apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "bitnami-redis-default-public-oci-supported"
spec:
  chart: "bitnami/redis"
  version: "25.5.3"
  decision: supported
  decisionDate: "2026-06-09"
  supportedSince: "2026-06-05T12:40:11Z"
  supportedBase: "default"
  targetScope:
    clusterClass: cub-lk-kind-vanilla
    namespace: "redis"
    deliveryPath: confighub-oci
    gitopsController: argo
    lastEvidenceAt: "2026-06-05T12:40:11Z"
    lastEvidenceTarget: helm-expt-parity-redis-0605-cluster/oci
    lastEvidenceKubeContext: kind-helm-expt-parity-redis-0605
    liveEvidenceTTL: 30d
    storageAssumptions:
      - "Use the chart's recorded StatefulSet, PVC, and service behavior for the supported scope unless a narrower scope is separately reviewed."
    networkAssumptions:
      - "Use the service behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    requiredTargetFacts: []
  supportBoundary:
    includes:
      - "bitnami/redis@25.5.3 default base"
      - ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope
      - rendered Redis StatefulSets, Services, PodDisruptionBudgets, labels, gates, receipts, and support objects produced by the recorded base
      - generated Redis password bound before render through the generated-fact receipt
      - separated Redis Secret staged outside the workload OCI artifact before apply or sync
      - recorded PDB warning acceptance for the declared public teaching and parity proof scope
      - recorded no-hooks lifecycle policy for the declared public teaching and parity proof scope
    excludes:
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "the reuse-existing-secret target-fact posture unless separately reviewed for a specific target"
      - "backup, restore, failover, persistence class, sizing, and customer SLO tuning"
      - "digest-pinned, availability-hardened, or customer production bases unless separately reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "no-open-image-digest-gap"
      detail: "the current image-digest workdown has no unresolved Redis image-digest gap"
    scanDecision:
      state: "pdb-policy-accepted-for-target-scope"
      detail: "PodDisruptionBudget unhealthy-pod-eviction policy warnings are accepted for the declared public teaching and parity proof scope; stricter availability scopes should create a reviewed PDB policy base or overlay"
    lifecycleDecision:
      state: "lifecycle-observed-for-proof-scope"
      detail: "the default base has no Helm hook execution requirement; generated Secret handling, StatefulSet/PVC readiness, Redis PONG, and ConfigHub OCI/Argo health are observed in the proof scope"
    targetFactDecision:
      state: "no-unresolved-target-prerequisite-in-candidate-base"
      detail: "the supported default base has no unresolved target prerequisite; reuse-existing-secret remains a separate target-fact variant"
    liveEvidenceDecision:
      state: "fresh-target-evidence-passed"
      detail: "fresh target-scoped ConfigHub OCI and Argo evidence passed on 2026-06-05 for the declared cub-lk vanilla kind Redis scope"
  evidence:
    - path: "recipes/bitnami/redis/25.5.3/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The supported base is Helm-equivalent under recorded inputs."
    - path: "recipes/bitnami/redis/25.5.3/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the supported base."
    - path: "runs/live-kind-parity/bitnami-redis-default/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the supported base."
    - path: "runs/live-helm-confighub-compare/bitnami-redis-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the supported base."
    - path: "data/production-support-decisions/bitnami-redis/fresh-target-evidence-2026-06-05.yaml"
      claim: "Fresh target-scoped ConfigHub OCI and Argo evidence passed for the declared cub-lk vanilla kind support scope."
    - path: "data/production-support-decisions/bitnami-redis/security-decision.yaml"
      claim: "The target-scoped security decision accepts Redis PDB warnings only for this public proof scope."
    - path: "data/production-support-decisions/bitnami-redis/lifecycle-decision.yaml"
      claim: "The target-scoped lifecycle decision binds generated facts, separated Secret staging, no-hooks policy, and OCI/Argo runtime health to proof-scope evidence."
    - path: "data/production-disposition/receipts/bitnami-redis/generated-fact-ownership.yaml"
      claim: "The generated fact ownership receipt exists for this chart."
    - path: "data/production-disposition/receipts/bitnami-redis/hook-lifecycle-phase-policy.yaml"
      claim: "The hook lifecycle phase policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/bitnami-redis/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning receipt exists for this chart."
    - path: "data/production-disposition/receipts/bitnami-redis/target-fact-preflight.yaml"
      claim: "The target fact preflight disposition exists for the reuse-existing-secret variant."
  requiredBeforeFinal: []
  nextAction: "Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate existing-secret, backup/restore, failover, storage-class, SLO, or availability-hardened bases for real customer Redis workloads."
