Hook And Secret Lifecycle Skill

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

UNOFFICIAL/EXPERIMENTAL

Use this skill when rendered YAML is not enough because the chart relies on Helm hooks, webhook certificate material, service-account token Secrets, or controller-generated state.

Hook Rule

Hooks are not proven by render parity. A hook must be routed as one of:

Read:

open data/hook-coverage/summary.md
open data/hook-lifecycle/summary.md
open data/lifecycle-boundary/summary.md

Secret Rule

Do not treat all Kubernetes Secrets the same.

User credential material includes passwords, tokens, TLS keys, object-store credentials, and existing Secret references. It must be delivered, separated, staged, or target-fact-bound.

Kubernetes lifecycle state includes webhook serving certificates and service-account token Secrets. It must be staged, observed, or refused before stronger live or production claims.

Read:

open data/secret-lifecycle/summary.md
open docs/reference/secret-lifecycle.md

Current Hard Rows

The current Secret lifecycle survey names rows that still need lane support. Treat those as real work, not as generic documentation debt.