apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ProductionLifecycleDecision"
metadata:
  name: "bitnami-mongodb-public-oci-lifecycle-decision"
spec:
  chart: "bitnami/mongodb"
  version: "19.0.7"
  targetScope:
    clusterClass: "cub-lk-kind-vanilla"
    namespace: "mongodb"
    deliveryPath: "confighub-oci"
    gitopsController: "argo"
  supportedBaseCandidate: "static-passwords"
  variantsCovered:
    - "existing-secret-replicaset"
    - "static-passwords"
  decision: "lifecycle-observed-for-proof-scope"
  decidedAt: "2026-06-09"
  claim: "The MongoDB static-passwords base has no Helm hook objects and reaches readiness through regular Helm, cub installer apply, and ConfigHub OCI/Argo. The generated root password is bound before render and the rendered Secret is separated by cub installer rather than hidden in workload units."
  lifecycleModel:
    hookPolicy: "no-chart-hooks"
    selectedTopology: "standalone-deployment-static-passwords"
    generatedFacts: "auth.rootPassword is generated and bound before render; the rendered Secret is deterministic and separated during cub installer output."
    storagePolicy: "The public proof uses the chart's standalone PVC posture. StorageClass, backup, restore, and rollback remain target decisions."
    excludedTopology: "existing-secret-replicaset is a useful target-fact example but remains outside this production-support claim until runtime behavior is separately reviewed."
  observedLifecycleSignals:
    twoClusterParity:
      result: "pass"
      observedAt: "2026-06-06T08:27:39Z"
      regularHelmRuntime: "pass"
      installerRuntime: "pass"
      semanticParity: "pass"
    confighubOciArgo:
      result: "pass"
      observedAt: "2026-06-05T18:46:27Z"
      regularHelmRuntime: "pass"
      confighubApplyRuntime: "pass"
      confighubOciRuntime: "pass"
      argoSync: "Synced"
      argoHealth: "Healthy"
      semanticParity: "pass"
      separatedSecrets:
        - "secret-mongodb-oci-mongodb.yaml"
  limits:
    - "This supports the static-passwords public proof base, not every MongoDB deployment topology."
    - "This proof does not test MongoDB backup, restore, point-in-time recovery, failover, or replica-set operation."
    - "Credential rotation and secret custody are target operating procedures outside this public proof."
    - "Populated init scripts or extended configuration slots require a new reviewed base."
  evidence:
    -
      path: "runs/live-kind-parity/bitnami-mongodb-static-passwords/receipt.yaml"
      claim: "Two-cluster Helm-vs-installer parity passes for static-passwords."
    -
      path: "runs/live-helm-confighub-compare/bitnami-mongodb-static-passwords/receipt.yaml"
      claim: "ConfigHub OCI/Argo live parity passes for static-passwords."
    -
      path: "data/production-disposition/receipts/bitnami-mongodb/generated-fact-ownership.yaml"
      claim: "Records generated credential ownership and the separated Secret policy."
    -
      path: "data/production-disposition/receipts/bitnami-mongodb/hook-and-lifecycle-phase-policy.yaml"
      claim: "Records the no-hooks lifecycle boundary for MongoDB."
    -
      path: "data/production-disposition/receipts/bitnami-mongodb/storage-backup-restore-and-rollback-policy.yaml"
      claim: "Records MongoDB storage, backup, restore, and rollback boundaries."
    -
      path: "data/production-disposition/receipts/bitnami-mongodb/extension-slot-provenance-and-scan-policy.yaml"
      claim: "Records the init-script and extended-configuration extension-slot policy."
    -
      path: "data/production-disposition/receipts/bitnami-mongodb/target-fact-preflight.yaml"
      claim: "Records the existing-secret target-fact path that remains outside this support claim."
  remainingSupportBlockers:
    - "Record image policy, scan/PDB acceptance, and fresh target-scoped ConfigHub OCI/GitOps evidence."
