prometheus-community/kube-prometheus-stack 85.3.3 Weirdness And Mitigations

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note records the Helm pain surfaced during catalog review and where the current ConfigHub/cub installer proof absorbs it.

Support Boundary

FieldValue
Catalog statuscatalog-supported
Support levelsupported-for-declared-scopes
Supported scopeslocal-test
Production readinessproduction-review-ready
Variants in this notedefault, no-crds

Production support is not implied by this file. A chart can be supported for local proof/demo use while still needing accepted scan, gate, lifecycle, and operating-policy dispositions plus a final target-scoped support decision.

Chart Notes

Catalog Mitigations

Control Points

Control pointStatusMitigation / evidence
source-lockhandledsource-lock.yaml
dependency-lockhandledchart declares CRD, kube-state-metrics, node-exporter, Grafana, and windows-exporter dependencies; promoted variants lock their metadata.
capability-profilehandledOpenShift and ServiceMonitor branches are bound to the named Kubernetes capability profile.
crd-policyvariant-controlled-and-target-factCRDs are ordinary rendered objects in the default variant; no-crds records those same CRDs as target prerequisites.
admission-webhooktarget-fact-and-observeConfig-only delivery must stage the kube-prometheus-stack-admission Secret because Helm normally creates the TLS material through hook lifecycle.
generated-factsvariant-controlledBoth promoted variants bind Grafana admin password before render so Helm output is deterministic.
cluster-rbacscan-and-reviewscan receipts
tplcontrolled-by-empty-defaultsPrometheus/Grafana rules, scrape configs, datasource config, and extraManifests can use templating; promoted variants keep raw slots empty.
installer-support-objecthandledv1\Namespace\\monitoring

Control Point Index