apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "GitOpsRuntimeReview"
metadata:
  name: "consul-secure-mesh-existing-secrets-argocd-health-watch"
  chart: "hashicorp/consul"
  version: "2.0.0"
spec:
  base: "secure-mesh-existing-secrets"
  controller: "Argo CD"
  targetShape: "kind proof rig with target profile kind-three-node"
  receipt: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/receipt.yaml"
  observedResult: "watch"
  currentSummary:
    sync: "Synced"
    health: "Progressing"
    semanticParity: "pass"
    targetProfile: "pass"
    regularHelmRuntime: "pass"
    configHubDirectRuntime: "pass"
    configHubOciRuntime: "pass"
    controllerResidue: "Ingress/consul/consul-consul-ui: Synced/Progressing"
  passed:
    - "regular Helm live leg reached readiness on a three-node kind target"
    - "ConfigHub direct apply reached readiness on the same target"
    - "ConfigHub OCI/Argo synced the uploaded Units"
    - "ConfigHub OCI/Argo workloads reached readiness"
    - "semantic object parity passed for direct apply and OCI/Argo"
    - "target facts were present and fresh enough for all live legs"
  watch:
    summary: "Argo aggregate health remains Progressing after the Consul workloads are ready."
    likelyResidue:
      - "Ingress/consul/consul-consul-ui: Synced/Progressing"
    nextAction:
      - "Inspect whether this target needs an ingress controller/load-balancer prerequisite for UI health."
      - "If the UI Ingress is not required for the secure-mesh proof scope, split or mark it as a target-scoped limitation."
      - "If Argo health should become Healthy on this target, rerun after modeling the missing ingress prerequisite."
  targetFactFreshness:
    lesson: "Target facts can expire. The failed pre-fix rerun reused generated TLS material after expiry and created a false runtime failure."
    harnessFix: "The live harness now regenerates target-fact TLS material when the certificate is missing or within 12 hours of expiry."
  evidence:
    argoCoreChildJson: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-child.json"
    argoCoreChildTree: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-child-tree.txt"
    argoCoreRootJson: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-root.json"
    argoCoreRootTree: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-root-tree.txt"
  notClaimed:
    - "This row does not prove Consul secure mesh production support for arbitrary clusters."
    - "This row does not prove that Argo CD aggregate health should be ignored in production."
    - "This row does not prove external gateway, ingress, ACL, backup, upgrade, or certificate rotation policy."
