring config; Secret/env injectionkeep empty in supported bases, or make a reviewed installer base when populated
grafana/loki@7.0.0raw/extra manifests; Secret/env injection; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
grafana/tempo@1.24.4volumes/mounts; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
hashicorp/consul@2.0.0controller/gateway config; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
hashicorp/vault@0.32.0sidecars; volumes/mounts; Secret/env injectionkeep empty in supported bases, or make a reviewed installer base when populated
jetstack/cert-manager@v1.20.2raw/extra manifests; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
prometheus-community/kube-prometheus-stack@85.3.3raw/extra manifests; monitoring config; tpl-powered valueskeep empty in supported bases, or make a reviewed installer base when populated
prometheus-community/prometheus@29.8.0raw/extra manifests; monitoring configkeep empty in supported bases, or make a reviewed installer base when populated
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0chart-specific tpl/raw/config slotskeep empty in supported bases, or make a reviewed installer base when populated

Use extension-slots/summary.md for the full NGINX-style extension-slot report.

Hook Residue

Hook chartSelected baseCurrent dispositionNext action
prometheus-community/kube-prometheus-stack@85.3.3defaultlifecycle-observedkeep receipt fresh when chart, base, or cluster version changes
kyverno/kyverno@3.8.1defaultlifecycle-observedkeep receipt fresh when chart, base, or cluster version changes
fluent/fluent-bit@0.57.6defaultlifecycle-observedkeep receipt fresh when chart, base, or cluster version changes
projectcalico/tigera-operator@v3.32.0defaultlifecycle-observedkeep receipt fresh when chart, base, or cluster version changes
gatekeeper/gatekeeper@3.22.2defaultlifecycle-observedkeep receipt fresh when chart, base, or cluster version changes

Hook rows are not support claims. Route-selected means the chart has an explicit handling plan; lifecycle-observed means that plan has runtime or execution evidence. The hook doctrine is Seven-Stage Helm Lifecycle and Hook Lifecycle Strategy.

The generated boundary table separates hook queue rows from hook-like controller lifecycle observations:

Lifecycle laneRows
helm-hook-lifecycle-queue5
hook-like-lifecycle-observation4
selected-hook-route4

Open lifecycle-boundary/summary.md when the question is whether a row proves hook execution or only proves controller lifecycle observation.

How To Use This

QuestionOpen
Can I use this chart today?chart-use-guide/summary.md
What is the underlying top-100 readiness row?top100-readiness/readiness.csv
Which top-100 rows satisfy the strict coverage contract?top100-coverage/coverage.csv
Which top-100 partial rows should move next?top100-coverage/work-queue.md
Which top-100 promotion rows are first?top100-promotion-wave/summary.md
Which top-100 rows need a human limitation decision?top100-coverage/decisions-needed.md
How much of the retained top500 source scan maps to current proof?top500-catalog-analysis/review.csv
Which base variants have which proof lanes?outcome-coverage/base-outcomes.csv
Which top-20 base variant should I start with?top20-base-readiness/summary.md
Which hooks, APIService, CRDs, generated facts, Secrets, or target facts matter?outcome-coverage/feature-outcomes.csv
Which Secrets are delivered, staged, observed, or still need lifecycle support?secret-lifecycle/summary.md
Which APIService charts have object, workload, parity, or aggregation evidence?apiservice-coverage/summary.md
Which APIService proof row should move next?apiservice-coverage/work-orders.md
Which charts have NGINX-like extension slots?extension-slots/summary.md
Which Helm quirk axes are still blind spots?quirk-coverage/coverage.csv
Which source-scan quirk gaps should move first?quirk-work-queue/summary.md
Which remote dependency closures are locked?remote-dependency-closure/summary.md
Which top-100 source rows contain Helm hooks, and are they covered?hook-coverage/summary.md
Which top-100 source rows contain Helm hooks?hook-lifecycle/source-top100-hooks.csv
Which maintained hook rows need lifecycle receipts?hook-lifecycle/maintained-hook-queue.csv
Which hook route candidates have assignable next work?hook-route-candidates/work-orders.md
Which hook claims are queued versus observed?lifecycle-boundary/summary.md
Which Helm artifacts have recovered graph fragments?edge-recovery/summary.md
Which live comparisons passed or failed?live-helm-confighub-compare/summary.csv
Which live rows should be rerun next?live-parity-rerun-plan/summary.md
Which top-20 charts are production-supported?production-support-decisions/summary.md
Which production-support tasks can be assigned?production-support-decisions/work-items.csv
Which top-20 upstream updates should move next?latest-top20-refresh/action-queue/summary.md
Which derived variants are specified or executed?variant-goldens/derived-expansion-wave/work-orders.csv

Regenerate:

npm run status:dashboard
npm run status:dashboard:verify