apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionDispositionReceipt
metadata:
  name: prometheus-scan-gate-warning-disposition
spec:
  chart: prometheus-community/prometheus
  version: "29.8.0"
  disposition: scan/gate warning disposition
  decision: accepted
  acceptedAt: "2026-06-09"
  scope:
    - local-test
    - production-review-input
  summary: The supported Prometheus bases have no high or critical local rendered-object scan findings. The local scan warnings are explicit review points for bundled component ownership, cluster RBAC, extension slots, monitoring workloads, scrape config, and storage. The external scanner adds stronger posture warnings for the full default stack, including node-exporter host access. This disposition accepts the scan evidence as production review input and recommends server-only-ephemeral as the narrower first production-review base; the full default stack remains a target-specific security decision.
  evidence:
    - path: data/external-scan-lane/review.csv
      claim: External kube-linter rows record resource, read-only-root-fs, host mount, host network, and host PID warnings across the two supported Prometheus bases.
    - path: data/scan-disposition-workdown/workdown.csv
      claim: The generated scan disposition workdown routes Prometheus to accept-or-split-privileged-infrastructure because the chart can install infrastructure needing node or host access.
    - path: recipes/prometheus-community/prometheus/29.8.0/revisions/default/r001/receipts/scan-receipt.yaml
      claim: The default rendered-object scan has zero high or critical local findings and records bundled components, RBAC, workload, scrape, storage, and extension-slot review points explicitly.
    - path: recipes/prometheus-community/prometheus/29.8.0/revisions/server-only-ephemeral/r001/receipts/scan-receipt.yaml
      claim: The server-only-ephemeral rendered-object scan has the narrower warning shape of RBAC, extension slots, workload rollout, and scrape-config review.
    - path: data/production-disposition/receipts/prometheus-community-prometheus/cluster-rbac-review.yaml
      claim: Prometheus cluster-scoped RBAC has an accepted production-review disposition.
    - path: data/production-disposition/receipts/prometheus-community-prometheus/extension-slot-provenance-and-scan-policy.yaml
      claim: Prometheus scrape, remote read/write, ingress, network policy, PDB, and extra-manifest extension slots have an accepted scan policy.
    - path: runs/live-kind-parity/prometheus-community-prometheus-default/receipt.yaml
      claim: The default base passes strict two-cluster live parity between regular Helm and cub installer apply.
    - path: runs/live-kind-parity/prometheus-community-prometheus-server-only-ephemeral/receipt.yaml
      claim: The server-only-ephemeral base passes strict two-cluster live parity between regular Helm and cub installer apply.
    - path: runs/live-helm-confighub-compare/prometheus-community-prometheus-server-only-ephemeral/receipt.yaml
      claim: The server-only-ephemeral base passes regular Helm, ConfigHub kubectl apply, and ConfigHub OCI/Argo live parity with healthy runtime.
  affectedVariants:
    - default
    - server-only-ephemeral
  acceptedWarnings:
    - bundle-component-review
    - cluster-rbac-review
    - extension-slot-review
    - monitoring-workload-review
    - scrape-config-review
    - storage-retention-review
    - no-read-only-root-fs
    - sensitive-host-mounts
    - host-network
    - host-pid
    - unset-cpu-requirements
    - unset-memory-requirements
  variantCaveats:
    - "server-only-ephemeral is the narrower first production-review base."
    - "default preserves the full chart shape, including bundled exporters and node-level access, and should not be treated as a generic production default without a target security decision."
    - "A hardened production base may split node-exporter and storage decisions into separate reviewed components."
  remainingProductionBlockers: []
  nextDecision: A production support decision should choose the supported Prometheus base, decide whether node-level exporter behavior is in scope, and attach target-specific scrape, storage, resource, and security posture requirements.
