apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "HelmPainReport"
metadata:
  name: "grafana-loki-7.0.0"
spec:
  chart:
    name: "grafana/loki"
    version: "7.0.0"
    source: "https://grafana.github.io/helm-charts"
    digest: "5eaa28e3535069de2a7ac1f7087ff558e5b4b4a24f0e158072a97e2391132f81"
  supportedScopeStatus: "no-unhandled-pain-points-for-supported-scopes"
  supportedScopes:
    - "local-test"
  supportedVariants:
    - "single-binary-filesystem"
    - "simple-scalable-minio"
  productionReadiness: "production-review-ready"
  notes:
    - "Default chart rendering fails before object creation until loki.storage.bucketNames.chunks and schemaConfig are supplied."
    - "single-binary-filesystem selects SingleBinary topology, filesystem storage, and one Loki StatefulSet for local proof."
    - "simple-scalable-minio selects the scalable topology, one read/write/backend replica, explicit S3 bucket names, and the bundled MinIO dependency as a local object-store fixture."
    - "Chart dependency metadata records MinIO, grafana-agent-operator, and rollout-operator from Chart.lock."
    - "Promoted variants render no hook objects with --no-hooks; future hook or test enablement must map to lifecycle policy."
    - "Loki and MinIO render StatefulSets that need storage/upgrade/rollback policy before production."
    - "Loki config, structuredConfig, extraEnv, and raw object slots are template-powered extension surfaces; promoted variants keep raw object slots empty."
  painPoints:
    -
      id: "source-lock"
      detectedPainPoint: "source-lock requires source-lock.yaml"
      evidence:
        - "source-lock.yaml"
      configHubHome: "source-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "source-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "dependency-lock"
      detectedPainPoint: "chart declares MinIO, grafana-agent-operator, and rollout-operator dependencies; promoted variants lock their metadata."
      evidence:
        - "dependency-lock.yaml"
      configHubHome: "dependency-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "dependency-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "capability-profile"
      detectedPainPoint: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
      evidence:
        - "control-points.yaml"
      configHubHome: "capability-profile"
      disposition: "handled-by-capability-profile"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/render-receipt.yaml"
      supportedVariantStatus: "handled"
    -
      id: "blocked-default-render"
      detectedPainPoint: "The chart default fails before render because required storage bucket/schema inputs are missing; the proof records the blocker and supplies two bounded variants."
      evidence:
        - "default-render-blocker.yaml"
      configHubHome: "recipe"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled"
    -
      id: "storage-config"
      detectedPainPoint: "Promoted variants bind storage mode, schemaConfig, and object-store settings before creating a rendered revision."
      evidence:
        - "loki.storage + loki.schemaConfig"
      configHubHome: "operate-policy"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "object-storage-policy"
      detectedPainPoint: "The MinIO variant renders a chart-owned object-store fixture and marks its Secret as review-required before production."
      evidence:
        - "simple-scalable-minio"
      configHubHome: "operate-policy"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "lifecycle-policy"
      detectedPainPoint: "Promoted Loki variants render with --no-hooks; hook or test enablement must map to lifecycle policy before production."
      evidence:
        - "no-hooks"
      configHubHome: "lifecycle-policy"
      disposition: "handled-by-lifecycle-policy"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "not-present-in-promoted-render"
    -
      id: "stateful-workload"
      detectedPainPoint: "stateful-workload affects apps/v1|StatefulSet|loki|loki"
      evidence:
        - "apps/v1|StatefulSet|loki|loki"
      configHubHome: "operate-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "pvc-policy"
      detectedPainPoint: "Loki and MinIO StatefulSets need storage, retention, upgrade, and rollback policy."
      evidence:
        - "control-points.yaml"
      configHubHome: "operate-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "cluster-rbac"
      detectedPainPoint: "cluster-rbac affects rbac.authorization.k8s.io/v1|ClusterRole||loki-clusterrole"
      evidence:
        - "rbac.authorization.k8s.io/v1|ClusterRole||loki-clusterrole"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/scan-receipt.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "tpl"
      detectedPainPoint: "Loki config, structuredConfig, extraEnv, and raw object slots can use templating; promoted variants keep raw object slots empty."
      evidence:
        - "control-points.yaml"
      configHubHome: "extension-slot"
      disposition: "handled-by-variant"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "controlled-by-empty-defaults"
    -
      id: "installer-support-object"
      detectedPainPoint: "installer-support-object affects v1|Namespace||loki"
      evidence:
        - "v1|Namespace||loki"
      configHubHome: "recipe"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled"
    -
      id: "scan-gate"
      detectedPainPoint: "Current scan gate is warn-production-blocked"
      evidence:
        - "helm-plan.yaml"
        - "scan receipts"
        - "install gates"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/single-binary-filesystem/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "warn-production-blocked"
    -
      id: "value-model-diagnostics"
      detectedPainPoint: "Helm values can be unknown, dead, misspelled, shadowed, or ignored unless the values model records the analysis boundary."
      evidence:
        - "value-model.yaml"
      configHubHome: "value-model"
      disposition: "absorbed-into-value-model"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "unknown=not-checked; dead=not-checked; ignored=not-checked"
  answerForSkepticalHelmUser: "grafana/loki@7.0.0 maps its detected Helm pain to 9 ConfigHub control areas: source-lock, dependency-lock, capability-profile, recipe, operate-policy, lifecycle-policy, scan-gate, extension-slot, value-model. Supported scopes have explicit variants, receipts, scans/gates, and control-point dispositions; production readiness remains production-review-ready."
