apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "metrics-server-metrics-server-default-public-oci-supported"
spec:
  chart: "metrics-server/metrics-server"
  version: "3.13.0"
  decision: supported
  decisionDate: "2026-06-09"
  supportedSince: "2026-06-05T15:44:11Z"
  supportedBase: "default"
  targetScope:
    clusterClass: cub-lk-kind-vanilla
    namespace: "kube-system"
    deliveryPath: confighub-oci
    gitopsController: argo
    lastEvidenceAt: "2026-06-05T15:44:11Z"
    lastEvidenceTarget: helm-expt-parity-metricsserver-mq13h1yo-154u-cluster/oci
    lastEvidenceKubeContext: kind-helm-expt-parity-metricsserver-mq13h1yo-154u
    liveEvidenceTTL: 30d
    storageAssumptions:
      - "The supported base is stateless; production resource sizing remains a target decision."
    networkAssumptions:
      - "Use the Service and APIService behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    requiredTargetFacts: []
  supportBoundary:
    includes:
      - "metrics-server/metrics-server@3.13.0 default base"
      - ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope
      - rendered Metrics Server Deployment, Service, APIService, cluster RBAC, labels, gates, receipts, and support objects produced by the recorded base
      - mutable-image exception backed by registry digest-resolution evidence for the rendered image references
      - recorded resource-warning acceptance, cluster RBAC review, no-hooks lifecycle policy, APIService availability, and metrics API observation for the declared public proof scope
    excludes:
      - "external-tls-ca unless separately reviewed with target certificate-chain evidence"
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "resource-hardened, RBAC-hardened, API aggregation hardened, custom TLS, or customer production bases unless separately reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "mutable-image-exception-accepted-for-target-scope"
      detail: "rendered Metrics Server image tags are mutable, with registry digest-resolution evidence recorded for this public proof scope; stricter environments should use digest-pinned bases or image overrides"
    scanDecision:
      state: "resource-defaults-accepted-for-target-scope"
      detail: "the chart resource warning is accepted only for the declared public proof scope; target production deployments should choose resource requests and limits"
    lifecycleDecision:
      state: "lifecycle-observed-for-proof-scope"
      detail: "the default base has no Helm hooks and reaches readiness through regular Helm, cub installer apply, ConfigHub OCI/Argo, APIService Available=True, and kubectl top nodes"
    targetFactDecision:
      state: "no-unresolved-target-prerequisite-in-candidate-base"
      detail: "no unresolved target prerequisite in candidate base"
    liveEvidenceDecision:
      state: "fresh-target-evidence-passed"
      detail: "fresh target-scoped ConfigHub OCI and Argo evidence passed on 2026-06-05 for the declared cub-lk vanilla kind Metrics Server default scope"
  evidence:
    - path: "recipes/metrics-server/metrics-server/3.13.0/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    - path: "recipes/metrics-server/metrics-server/3.13.0/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    - path: "runs/live-kind-parity/metrics-server-metrics-server-default/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the candidate base."
    - path: "runs/live-helm-confighub-compare/metrics-server-metrics-server-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    - path: "data/runtime-gitops/receipts/metrics-server-metrics-server/default/latest.yaml"
      claim: "The runtime/GitOps receipt records APIService Available=True and kubectl top nodes returning metrics for the default base."
    - path: "data/production-support-decisions/metrics-server-metrics-server/fresh-target-evidence-2026-06-05.yaml"
      claim: "Fresh target-scoped ConfigHub OCI and Argo evidence passed for the declared cub-lk vanilla kind support scope."
    - path: "data/image-digest-workdown/receipts/metrics-server-metrics-server/default/image-digest-resolution.yaml"
      claim: "Registry digest resolution exists for the rendered default Metrics Server image reference."
    - path: "data/production-support-decisions/metrics-server-metrics-server/image-policy-decision.yaml"
      claim: "The target-scoped image policy decision records the mutable-image exception and digest-resolution evidence."
    - path: "data/production-support-decisions/metrics-server-metrics-server/security-decision.yaml"
      claim: "The target-scoped security decision accepts the default resource-warning shape only for this public proof scope."
    - path: "data/production-support-decisions/metrics-server-metrics-server/lifecycle-decision.yaml"
      claim: "The target-scoped lifecycle decision binds no-hooks policy, cluster RBAC, APIService observation, metrics API proof, and OCI/Argo runtime health to proof-scope evidence."
    - path: "data/production-disposition/receipts/metrics-server-metrics-server/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    - path: "data/production-disposition/receipts/metrics-server-metrics-server/generated-fact-ownership.yaml"
      claim: "The generated fact ownership receipt exists for this chart."
    - path: "data/production-disposition/receipts/metrics-server-metrics-server/hook-lifecycle-phase-policy.yaml"
      claim: "The hook lifecycle phase policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/metrics-server-metrics-server/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
    - path: "data/production-disposition/receipts/metrics-server-metrics-server/target-fact-preflight.yaml"
      claim: "The target fact preflight receipt exists for this chart."
  requiredBeforeFinal: []
  nextAction: "Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate external-tls-ca, resource-hardened, RBAC-hardened, API aggregation hardened, digest-pinned, or customer production bases for real Metrics Server workloads."
