apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionDispositionReceipt
metadata:
  name: bitnami-mongodb-scan-gate-warning-disposition
spec:
  chart: bitnami/mongodb
  version: "19.0.7"
  disposition: scan/gate warning disposition
  decision: accepted
  acceptedAt: "2026-06-09"
  scope:
    - local-test
    - production-review-input
  summary: The supported MongoDB bases have no high or critical rendered-object scan findings. The external scanner's remaining findings are PodDisruptionBudget policy warnings. The local scan warnings are covered by explicit production-disposition receipts for generated facts, target facts, lifecycle boundary, extension slots, and storage/rollback boundary. This accepts the current warnings as reviewed production-input warnings, not as hidden render defects.
  evidence:
    - path: data/external-scan-lane/chart-workdown.csv
      claim: The external scan workdown records three MongoDB findings, all for pdb-unhealthy-pod-eviction-policy across the supported bases.
    - path: data/scan-disposition-workdown/workdown.csv
      claim: The generated scan disposition workdown routes bitnami/mongodb to accept-or-patch-pdb-policy rather than image-pin, security-hardening, endpoint, or privileged-infrastructure work.
    - path: recipes/bitnami/mongodb/19.0.7/revisions/static-passwords/r001/receipts/scan-receipt.yaml
      claim: The static-passwords local rendered-object scan has zero high or critical findings and records the remaining warnings explicitly.
    - path: recipes/bitnami/mongodb/19.0.7/revisions/existing-secret-replicaset/r001/receipts/scan-receipt.yaml
      claim: The existing-secret-replicaset local rendered-object scan has zero high or critical findings and records the remaining warnings explicitly.
    - path: data/production-disposition/receipts/bitnami-mongodb/generated-fact-ownership.yaml
      claim: Generated credential ownership is accepted for the reviewed bases.
    - path: data/production-disposition/receipts/bitnami-mongodb/target-fact-preflight.yaml
      claim: Target Secret preflight is accepted for the existing-secret-replicaset base.
    - path: data/production-disposition/receipts/bitnami-mongodb/hook-and-lifecycle-phase-policy.yaml
      claim: Lifecycle/no-hooks policy is accepted for the reviewed bases.
    - path: data/production-disposition/receipts/bitnami-mongodb/extension-slot-provenance-and-scan-policy.yaml
      claim: Extension slots are accepted only while empty in the supported bases.
    - path: data/production-disposition/receipts/bitnami-mongodb/storage-backup-restore-and-rollback-policy.yaml
      claim: Storage and rollback boundaries are accepted as production review input.
  affectedVariants:
    - static-passwords
    - existing-secret-replicaset
  acceptedWarnings:
    - pdb-unhealthy-pod-eviction-policy
    - dependency-lock-review
    - extension-slot-review
    - generated-secret-ownership
    - helm-hook-lifecycle-policy:no-hooks-boundary
    - stateful-workload-review
  remainingProductionBlockers: []
  nextDecision: Keep existing-secret-replicaset marked runtime-review-needed until its kind runtime behavior is understood or a narrower production base is selected.
