apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "external-secrets-external-secrets-default-public-oci-supported"
spec:
  chart: "external-secrets/external-secrets"
  version: "2.5.0"
  decision: supported
  decisionDate: "2026-06-11"
  supportedSince: "2026-06-11T07:51:39Z"
  supportedBase: "default"
  targetScope:
    clusterClass: cub-lk-kind-vanilla
    namespace: "external-secrets"
    deliveryPath: confighub-oci
    gitopsController: argo
    lastEvidenceAt: "2026-06-11T07:34:49Z"
    lastEvidenceTarget: codex-es-provider-082730-cluster/oci
    lastEvidenceKubeContext: kind-codex-es-provider-082730
    capabilityProfileEvidence: "kind-kubernetes-1.35 selectableFields witness"
    liveEvidenceTTL: 30d
    storageAssumptions:
      - "Use the chart's recorded storage behavior for the supported scope unless a narrower scope is separately reviewed."
    networkAssumptions:
      - "Use the service, webhook, and certificate behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    requiredTargetFacts:
      - "Secret external-secrets/external-secrets-webhook must be delivered from installer out/secrets before GitOps sync for this proof scope."
  supportBoundary:
    includes:
      - "external-secrets/external-secrets@2.5.0 default base"
      - candidate ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope with the separated webhook Secret pre-staged
      - rendered objects, labels, gates, receipts, and support objects produced by the recorded base
      - recorded mutable-image exception for the declared public controller support scope
      - recorded resource-policy acceptance for the declared public controller support scope
      - controller-owned webhook lifecycle observation for the declared public controller support scope
      - disposable fake-provider SecretStore and ExternalSecret round-trip evidence for the declared public controller support scope
      - Kubernetes 1.35 selectableFields capability-profile witness for the rendered ExternalSecret CRD
    excludes:
      - "workload-only OCI delivery that omits the rendered external-secrets-webhook Secret"
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "production SecretStore, ClusterSecretStore, ExternalSecret, PushSecret, provider credentials, and provider-specific workloads unless separately reviewed"
      - "digest-pinned, resource-hardened, or provider-specific production bases unless separately reviewed"
      - "Kubernetes targets that drop selectableFields unless a profile-specific base or separate route is reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "mutable-image-exception-accepted-for-target-scope"
      detail: "both recorded base variants have digest-resolution receipts; mutable image tags are accepted only for the declared public controller support scope, while stricter scopes may require digest-pinned bases or image overrides"
    scanDecision:
      state: "resource-policy-accepted-for-target-scope"
      detail: "missing CPU and memory requests/limits are accepted for the declared public cub-lk controller proof scope; stricter scopes should create a resource-policy base or overlay"
    lifecycleDecision:
      state: "lifecycle-observed-for-proof-scope"
      detail: "no Helm hooks are required for the supported base; lifecycle observations prove CRDs established, webhook certificate data and caBundle populated, controller Deployments ready, and SecretStore server dry-run accepted"
    targetFactDecision:
      state: "explicit-separated-secret-prerequisite-rehearsed-for-target-scope"
      detail: "the rendered external-secrets-webhook Secret is separated by installer under out/secrets; a fresh 2026-06-11 run pre-staged that Secret before Argo sync and the workload became healthy"
    liveEvidenceDecision:
      state: "fresh-target-evidence-passed"
      detail: "fresh 2026-06-11 evidence passed for the declared scope: Argo synced the ConfigHub OCI artifact, all controller Deployments became ready after the rendered external-secrets-webhook Secret was pre-staged from installer out/secrets, the fake-provider round trip passed, and the rendered ExternalSecret CRD preserved selectableFields on the kind-kubernetes-1.35 capability profile"
    providerRoundTripDecision:
      state: "disposable-fake-provider-roundtrip-passed"
      detail: "a fresh 2026-06-11 default-base ConfigHub OCI rehearsal created a fake-provider SecretStore and ExternalSecret; ExternalSecret reached Ready=True and produced a controller-owned Kubernetes Secret without storing secret data in the receipt"
  evidence:
    - path: "recipes/external-secrets/external-secrets/2.5.0/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    - path: "recipes/external-secrets/external-secrets/2.5.0/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    - path: "runs/live-kind-parity/external-secrets-external-secrets-default/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the candidate base."
    - path: "runs/live-helm-confighub-compare/external-secrets-external-secrets-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    - path: "data/production-support-decisions/external-secrets-external-secrets/fresh-target-evidence-2026-06-08.yaml"
      claim: "Earlier target-scoped ConfigHub OCI and Argo evidence passed for the declared cub-lk vanilla kind support scope before the separated Secret delivery gap was isolated."
    - path: "data/runtime-gitops/receipts/external-secrets-external-secrets/default-prestaged-secret/latest.yaml"
      claim: "Fresh default-base ConfigHub OCI rehearsal passed through Argo and runtime readiness after the rendered webhook Secret was pre-staged as an explicit target prerequisite."
    - path: "data/runtime-gitops/receipts/external-secrets-external-secrets/default-fake-provider-roundtrip/latest.yaml"
      claim: "Fresh default-base ConfigHub OCI rehearsal passed a disposable fake-provider SecretStore and ExternalSecret round-trip, producing a controller-owned Kubernetes Secret without recording secret data."
    - path: "data/capability-profile-witnesses/selectablefields/receipts/external-secrets-external-secrets-default-kind-1.35.yaml"
      claim: "The rendered ExternalSecret CRD preserved selectableFields after server-side apply on the kind-kubernetes-1.35 capability profile."
    - path: "data/image-digest-workdown/receipts/external-secrets-external-secrets/default/image-digest-resolution.yaml"
      claim: "The rendered mutable image references for the candidate base have registry digest-resolution evidence."
    - path: "data/production-support-decisions/external-secrets-external-secrets/image-policy-decision.yaml"
      claim: "The target-scoped image policy decision accepts mutable rendered tags for this public controller support scope with explicit limits."
    - path: "data/production-support-decisions/external-secrets-external-secrets/security-decision.yaml"
      claim: "The target-scoped security decision accepts missing resource requests/limits only for this public cub-lk proof scope."
    - path: "data/production-support-decisions/external-secrets-external-secrets/lifecycle-decision.yaml"
      claim: "The target-scoped lifecycle decision binds controller-owned webhook fields and CRD readiness to proof-scope observation evidence."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/crd-lifecycle-and-upgrade-policy.yaml"
      claim: "The crd lifecycle and upgrade policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/extension-slot-provenance-and-scan-policy.yaml"
      claim: "The extension slot provenance and scan policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/target-fact-preflight.yaml"
      claim: "The target fact preflight receipt exists for this chart."
    - path: "data/production-disposition/receipts/external-secrets-external-secrets/webhook-readiness-and-failure-policy.yaml"
      claim: "The webhook readiness and failure policy receipt exists for this chart."
  requiredBeforeFinal: []
  nextAction: "Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate provider-specific, credential, resource-hardened, or profile-specific bases for real customer External Secrets workloads."
