apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "HelmPainReport"
metadata:
  name: "grafana-grafana-10.5.15"
spec:
  chart:
    name: "grafana/grafana"
    version: "10.5.15"
    source: "https://grafana.github.io/helm-charts"
    digest: "c08c87969270402e7d5227edb8385af67cc32ee34817bff89773ad02303b5d79"
  supportedScopeStatus: "no-unhandled-pain-points-for-supported-scopes"
  supportedScopes:
    - "local-test"
  supportedVariants:
    - "static-passwords"
    - "existing-secret-ingress"
  productionReadiness: "production-review-ready"
  notes:
    - "Chart.yaml marks this chart version deprecated, and the proof records that status."
    - "Default chart rendering is nondeterministic unless adminPassword is bound before render."
    - "static-passwords variant persists adminPassword as a generated fact and renders the Secret deterministically."
    - "existing-secret-ingress variant does not render a Secret and instead declares grafana/grafana-admin as a target fact."
    - "existing-secret-ingress variant adds explicit UI ingress host and ingress class."
    - "Datasource, dashboard, plugin, sidecar, and Secret/env injection slots are powerful extension surfaces; promoted variants keep them empty."
  painPoints:
    -
      id: "source-lock"
      detectedPainPoint: "source-lock requires source-lock.yaml"
      evidence:
        - "source-lock.yaml"
      configHubHome: "source-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "source-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "dependency-lock"
      detectedPainPoint: "chart declares no subchart dependencies; the empty closure is recorded explicitly."
      evidence:
        - "dependency-lock.yaml"
      configHubHome: "dependency-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "dependency-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "capability-profile"
      detectedPainPoint: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
      evidence:
        - "control-points.yaml"
      configHubHome: "capability-profile"
      disposition: "handled-by-capability-profile"
      linkedReceipt: "revisions/static-passwords/r001/receipts/render-receipt.yaml"
      supportedVariantStatus: "handled"
    -
      id: "generated-facts"
      detectedPainPoint: "The static-passwords variant binds the generated Grafana admin password before render so Helm output is deterministic."
      evidence:
        - "adminPassword"
      configHubHome: "generated-fact"
      disposition: "handled-by-generated-facts"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "target-facts"
      detectedPainPoint: "The existing-secret-ingress variant declares the target Secret instead of rendering one."
      evidence:
        - "admin.existingSecret"
      configHubHome: "target-fact-requirement"
      disposition: "handled-by-target-fact-values"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "deployment-workload"
      detectedPainPoint: "deployment-workload affects apps/v1|Deployment|grafana|grafana"
      evidence:
        - "apps/v1|Deployment|grafana|grafana"
      configHubHome: "recipe"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "ui-ingress-policy"
      detectedPainPoint: "ui-ingress-policy affects networking.k8s.io/v1|Ingress|grafana|grafana"
      evidence:
        - "networking.k8s.io/v1|Ingress|grafana|grafana"
      configHubHome: "recipe"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "cluster-rbac"
      detectedPainPoint: "cluster-rbac affects rbac.authorization.k8s.io/v1|ClusterRole||grafana-clusterrole"
      evidence:
        - "rbac.authorization.k8s.io/v1|ClusterRole||grafana-clusterrole"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/scan-receipt.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "extension-slots"
      detectedPainPoint: "datasource, dashboard, plugin, sidecar, and Secret/env slots are empty in promoted variants."
      evidence:
        - "control-points.yaml"
      configHubHome: "extension-slot"
      disposition: "handled-by-variant"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "controlled-by-empty-defaults"
    -
      id: "chart-deprecation"
      detectedPainPoint: "Chart.yaml marks this chart version as deprecated; the proof records the fact but still verifies the public chart output."
      evidence:
        - "control-points.yaml"
      configHubHome: "recipe"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "noted"
    -
      id: "installer-support-object"
      detectedPainPoint: "installer-support-object affects v1|Namespace||grafana"
      evidence:
        - "v1|Namespace||grafana"
      configHubHome: "recipe"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled"
    -
      id: "scan-gate"
      detectedPainPoint: "Current scan gate is warn-production-blocked"
      evidence:
        - "helm-plan.yaml"
        - "scan receipts"
        - "install gates"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/static-passwords/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "warn-production-blocked"
    -
      id: "value-model-diagnostics"
      detectedPainPoint: "Helm values can be unknown, dead, misspelled, shadowed, or ignored unless the values model records the analysis boundary."
      evidence:
        - "value-model.yaml"
      configHubHome: "value-model"
      disposition: "absorbed-into-value-model"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "unknown=not-checked; dead=not-checked; ignored=not-checked"
  answerForSkepticalHelmUser: "grafana/grafana@10.5.15 maps its detected Helm pain to 9 ConfigHub control areas: source-lock, dependency-lock, capability-profile, generated-fact, target-fact-requirement, recipe, scan-gate, extension-slot, value-model. Supported scopes have explicit variants, receipts, scans/gates, and control-point dispositions; production readiness remains production-review-ready."
