apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ProductionLifecycleDecision"
metadata:
  name: "secrets-store-csi-driver-secrets-store-csi-driver-public-oci-lifecycle-decision"
spec:
  chart: "secrets-store-csi-driver/secrets-store-csi-driver"
  version: "1.6.0"
  targetScope:
    clusterClass: "cub-lk-kind-vanilla"
    namespace: "kube-system"
    deliveryPath: "confighub-oci"
    gitopsController: "argo"
  supportedBaseCandidate: "default"
  variantsCovered:
    - "default"
    - "sync-secret-rotation"
  decision: "node-daemonset-and-crds-observed-for-proof-scope"
  decidedAt: "2026-06-09"
  claim: "The default base has no Helm hooks. CRDs, cluster RBAC, and the CSI node DaemonSet are applied as reviewed desired objects and observed healthy through regular Helm, cub installer apply, and ConfigHub OCI/Argo."
  lifecycleModel:
    hookPolicy: "no-chart-hooks"
    selectedTopology: "default-node-csi-driver"
    excludedTopologies:
      - "sync-secret-rotation"
  observedLifecycleSignals:
    twoClusterParity:
      result: "pass"
      observedAt: "2026-06-06T08:15:57Z"
      regularHelmRuntime: "pass"
      installerRuntime: "pass"
      semanticParity: "pass"
    confighubOciArgo:
      result: "pass"
      observedAt: "2026-06-05T20:42:11Z"
      regularHelmRuntime: "pass"
      confighubApplyRuntime: "pass"
      confighubOciRuntime: "pass"
      argoSync: "Synced"
      argoHealth: "Healthy"
      semanticParity: "pass"
      allowedExtraConfigHubObjects:
        - "v1|Namespace||kube-system"
  limits:
    - "This is not a blanket security approval for customer clusters, private overlays, regulated environments, or future chart versions."
    - "This does not support SecretProviderClass provider configuration, secret sync, or rotation workflows."
    - "Provider credentials, IAM, external secret-store connectivity, and sync/rotation behavior remain separate target decisions."
  evidence:
    -
      path: "runs/live-kind-parity/secrets-store-csi-driver-secrets-store-csi-driver-default/receipt.yaml"
      claim: "Two-cluster Helm-vs-installer parity passes for default."
    -
      path: "runs/live-helm-confighub-compare/secrets-store-csi-driver-secrets-store-csi-driver-default/receipt.yaml"
      claim: "ConfigHub OCI/Argo live parity passes for default."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/crd-lifecycle-and-upgrade-policy.yaml"
      claim: "The crd lifecycle and upgrade policy receipt exists for this chart."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
  remainingSupportBlockers:
    - "Record image policy, security acceptance, and fresh target-scoped ConfigHub OCI/GitOps evidence."
