apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ProductionSupportDecision"
metadata:
  name: "secrets-store-csi-driver-secrets-store-csi-driver-default-public-oci-supported"
spec:
  chart: "secrets-store-csi-driver/secrets-store-csi-driver"
  version: "1.6.0"
  decision: "supported"
  decisionDate: "2026-06-09"
  supportedSince: "2026-06-05T20:42:11Z"
  supportedBase: "default"
  targetScope:
    clusterClass: "cub-lk-kind-vanilla"
    namespace: "kube-system"
    deliveryPath: "confighub-oci"
    gitopsController: "argo"
    lastEvidenceAt: "2026-06-05T20:42:11Z"
    lastEvidenceTarget: "helm-expt-parity-secretsstorece4481-mq1e49vr-12eh-cluster/oci"
    lastEvidenceKubeContext: "kind-helm-expt-parity-secretsstorece4481-mq1e49vr-12eh"
    liveEvidenceTTL: "30d"
    storageAssumptions:
      - "Use the Secrets Store CSI Driver default storage behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    networkAssumptions:
      - "Use the Secrets Store CSI Driver service, webhook, CRD, and node behavior recorded by the supported scope unless a narrower scope is separately reviewed."
    requiredTargetFacts:
      []
  supportBoundary:
    includes:
      - "secrets-store-csi-driver/secrets-store-csi-driver@1.6.0 default base"
      - "ConfigHub OCI delivery through Argo for the declared cub-lk vanilla kind target scope"
      - "rendered CRDs, CSI DaemonSet, cluster RBAC, labels, gates, receipts, and support objects produced by the default base"
      - "mutable-image exception backed by registry digest-resolution evidence for the rendered image references"
      - "recorded security acceptance, lifecycle observation, live Helm-vs-ConfigHub parity, and two-cluster Helm-vs-installer parity for the declared public proof scope"
    excludes:
      - "sync-secret-rotation unless separately reviewed with provider-specific SecretProviderClass and synced-Secret runtime evidence"
      - "provider-specific SecretProviderClass, external provider, cloud IAM, or secret-store integration unless separately reviewed"
      - "private values overlays, wrapper charts, and populated extension slots unless separately reviewed"
      - "non-vanilla Kubernetes distributions unless separately reviewed"
      - "other delivery controllers or target scopes unless separately reviewed"
  decisions:
    imageDecision:
      state: "mutable-image-exception-accepted-for-target-scope"
      detail: "rendered Secrets Store CSI Driver image tags are mutable, with registry digest-resolution evidence recorded for this public proof scope; stricter environments should use digest-pinned bases or image overrides"
    scanDecision:
      state: "privileged-node-driver-accepted-for-target-scope"
      detail: "The default base installs a node CSI driver with privileged and privilege-escalation containers. That is accepted only for this public proof scope because it is the normal operating shape of this infrastructure component. Customer production scopes should review provider integration, node policy, sync/rotation behavior, and whether a hardened base is possible."
    lifecycleDecision:
      state: "node-daemonset-and-crds-observed-for-proof-scope"
      detail: "The default base has no Helm hooks. CRDs, cluster RBAC, and the CSI node DaemonSet are applied as reviewed desired objects and observed healthy through regular Helm, cub installer apply, and ConfigHub OCI/Argo."
    targetFactDecision:
      state: "no-unresolved-target-prerequisite-in-candidate-base"
      detail: "no unresolved target prerequisite in candidate base"
    liveEvidenceDecision:
      state: "fresh-target-evidence-passed"
      detail: "fresh target-scoped ConfigHub OCI and Argo evidence passed on 2026-06-05 for the declared cub-lk vanilla kind Secrets Store CSI Driver default scope"
  evidence:
    -
      path: "recipes/secrets-store-csi-driver/secrets-store-csi-driver/1.6.0/revisions/default/r001/receipts/helm-equivalence-receipt.yaml"
      claim: "The candidate base is Helm-equivalent under recorded inputs."
    -
      path: "recipes/secrets-store-csi-driver/secrets-store-csi-driver/1.6.0/revisions/default/r001/receipts/scan-receipt.yaml"
      claim: "The rendered-object scan receipt exists for the candidate base."
    -
      path: "runs/live-kind-parity/secrets-store-csi-driver-secrets-store-csi-driver-default/receipt.yaml"
      claim: "The two-cluster Helm-vs-installer parity receipt exists for the candidate base."
    -
      path: "runs/live-helm-confighub-compare/secrets-store-csi-driver-secrets-store-csi-driver-default/receipt.yaml"
      claim: "The selected live Helm-vs-ConfigHub comparison receipt exists for the candidate base."
    -
      path: "data/production-support-decisions/secrets-store-csi-driver-secrets-store-csi-driver/fresh-target-evidence-2026-06-05.yaml"
      claim: "Fresh target-scoped ConfigHub OCI and Argo evidence passed for the declared cub-lk vanilla kind support scope."
    -
      path: "data/image-digest-workdown/receipts/secrets-store-csi-driver-secrets-store-csi-driver/default/image-digest-resolution.yaml"
      claim: "Registry digest resolution exists for the rendered default image references."
    -
      path: "data/production-support-decisions/secrets-store-csi-driver-secrets-store-csi-driver/image-policy-decision.yaml"
      claim: "The target-scoped image policy decision records the mutable-image exception and digest-resolution evidence."
    -
      path: "data/production-support-decisions/secrets-store-csi-driver-secrets-store-csi-driver/security-decision.yaml"
      claim: "The target-scoped security decision records the accepted infrastructure security boundary."
    -
      path: "data/production-support-decisions/secrets-store-csi-driver-secrets-store-csi-driver/lifecycle-decision.yaml"
      claim: "The target-scoped lifecycle decision binds CRD, webhook, node, runtime, and OCI/Argo health to proof-scope evidence."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/cluster-rbac-review.yaml"
      claim: "The cluster rbac review receipt exists for this chart."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/crd-lifecycle-and-upgrade-policy.yaml"
      claim: "The crd lifecycle and upgrade policy receipt exists for this chart."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/extension-slot-provenance-and-scan-policy.yaml"
      claim: "The extension slot provenance and scan policy receipt exists for this chart."
    -
      path: "data/production-disposition/receipts/secrets-store-csi-driver-secrets-store-csi-driver/scan-gate-warning-disposition.yaml"
      claim: "The scan gate warning disposition receipt exists for this chart."
  requiredBeforeFinal:
    []
  nextAction: "Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate provider, sync-secret-rotation, IAM, node-policy, resource-hardened, or digest-pinned bases for real customer secret-store workloads."
