apiVersion: "catalog.confighub.com/v1alpha1"
kind: "OciEvidenceChain"
metadata:
  name: "rendered-config-nginx-two-cluster-fleet"
  labels:
    sourceType: "rendered-config"
spec:
  sourceType: "rendered-config"
  example: "Literal NGINX OCI promoted through ConfigHub and rolled out to two clusters"
  boundaries:
    source:
      result: "pass"
      digest: "sha256:ba9d5aa8f05766037d61f2ed04bfed5543bc5e7328cce193a3c577fe9071d714"
      reference: "oci://127.0.0.1:32812/bitnami-nginx-http-clusterip-config:24.0.2"
      identifiers:
        - "objects:5"
      evidence:
        - "data/base-variant-records/records/bitnami-nginx-24-0-2-http-clusterip.yaml"
        - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      detail: "The literal Kubernetes OCI is resolved and compared with the recorded source objects before upload."
      observedAt: ""
      expiresAt: ""
    reviewedConfiguration:
      result: "pass"
      digest: "sha256:d236f619e2e4ea8f22160be1b453e3224e3f82b6e407182903d9d8aa3568c111"
      reference: "reviewed staging Kubernetes objects"
      identifiers:
        - "objects:5"
        - "change:Deployment/nginx spec.replicas 1 -> 2"
      evidence:
        - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      detail: "The reviewed staging configuration contains the exact five objects after the replica change."
      observedAt: ""
      expiresAt: ""
    configHubRecord:
      result: "pass"
      digest: ""
      reference: "space:hx-oci-flow-20260729-s3t-staging"
      identifiers:
        - "variant:staging"
        - "upstream-space-id:9c0447aa-485a-4ee7-ac58-e2f64bb56e77"
        - "release-id:63ca45b8-865b-460b-b137-c362f23be639"
      evidence:
        - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      detail: "ConfigHub stores the base, development, and staging chain and records both promotions."
      observedAt: ""
      expiresAt: ""
    outputOci:
      result: "pass"
      digest: "sha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b55"
      reference: "oci://127.0.0.1:32812/reviewed-nginx-staging:latest"
      identifiers:
        - "objects:5"
      evidence:
        - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      detail: "The reviewed staging objects were exported as one portable OCI for both targets."
      observedAt: ""
      expiresAt: ""
    delivery:
      result: "pass"
      digest: "sha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b55"
      reference: "oci://host.docker.internal:32812/reviewed-nginx-staging"
      identifiers:
        - "consumer:Argo CD"
        - "targets:2"
      evidence:
        - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      detail: "Argo CD reconciled the same portable OCI digest on both clusters."
      observedAt: ""
      expiresAt: ""
    observation:
      result: "pass"
      digest: "sha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b55"
      reference: ""
      identifiers:
        - "targets:2"
        - "object-sets:matched"
        - "workloads:converged"
      evidence:
        - "runs/oci-deploy-stage-rollout-proof/observations/target-a-object-set.json"
        - "runs/oci-deploy-stage-rollout-proof/observations/target-a-workloads.json"
        - "runs/oci-deploy-stage-rollout-proof/observations/target-b-object-set.json"
        - "runs/oci-deploy-stage-rollout-proof/observations/target-b-workloads.json"
      detail: "Fingerprint receipts show that both live object sets matched and both NGINX workloads converged."
      observedAt: "2026-07-29T09:08:07.903Z"
      expiresAt: "2026-07-29T10:15:59Z"
  companionRecords:
    sourceInputs:
      - "data/base-variant-records/records/bitnami-nginx-24-0-2-http-clusterip.yaml"
    lifecycle:
      - "data/base-variant-records/records/bitnami-nginx-24-0-2-http-clusterip.yaml"
    checks:
      - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
      - "runs/oci-deploy-stage-rollout-proof/observations/target-a-object-set.json"
      - "runs/oci-deploy-stage-rollout-proof/observations/target-a-workloads.json"
      - "runs/oci-deploy-stage-rollout-proof/observations/target-b-object-set.json"
      - "runs/oci-deploy-stage-rollout-proof/observations/target-b-workloads.json"
    receipts:
      - "runs/oci-deploy-stage-rollout-proof/receipt.yaml"
status:
  coverage: "managed-and-observed"
  completeThrough: "observation"
  claim: "One literal Kubernetes OCI can be followed through ConfigHub variants and promotion to a portable OCI consumed at the same digest by Argo CD on two observed clusters."
  limits:
    - "The input and portable output OCI packages used a temporary local registry. Public Google Artifact Registry publication is a separate receipt."
    - "This proves one NGINX catalog configuration on two throwaway Argo CD clusters and one throwaway Flux cluster, not every chart or production target."
    - "cub-scout recorded fingerprinted object-match and workload-convergence receipts locally. This test did not submit those receipts to ConfigHub observation storage."
    - "The test did not exercise hooks, CRDs, Secrets, or admission webhooks; those keep their separate lifecycle routes and receipts."
    - "ConfigHub's target-scoped OCI credential was not shared between clusters. The fleet consumed the portable anonymous OCI output instead."
