apiVersion: "catalog.confighub.com/v1alpha1"
kind: "BaseVariantRecord"
metadata:
  name: "aws-controllers-k8s-iam-chart-1-7-3-eks-inference"
  labels:
    sourceType: "helm"
    component: "aws-controllers-k8s/iam-chart"
    sourceVersion: "1.7.3"
    base: "eks-inference"
spec:
  source:
    type: "helm"
    name: "aws-controllers-k8s/iam-chart"
    version: "1.7.3"
    record: "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    packageOciRef: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/aws-controllers-k8s-iam-chart:1.7.3@sha256:bc64855b8024441acf8626c2d586f19661b8750db07eb69064cec52220907aac"
    selection:
      name: "eks-inference"
      kind: "catalog-preset"
      provider: "Config Workshop"
      record: "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
  baseVariant:
    name: "eks-inference"
    revision: "r001"
    digest: "cfb019239b2a3c17d763b54da9071c8e84767d2c851356beaea43fbce2ecbd84"
    digestRole: "helm-variant-revision"
    digestRecord: "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/variant-revision.yaml"
  configuration:
    format: "kubernetes-yaml"
    objects: "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/rendered/release-objects.yaml"
    inventory: "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/rendered/object-inventory.yaml"
    objectCount: 19
    digest: "6f0442b679faf210cd45a2b44856acd2d96b675d5dc004f5b53f33677ec9c67d"
    digestRole: "canonical-object-set"
    digestRecord: "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/variant-revision.yaml"
  processing:
    sourceIntent:
      status: "recorded"
      record: "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    materialization:
      method: "helm-render"
      status: "captured"
      outputDigest: "6f0442b679faf210cd45a2b44856acd2d96b675d5dc004f5b53f33677ec9c67d"
      record: "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/variant-revision.yaml"
    flattening:
      status: "decided"
      verdict: "flatten-with-routes"
      action: "retain-exact-objects-with-routes"
      scope: "aws-controllers-k8s/iam-chart@1.7.3/eks-inference; recheck after source, lifecycle-sensitive variant, destination, or delivery-runtime changes"
      record: "recipes/aws-controllers-k8s/iam-chart/1.7.3/publication/flattening-safety-verdict.yaml"
    boundaries:
      - "Helm rendered the pinned chart and values into the exact objects retained by this base."
  assessment:
    stages:
      -
        id: "inspection"
        question: "What do I have?"
        answer: "Inspect the helm source, choices, locks, and any existing output before selecting a destination."
        requiredInputs:
          - "The chart and values, a rendered object set, or a package that contains them"
        catalogMatchRequired: false
        sourceIntentRequired: false
        destinationAccessRequired: false
        deploymentRequired: false
        evidenceState: "completed"
        resultState: "available"
        records:
          - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
          - "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/rendered/release-objects.yaml"
          - "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/rendered/object-inventory.yaml"
        nextAction: "Inspect or compare the source and exact files before choosing a destination."
      -
        id: "materialization"
        question: "What will it produce?"
        answer: "Run the recorded Helm render step to produce the exact Kubernetes objects for this configuration."
        requiredInputs:
          - "The pinned chart, version, values, namespace, release name, and render capabilities"
        catalogMatchRequired: false
        sourceIntentRequired: true
        destinationAccessRequired: false
        deploymentRequired: false
        evidenceState: "completed"
        resultState: "pass"
        records:
          - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
          - "recipes/aws-controllers-k8s/iam-chart/1.7.3/revisions/eks-inference/r001/variant-revision.yaml"
        nextAction: "Review the exact object set and its digest."
      -
        id: "destination"
        question: "Can this destination accept it?"
        answer: "The destination has not been checked for this exact configuration. A recorded source or render result is not a destination pass."
        requiredInputs:
          - "The exact candidate configuration"
          - "The selected destination and its current APIs, prerequisites, policies, credentials, controllers, and hardware facts"
        catalogMatchRequired: false
        sourceIntentRequired: true
        destinationAccessRequired: true
        deploymentRequired: false
        evidenceState: "not-run"
        resultState: "not-run"
        records:
          - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
        nextAction: "Choose a destination and check its APIs, prerequisites, policies, credentials, controllers, and hardware before apply."
