bitnami/mongodb 19.0.7 Weirdness And Mitigations

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note records the Helm pain surfaced during catalog review and where the current ConfigHub/cub installer proof absorbs it.

Support Boundary

FieldValue
Catalog statuscatalog-supported
Support levelsupported-for-declared-scopes
Supported scopeslocal-test
Production readinessproduction-review-ready
Variants in this notestatic-passwords, existing-secret-replicaset

Production support is not implied by this file. A chart can be supported for local proof/demo use while still needing accepted scan, gate, lifecycle, and operating-policy dispositions plus a final target-scoped support decision.

Chart Notes

Catalog Mitigations

Control Points

Control pointStatusMitigation / evidence
source-lockhandledsource-lock.yaml
dependency-lockhandledchart declares the Bitnami common dependency; promoted variants lock its metadata.
capability-profilehandledKubernetes API and version branches are bound to the named Kubernetes capability profile.
generated-factsvariant-controlledThe static-passwords variant binds the generated root password before render so Helm output is deterministic.
target-factsvariant-controlledThe existing-secret-replicaset variant declares the target Secret and its MongoDB-valid replica-set key requirement instead of rendering one.
image-digesthandledSupported bases pin the Bitnami MongoDB image by digest.
hook-policyhandled-for-renderThe retained source scan records hook count 0 for this pinned chart line. Supported bases render no hook objects; future hook-producing paths must map to lifecycle policy before production.
replicaset-topologyvariant-controlledapps/v1\StatefulSet\mongodb\mongodb
stateful-workloadscan-and-reviewMongoDB Deployment/PVC and StatefulSet workloads need storage, retention, upgrade, and rollback policy.
pvc-policyscan-and-reviewPersistent volumes and StatefulSet volumeClaimTemplates need storage class, retention, backup, restore, and rollback policy.
network-policyscan-and-reviewnetworking.k8s.io/v1\NetworkPolicy\mongodb\mongodb
pdb-policyscan-and-reviewpolicy/v1\PodDisruptionBudget\mongodb\mongodb
tplcontrolled-by-empty-defaultsinitdb and extended configuration slots use templating; promoted variants do not populate them.
installer-support-objecthandledv1\Namespace\\mongodb

Control Point Index