apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "InstallGate"
metadata:
  name: "tempo-s3-query-observability-r001"
spec:
  variantRevision: "../variant-revision.yaml"
  renderedObjectSetSHA256: "4e981336df773cdd82b2551d35d27d61f4b39e6a3df0a9a693ac81fd0d3cf8ed"
  decision: "warn"
  allowedScopes:
    - "local-test"
  blockedScopes:
    - "production"
  reasons:
    - "Helm equivalence passed for s3-query-observability"
    - "Tempo storage backend and query/observability posture are explicit variant choices"
    - "Helm hook behavior needs explicit lifecycle policy before production"
    - "Tempo StatefulSet, storage, S3 credential Secret, query ingress, NetworkPolicy, ServiceMonitor, and extension slots need production review"
    - "requires target Secret tempo/tempo-s3-credentials, a reachable S3-compatible object store, and the Prometheus Operator ServiceMonitor CRD before runtime readiness"
