Top-500 Catalog Analysis

A repository document, rendered for the site. View source markdown.

What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This is the public catalog proof index for the Helm mission.

It combines two kinds of evidence:

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

source-feature reconnaissance
  + current ConfigHub/cub installer recipe evidence

The source scan tells us what Helm complexity exists in popular charts. The catalog proof columns tell us whether this repo already has a current recipe, package, variant, rendered digest, scan/gate evidence, and catalog status for that chart.

Summary

rows: 500
source scanned: 495
source failed: 5
current proof recipes in repo: 100
retained newer candidate proof versions: 10
current proof recipes matched to retained source-scan rows: 91
current proof recipes not represented in retained source-scan rows: 9
current recipe proofs: 91
proof matched by exact chart ref: 63
proof matched by chart name and version: 16
proof matched by chart name only: 12
exact source/current version matches: 70
current recipe version differs from retained source-scan row: 21
no current recipe proof: 409
catalog-supported: 20
proof-grade: 71
multi-variant proofs: 62
default-only proofs: 29
catalog-supported production-blocked: 0
catalog-supported production-review-ready: 20

What We Learn

Recent Catalog Learnings (2026-06)

How To Read The Files

FileUse
summary.mdHuman summary and next actions.
review.csvShort front sheet: one row per top-500 chart with proof/catalog status.
drilldown.csvWider evidence table for control points and source features.
raw.jsonMachine-readable generated report.
source/source-feature-scan.raw.jsonHistorical source scan input used to build the current catalog analysis.

Important Boundary

This matrix is an evidence map, not a blanket certification.

catalog-supported = recommended only for the declared scope
proof-grade = deterministic proof exists, but product variants/review remain
source reconnaissance only = no product proof yet

Next Promotion Candidates

These are high-rank proof-grade rows that need real variants before promotion.

RankChartCurrent versionSource featuresNext action
21gitlab/gitlab-runner0.89.0generated-facts;tpl;capabilitiesadd user-shaped variants before catalog promotion
35istio-official/istiod1.30.0tpl;cluster-rbac;webhooksadd user-shaped variants before catalog promotion
42fluent/fluent-bit0.57.6tpl;capabilities;hooks;cluster-rbacadd user-shaped variants before catalog promotion
45runix/pgadmin41.62.0tpl;capabilities;stateful-storageadd user-shaped variants before catalog promotion
51nfs-subdir-external-provisioner/nfs-subdir-external-provisioner4.0.18capabilities;cluster-rbac;stateful-storageadd user-shaped variants before catalog promotion
62elastic/kibana8.5.1tpladd user-shaped variants before catalog promotion
64descheduler/descheduler0.36.0tpl;cluster-rbacadd user-shaped variants before catalog promotion
70jaegertracing/jaeger4.8.0lookup;generated-facts;tpl;capabilitiesadd user-shaped variants before catalog promotion
80dex/dex0.24.0tpl;capabilities;cluster-rbacadd user-shaped variants before catalog promotion
81argo/argocd-image-updater1.2.2tpl;cluster-rbacadd user-shaped variants before catalog promotion

First Rows Without Current Proof

RankChartSource versionSource classificationNext action
9k8s-dashboard/kubernetes-dashboard7.14.0P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
13gitlab/gitlab10.0.0P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
14harbor/harbor1.19.0P1 compiler policy neededcreate recipe, package, variants, rendered digest, scans, and receipts
15bitnami/keycloak25.2.0P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
16jenkinsci/jenkins5.9.22P1 compiler policy neededcreate recipe, package, variants, rendered digest, scans, and receipts
22aws/aws-load-balancer-controller3.3.0P1 compiler policy neededcreate recipe, package, variants, rendered digest, scans, and receipts
23bitnami/kafka32.4.3P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
25bitnami/external-dns9.0.3P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
26apache-airflow/airflow1.21.0P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts
29nextcloud/nextcloud9.1.0P0 source/dependency riskcreate recipe, package, variants, rendered digest, scans, and receipts

Outputs

data/top500-catalog-analysis/raw.json
data/top500-catalog-analysis/review.csv
data/top500-catalog-analysis/drilldown.csv
data/top500-catalog-analysis/summary.md
data/top500-catalog-analysis/source/source-feature-scan.raw.json