hashicorp/consul 2.0.0 Weirdness And Mitigations

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note records the Helm pain surfaced during catalog review and where the current ConfigHub/cub installer proof absorbs it.

Support Boundary

FieldValue
Catalog statuscatalog-supported
Support levelsupported-for-declared-scopes
Supported scopeslocal-test
Production readinessproduction-review-ready
Variants in this notedefault-control-plane, secure-mesh-existing-secrets

Production support is not implied by this file. A chart can be supported for local proof/demo use while still needing accepted scan, gate, lifecycle, and operating-policy dispositions plus a final target-scoped support decision.

Chart Notes

Catalog Mitigations

Control Points

Control pointStatusMitigation / evidence
source-lockhandledsource-lock.yaml
dependency-lockhandledchart declares no subchart dependencies; the empty closure is recorded explicitly.
capability-profilehandledKubernetes API and version branches are bound to the named Kubernetes capability profile.
target-factsvariant-controlledThe secure-mesh-existing-secrets variant declares target Secrets for TLS, gossip encryption, and ACL bootstrap material. The server TLS Secret contract includes certificate identity, not just Secret/key presence.
crd-ownershipscan-and-reviewThe chart templates 28 CRDs, including Gateway API CRDs that may already be cluster-managed.
stateful-workloadscan-and-reviewapps/v1\StatefulSet\consul\consul-consul-server
target-topologytarget-fit-requiredThe secure-mesh-existing-secrets base renders three Consul server replicas with pod anti-affinity, so the strict one-node kind target is expected to leave two server pods pending. Use a multi-node target or a separate single-node/evaluation base for live readiness. A three-node rehearsal first exposed invalid server TLS SANs; after SAN-aware target facts, the regular Helm leg converged.
namespace-referencestarget-fit-requiredThe secure-mesh-existing-secrets base contains Consul service DNS, Secret namespace, and ACL init command references that are part of the rendered contract. Deploying the same render into a different namespace needs an explicit namespace-reference preflight, fixed-namespace live mode, or a rerendered base.
admission-webhookscan-and-reviewadmissionregistration.k8s.io/v1\MutatingWebhookConfiguration\consul\consul-consul-connect-injector
cluster-rbacscan-and-reviewDefault and secure variants render broad cluster RBAC for server, injector, gateway resources, and webhook certificate manager.
mesh-gateway-policyvariant-controlledThe secure-mesh-existing-secrets variant enables mesh, ingress, and terminating gateways with ClusterIP services.
ui-ingress-policyvariant-controllednetworking.k8s.io/v1\Ingress\consul\consul-consul-ui
lifecycle-policyscan-and-reviewHooks are disabled in the proof render, while normal ACL init Job remains visible in the secure variant.
extension-slotscontrolled-by-empty-defaultsserver extra config, injector, controller, gateway, and tpl-controlled strings are controlled in promoted variants.
installer-support-objecthandledv1\Namespace\\consul

Control Point Index