apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ProductionLifecycleDecision"
metadata:
  name: "bitnami-rabbitmq-public-oci-lifecycle-decision"
spec:
  chart: "bitnami/rabbitmq"
  version: "16.0.14"
  targetScope:
    clusterClass: "cub-lk-kind-vanilla"
    namespace: "rabbitmq"
    deliveryPath: "confighub-oci"
    gitopsController: "argo"
  supportedBaseCandidate: "static-passwords"
  variantsCovered:
    - "existing-secret"
    - "static-passwords"
  decision: "lifecycle-observed-for-proof-scope"
  decidedAt: "2026-06-09"
  claim: "The RabbitMQ static-passwords base has no Helm hook objects and reaches readiness through regular Helm, cub installer apply, and ConfigHub OCI/Argo. The generated administrator password and Erlang cookie are bound before render, and the rendered Secrets are separated by cub installer rather than hidden in workload units."
  lifecycleModel:
    hookPolicy: "no-chart-hooks"
    selectedTopology: "standalone-statefulset-static-passwords"
    generatedFacts: "auth.password and auth.erlangCookie are generated and bound before render; the rendered credential and configuration Secrets are deterministic and separated during cub installer output."
    storagePolicy: "The public proof uses the chart's default standalone StatefulSet PVC posture. StorageClass, backup, restore, queue recovery, and rollback remain target decisions."
    excludedTopology: "existing-secret is a useful target-fact path but remains outside this production-support claim until its target password, Erlang cookie, custody, and rotation policy are separately reviewed."
  observedLifecycleSignals:
    twoClusterParity:
      result: "pass"
      observedAt: "2026-06-06T08:27:39Z"
      regularHelmRuntime: "pass"
      installerRuntime: "pass"
      semanticParity: "pass"
    confighubOciArgo:
      result: "pass"
      observedAt: "2026-06-05T18:25:30Z"
      regularHelmRuntime: "pass"
      confighubApplyRuntime: "pass"
      confighubOciRuntime: "pass"
      argoSync: "Synced"
      argoHealth: "Healthy"
      semanticParity: "pass"
      separatedSecrets:
        - "secret-rabbitmq-rabbitmq-config.yaml"
        - "secret-rabbitmq-rabbitmq.yaml"
  limits:
    - "This supports the static-passwords public proof base, not every RabbitMQ deployment topology."
    - "This proof does not test RabbitMQ backup, restore, queue recovery, clustering, failover, or credential and Erlang-cookie rotation."
    - "Credential rotation, Erlang-cookie rotation, and secret custody are target operating procedures outside this public proof."
    - "Populated init scripts, custom configuration, or external credential paths require a new reviewed base."
  evidence:
    -
      path: "runs/live-kind-parity/bitnami-rabbitmq-static-passwords/receipt.yaml"
      claim: "Two-cluster Helm-vs-installer parity passes for static-passwords."
    -
      path: "runs/live-helm-confighub-compare/bitnami-rabbitmq-static-passwords/receipt.yaml"
      claim: "ConfigHub OCI/Argo live parity passes for static-passwords."
    -
      path: "data/production-disposition/receipts/bitnami-rabbitmq/generated-fact-ownership.yaml"
      claim: "Records generated credential ownership and the separated Secret policy."
    -
      path: "data/production-disposition/receipts/bitnami-rabbitmq/hook-and-lifecycle-phase-policy.yaml"
      claim: "Records the no-hooks lifecycle boundary for RabbitMQ."
    -
      path: "data/production-disposition/receipts/bitnami-rabbitmq/storage-backup-restore-and-rollback-policy.yaml"
      claim: "Records RabbitMQ storage, backup, restore, and rollback boundaries."
    -
      path: "data/production-disposition/receipts/bitnami-rabbitmq/target-fact-preflight.yaml"
      claim: "Records the existing-secret target-fact path that remains outside this support claim."
  remainingSupportBlockers:
    - "Record image policy, scan/PDB acceptance, and fresh target-scoped ConfigHub OCI/GitOps evidence."
