apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "HelmPainReport"
metadata:
  name: "bitnami-mysql-14.0.3"
spec:
  chart:
    name: "bitnami/mysql"
    version: "14.0.3"
    source: "https://charts.bitnami.com/bitnami"
    digest: "fc7c297ce7e2953190e313d4afc4f3093a9f8d47e82d15e6c933982c0d0b8ac2"
  supportedScopeStatus: "no-unhandled-pain-points-for-supported-scopes"
  supportedScopes:
    - "local-test"
  supportedVariants:
    - "static-passwords"
    - "existing-secret"
  productionReadiness: "production-review-ready"
  notes:
    - "Default chart rendering is nondeterministic unless auth.rootPassword, auth.password, and auth.replicationPassword are bound before render."
    - "static-passwords variant persists all three password fields as generated facts and renders the Secret deterministically."
    - "existing-secret variant does not render a Secret and instead declares mysql/mysql-auth as a target fact."
    - "Chart declares the Bitnami common dependency and records it in dependency-lock.yaml."
    - "Supported bases render no hook objects, and future hook-producing paths must map to lifecycle policy before production."
    - "MySQL renders a StatefulSet with volumeClaimTemplates and needs storage/upgrade/rollback policy."
    - "initdb and extended configuration are template-powered extension slots; promoted variants keep them empty."
  painPoints:
    -
      id: "source-lock"
      detectedPainPoint: "source-lock requires source-lock.yaml"
      evidence:
        - "source-lock.yaml"
      configHubHome: "source-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "source-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "dependency-lock"
      detectedPainPoint: "chart declares the Bitnami common dependency; promoted variants lock its metadata."
      evidence:
        - "dependency-lock.yaml"
      configHubHome: "dependency-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "dependency-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "capability-profile"
      detectedPainPoint: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
      evidence:
        - "control-points.yaml"
      configHubHome: "capability-profile"
      disposition: "handled-by-capability-profile"
      linkedReceipt: "revisions/static-passwords/r001/receipts/render-receipt.yaml"
      supportedVariantStatus: "handled"
    -
      id: "generated-facts"
      detectedPainPoint: "The static-passwords variant binds all generated password fields before render so Helm output is deterministic."
      evidence:
        - "auth.rootPassword + auth.password + auth.replicationPassword"
      configHubHome: "generated-fact"
      disposition: "handled-by-generated-facts"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "target-facts"
      detectedPainPoint: "The existing-secret variant declares the target Secret instead of rendering one."
      evidence:
        - "auth.existingSecret"
      configHubHome: "target-fact-requirement"
      disposition: "handled-by-target-fact-values"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "hook-policy"
      detectedPainPoint: "The retained source scan records hook count 0 for this pinned chart version. Supported bases render no hook objects; future hook-producing paths must map to lifecycle policy before production."
      evidence:
        - "no-hooks"
      configHubHome: "lifecycle-policy"
      disposition: "handled-by-lifecycle-policy"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled-for-render"
    -
      id: "stateful-workload"
      detectedPainPoint: "stateful-workload affects apps/v1|StatefulSet|mysql|mysql"
      evidence:
        - "apps/v1|StatefulSet|mysql|mysql"
      configHubHome: "operate-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "pvc-policy"
      detectedPainPoint: "StatefulSet volumeClaimTemplates need storage, retention, upgrade, and rollback policy."
      evidence:
        - "control-points.yaml"
      configHubHome: "operate-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "tpl"
      detectedPainPoint: "initdb and extended configuration slots use templating; promoted variants do not populate them."
      evidence:
        - "control-points.yaml"
      configHubHome: "extension-slot"
      disposition: "handled-by-variant"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "controlled-by-empty-defaults"
    -
      id: "installer-support-object"
      detectedPainPoint: "installer-support-object affects v1|Namespace||mysql"
      evidence:
        - "v1|Namespace||mysql"
      configHubHome: "recipe"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled"
    -
      id: "scan-gate"
      detectedPainPoint: "Current scan gate is warn-production-blocked"
      evidence:
        - "helm-plan.yaml"
        - "scan receipts"
        - "install gates"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "warn-production-blocked"
    -
      id: "value-model-diagnostics"
      detectedPainPoint: "Helm values can be unknown, dead, misspelled, shadowed, or ignored unless the values model records the analysis boundary."
      evidence:
        - "value-model.yaml"
      configHubHome: "value-model"
      disposition: "absorbed-into-value-model"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "unknown=not-checked; dead=not-checked; ignored=not-checked"
  answerForSkepticalHelmUser: "bitnami/mysql@14.0.3 maps its detected Helm pain to 11 ConfigHub control areas: source-lock, dependency-lock, capability-profile, generated-fact, target-fact-requirement, lifecycle-policy, operate-policy, extension-slot, recipe, scan-gate, value-model. Supported scopes have explicit variants, receipts, scans/gates, and control-point dispositions; production readiness remains production-review-ready."
