apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "Top100PromotionReviewPacket"
metadata:
  name: "stakater-reloader-2-2-12-promotion-review"
spec:
  chart: "stakater/reloader"
  version: "2.2.12"
  selectedBaseCandidate: "controller-default-reviewed"
  candidateVariants:
    - "default"
    - "controller-default-reviewed"
  decisionState: "review-input-only"
  catalogSupportClaimAllowed: false
  whyThisChartIsInTheWave:
    - "The chart is proof-grade in the maintained top-100 corpus."
    - "The chart has multiple named variants, so there is a real selection question."
    - "The selected base has strict parity evidence."
    - "No named limitation currently blocks promotion review."
  currentEvidence:
    catalog: "recipes/stakater/reloader/2.2.12/CATALOG.md"
    helmPainReport: "recipes/stakater/reloader/2.2.12/helm-pain-report.yaml"
    controlPoints: "recipes/stakater/reloader/2.2.12/control-points.yaml"
    valueModel: "recipes/stakater/reloader/2.2.12/value-model.yaml"
    helmPlan: "recipes/stakater/reloader/2.2.12/helm-plan.yaml"
    variant: "recipes/stakater/reloader/2.2.12/variants/controller-default-reviewed/variant.yaml"
    variantRevision: "recipes/stakater/reloader/2.2.12/revisions/controller-default-reviewed/r001/variant-revision.yaml"
    helmEquivalence: "recipes/stakater/reloader/2.2.12/revisions/controller-default-reviewed/r001/receipts/helm-equivalence-receipt.yaml"
    scanReceipt: "recipes/stakater/reloader/2.2.12/revisions/controller-default-reviewed/r001/receipts/scan-receipt.yaml"
    installGate: "recipes/stakater/reloader/2.2.12/revisions/controller-default-reviewed/r001/receipts/install-gate.yaml"
    packageBase: "packages/stakater/reloader/2.2.12/bases/controller-default-reviewed/kustomization.yaml"
    twoClusterKindParity: "runs/live-kind-parity/stakater-reloader-controller-default-reviewed/receipt.yaml"
    liveHelmConfigHubParity: "runs/live-helm-confighub-compare/stakater-reloader-controller-default-reviewed/receipt.yaml"
  currentState:
    supportLevel: "machine-proof-only"
    productionReadiness: "not-reviewed-for-production"
    catalogStatus: "proof-grade"
    strongestEvidence: "live-helm-vs-confighub-parity"
    scanHigh: 0
    scanMedium: 4
    gateDecisions:
      - "warn"
    featureFocus:
      - "tpl"
      - "capabilities"
      - "cluster-rbac"
  decisionsNeeded:
    -
      workType: "variant-selection"
      reviewer: "catalog reviewer"
      reason: "Confirm the promoted base is a real Helm-user path, not merely the first rendered baseline."
      doneWhen: "A selected variant is named from default;controller-default-reviewed and the non-selected variants have a written promote/defer reason."
      evidence: "recipes/stakater/reloader/2.2.12/CATALOG.md"
    -
      workType: "scan-and-gate-disposition"
      reviewer: "security reviewer"
      reason: "Scan/gate state is high=0, medium=4, gates=warn."
      doneWhen: "Every warning is fixed, accepted with rationale, or routed to a narrower base before catalog support."
      evidence: "data/catalog-promotion-review/review.csv"
    -
      workType: "rbac-scope"
      reviewer: "security reviewer"
      reason: "The chart creates cluster-scoped RBAC or similar permissions."
      doneWhen: "Cluster permissions are accepted for the support scope or a narrower base is selected."
      evidence: "recipes/stakater/reloader/2.2.12/helm-pain-report.yaml"
    -
      workType: "template-and-capability-boundary"
      reviewer: "catalog reviewer"
      reason: "The chart has template-powered inputs or Kubernetes capability branches."
      doneWhen: "The supported values, capability profile, and extension-slot policy are catalog-readable for the selected base."
      evidence: "recipes/stakater/reloader/2.2.12/helm-plan.yaml"
    -
      workType: "selected-live-evidence"
      reviewer: "operator reviewer"
      reason: "Strict parity evidence exists (live-helm-vs-confighub-parity); catalog promotion needs the selected runtime evidence boundary."
      doneWhen: "The selected base has linked live evidence, GitOps/OCI evidence, live parity evidence, or a routed deferral with rationale."
      evidence: "data/live-kind-parity/summary.csv;data/live-helm-confighub-compare/summary.csv"
    -
      workType: "target-scoped-support-decision"
      reviewer: "catalog owner"
      reason: "Catalog support is not implied by machine proof."
      doneWhen: "A target-scoped support decision exists with supported, deferred, superseded, or blocked outcome."
      evidence: "data/production-support-decisions/summary.md"
  claimsNotMade:
    - "catalog support"
    - "production support"
    - "support for non-selected variants"
    - "support for private values overlays or wrapper charts"
    - "support outside the eventual target scope"
    - "least-privilege RBAC hardening"
  nextAction: "Use this packet to choose the promoted base, close the listed review decisions, link selected live evidence or a routed deferral, then write a target-scoped support decision before changing catalog status."
