apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "HelmRenderIntent"
metadata:
  name: "grafana-tempo-1-24-4-s3-query-observability"
  labels:
    component: "grafana/tempo"
    chart: "grafana/tempo"
    version: "1.24.4"
    base: "s3-query-observability"
    catalogLayer: "F2b"
spec:
  component: "grafana/tempo"
  chart:
    name: "grafana/tempo"
    version: "1.24.4"
    sourceRepository: "https://grafana.github.io/helm-charts"
    sourceContent: ""
  baseVariant: "s3-query-observability"
  renderInputs:
    recipe: "recipes/grafana/tempo/1.24.4"
    variant: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
    revision: "recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/variant-revision.yaml"
    packageBase: "packages/grafana/tempo/1.24.4/bases/s3-query-observability"
    installerPackageOciRef: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-tempo:1.24.4"
    sourceLock: "recipes/grafana/tempo/1.24.4/source-lock.yaml"
    namespace: "tempo"
    releaseName: "tempo"
    valuesProfile: "recipes/grafana/tempo/1.24.4/effective-values-s3-query-observability.yaml"
    capabilityProfile:
      apiVersions:
        - "networking.k8s.io/v1"
        - "monitoring.coreos.com/v1"
      kubeVersion: "1.30.0"
    hookPolicy: "no-hooks"
  renderOutput:
    renderedObjects: "recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/rendered/release-objects.yaml"
    objectInventory: "recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/rendered/object-inventory.yaml"
    revision: "recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/variant-revision.yaml"
    packageBase: "packages/grafana/tempo/1.24.4/bases/s3-query-observability"
  evidence:
    renderParity: "yes"
    confighubScanOps: "yes"
    localKind: "no"
    lifecycleObserved: "n/a"
    gitopsOciLive: "watch"
    liveDualParity: "watch"
    twoClusterKind: "yes"
    variantPromotion: "proven"
  lifecycle:
    routeContract: "n/a"
    routeCount: "0"
    dispositions: "n/a"
    executionModes: "n/a"
    safeAutomatic: "n/a"
    contractPath: ""
    jsonPath: ""
    variantRoutes:
      []
    coverage:
      state: "no-route-required"
      reason: "The current catalog record has no source hook or separate lifecycle step for this base."
      evidence:
        []
      nextAction: ""
  targetFacts:
    status: "declared-target-facts"
    declared:
      requiredCRDs:
        -
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
            - "configHubKubectlApply"
            - "configHubOciArgo"
          name: "servicemonitors.monitoring.coreos.com"
          purpose: "Prometheus Operator ServiceMonitor CRD required by Tempo's ServiceMonitor object"
          sourcePath: "../../../prometheus-community/kube-prometheus-stack/85.3.3/revisions/default/r001/rendered/release-objects.yaml"
          sourceVariant: "prometheus-community/kube-prometheus-stack@85.3.3/default"
          packageSource: "package://prerequisites/target-facts/s3-query-observability-crds.yaml"
          packagePath: "packages/grafana/tempo/1.24.4/prerequisites/target-facts/s3-query-observability-crds.yaml"
      requiredObjectStores:
        -
          bucket: "tempo-traces"
          credentialsSecret:
            accessKey: "access_key"
            name: "tempo-s3-credentials"
            secretKey: "secret_key"
          deliveryLanes:
            - "regularHelm"
            - "cubInstallerApply"
          endpoint: "tempo-object-store.tempo.svc.cluster.local:9000"
          kind: "S3CompatibleObjectStore"
          name: "tempo-object-store"
          namespace: "tempo"
          purpose: "Local S3-compatible object-store fixture used to prove the S3 base can become ready when its target prerequisite exists"
          serviceName: "tempo-object-store"
      requiredSecrets:
        -
          keys:
            - "access_key"
            - "secret_key"
          name: "tempo-s3-credentials"
          namespace: "tempo"
          purpose: "S3 access credentials referenced by Tempo environment variables"
      requiredValues:
        -
          deliveryLanes:
            - "recipe"
          path: "tempo.storage.trace.s3.endpoint"
          purpose: "S3-compatible endpoint that Tempo will write traces to"
          stage: "pre-render"
        -
          deliveryLanes:
            - "recipe"
          path: "tempo.storage.trace.s3.bucket"
          purpose: "Existing bucket for Tempo trace blocks"
          stage: "pre-render"
        -
          deliveryLanes:
            - "recipe"
          path: "tempo.storage.trace.s3.region"
          purpose: "Object-store region used with the selected endpoint and bucket"
          stage: "pre-render"
    requirements:
      -
        category: "crd"
        name: "servicemonitors.monitoring.coreos.com"
        namespace: ""
        requiredBefore: "apply"
        freshness:
          policy: "recheck-before-apply"
          maxAge: "one-apply"
        purpose: "Prometheus Operator ServiceMonitor CRD required by Tempo's ServiceMonitor object"
        check: "package://prerequisites/target-facts/s3-query-observability-crds.yaml"
        packageSource: "package://prerequisites/target-facts/s3-query-observability-crds.yaml"
        packagePath: "packages/grafana/tempo/1.24.4/prerequisites/target-facts/s3-query-observability-crds.yaml"
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: "prometheus-community/kube-prometheus-stack@85.3.3/default"
        sourcePath: "../../../prometheus-community/kube-prometheus-stack/85.3.3/revisions/default/r001/rendered/release-objects.yaml"
        deliveryLanes:
          - "regularHelm"
          - "cubInstallerApply"
          - "configHubKubectlApply"
          - "configHubOciArgo"
