apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: ingress-nginx-ingress-nginx-internal-clusterip-public-oci-supported
spec:
  chart: ingress-nginx/ingress-nginx
  version: "4.15.1"
  decision: supported
  decisionDate: "2026-06-09"
  supportedSince: "2026-06-09T20:44:02Z"
  supportedBase: internal-clusterip
  targetScope:
    clusterClass: cub-lk-kind-vanilla
    namespace: ingress-nginx
    deliveryPath: confighub-oci
    gitopsController: argo
    lastEvidenceAt: "2026-06-09T20:44:02Z"
    lastEvidenceTarget: helm-expt-parity-ingressnginx-mq73y283-241h-cluster/oci
    lastEvidenceKubeContext: kind-helm-expt-parity-ingressnginx-mq73y283-241h
    liveEvidenceTTL: 30d
    storageAssumptions:
      - no persistent volume required for the supported base
    networkAssumptions:
      - controller Service is ClusterIP
      - external LoadBalancer provisioning, public ingress, DNS, and TLS certificates are outside this supported base
    requiredTargetFacts: []
  supportBoundary:
    includes:
      - ingress-nginx/ingress-nginx@4.15.1 internal-clusterip base
      - admission webhook objects disabled in the supported base
      - rendered Deployment, Service, IngressClass, RBAC, ConfigMap, ServiceAccount, and Namespace support object produced by the recorded base
      - ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope
    excludes:
      - default base with admission webhook and LoadBalancer behavior
      - admission-disabled base with LoadBalancer behavior
      - public LoadBalancer provisioning
      - production ingress, DNS, and certificate management
      - private values overlays, wrapper charts, and populated extension slots unless separately reviewed
      - non-vanilla Kubernetes distributions unless separately reviewed
  decisions:
    imageDecision:
      state: no-open-image-digest-gap
      detail: The rendered controller image is pinned by digest in the supported base.
    scanDecision:
      state: accepted-for-scope
      detail: Cluster RBAC findings are accepted for the declared ingress controller scope; the admission webhook and hook path are outside this base.
    lifecycleDecision:
      state: no-chart-hooks-for-supported-base
      detail: The supported base disables admission webhooks, so the admission hook Jobs and webhook readiness path are excluded from this support scope.
    targetFactDecision:
      state: none-required
      detail: The internal-clusterip base has no required target facts.
    liveEvidenceDecision:
      state: fresh-target-evidence-passed
      detail: Fresh target-scoped ConfigHub OCI and Argo evidence passed on 2026-06-09 for the declared cub-lk vanilla kind scope.
  evidence:
    - path: recipes/ingress-nginx/ingress-nginx/4.15.1/revisions/internal-clusterip/r001/receipts/helm-equivalence-receipt.yaml
      claim: The supported base is Helm-equivalent under recorded inputs, with only the installer Namespace support object added.
    - path: recipes/ingress-nginx/ingress-nginx/4.15.1/revisions/internal-clusterip/r001/receipts/scan-receipt.yaml
      claim: The supported base records cluster RBAC findings and has no high or critical rendered-object scan findings.
    - path: runs/ingress-nginx-confighub-proof/latest/confighub-proof-receipt.yaml
      claim: ConfigHub upload, plan, safe operations, labels, and server-side variant clone proof passed for the supported base.
    - path: runs/top20-local-kind/ingress-nginx-internal-clusterip/observation-receipt.json
      claim: Local kind apply, rollout, cub-scout object-set, closed-world, and workload convergence checks passed for the supported base.
    - path: runs/live-kind-parity/ingress-nginx-ingress-nginx-internal-clusterip/receipt.yaml
      claim: The supported base passes strict two-cluster live parity between regular Helm and cub installer apply.
    - path: runs/live-helm-confighub-compare/ingress-nginx-ingress-nginx-internal-clusterip/receipt.yaml
      claim: Regular Helm, ConfigHub kubectl apply, and ConfigHub OCI/Argo delivery reached the same live outcome for the supported base.
    - path: data/production-support-decisions/ingress-nginx-ingress-nginx/fresh-target-evidence-2026-06-09.yaml
      claim: Fresh target-scoped ConfigHub OCI and Argo evidence passed for the declared support scope.
  requiredBeforeFinal: []
  nextAction: Keep the target-scoped evidence fresh before using this supported scope as a production-support example.
