apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "grafana-grafana-existing-secret-ingress-public-oci-superseded"
spec:
  chart: "grafana/grafana"
  version: "10.5.15"
  decision: superseded
  decisionDate: "2026-06-09"
  supportedBase: "existing-secret-ingress"
  targetScope:
    clusterClass: vanilla-kubernetes
    namespace: "grafana"
    deliveryPath: confighub-oci
    gitopsController: argo-or-flux
    storageAssumptions:
      - "Use the chart's recorded storage behavior for the candidate base unless this draft is narrowed before final support."
    networkAssumptions:
      - "Use the service, ingress, DNS, and certificate behavior recorded by the candidate base unless this draft is narrowed before final support."
    requiredTargetFacts:
      - "Secret grafana/grafana-admin with admin-user and admin-password"
  supportBoundary:
    includes:
      - "grafana/grafana@10.5.15 existing-secret-ingress base"
      - ConfigHub OCI delivery for the declared target scope after fresh target evidence is recorded
      - rendered objects, labels, gates, receipts, and support objects produced by the recorded base
    excludes:
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "not-reviewed-because-source-chart-is-deprecated"
      detail: "the source chart version is marked deprecated, so image digest work should move to a maintained Grafana chart or a replacement catalog source"
    scanDecision:
      state: "not-reviewed-because-source-chart-is-deprecated"
      detail: "scanner findings remain useful proof data, but this deprecated source chart is not promoted as a production-supported scope"
    lifecycleDecision:
      state: "no-lifecycle-specific-decision"
      detail: "no lifecycle-specific decision beyond standard support boundary"
    targetFactDecision:
      state: "target-secret-required-and-staged-in-receipts"
      detail: "existing-secret-ingress requires Secret grafana/grafana-admin with admin-user and admin-password; committed live receipts stage that target fact for the tested scope"
    liveEvidenceDecision:
      state: "not-production-supported-because-source-chart-is-deprecated"
      detail: "live evidence exists for the proof corpus, but production support should be based on a maintained Grafana chart or replacement catalog source"
  evidence:
    - path: "recipes/grafana/grafana/10.5.15/revisions/existing-secret-ingress/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    - path: "recipes/grafana/grafana/10.5.15/revisions/existing-secret-ingress/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    - path: "runs/live-kind-parity/grafana-grafana-existing-secret-ingress/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the candidate base."
    - path: "runs/live-helm-confighub-compare/grafana-grafana-existing-secret-ingress/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    - path: "data/production-disposition/receipts/grafana-grafana/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    - path: "data/production-disposition/receipts/grafana-grafana/extension-slot-provenance-and-scan-policy.yaml"
      claim: "The extension slot provenance and scan policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/grafana-grafana/generated-fact-ownership.yaml"
      claim: "The generated fact ownership receipt exists for this chart."
    - path: "data/production-disposition/receipts/grafana-grafana/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
    - path: "data/production-disposition/receipts/grafana-grafana/target-fact-preflight.yaml"
      claim: "The target fact preflight receipt exists for this chart."
  requiredBeforeFinal: []
  nextAction: "Keep this as catalog proof evidence only; review a maintained Grafana chart or replacement catalog source before making a production-support claim."
