apiVersion: "catalog.confighub.com/v1alpha1"
kind: "BaseVariantRecord"
metadata:
  name: "elastic-filebeat-8-5-1-node-or-cluster-collector"
  labels:
    sourceType: "helm"
    component: "elastic/filebeat"
    sourceVersion: "8.5.1"
    base: "node-or-cluster-collector"
spec:
  source:
    type: "helm"
    name: "elastic/filebeat"
    version: "8.5.1"
    record: "data/helm-render-intents/intents/elastic-filebeat-8-5-1-node-or-cluster-collector.yaml"
    packageOciRef: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/elastic-filebeat:8.5.1"
  baseVariant:
    name: "node-or-cluster-collector"
    revision: "r001"
    digest: "7682debd6c360ad39daf54d962a5f2be5dae84683c6e0631412093803dc4e972"
  configuration:
    format: "kubernetes-yaml"
    objects: "recipes/elastic/filebeat/8.5.1/revisions/node-or-cluster-collector/r001/rendered/release-objects.yaml"
    inventory: "recipes/elastic/filebeat/8.5.1/revisions/node-or-cluster-collector/r001/rendered/object-inventory.yaml"
    objectCount: 7
  inputs:
    fixedAtBuildTime:
      - "chart=elastic/filebeat"
      - "version=8.5.1"
      - "base=node-or-cluster-collector"
      - "valuesProfile=recipes/elastic/filebeat/8.5.1/effective-values.yaml"
      - "namespace=default"
      - "releaseName=filebeat"
      - "capabilityProfile={\"apiVersions\":[],\"kubeVersion\":\"1.30.0\"}"
    installTime:
      -
        name: "elasticsearch-master-certs"
        type: "requiredSecrets"
        required: true
        details:
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
            - "configHubKubectlApply"
            - "configHubOciArgo"
          evidence:
            - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
          name: "elasticsearch-master-certs"
          namespace: "default"
          purpose: "CA certificate material mounted by the Filebeat DaemonSet for its Elasticsearch connection"
          sourcePath: "../../target-prerequisite-plan.yaml"
          suggestedSource: "kubectl -n default create secret generic elasticsearch-master-certs --from-file=ca.crt=<path-to-ca.crt>"
      -
        name: "elasticsearch-master-credentials"
        type: "requiredSecrets"
        required: true
        details:
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
            - "configHubKubectlApply"
            - "configHubOciArgo"
          evidence:
            - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
          keys:
            - "username"
            - "password"
          name: "elasticsearch-master-credentials"
          namespace: "default"
          purpose: "Elasticsearch username and password read by the Filebeat container"
          sourcePath: "../../target-prerequisite-plan.yaml"
          suggestedSource: "kubectl -n default create secret generic elasticsearch-master-credentials --from-literal=username=<username> --from-literal=password=<password>"
    installTimeStatus: "partly-declared"
  routing:
    routes:
      []
    targetFacts:
      status: "declared-target-facts-and-observed-action-records"
      declared:
        requiredSecrets:
          -
            deliveryLanes:
              - "regularHelm"
              - "cubInstallerApply"
              - "configHubKubectlApply"
              - "configHubOciArgo"
            evidence:
              - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
              - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            name: "elasticsearch-master-certs"
            namespace: "default"
            purpose: "CA certificate material mounted by the Filebeat DaemonSet for its Elasticsearch connection"
            sourcePath: "../../target-prerequisite-plan.yaml"
            suggestedSource: "kubectl -n default create secret generic elasticsearch-master-certs --from-file=ca.crt=<path-to-ca.crt>"
          -
            deliveryLanes:
              - "regularHelm"
              - "cubInstallerApply"
              - "configHubKubectlApply"
              - "configHubOciArgo"
            evidence:
              - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
              - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            keys:
              - "username"
              - "password"
            name: "elasticsearch-master-credentials"
            namespace: "default"
            purpose: "Elasticsearch username and password read by the Filebeat container"
            sourcePath: "../../target-prerequisite-plan.yaml"
            suggestedSource: "kubectl -n default create secret generic elasticsearch-master-credentials --from-literal=username=<username> --from-literal=password=<password>"
      requirements:
        -
          category: "secret"
          name: "default/elasticsearch-master-certs"
          namespace: "default"
          requiredBefore: "apply"
          freshness:
            policy: "recheck-before-apply"
            maxAge: "one-apply"
          purpose: "CA certificate material mounted by the Filebeat DaemonSet for its Elasticsearch connection"
          check: "kubectl -n default create secret generic elasticsearch-master-certs --from-file=ca.crt=<path-to-ca.crt>"
          declarationPath: "recipes/elastic/filebeat/8.5.1/variants/node-or-cluster-collector/variant.yaml"
