apiVersion: helm-expt.confighub.com/v1alpha1
kind: CatalogStatus
metadata:
  name: "hashicorp-consul-2.0.0"
spec:
  chart: "hashicorp/consul"
  version: "2.0.0"
  status: "catalog-supported"
  supportLevel: "supported-for-declared-scopes"
  supportedScopes:
    - local-test
  productionReadiness: "production-review-ready"
  supportedVariants:
    - "default-control-plane"
    - "secure-mesh-existing-secrets"
  candidateVariants:
    []
  deferredVariants: []
  review:
    lastReviewed: "2026-05-27"
    humanReviewRequired: false
    productReviewRequired: false
  notes:
    - "Supported for local-test and proof-demo usage through real cub installer and ConfigHub receipts."
    - "default-control-plane is the simplest local Consul control-plane path."
    - "secure-mesh-existing-secrets is supported when the declared Secret target facts are satisfied."
    - "default-control-plane has regular Helm, ConfigHub kubectl apply, and ConfigHub OCI/Argo live parity with healthy runtime, and is the stronger first production-review base."
    - "secure-mesh-existing-secrets is useful review input for TLS, ACL, gossip, gateway, UI ingress, and mesh topology, but remains target-fit-needed until target capacity and bootstrap policy are proven."
    - "CRD ownership, cluster RBAC, target Secret preflight, webhook readiness, lifecycle boundary, extension slots, storage/rollback, and scan/gate warnings are recorded as production review input."
    - "Production recommendation remains a separate decision; Consul needs target CRD ownership, TLS/ACL/secret rotation, mesh/gateway posture, security policy, backup/restore, and fresh runtime checks before support."
