apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ControlPoints"
metadata:
  name: "grafana-tempo-1.24.4"
spec:
  points:
    -
      category: "source-lock"
      status: "handled"
      evidence: "source-lock.yaml"
    -
      category: "dependency-lock"
      status: "handled"
      evidence: "dependency-lock.yaml"
      note: "chart declares no subchart dependencies; the empty closure is recorded explicitly."
    -
      category: "capability-profile"
      status: "handled"
      kubeVersion: "1.30.0"
      note: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
    -
      category: "chart-deprecation"
      status: "noted"
      note: "The literal grafana/tempo chart is deprecated; the proof records that status and notes the maintained successor chart separately."
    -
      category: "target-facts"
      status: "variant-controlled"
      evidence: "tempo.storage.trace.s3 and tempo.extraEnv secretKeyRef"
      note: "The s3-query-observability variant declares S3 endpoint, bucket, and region as pre-render values, and references credentials from a target Secret instead of embedding access keys in rendered ConfigMaps."
    -
      category: "object-store-runtime-prerequisite"
      status: "target-fact-required"
      evidence: "tempo.storage.trace.s3"
      note: "The S3 variant needs the declared endpoint, bucket, region, and credentials to be real before Tempo becomes ready; the strict live parity lane stages a local S3-compatible target prerequisite."
    -
      category: "capability-profile"
      status: "variant-controlled"
      evidence: "monitoring.coreos.com/v1"
      note: "The ServiceMonitor variant records the Prometheus Operator API as an explicit target capability."
    -
      category: "servicemonitor-crd-target-fact"
      status: "target-fact"
      object: "apiextensions.k8s.io/v1|CustomResourceDefinition||servicemonitors.monitoring.coreos.com"
      note: "The Tempo chart renders a ServiceMonitor when the API is declared, but the Prometheus Operator CRD must already exist in the target cluster."
    -
      category: "stateful-workload"
      status: "scan-and-review"
      object: "apps/v1|StatefulSet|tempo|tempo"
    -
      category: "query-ingress-policy"
      status: "variant-controlled"
      object: "networking.k8s.io/v1|Ingress|tempo|tempo"
    -
      category: "network-policy"
      status: "scan-and-review"
      object: "networking.k8s.io/v1|NetworkPolicy|tempo|tempo"
    -
      category: "servicemonitor-capability"
      status: "variant-controlled"
      object: "monitoring.coreos.com/v1|ServiceMonitor|tempo|tempo"
    -
      category: "upstream-runtime-risk"
      status: "scan-and-review"
      note: "The chart StatefulSet references serviceName tempo-headless, but the chart renders no headless Service in these variants."
    -
      category: "extension-slots"
      status: "controlled-by-empty-defaults"
      note: "config, structuredConfig, extra volume/mount, and tpl-controlled strings are controlled in promoted variants."
    -
      category: "installer-support-object"
      status: "handled"
      object: "v1|Namespace||tempo"
