apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "RuntimeReview"
metadata:
  name: "consul-secure-mesh-existing-secrets-runtime-watch"
  chart: "hashicorp/consul"
  version: "2.0.0"
spec:
  base: "secure-mesh-existing-secrets"
  controller: "Argo CD"
  targetShape: "kind proof rig with target profile kind-three-node"
  receipt: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/receipt.yaml"
  observedResult: "watch"
  currentSupportArtifact: "recipes/hashicorp/consul/2.0.0/gitops-runtime-review.yaml"
  targetProfile:
    name: "kind-three-node"
    result: "pass"
    observedSchedulableNodes: 3
    provides:
      - "three schedulable Kubernetes nodes for Consul server anti-affinity"
      - "target topology for the HA/quorum shape exercised by this base"
  passed:
    - "regular Helm live leg reached the expected workload runtime state"
    - "ConfigHub direct-apply leg reached the expected workload runtime state"
    - "ConfigHub OCI/Argo leg synced successfully"
    - "ConfigHub OCI/Argo leg reached the expected workload runtime state"
    - "Helm-vs-ConfigHub semantic parity passed for the direct-apply leg"
    - "Helm-vs-ConfigHub semantic parity passed for the OCI/Argo leg"
    - "target Secret prerequisites were staged for every live leg"
    - "the proof target provided the required three schedulable nodes"
  watch:
    summary: "The latest ConfigHub OCI/Argo leg is Synced and its Consul workloads converged, but Argo aggregate health remains Progressing."
    gitOpsCondition:
      sync: "Synced"
      health: "Progressing"
      operationState: "Succeeded"
      message: "successfully synced (all tasks run)"
    runtimeResidue:
      - "Ingress/consul/consul-consul-ui: Synced/Progressing"
  operationTimings:
    regularHelmInstallSeconds: 154.549
    configHubDirectReadinessSeconds: 40.675
    configHubOciUploadSeconds: 302.519
    configHubOciUnitApplySeconds: 326.841
    configHubOciUnitApplyUnitCount: 97
    configHubOciArgoWaitSeconds: 422.615
    configHubOciReadinessSeconds: 0.110
  diagnosis:
    summary: "This is now a narrow GitOps controller-health watch row, not a render parity defect, not a workload-runtime defect, and not a ConfigHub worker requirement."
    interpretation: "The desired object set matched Helm semantically, the target topology was adequate, the server accepted and synced the ConfigHub OCI objects, and the Consul workloads reached readiness. The remaining question is whether Argo aggregate health should become Healthy for this target shape or whether the UI Ingress Progressing condition is an accepted target-scope limitation."
    targetShapeBoundary: "The base needs a Kubernetes target with enough schedulable nodes for Consul server anti-affinity and quorum. ConfigHub remains workerless from the target cluster's point of view."
    targetFactFreshness: "A stale generated TLS target-fact certificate produced an earlier false runtime failure. The live harness now regenerates target-fact TLS material when it is missing or within 12 hours of expiry."
    nextInvestigation:
      - "Inspect the Argo application health tree for the UI Ingress Progressing condition."
      - "Decide whether the target scope needs an ingress controller/load-balancer prerequisite for Consul UI health."
      - "Decide whether the UI Ingress should be separated from the secure mesh proof base or recorded as a target-scoped limitation."
      - "Keep the row as watch until Argo aggregate health becomes Healthy or the target limitation is explicitly accepted."
  evidence:
    argoCoreChildJson: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-child.json"
    argoCoreChildTree: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-child-tree.txt"
    argoCoreRootJson: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-root.json"
    argoCoreRootTree: "runs/live-helm-confighub-compare/hashicorp-consul-secure-mesh-existing-secrets/argocd-core-root-tree.txt"
  notClaimed:
    - "This row does not prove Consul secure mesh production support for arbitrary clusters."
    - "This row does not prove external gateway, ingress, ACL, backup, upgrade, or certificate rotation policy."
    - "This row does not prove that Argo CD aggregate health should be ignored in production."
