Derived Variant Live Proof

A repository document, rendered for the site. View source markdown.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note tracks the first live ConfigHub execution receipts for the derived variant expansion wave.

The executed slice now covers all five reviewed base Spaces from the generated derived-variant expansion wave:

helm-nginx-confighub-proof
helm-redis-confighub-proof
helm-prometheus-confighub-proof
helm-grafana-confighub-proof
helm-vault-confighub-proof

It proves that the current cub variant create substrate can create downstream ConfigHub variants without re-rendering Helm:

helm-nginx-confighub-proof
  -> NGINX-prod-us-east
  -> NGINX-customer-acme-prod

helm-redis-confighub-proof
  -> Redis-prod-us-east
  -> Redis-staging-eu-west

helm-prometheus-confighub-proof
  -> Prometheus-prod-us-east
  -> Prometheus-staging-eu-west

helm-grafana-confighub-proof
  -> Grafana-prod-us-east
  -> Grafana-customer-acme-prod

helm-vault-confighub-proof
  -> Vault-regulated-prod-us-east
  -> Vault-staging-us-east

The ten live receipts are:

runs/derived-variant-execution/nginx-prod-us-east/variant-create-receipt.yaml
runs/derived-variant-execution/nginx-customer-acme-prod/variant-create-receipt.yaml
runs/derived-variant-execution/redis-prod-us-east/variant-create-receipt.yaml
runs/derived-variant-execution/redis-staging-eu-west/variant-create-receipt.yaml
runs/derived-variant-execution/prometheus-prod-us-east/variant-create-receipt.yaml
runs/derived-variant-execution/prometheus-staging-eu-west/variant-create-receipt.yaml
runs/derived-variant-execution/grafana-prod-us-east/variant-create-receipt.yaml
runs/derived-variant-execution/grafana-customer-acme-prod/variant-create-receipt.yaml
runs/derived-variant-execution/vault-regulated-prod-us-east/variant-create-receipt.yaml
runs/derived-variant-execution/vault-staging-us-east/variant-create-receipt.yaml

The receipts prove:

The Grafana receipts also record a corrective update on deployment-grafana-grafana: the initial clone replaced one duplicated 9094 port's name and protocol with confighubplaceholder. The corrective update restored the reviewed source deployment data before the final data-hash check. That is useful product evidence, not a clean-clone claim.

The active ConfigHub context did not have the desired work-order targets, so these receipts intentionally stop before target binding and live apply. They are live ConfigHub intended-state proofs, not live Kubernetes deployment proofs.

The verifier is:

npm run derived-variants:verify