* feat(bp-falco): umbrella chart for security layer
Catalyst Blueprint umbrella chart for falco — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-kyverno): umbrella chart for security layer
Catalyst Blueprint umbrella chart for kyverno — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-trivy): umbrella chart for security layer
Catalyst Blueprint umbrella chart for trivy — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-sigstore): umbrella chart for security layer
Catalyst Blueprint umbrella chart for sigstore — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-syft-grype): umbrella chart for security layer
Catalyst Blueprint umbrella chart for syft-grype — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-reloader): umbrella chart for security layer
Catalyst Blueprint umbrella chart for reloader — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-coraza): umbrella chart for security layer
Catalyst Blueprint umbrella chart for coraza — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
* feat(bp-litmus): umbrella chart for security layer
Catalyst Blueprint umbrella chart for litmus — security/policy layer.
Pinned upstream + appVersion verified against the helm index on
2026-04-30. ServiceMonitor disabled per BLUEPRINT-AUTHORING.md §11.2.
Solo-Sovereign defaults; per-Sovereign overlays bump to HA later.
Part of security-stack umbrellas batch 3.
---------
Co-authored-by: hatiyildiz <hatice.yildiz@openova.io>
Seven more Application Blueprint banners landed:
- temporal (§4.3): durable workflow orchestration; bp-fabric.
- flink (§4.3): stream + batch processing; bp-fabric.
- debezium (§4.2): CDC into Strimzi/Kafka; bp-fabric pipeline source.
- iceberg (§4.4): open table format on MinIO + archival S3.
- openmeter (§4.8): API metering for bp-fingate.
- litmus (§4.9): chaos engineering required by DORA / NIS2.
- valkey (§4.1): banner explicitly states NOT a Catalyst control-
plane component — control plane uses NATS JetStream KV per
ARCHITECTURE §5 / GLOSSARY event-spine. Valkey is Application-tier
caching only. This is the disambiguation that PLATFORM-TECH-STACK
§1 establishes ("same upstream technology can serve in multiple
categories") — pinned in the per-component README so it can't be
misread.
VALIDATION-LOG: Pass 14 entry added.
Refs #37