grafana/tempo 1.24.4 Weirdness And Mitigations

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note records the Helm pain surfaced during catalog review and where the current ConfigHub/cub installer proof absorbs it.

Support Boundary

FieldValue
Catalog statuscatalog-supported
Support levelsupported-for-declared-scopes
Supported scopeslocal-test
Production readinessproduction-review-ready
Variants in this notelocal-persistent, s3-query-observability

Production support is not implied by this file. A chart can be supported for local proof/demo use while still needing accepted scan, gate, lifecycle, and operating-policy dispositions plus a final target-scoped support decision.

Chart Notes

Catalog Mitigations

Control Points

Control pointStatusMitigation / evidence
source-lockhandledsource-lock.yaml
dependency-lockhandledchart declares no subchart dependencies; the empty closure is recorded explicitly.
capability-profilehandledKubernetes API and version branches are bound to the named Kubernetes capability profile.
chart-deprecationnotedThe literal grafana/tempo chart is deprecated; the proof records that status and notes the maintained successor chart separately.
target-factsvariant-controlledThe s3-query-observability variant declares S3 endpoint, bucket, and region as pre-render values, and references credentials from a target Secret instead of embedding access keys in rendered ConfigMaps.
object-store-runtime-prerequisitetarget-fact-requiredThe S3 variant needs the declared endpoint, bucket, region, and credentials to be real before Tempo becomes ready; the strict live parity lane stages a local S3-compatible target prerequisite.
capability-profilevariant-controlledThe ServiceMonitor variant records the Prometheus Operator API as an explicit target capability.
servicemonitor-crd-target-facttarget-factThe Tempo chart renders a ServiceMonitor when the API is declared, but the Prometheus Operator CRD must already exist in the target cluster.
stateful-workloadscan-and-reviewapps/v1\StatefulSet\tempo\tempo
query-ingress-policyvariant-controllednetworking.k8s.io/v1\Ingress\tempo\tempo
network-policyscan-and-reviewnetworking.k8s.io/v1\NetworkPolicy\tempo\tempo
servicemonitor-capabilityvariant-controlledmonitoring.coreos.com/v1\ServiceMonitor\tempo\tempo
upstream-runtime-riskscan-and-reviewThe chart StatefulSet references serviceName tempo-headless, but the chart renders no headless Service in these variants.
extension-slotscontrolled-by-empty-defaultsconfig, structuredConfig, extra volume/mount, and tpl-controlled strings are controlled in promoted variants.
installer-support-objecthandledv1\Namespace\\tempo

Control Point Index