apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "hashicorp-vault-default-public-oci-rejected"
spec:
  chart: "hashicorp/vault"
  version: "0.32.0"
  decision: rejected
  decisionDate: "2026-07-28"
  supportedBase: "default"
  targetScope:
    clusterClass: kind-vanilla
    namespace: "vault"
    deliveryPath: confighub-oci
    gitopsController: argo
    storageAssumptions:
      - "The evaluated default base uses the chart's single-node file-storage behavior."
    networkAssumptions:
      - "The evaluated default base does not establish a production TLS and certificate policy."
    requiredTargetFacts: []
  supportBoundary:
    includes:
      - "the production-support decision for hashicorp/vault@0.32.0 default"
      - "the recorded Helm, ConfigHub direct-apply, and ConfigHub OCI/Argo evidence used to evaluate that base"
      - "continued use of the default base as a ready-to-try catalog and parity example"
    excludes:
      - "a production-support claim for the default base"
      - "a production Vault storage, TLS, unseal, recovery, backup, or upgrade policy"
      - "private values overlays, wrapper charts, populated extension slots, and other target scopes"
  decisions:
    imageDecision:
      state: "mutable-tags-prevent-production-support"
      detail: "the default base renders mutable image tags; this decision does not grant an exception for production use"
    scanDecision:
      state: "default-security-posture-not-accepted-for-production"
      detail: "the recorded findings include disabled TLS, cluster-wide access, service exposure, and webhook policy that need a separate hardened base"
    lifecycleDecision:
      state: "manual-vault-operations-not-production-supported"
      detail: "the proof initializes and unseals Vault after delivery, but it does not define a production unseal, recovery, backup, rollback, or upgrade procedure"
    targetFactDecision:
      state: "production-target-contract-not-defined"
      detail: "the default base does not state the storage, certificate, identity, availability, and recovery facts required for a production target"
    liveEvidenceDecision:
      state: "parity-passed-production-support-rejected"
      detail: "the committed evidence proves the evaluated paths can install the same working example; it does not make the default base production-ready"
  evidence:
    - path: "recipes/hashicorp/vault/0.32.0/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    - path: "recipes/hashicorp/vault/0.32.0/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    - path: "runs/live-kind-parity/hashicorp-vault-default/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the candidate base."
    - path: "runs/live-helm-confighub-compare/hashicorp-vault-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    - path: "data/production-disposition/receipts/hashicorp-vault/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    - path: "data/production-disposition/receipts/hashicorp-vault/extension-slot-provenance-and-scan-policy.yaml"
      claim: "The extension slot provenance and scan policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/hashicorp-vault/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
    - path: "data/production-disposition/receipts/hashicorp-vault/storage-backup-restore-and-rollback-policy.yaml"
      claim: "The storage backup restore and rollback policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/hashicorp-vault/webhook-readiness-and-failure-policy.yaml"
      claim: "The webhook readiness and failure policy receipt exists for this chart."
  requiredBeforeFinal: []
  nextAction: "Keep the default base as a ready-to-try parity example. Create a separate TLS-enabled, digest-pinned, persistent-storage base with explicit init, unseal, recovery, backup, and upgrade procedures before reconsidering production support."
