NGINX ConfigHub Proof Target Plan

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

Decision

NGINX is the next live evidence target after Redis.

Status: completed for the http-clusterip baseline on 2026-05-27.

Why NGINX

NGINX is the right next chart because it is the easiest happy-path contrast with Helm:

install a common web component
see the exact objects
scan the uploaded Units
prove target facts for the TLS/Ingress variant
stop before live apply unless a target exists

It is also not trivial. The current recipe has two candidate variants:

VariantWhy It Matters
http-clusteripsimple baseline that should feel easier than Helm
existing-tls-ingressproves target facts for existing TLS Secrets and ingress exposure

Acceptance Contract

Before NGINX can move beyond local/test support, the live evidence lane should prove:

Current Status

NGINX is a top-20 catalog entry and is catalog-supported for the declared local/test scope. The machine proof shows Helm equivalence:

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

http-clusterip: 5 Helm objects, 6 cub installer objects including Namespace
existing-tls-ingress: 6 Helm objects, 7 cub installer objects including Namespace

The Redis ConfigHub proof transcript shape has now been repeated for NGINX, starting with http-clusterip.

Evidence:

docs/demo/nginx/confighub-proof.md
docs/demo/nginx/confighub-proof-transcript.md
runs/nginx-confighub-proof/latest/confighub-proof-receipt.yaml
runs/nginx-confighub-proof/latest/function-scan-receipt.yaml
runs/nginx-confighub-proof/latest/safe-ops-receipt.yaml

Recommended next chart target: Metrics Server, because it is still small but exercises APIService and target-fact/capability behavior that NGINX does not.