apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ProductionImagePolicyDecision"
metadata:
  name: "hashicorp-consul-public-oci-image-policy-decision"
spec:
  chart: "hashicorp/consul"
  version: "2.0.0"
  targetScope:
    clusterClass: "cub-lk-kind-vanilla"
    namespace: "consul"
    deliveryPath: "confighub-oci"
    gitopsController: "argo"
  supportedBaseCandidate: "default-control-plane"
  variantsCovered:
    - "default-control-plane"
    - "secure-mesh-existing-secrets"
  decision: "mutable-image-exception-accepted-for-target-scope"
  decidedAt: "2026-06-09"
  claim: "The rendered Consul bases still contain mutable image tags, but each rendered image reference has digest-resolution evidence. For the default control-plane public proof scope, the mutable tags are accepted as a target-scoped exception while stricter environments remain free to require digest-pinned bases or image overrides."
  renderedImageSummary:
    renderedSubjects: 2
    subjectsNeedingResolution: 2
    imageRefs: 15
    mutableTagRefs: 15
    floatingLatestOrUntaggedRefs: 0
    resolutionReceipts: 2
  variantReceipts:
    default-control-plane:
      renderedObjectSetSHA256: "7efa3e8b59c702c8b8fa744a0ff91198e09ad8ba0fb93a86b50c3fd9e39d29f7"
      sourceImageReviewRows: 4
      uniqueImages: 2
      receiptPath: "data/image-digest-workdown/receipts/hashicorp-consul/default-control-plane/image-digest-resolution.yaml"
    secure-mesh-existing-secrets:
      renderedObjectSetSHA256: "0acc8c339c2965446b754c3a9c948c4f154ca6e47b074ddc3b8d315e2cb7c468"
      sourceImageReviewRows: 11
      uniqueImages: 3
      receiptPath: "data/image-digest-workdown/receipts/hashicorp-consul/secure-mesh-existing-secrets/image-digest-resolution.yaml"
  acceptedException:
    reason: "The public proof target uses upstream Consul image tags. The receipt set records the registry digest each tag resolved to at decision time, so reviewers can rerun the decision when upstream tags move."
    operatorAction: "For stricter production environments, create a digest-pinned base or image override policy before support expansion."
  limits:
    - "This does not mean the rendered manifests are digest-pinned."
    - "This is not a blanket approval for all clusters, private overlays, regulated environments, or future chart versions."
    - "This does not make the secure mesh, TLS, ACL, gateway, or UI-ingress topology production-supported."
    - "If an upstream image tag is retargeted, rerun digest resolution and re-review this decision before promotion."
  evidence:
    -
      path: "data/image-digest-workdown/chart-summary.csv"
      claim: "Summarizes Consul rendered image references."
    -
      path: "data/attack-plan-workdown/image-digest-review.csv"
      claim: "Lists every rendered image reference found in the Consul object sets."
    -
      path: "data/image-digest-workdown/receipts/hashicorp-consul/default-control-plane/image-digest-resolution.yaml"
      claim: "Records registry digest resolution for the default-control-plane rendered object set."
    -
      path: "data/image-digest-workdown/receipts/hashicorp-consul/secure-mesh-existing-secrets/image-digest-resolution.yaml"
      claim: "Records registry digest resolution for the secure-mesh-existing-secrets rendered object set."
  remainingSupportBlockers:
    - "Record security acceptance and fresh target-scoped ConfigHub OCI/GitOps evidence for the selected default control-plane base."
