helm-expt Test Map

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This is the starting page for all helm-expt testing. It maps every test class across the four systems we exercise - Helm · Kubernetes · ConfigHub · cub - to where it lives and its honest coverage. The detailed strategy, command runbooks, runners, and UX surfaces are the layers beneath it (see The layers).

UNOFFICIAL/EXPERIMENTAL. Testing here means claims matched to evidence, not green-for-its-own-sake. The bar is verified disposition, not "everything green" (see How we state coverage).

The four systems we test

Test classes

GroupClasses
A. Static verification (offline npm run verify)corpus representation · render parity · disposition/frontier · chart-page claim integrity · chart-page omission lint · consistency gates (doc-map, data-index, npm-script-catalog, site, no-personal-names)
B. Live cluster proof (kind, serial, receipted)local k8s live · strict two-cluster kind-parity · GitOps/OCI (Argo/Flux) · live Helm-vs-ConfigHub parity · variant-promotion
C. Lifecycle / hooksobserve → executeemit (GitOps-native)
D. Day-1 preview (cub-scout)compare three-way --dry-from (desired-vs-live, drift)
E. UX / journeyjourney pathways · website-UX walkthrough · outside-user · adversarial-persona probe
F. Adversarial / refusal boundary (a deliberate skeptic breaking the model)torture suite · adversarial-10 · quirk & pain-point coverage
G. Careless-dev randomness (an ordinary dev making silly decisions, repeatedly, at volume)random-bad-decisions fuzz
cub-installer fuzz (bad or weird input aimed at our tool)cub installer fuzz · namespace/input/image validation · injection checks
H. Helm-fluent migrant friction (valid Helm habits applied to cub)Helm idioms rejected safely, with migration guidance measured
I. Agent-generated variants (an agent authors intent; parity decides existence - doctrine #9)switch-effect maps classified by rendering · generate-on-demand parity gate (composition, determinism, routes) · refusal receipts

The coverage matrix

Which system each class exercises, where it lives, and its honest coverage. Legend: ● exercises · ○ partial/indirect · – n/a. Counts are indicative - the authoritative live numbers are in the generated surface linked per row.

Test classHelmk8sConfigHubcubLives inHonest coverage
Render parity<chart>:compare, helm-equivalence receiptscomplete - every catalog base (R all pass) → outcome-coverage
Disposition / frontiermetametametametadisposition-frontier, master-catalog-matrix100% verified disposition, 0 genuine todo
Chart-page claim integritychart-claim-integrity:verify, claim-integrity auditgate is green: chart pages must not make claims that contradict their cited receipts; remaining warnings stay visible → live findings
Chart-page omission lintsite:ux:verifygate is green: chart pages must not leak unresolved <action>: unknown next-action placeholders or raw <tmp> work-dir placeholders
No personal names in committed filesverify:no-personal-namesgate: tracked files outside runs/ must not name people (receipts stay exempt as recorded evidence); green once the #1102 sweep is in
ConfigHub proof (scan/safe-ops)confighub proof lanes, <chart>:verify-proofcomplete in-ConfigHub → outcome-coverage
Local k8s livechart-install-test, local-live receiptspartial, receipt-gated → status-dashboard
Strict kind-parity (2-cluster)live-helm-installer-kind-parity-test, kind-parity:runpartial → live-kind-parity
GitOps / OCI livechart-install-test, runtime-gitopspartial → live-helm-confighub-compare
Live Helm-vs-ConfigHub paritylive-helm-confighub-parity-testpartial → live-parity-rerun-plan
Variant-promotiontarget-bound-derived-variant-test, promotion receipts180 proven → variant-promotion
Lifecycle / hooks (observe→execute→emit)hook-lifecycle, run-hook-test-proof / run-hook-execution-proof, gitops-route-emissionpartial - observed for maintained hook charts; execute + emit proven; routed-but-unobserved cells remain → lifecycle-boundary
cub-scout day-1 previewcub-scout compare three-way --dry-fromshipped command, design-stage coverage → cub-scout-diff
UX: journey pathwaysdocs/user/pathway-*, user-journey-test-pathways-planpartial - Pathway 1 (hooks) shipped; others pending
UX: website / outside-user / adversarialspansspansspansspansWEBSITE_UX_TEST.md, outside-user-test, pilot-adversarial-testing, adversarial-strategy.mdrunbook + plan + probe method
Persona UX strategyspansspansspansspanspersona-ux-strategy.md, issue #1018repeatable site critique method: personas, seed questions, run log, ranked improvements
Adversarial / refusal boundarytorture-suite, adversarial10, quirk-coveragerefusal boundary covered
Random-bad-decisions fuzzrun-bad-decisions-fuzz, bad-decisions-fuzz180 cases, 0 unclassified (rejected 1% / leaked 33% / absorbed 66%)
cub-installer fuzzcub-installer:fuzz, cub-installer-fuzzpass - 96 cases, 0 serious bugs; namespace validation rough edges visible
Helm-fluent migrant frictionhelm-habit:friction, helm-habit-friction, Helm→cub migration guidepass for safety - 72/72 valid Helm idioms rejected; watch the 72/72 opaque guidance gap
Agent-generated variants (parity-gated)pilot:switch-map, pilot:generate-variant, pilot-switch-map, demo-proof planprototype - 5 charts mapped (65 switches classified by rendering); one PASS and one REFUSED receipt (doctrine #9); head-to-head benchmark designed, not yet run
cub-installer determinismcub-installer:determinism, cub-installer-determinismpass - 12/12 packages rendered byte-identically twice
Default credential checkdefault-credential:check, default-credential-checkwatch - 5/12 default bases ship fixed placeholder credentials; 4 names are misleading
cub-scout drift field coveragedrift-gap:proof, drift-detection-gapwatch - replicas drift detected; container env-var drift missed
cub-direct CRD orderingcrd-ordering:proof, crd-ordering-gapwatch - first install of CRD+CR bundles needs CRD-first ordering or a controller
cub-direct prune gapprune-gap:proof, prune-gap-proofwatch - cub-direct plain apply leaves removed resources orphaned; Argo/Flux prune
SSA conflict gapssa-conflict:proof, ssa-conflict-gapwatch - server-side apply protects manual edits with a conflict, but the raw error needs a plain reconcile/force path