          sourceVariant: ""
          sourcePath: "../../target-prerequisite-plan.yaml"
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
            - "configHubKubectlApply"
            - "configHubOciArgo"
          evidence:
            - "recipes/elastic/filebeat/8.5.1/variants/node-or-cluster-collector/variant.yaml"
            - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
        -
          category: "secret"
          name: "default/elasticsearch-master-credentials"
          namespace: "default"
          requiredBefore: "apply"
          freshness:
            policy: "recheck-before-apply"
            maxAge: "one-apply"
          purpose: "Elasticsearch username and password read by the Filebeat container"
          check: "kubectl -n default create secret generic elasticsearch-master-credentials --from-literal=username=<username> --from-literal=password=<password>"
          declarationPath: "recipes/elastic/filebeat/8.5.1/variants/node-or-cluster-collector/variant.yaml"
          sourceVariant: ""
          sourcePath: "../../target-prerequisite-plan.yaml"
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
            - "configHubKubectlApply"
            - "configHubOciArgo"
          evidence:
            - "recipes/elastic/filebeat/8.5.1/variants/node-or-cluster-collector/variant.yaml"
            - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
      actions:
        -
          lane: "G/P"
          prerequisiteKind: "unknown"
          prerequisiteName: "unknown"
          actionKind: "operator-review"
          ownerClass: "operator-review"
          requiredInputs: "operator review of the runtime residue"
          evidenceRequired: "an operator decision recorded for this base/target; then a fresh G/P parity receipt for this base"
          automatic: false
          supportArtifact: "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml"
          sourceReceipt: "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
          rerunCommand: "npm run live-parity:run -- --recipe recipes/elastic/filebeat/8.5.1 --base node-or-cluster-collector"
          requiredBefore: "apply"
          freshness:
            policy: "recheck-before-apply"
            maxAge: "one-apply"
          evidence:
            - "runs/live-helm-confighub-compare/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml"
        -
          lane: "K"
          prerequisiteKind: "external-api"
          prerequisiteName: "unknown"
          actionKind: "provide-external-service"
          ownerClass: "operator-review"
          requiredInputs: "the upstream service/endpoint the workload connects to"
          evidenceRequired: "the upstream service/endpoint reachable from the workload; then a fresh K parity receipt for this base"
          automatic: false
          supportArtifact: "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml"
          sourceReceipt: "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
          rerunCommand: "npm run kind-parity:run -- --chart elastic/filebeat --version 8.5.1 --base node-or-cluster-collector"
          requiredBefore: "apply"
          freshness:
            policy: "recheck-before-apply"
            maxAge: "one-apply"
          evidence:
            - "runs/live-kind-parity/elastic-filebeat-node-or-cluster-collector/receipt.yaml"
            - "recipes/elastic/filebeat/8.5.1/target-prerequisite-plan.yaml"
      coverage:
        state: "attached-with-observed-actions"
        reason: "2 prerequisite declarations and 2 follow-up action records are attached."
        declarationSource: "recipes/elastic/filebeat/8.5.1/variants/node-or-cluster-collector/variant.yaml"
        nextAction: ""
    sourceRecord: "data/helm-render-intents/intents/elastic-filebeat-8-5-1-node-or-cluster-collector.yaml"
  delivery:
    literalConfigOci:
      status: "not-published-in-this-record"
      note: "The installer package contains several preset configurations. A literal OCI bundle for this one base needs its own publication receipt."
    configHubReleaseOci:
      status: "not-recorded-for-this-base"
      note: "No current ConfigHub Space release OCI receipt is recorded for this exact base."
    argoCd: "not-recorded-for-this-base"
    flux: "not-recorded-for-this-base"
    direct: "not-recorded-for-this-base"
    historicalGitopsOciStatus: "watch"
  policy:
    profile: "catalog-standard"
    productionAdds:
      - "human-approval"
  evidence:
    renderParity: "yes"
    confighubScanOps: "yes"
    localKind: "no"
    lifecycleObserved: "n/a"
    gitopsOciLive: "watch"
    liveDualParity: "watch"
    twoClusterKind: "no"
    variantPromotion: "proven"
  operations:
    resourceClass: "not-yet-classified"
    ownerClass: "not-yet-classified"
    changeCadence: "not-yet-classified"
status:
  level: "available"
  claim: "The Helm source record, committed rendered objects, revision digest, routes, target facts, and proof-lane statuses are indexed here."
  limits:
    - "This record does not claim that the base has been uploaded to a live ConfigHub Space."
    - "The small typed install-time surface is not yet complete for every Helm base."
    - "A multi-preset installer package OCI is not the same as a single literal configuration OCI."
