apiVersion: helm-expt.confighub.com/v1alpha1
kind: ProductionSupportDecision
metadata:
  name: "prometheus-community-kube-prometheus-stack-default-public-oci-supported"
spec:
  chart: "prometheus-community/kube-prometheus-stack"
  version: "85.3.3"
  decision: supported
  decisionDate: "2026-06-09"
  supportedSince: "2026-06-09T09:59:35Z"
  supportedBase: "default"
  targetScope:
    clusterClass: cub-lk-kind-vanilla
    namespace: "monitoring"
    deliveryPath: confighub-oci
    gitopsController: argo
    lastEvidenceAt: "2026-06-09T09:59:35Z"
    lastEvidenceTarget: helm-expt-parity-kubeprometheudecd9-mq6gxaw5-jvz-cluster/oci
    lastEvidenceKubeContext: kind-helm-expt-parity-kubeprometheudecd9-mq6gxaw5-jvz
    liveEvidenceTTL: 30d
    storageAssumptions:
      - "Use the chart's recorded storage behavior for the supported scope unless a narrower scope is separately reviewed."
    networkAssumptions:
      - "Use the service, ingress, DNS, and certificate behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    requiredTargetFacts:
      - kind: Secret
        namespace: monitoring
        name: kube-prometheus-stack-admission
        keys:
          - cert
          - key
        purpose: Prometheus Operator admission webhook TLS material normally created by Helm hook lifecycle.
  supportBoundary:
    includes:
      - "prometheus-community/kube-prometheus-stack@85.3.3 default base"
      - ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope
      - rendered objects, labels, gates, receipts, and support objects produced by the recorded base
      - declared target-fact preflight for the Prometheus Operator admission webhook TLS Secret
      - recorded mutable-image exception for the declared public monitoring support scope
      - recorded scan and lifecycle decisions for the declared public monitoring support scope
    excludes:
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "digest-pinned or hardened production bases unless separately reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "mutable-image-exception-accepted-for-target-scope"
      detail: "both recorded base variants have digest-resolution receipts; mutable image tags are accepted only for the declared public monitoring support scope, while stricter scopes may require digest-pinned bases or image overrides"
    scanDecision:
      state: "security-accepted-for-target-scope"
      detail: "scan findings are accepted for the declared public monitoring support scope; stricter environments may still require a hardened base"
    lifecycleDecision:
      state: "lifecycle-observed-for-proof-scope"
      detail: "the selected hook/lifecycle route has proof-scope observation evidence for webhook TLS prerequisites, CRD bootstrap, workload rollout, and ConfigHub OCI/Argo runtime health; upgrade and final target evidence remain scoped separately"
    targetFactDecision:
      state: "no-unresolved-target-prerequisite-in-candidate-base"
      detail: "the candidate base declares monitoring/kube-prometheus-stack-admission cert and key as target facts, and the scoped support evidence records prerequisite staging"
    liveEvidenceDecision:
      state: "fresh-target-evidence-passed"
      detail: "fresh target-scoped ConfigHub OCI and Argo evidence passed on 2026-06-09 for the declared cub-lk vanilla kind monitoring scope"
  evidence:
    - path: "recipes/prometheus-community/kube-prometheus-stack/85.3.3/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    - path: "recipes/prometheus-community/kube-prometheus-stack/85.3.3/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    - path: "runs/live-helm-confighub-compare/prometheus-community-kube-prometheus-stack-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    - path: "data/production-support-decisions/prometheus-community-kube-prometheus-stack/fresh-target-evidence-2026-06-09.yaml"
      claim: "Fresh target-scoped ConfigHub OCI and Argo evidence passed for the declared cub-lk vanilla kind support scope."
    - path: "data/image-digest-workdown/receipts/prometheus-community-kube-prometheus-stack/default/image-digest-resolution.yaml"
      claim: "The rendered mutable image references for the candidate base have registry digest-resolution evidence."
    - path: "data/production-support-decisions/prometheus-community-kube-prometheus-stack/image-policy-decision.yaml"
      claim: "The target-scoped image policy decision accepts mutable rendered tags for this public monitoring support draft with explicit limits."
    - path: "data/production-support-decisions/prometheus-community-kube-prometheus-stack/security-decision.yaml"
      claim: "The target-scoped production security decision accepts the recorded scan findings for this public monitoring support draft."
    - path: "data/production-support-decisions/prometheus-community-kube-prometheus-stack/lifecycle-decision.yaml"
      claim: "The target-scoped lifecycle decision binds the selected hook route to proof-scope observation evidence."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/crd-lifecycle-and-upgrade-policy.yaml"
      claim: "The crd lifecycle and upgrade policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/extension-slot-provenance-and-scan-policy.yaml"
      claim: "The extension slot provenance and scan policy receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/generated-fact-ownership.yaml"
      claim: "The generated fact ownership receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/target-fact-preflight.yaml"
      claim: "The target fact preflight receipt exists for this chart."
    - path: "data/production-disposition/receipts/prometheus-community-kube-prometheus-stack/webhook-readiness-and-failure-policy.yaml"
      claim: "The webhook readiness and failure policy receipt exists for this chart."
    - path: "data/hook-lifecycle/receipts/prometheus-community-kube-prometheus-stack/default/latest.yaml"
      claim: "The hook lifecycle route is selected; the lifecycle decision binds it to proof-scope observation evidence."
  requiredBeforeFinal: []
  nextAction: "Keep the target-scoped evidence fresh before using this supported scope as a production-support example."
