Known Adversarial Public Charts

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

Use this list to keep top-20/top-50 proof runs grounded in real public Helm chart behavior. Enterprise-internal chart variants are out of scope for this catalog proof.

The point is not to pick impossible charts. The point is to prove that ConfigHub can classify, control, render, scan, gate, publish, and explain real public-chart behavior.

ChartStress FeaturesProof Focus
bitnami/redisgenerated password, existing secret, StatefulSet/PVC, secret separationfirst complete proof, Helm equivalence, variants
jetstack/cert-managerCRDs, webhooks, hook-like lifecycle, cert bootstrapCRD readiness, webhook/admission risk, lifecycle policy
prometheus-community/kube-prometheus-stacklarge CRD set, umbrella chart, dependencies, RBAC, webhooksscale, CRD ordering, dependency closure, policy scans
external-secrets/external-secretsCRDs, webhooks, RBAC, controller semanticsCRD/webhook/RBAC control points
argo-cd/argo-cdCRDs, RBAC, raw/extra manifests, GitOps integrationConfigHub OCI -> GitOps handoff, extension slots
ingress-nginx/ingress-nginxcapability branching, admission webhook, cluster RBACcapability profiles, webhooks, cluster-scope resources
grafana/lokiobject graph complexity, storage modes, generated configvariants, graph checks, storage risk
kubernetes-dashboard/kubernetes-dashboardgenerated certs, RBAC, service exposuregenerated facts, RBAC scan, ingress/service variants
bitnami/postgresql-hastateful/PVC, generated credentials, upgrade hooksgenerated facts, PVC policy, upgrade/rollback receipts
longhorn/longhornCRDs, daemonsets, cluster permissions, storage lifecycleCRD/RBAC/storage lifecycle readiness
istio/istiodCRDs, webhooks, APIService/aggregation, capability sensitivityAPI capability profile, admission risks

Required Coverage

The first adversarial public chart set must include:

Linked P0 Gates

Rows in generated spreadsheets should point back to the chart's readiness card, control points, rendered object digest, scan/gate result, and proof receipts.

Hook-Heavy Coverage

The top-500 source scan found 54 charts with Helm hooks. A first-pass risk pass classified 42 as likely problematic for production lifecycle support, because they include non-test lifecycle phases, hook ordering/delete policy, Jobs, cluster RBAC, CRDs, webhooks, APIServices, lookup, or generated-fact signals.

Keep these public examples in adversarial coverage:

ChartWhy
prometheus-community/kube-prometheus-stackpost/pre lifecycle hooks, CRDs, webhooks, RBAC, lookup, generated facts.
jetstack/cert-managerpost-install startup API check, CRDs, admission webhooks, cluster RBAC.
kyverno/kyvernopost-upgrade/pre-delete hooks, hook weights/delete policy, admission/CRD risk.
kubernetes-dashboard/kubernetes-dashboardupgrade hooks, generated facts, RBAC, APIService.
kong/kongpre/post-upgrade hooks, CRDs, webhooks, RBAC.
ory/hydra / ory/kratospre-install/pre-upgrade hooks with migration-style lifecycle concerns.

For each, the proof target is not "run Helm hooks invisibly." The target is:

hook inventory -> lifecycle disposition -> safe translation or blocker ->
receipt / observation