apiVersion: helm-expt.confighub.com/v1alpha1
kind: CatalogStatus
metadata:
  name: "hashicorp-vault-0.32.0"
spec:
  chart: "hashicorp/vault"
  version: "0.32.0"
  status: "catalog-supported"
  supportLevel: "supported-for-declared-scopes"
  supportedScopes:
    - local-test
  productionReadiness: "production-review-ready"
  supportedVariants:
    - "dev-mode"
    - "default"
    - "ha-raft-ui"
  candidateVariants:
    []
  deferredVariants: []
  review:
    lastReviewed: "2026-05-27"
    humanReviewRequired: false
    productReviewRequired: false
  notes:
    - "Supported for local-test and proof-demo usage through real cub installer and ConfigHub receipts."
    - "default is the simplest local Vault chart path and the safer first production-review base."
    - "ha-raft-ui is supported as a richer HA/Raft/UI proof, but has target-sensitive service-selector and runtime caveats."
    - "RBAC, injector webhook, extension slots, storage/init/unseal/recovery, TLS posture, service exposure, and scan/gate warnings are recorded as production review input."
    - "Production recommendation remains a separate decision; Vault needs explicit init/unseal, recovery material, TLS, backup/restore, and live observation procedures before support."
