apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionDispositionReceipt
metadata:
  name: grafana-loki-scan-gate-warning-disposition
spec:
  chart: grafana/loki
  version: "7.0.0"
  disposition: scan/gate warning disposition
  decision: accepted
  acceptedAt: "2026-06-09"
  scope:
    - local-test
    - production-review-input
  summary: >-
    Loki has no high or critical findings in the local rendered-object scanner.
    The external scanner records one high warning family and multiple medium
    warnings for resource requests, PDB policy, and read-only-root-filesystem
    posture. This disposition accepts those warnings as explicit production
    review inputs, not as final production support.
  evidence:
    - path: data/external-scan-lane/review.csv
      claim: External kube-linter rows record resource, PDB, and root filesystem warnings for both supported bases.
    - path: data/scan-disposition-workdown/workdown.csv
      claim: The generated scan disposition workdown routes Loki to harden-security-context before production support.
    - path: recipes/grafana/loki/7.0.0/revisions/single-binary-filesystem/r001/receipts/scan-receipt.yaml
      claim: The single-binary-filesystem rendered-object scan has zero high or critical findings and records storage, RBAC, lifecycle, extension, and StatefulSet warnings.
    - path: recipes/grafana/loki/7.0.0/revisions/simple-scalable-minio/r001/receipts/scan-receipt.yaml
      claim: The simple-scalable-minio rendered-object scan records object-store, MinIO Secret, StatefulSet, RBAC, lifecycle, and extension warnings.
    - path: recipes/grafana/loki/7.0.0/revisions/single-binary-filesystem/r001/receipts/install-gate.yaml
      claim: The single-binary-filesystem gate allows local-test and blocks production until storage, schema, lifecycle, and extension policy are reviewed.
    - path: recipes/grafana/loki/7.0.0/revisions/simple-scalable-minio/r001/receipts/install-gate.yaml
      claim: The MinIO gate records the same production policy boundary with object-store fixture caveats.
    - path: data/production-disposition/receipts/grafana-loki/cluster-rbac-review.yaml
      claim: Cluster RBAC handling has an accepted production-review disposition.
    - path: data/production-disposition/receipts/grafana-loki/extension-slot-provenance-and-scan-policy.yaml
      claim: Extension-slot handling has an accepted production-review disposition.
    - path: data/production-disposition/receipts/grafana-loki/hook-and-lifecycle-phase-policy.yaml
      claim: Hook and lifecycle handling has an accepted production-review disposition.
    - path: data/production-disposition/receipts/grafana-loki/storage-backup-restore-and-rollback-policy.yaml
      claim: Storage, backup, restore, and rollback handling has an accepted production-review disposition.
    - path: runs/live-helm-confighub-compare/grafana-loki-single-binary-filesystem/receipt.yaml
      claim: The single-binary-filesystem base passes regular Helm, ConfigHub kubectl apply, and ConfigHub OCI/Argo live parity.
  affectedVariants:
    - single-binary-filesystem
    - simple-scalable-minio
  acceptedWarnings:
    - blocked-default-render
    - cluster-rbac-review
    - dependency-lock-review
    - extension-slot-review
    - lifecycle-policy
    - no-read-only-root-fs
    - object-storage-policy
    - pdb-unhealthy-pod-eviction-policy
    - rendered-secret-ownership
    - stateful-workload-review
    - storage-config-required
    - unset-cpu-requirements
    - unset-memory-requirements
  variantCaveats:
    - "single-binary-filesystem is the stronger first production-review base because it has full live Helm-vs-ConfigHub OCI parity."
    - "simple-scalable-minio is useful proof of the object-store path, but target runtime capacity and object-store credential policy must be reviewed before production use."
    - "A hardened production base may add resource requests/limits, PDB policy, and workload security settings where the upstream chart supports them."
  remainingProductionBlockers: []
  nextDecision: A production support decision should choose the supported base, resource/security hardening policy, storage backend, and live observation requirements for the target.
