Top-20 Start-Here Bases

A repository document, rendered for the site. View source markdown.

What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated page lists the catalog bases that are currently the easiest first paths. Each row has render parity, ConfigHub proof, local live evidence, GitOps/OCI evidence, selected live Helm-vs-ConfigHub parity, and two-cluster kind parity passing for that base.

These are not production support claims. Before production use, check the target-scoped support decision for the chart/base/target you intend to use.

Summary

start-here bases: 26
top-20 base variants: 42
target-scoped supported decisions: 17
target-scoped superseded decisions: 2
target-scoped rejected decisions: 1
target-scoped draft decisions: 0

First Paths

ChartBaseCommandBefore production
argo-cd/argo-cd@9.5.15defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/argo-cd-argo-cd:9.5.15 --base default --work-dir <tmp> --non-interactive --namespace argocdcheck production decision for argo-cd/argo-cd
bitnami/mysql@14.0.3existing-secretcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-mysql:14.0.3 --base existing-secret --work-dir <tmp> --non-interactive --namespace mysqlcheck production decision for bitnami/mysql
bitnami/mysql@14.0.3static-passwordscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-mysql:14.0.3 --base static-passwords --work-dir <tmp> --non-interactive --namespace mysqlcheck production decision for bitnami/mysql
bitnami/rabbitmq@16.0.14existing-secretcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-rabbitmq:16.0.14 --base existing-secret --work-dir <tmp> --non-interactive --namespace rabbitmqcheck production decision for bitnami/rabbitmq
bitnami/rabbitmq@16.0.14static-passwordscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-rabbitmq:16.0.14 --base static-passwords --work-dir <tmp> --non-interactive --namespace rabbitmqcheck production decision for bitnami/rabbitmq
external-secrets/external-secrets@2.5.0defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/external-secrets-external-secrets:2.5.0 --base default --work-dir <tmp> --non-interactive --namespace external-secretscheck production decision for external-secrets/external-secrets
external-secrets/external-secrets@2.5.0no-crdscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/external-secrets-external-secrets:2.5.0 --base no-crds --work-dir <tmp> --non-interactive --namespace external-secretscheck production decision for external-secrets/external-secrets
grafana/grafana@10.5.15existing-secret-ingresscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-grafana:10.5.15 --base existing-secret-ingress --work-dir <tmp> --non-interactive --namespace grafanacheck production decision for grafana/grafana
grafana/grafana@10.5.15static-passwordscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-grafana:10.5.15 --base static-passwords --work-dir <tmp> --non-interactive --namespace grafanacheck production decision for grafana/grafana
grafana/loki@7.0.0single-binary-filesystemcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-loki:7.0.0 --base single-binary-filesystem --work-dir <tmp> --non-interactive --namespace lokicheck production decision for grafana/loki
grafana/loki@7.0.0simple-scalable-miniocub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-loki:7.0.0 --base simple-scalable-minio --work-dir <tmp> --non-interactive --namespace lokicheck production decision for grafana/loki
grafana/tempo@1.24.4local-persistentcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-tempo:1.24.4 --base local-persistent --work-dir <tmp> --non-interactive --namespace tempocheck production decision for grafana/tempo
hashicorp/consul@2.0.0default-control-planecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-consul:2.0.0 --base default-control-plane --work-dir <tmp> --non-interactive --namespace consulcheck production decision for hashicorp/consul
hashicorp/vault@0.32.0defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-vault:0.32.0 --base default --work-dir <tmp> --non-interactive --namespace vaultcheck production decision for hashicorp/vault
hashicorp/vault@0.32.0dev-modecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/hashicorp-vault:0.32.0 --base dev-mode --work-dir <tmp> --non-interactive --namespace vaultcheck production decision for hashicorp/vault
ingress-nginx/ingress-nginx@4.15.1internal-clusteripcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/ingress-nginx-ingress-nginx:4.15.1 --base internal-clusterip --work-dir <tmp> --non-interactive --namespace ingress-nginxcheck production decision for ingress-nginx/ingress-nginx
ingress-nginx/ingress-nginx@4.15.1admission-disabledcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/ingress-nginx-ingress-nginx:4.15.1 --base admission-disabled --work-dir <tmp> --non-interactive --namespace ingress-nginxcheck production decision for ingress-nginx/ingress-nginx
ingress-nginx/ingress-nginx@4.15.1defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/ingress-nginx-ingress-nginx:4.15.1 --base default --work-dir <tmp> --non-interactive --namespace ingress-nginxcheck production decision for ingress-nginx/ingress-nginx
jetstack/cert-manager@v1.20.2crds-enabledcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/jetstack-cert-manager:v1.20.2 --base crds-enabled --work-dir <tmp> --non-interactive --namespace cert-managercheck production decision for jetstack/cert-manager
jetstack/cert-manager@v1.20.2defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/jetstack-cert-manager:v1.20.2 --base default --work-dir <tmp> --non-interactive --namespace cert-managercheck production decision for jetstack/cert-manager
longhorn/longhorn@1.11.2defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/longhorn-longhorn:1.11.2 --base default --work-dir <tmp> --non-interactive --namespace longhorn-systemcheck production decision for longhorn/longhorn
longhorn/longhorn@1.11.2ui-ingresscub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/longhorn-longhorn:1.11.2 --base ui-ingress --work-dir <tmp> --non-interactive --namespace longhorn-systemcheck production decision for longhorn/longhorn
metrics-server/metrics-server@3.13.0defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/metrics-server-metrics-server:3.13.0 --base default --work-dir <tmp> --non-interactive --namespace kube-systemcheck production decision for metrics-server/metrics-server
metrics-server/metrics-server@3.13.0external-tls-cacub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/metrics-server-metrics-server:3.13.0 --base external-tls-ca --work-dir <tmp> --non-interactive --namespace kube-systemcheck production decision for metrics-server/metrics-server
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0defaultcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/secrets-store-csi-driver-secrets-store-csi-driver:1.6.0 --base default --work-dir <tmp> --non-interactive --namespace kube-systemcheck production decision for secrets-store-csi-driver/secrets-store-csi-driver
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0sync-secret-rotationcub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/secrets-store-csi-driver-secrets-store-csi-driver:1.6.0 --base sync-secret-rotation --work-dir <tmp> --non-interactive --namespace kube-systemcheck production decision for secrets-store-csi-driver/secrets-store-csi-driver

After Setup

Replace <tmp> with the work directory from the row you used.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

cub installer render --work-dir <tmp>
cub installer plan --work-dir <tmp>

For a direct local Kubernetes check, apply separated Secrets first only when the work directory contains out/secrets, then apply the manifests:

kubectl apply -f <tmp>/out/secrets
kubectl apply -f <tmp>/out/manifests

For ConfigHub, upload the work directory with the chart's component and variant labels. Use the chart demo transcript for exact labels, or start with the Redis tutorial for the smallest worked example:

cub installer upload --work-dir <tmp> --space <space> ...
FileUse
data/top20-base-readiness/base-readiness.csvFull one-row-per-base table.
data/top20-base-readiness/summary.mdAll readiness categories, including runtime and prerequisite rows.
data/production-support-decisions/summary.mdCurrent target-scoped production support decisions.
data/production-disposition/support-decision-contract.mdPre-decision contract used to create the current support decisions.
CATALOG.mdTop-level chart and variant catalog.