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
          - "packages/grafana/tempo/1.24.4/prerequisites/target-facts/s3-query-observability-crds.yaml"
      -
        category: "object-store"
        name: "tempo-object-store"
        namespace: "tempo"
        requiredBefore: "apply"
        freshness:
          policy: "recheck-before-apply"
          maxAge: "one-apply"
        purpose: "Local S3-compatible object-store fixture used to prove the S3 base can become ready when its target prerequisite exists"
        check: ""
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: ""
        sourcePath: ""
        deliveryLanes:
          - "regularHelm"
          - "cubInstallerApply"
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
      -
        category: "secret"
        name: "tempo/tempo-s3-credentials"
        namespace: "tempo"
        requiredBefore: "apply"
        freshness:
          policy: "recheck-before-apply"
          maxAge: "one-apply"
        purpose: "S3 access credentials referenced by Tempo environment variables"
        check: ""
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: ""
        sourcePath: ""
        deliveryLanes:
          []
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
      -
        category: "value"
        name: "tempo.storage.trace.s3.endpoint"
        namespace: ""
        requiredBefore: "render"
        freshness:
          policy: "recheck-before-render"
          maxAge: "one-render"
        purpose: "S3-compatible endpoint that Tempo will write traces to"
        check: ""
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: ""
        sourcePath: ""
        deliveryLanes:
          - "recipe"
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
      -
        category: "value"
        name: "tempo.storage.trace.s3.bucket"
        namespace: ""
        requiredBefore: "render"
        freshness:
          policy: "recheck-before-render"
          maxAge: "one-render"
        purpose: "Existing bucket for Tempo trace blocks"
        check: ""
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: ""
        sourcePath: ""
        deliveryLanes:
          - "recipe"
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
      -
        category: "value"
        name: "tempo.storage.trace.s3.region"
        namespace: ""
        requiredBefore: "render"
        freshness:
          policy: "recheck-before-render"
          maxAge: "one-render"
        purpose: "Object-store region used with the selected endpoint and bucket"
        check: ""
        declarationPath: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
        sourceVariant: ""
        sourcePath: ""
        deliveryLanes:
          - "recipe"
        evidence:
          - "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
    actions:
      []
    coverage:
      state: "attached"
      reason: "6 target prerequisites declared by this base."
      declarationSource: "recipes/grafana/tempo/1.24.4/variants/s3-query-observability/variant.yaml"
      nextAction: ""
  settingSources:
    helmValues:
      status: "recorded"
      valuesProfile: "recipes/grafana/tempo/1.24.4/effective-values-s3-query-observability.yaml"
      controls: "base-render"
    configHubChanges:
      status: "none-in-catalog-base"
      controls: "post-render-fields"
      recordsAfterUpload:
        - "Unit revisions"
        - "derived variants"
        - "promotion receipts"
    installWork:
      status: "recorded"
      controls: "prerequisites-and-lifecycle"
      targetRequirementCount: 6
      lifecycleRouteCount: 0
    liveCluster:
      status: "observation-only"
      controls: "observed-state"
    overlapPolicy: "review-required"
  provenance:
    matrixRowKind: "base"
    catalogLayer: "F2b"
    customizationLayer: "F2b rendered standard fork"
    rowStatus: "real"
    githubRecipeUrl: "https://github.com/confighub/helm-expt/tree/main/recipes/grafana/tempo/1.24.4"
    githubPackageBaseUrl: "https://github.com/confighub/helm-expt/tree/main/packages/grafana/tempo/1.24.4/bases/s3-query-observability"
    fullModelPath:
      - "chart/version: grafana/tempo@1.24.4"
      - "recipe: recipes/grafana/tempo/1.24.4"
      - "base variant: s3-query-observability"
      - "render intent: data/helm-render-intents/intents/grafana-tempo-1-24-4-s3-query-observability.yaml"
      - "rendered revision: recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/variant-revision.yaml"
      - "full rendered YAML: recipes/grafana/tempo/1.24.4/revisions/s3-query-observability/r001/rendered/release-objects.yaml"
      - "installer package OCI: oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/grafana-tempo:1.24.4"
      - "package base: packages/grafana/tempo/1.24.4/bases/s3-query-observability"
      - "ConfigHub Units: created when the package is uploaded"
      - "managed variants: created after upload with cub variant create/promote"
      - "targets and observations: recorded by the live lanes when run"
status:
  disposition: "real-base-render-intent"
  claim: "This intent describes a committed real base variant and its render inputs. It is not a claim that every live delivery lane is green."
  limits:
    - "Candidate and custom-discussion rows are not emitted as runnable render intents."
    - "Declared target facts are copied from the base variant. Observed action records appear only when committed failure evidence exists; their absence does not erase the declaration."
    - "Missing lifecycle route data is not treated as proof that no route is needed."
    - "ConfigHub server objects and managed variants are created after upload. This file records the render intent, not a live server object."
