apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ControlPoints"
metadata:
  name: "hashicorp-consul-2.0.0"
spec:
  points:
    -
      category: "source-lock"
      status: "handled"
      evidence: "source-lock.yaml"
    -
      category: "dependency-lock"
      status: "handled"
      evidence: "dependency-lock.yaml"
      note: "chart declares no subchart dependencies; the empty closure is recorded explicitly."
    -
      category: "capability-profile"
      status: "handled"
      kubeVersion: "1.30.0"
      note: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
    -
      category: "target-facts"
      status: "variant-controlled"
      evidence: "global.tls.caCert / server.serverCert / gossipEncryption / acl bootstrap token"
      note: "The secure-mesh-existing-secrets variant declares target Secrets for TLS, gossip encryption, and ACL bootstrap material. The server TLS Secret contract includes certificate identity, not just Secret/key presence."
    -
      category: "crd-ownership"
      status: "scan-and-review"
      evidence: "28 rendered CRDs"
      note: "The chart templates 28 CRDs, including Gateway API CRDs that may already be cluster-managed."
    -
      category: "stateful-workload"
      status: "scan-and-review"
      object: "apps/v1|StatefulSet|consul|consul-consul-server"
    -
      category: "target-topology"
      status: "target-fit-required"
      evidence: "target-topology.yaml"
      note: "The secure-mesh-existing-secrets base renders three Consul server replicas with pod anti-affinity, so the strict one-node kind target is expected to leave two server pods pending. Use a multi-node target or a separate single-node/evaluation base for live readiness. A three-node rehearsal first exposed invalid server TLS SANs; after SAN-aware target facts, the regular Helm leg converged."
    -
      category: "namespace-references"
      status: "target-fit-required"
      evidence: "target-prerequisite-plan.yaml"
      note: "The secure-mesh-existing-secrets base contains Consul service DNS, Secret namespace, and ACL init command references that are part of the rendered contract. Deploying the same render into a different namespace needs an explicit namespace-reference preflight, fixed-namespace live mode, or a rerendered base."
    -
      category: "admission-webhook"
      status: "scan-and-review"
      object: "admissionregistration.k8s.io/v1|MutatingWebhookConfiguration|consul|consul-consul-connect-injector"
    -
      category: "cluster-rbac"
      status: "scan-and-review"
      note: "Default and secure variants render broad cluster RBAC for server, injector, gateway resources, and webhook certificate manager."
    -
      category: "mesh-gateway-policy"
      status: "variant-controlled"
      note: "The secure-mesh-existing-secrets variant enables mesh, ingress, and terminating gateways with ClusterIP services."
    -
      category: "ui-ingress-policy"
      status: "variant-controlled"
      object: "networking.k8s.io/v1|Ingress|consul|consul-consul-ui"
    -
      category: "lifecycle-policy"
      status: "scan-and-review"
      note: "Hooks are disabled in the proof render, while normal ACL init Job remains visible in the secure variant."
    -
      category: "extension-slots"
      status: "controlled-by-empty-defaults"
      note: "server extra config, injector, controller, gateway, and tpl-controlled strings are controlled in promoted variants."
    -
      category: "installer-support-object"
      status: "handled"
      object: "v1|Namespace||consul"