How we state coverage

This is the honesty rule that keeps the map trustworthy:

  1. "Complete / 100%" applies only to the static catalog parity & verification - render parity and verified disposition. That part is genuinely finished (1194 frontier cells, 100% verified disposition, 0 genuine todo).
  2. Every live / lifecycle / UX class states its own honest coverage - counts, watch/blocked, and what's pending - never rolled up into a blanket "100% of everything." watchpass; promotion-proven ≠ production-proven; render parity ≠ live-ready; a routed hook ≠ an executed hook.
  3. Each number cites its generated surface (linked above), so the map stays honest and current instead of asserting. The live dashboard is status-dashboard; this page is the map.

The layers

The map routes into the existing detail - fit around this page, not replaced by it:

For…Go to
The standing principles (OCI transport · Argo+Flux+kubectl · never-silent · quirks through ConfigHub)doctrine.md
What claim each lane proves (the Coverage Ladder)strategy.md
Which npm run … matches my editnpm-scripts.md
The generated inventory of every scriptnpm-script-catalog.md
The exact reproducible per-chart procedurerunbook.md
The persona / tier-aware adversarial usage probeadversarial-strategy.md
Persona-based public-site UX testingpersona-ux-strategy.md
Whether a chart page's claims match its cited receiptschart-claim-integrity:verify · claim-integrity audit
Whether chart pages leak unresolved UX placeholderssite:ux:verify
Whether committed files keep personal names outverify:no-personal-names
The fuzz and Helm-migrant roadmapfuzz-corpus-tests-roadmap.md
The recorded F1–F4 findingsfindings.md
The top-100 runtime/GitOps sweep plantop100-runtime-gitops.md
Current aggregate status (the live dashboard)status-dashboard

Test cadence

Use scoped checks while working. Use the full repository verifier (npm run verify) as a broad release gate after focused checks pass. Use live tests only to create or refresh live evidence.

QuestionStart with
Which check matches my edit?npm-scripts.md
What does this exact npm run … do?npm-script-catalog.md
What claim does each lane prove?strategy.md
What is the current chart/base status?status-dashboard
Which live rows to rerun next?live-parity-rerun-plan

Do not use npm run verify as a substitute for a fresh live test (it verifies the committed corpus and receipts). Do not use a live test as a substitute for render parity. They prove different things.

Cluster/runtime runners (resolve the repo from their own location)

Run (standalone)

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

cub auth login                      # verify: cub organization list (NOT cub info)
cub cluster up --name myrig
tests/chart-install-test --package packages/bitnami/nginx/24.0.2 --slug nginx \
  --namespace nginx --rig myrig --json     # add --helm-expt . if run from elsewhere
cub cluster down --name myrig