      -
        id: "post-deployment"
        question: "Did it work?"
        answer: "No post-deployment result is recorded for this exact configuration. Publication, upload, or rendering is not proof that it ran correctly."
        requiredInputs:
          - "The exact delivered revision and destination"
          - "Live controller, resource, health, runtime, drift, and rollback observations required by the claim"
        catalogMatchRequired: false
        sourceIntentRequired: true
        destinationAccessRequired: true
        deploymentRequired: true
        evidenceState: "not-run"
        resultState: "not-run"
        records:
          []
        nextAction: "Deliver the exact revision, then record controller, resource, health, runtime, drift, and rollback results separately."
  inputs:
    fixedAtBuildTime:
      - "chart=aws-controllers-k8s/iam-chart"
      - "version=1.7.3"
      - "base=eks-inference"
      - "valuesProfile=recipes/aws-controllers-k8s/iam-chart/1.7.3/effective-values-eks-inference.yaml"
      - "namespace=ack-system"
      - "releaseName=ack-iam"
      - "capabilityProfile={\"apiVersions\":[],\"kubeVersion\":\"1.31.0\"}"
    installTime:
      -
        name: "aws-creds"
        type: "requiredSecrets"
        required: true
        details:
          keys:
            - "credentials"
          name: "aws-creds"
          namespace: "ack-system"
          purpose: "AWS shared credentials file; the Deployment mounts the Secret volume read-only at /var/run/secrets/aws and AWS_SHARED_CREDENTIALS_FILE points at /var/run/secrets/aws/credentials"
      -
        name: "requiredValues-1"
        type: "requiredValues"
        required: true
        details:
          installerInput: "awsRegion"
          path: "aws.region"
          purpose: "AWS region for the controller; deliberately the confighubplaceholder sentinel because the region belongs to the environment, not the chart"
          source: "platform-profile"
          stage: "pre-apply"
    installTimeStatus: "partly-declared"
  lifecycle:
    requirements:
      status: "recorded"
      items:
        -
          id: "ack-system/aws-creds"
          origin: "base"
          type: "target-fact"
          detail: "AWS shared credentials file; the Deployment mounts the Secret volume read-only at /var/run/secrets/aws and AWS_SHARED_CREDENTIALS_FILE points at /var/run/secrets/aws/credentials"
        -
          id: "aws.region"
          origin: "base"
          type: "target-fact"
          detail: "AWS region for the controller; deliberately the confighubplaceholder sentinel because the region belongs to the environment, not the chart"
      records:
        - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    routeIntent:
      status: "required-at-destination"
      routes:
        []
      records:
        - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    targetFacts:
      status: "recorded"
      declared:
        requiredSecrets:
          -
            keys:
              - "credentials"
            name: "aws-creds"
            namespace: "ack-system"
            purpose: "AWS shared credentials file; the Deployment mounts the Secret volume read-only at /var/run/secrets/aws and AWS_SHARED_CREDENTIALS_FILE points at /var/run/secrets/aws/credentials"
        requiredValues:
          -
            installerInput: "awsRegion"
            path: "aws.region"
            purpose: "AWS region for the controller; deliberately the confighubplaceholder sentinel because the region belongs to the environment, not the chart"
            source: "platform-profile"
            stage: "pre-apply"
      requirementRefs:
        - "ack-system/aws-creds"
        - "aws.region"
      records:
        - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    resolution:
      status: "awaits-variant-and-target"
      rule: "Re-resolve after a lifecycle-sensitive variant change, destination assignment, or delivery-runtime change; bind the result to the exact configuration digest."
      records:
        []
  ownership:
    status: "partly-declared"
    sourceControlled:
      - "Fields produced from the recorded chart values and render context"
    variantControlled:
      - "Post-render object fields recorded in ConfigHub after upload"
    targetSupplied:
      - "ack-system/aws-creds"
      - "aws.region"
    deliveryProtected:
      []
    records:
      - "data/helm-render-intents/intents/aws-controllers-k8s-iam-chart-1-7-3-eks-inference.yaml"
    rule: "Re-evaluate ownership when the source, variant, destination, or delivery behavior changes; overlapping source and variant edits require review."
  delivery:
    literalConfigOci:
      status: "not-published-in-this-record"
      note: "The installer package contains several preset configurations. A literal OCI bundle for this one base needs its own publication receipt."
    configHubReleaseOci:
      status: "not-recorded-for-this-base"
      note: "No current ConfigHub Space release OCI receipt is recorded for this exact base."
    argoCd: "not-recorded-for-this-base"
    flux: "not-recorded-for-this-base"
    direct: "not-recorded-for-this-base"
    historicalGitopsOciStatus: "todo"
  policy:
    profile: "catalog-standard"
    productionAdds:
      - "human-approval"
  evidence:
    renderParity: "yes"
    confighubScanOps: "todo"
    localKind: "todo"
    lifecycleObserved: "n/a"
    gitopsOciLive: "todo"
    liveDualParity: "todo"
    twoClusterKind: "todo"
    variantPromotion: "missing-confighub-proof"
  operations:
    resourceClass: "not-yet-classified"
    ownerClass: "not-yet-classified"
    changeCadence: "not-yet-classified"
status:
  level: "available"
  claim: "The Helm source record, committed rendered objects, revision digest, routes, target facts, and proof-lane statuses are indexed here."
  limits:
    - "This record does not claim that the base has been uploaded to a live ConfigHub Space."
    - "The inputs still required at installation are not yet fully recorded for every Helm configuration."
    - "A multi-preset installer package OCI is not the same as a single literal configuration OCI."
