apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "HelmPainReport"
metadata:
  name: "hashicorp-vault-0.32.0"
spec:
  chart:
    name: "hashicorp/vault"
    version: "0.32.0"
    source: "https://helm.releases.hashicorp.com"
    digest: "e31ddf3f6dd031c0f5407dd6b63361ea5ff655f89c781049b39f4c2a95a6f88a"
  supportedScopeStatus: "no-unhandled-pain-points-for-supported-scopes"
  supportedScopes:
    - "local-test"
  supportedVariants:
    - "dev-mode"
    - "default"
    - "ha-raft-ui"
  productionReadiness: "production-review-ready"
  notes:
    - "The chart renders deterministically under pinned Helm, chart version, kube version, and values."
    - "The default variant keeps the chart defaults: standalone Vault server, injector webhook, and TLS disabled in the rendered Vault config."
    - "The ha-raft-ui variant enables integrated Raft HA and the UI Service as deliberate variant-controlled outputs."
    - "The dev-mode variant uses the upstream chart's dev server path for local proof and demos; it starts without init/unseal and is not a production support claim."
    - "The chart does not initialize or unseal Vault; init/unseal and recovery material are operating controls, not hidden render inputs."
    - "operating-policy.yaml records the post-render procedure required before default and HA bases can be called ready."
    - "The HA Raft variant needs a target that can schedule three Vault server replicas; one-node kind is useful for object parity but not for HA readiness."
    - "Injector webhook, cluster RBAC, TLS posture, storage, and service exposure are scan/gate review points."
    - "extra environment, Secret, volume, plugin, init, and sidecar extension slots are powerful config surfaces; promoted variants keep them empty."
  painPoints:
    -
      id: "source-lock"
      detectedPainPoint: "source-lock requires source-lock.yaml"
      evidence:
        - "source-lock.yaml"
      configHubHome: "source-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "source-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "dependency-lock"
      detectedPainPoint: "chart declares no subchart dependencies; the empty closure is recorded explicitly."
      evidence:
        - "dependency-lock.yaml"
      configHubHome: "dependency-lock"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "dependency-lock.yaml"
      supportedVariantStatus: "handled"
    -
      id: "capability-profile"
      detectedPainPoint: "Kubernetes API and version branches are bound to the named Kubernetes capability profile."
      evidence:
        - "control-points.yaml"
      configHubHome: "capability-profile"
      disposition: "handled-by-capability-profile"
      linkedReceipt: "revisions/dev-mode/r001/receipts/render-receipt.yaml"
      supportedVariantStatus: "handled"
    -
      id: "stateful-workload"
      detectedPainPoint: "stateful-workload affects apps/v1|StatefulSet|vault|vault"
      evidence:
        - "apps/v1|StatefulSet|vault|vault"
      configHubHome: "operate-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "admission-webhook"
      detectedPainPoint: "admission-webhook affects admissionregistration.k8s.io/v1|MutatingWebhookConfiguration||vault-agent-injector-cfg"
      evidence:
        - "admissionregistration.k8s.io/v1|MutatingWebhookConfiguration||vault-agent-injector-cfg"
      configHubHome: "lifecycle-policy"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "service-exposure"
      detectedPainPoint: "service-exposure affects v1|Service|vault|vault-ui"
      evidence:
        - "v1|Service|vault|vault-ui"
      configHubHome: "recipe"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "variant-controlled"
    -
      id: "tls-posture"
      detectedPainPoint: "tls-posture requires v1|ConfigMap|vault|vault-config"
      evidence:
        - "v1|ConfigMap|vault|vault-config"
      configHubHome: "recipe"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "cluster-rbac"
      detectedPainPoint: "cluster-rbac affects rbac.authorization.k8s.io/v1|ClusterRole||vault-agent-injector-clusterrole"
      evidence:
        - "rbac.authorization.k8s.io/v1|ClusterRole||vault-agent-injector-clusterrole"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/dev-mode/r001/receipts/scan-receipt.yaml"
      supportedVariantStatus: "scan-and-review"
    -
      id: "operate-policy"
      detectedPainPoint: "Vault init, unseal, seal migration, recovery material, and freshness evidence are post-render operating controls."
      evidence:
        - "operating-policy.yaml"
      configHubHome: "recipe"
      disposition: "needs-operator-decision"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "policy-required"
    -
      id: "target-topology"
      detectedPainPoint: "The ha-raft-ui base renders three Vault server replicas. A one-node kind target is useful for object parity, but HA live readiness needs a target that can schedule the declared topology plus an init/unseal operating path."
      evidence:
        - "control-points.yaml"
      configHubHome: "target-fact-requirement"
      disposition: "handled-by-target-fact-values"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "target-review"
    -
      id: "extension-slots"
      detectedPainPoint: "extra environment, Secret, volume, plugin, init, and sidecar slots are empty in promoted variants."
      evidence:
        - "control-points.yaml"
      configHubHome: "extension-slot"
      disposition: "handled-by-variant"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "controlled-by-empty-defaults"
    -
      id: "installer-support-object"
      detectedPainPoint: "installer-support-object affects v1|Namespace||vault"
      evidence:
        - "v1|Namespace||vault"
      configHubHome: "recipe"
      disposition: "absorbed-into-recipe"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "handled"
    -
      id: "scan-gate"
      detectedPainPoint: "Current scan gate is warn-production-blocked"
      evidence:
        - "helm-plan.yaml"
        - "scan receipts"
        - "install gates"
      configHubHome: "scan-gate"
      disposition: "handled-by-scan-or-gate"
      linkedReceipt: "revisions/dev-mode/r001/receipts/install-gate.yaml"
      supportedVariantStatus: "warn-production-blocked"
    -
      id: "value-model-diagnostics"
      detectedPainPoint: "Helm values can be unknown, dead, misspelled, shadowed, or ignored unless the values model records the analysis boundary."
      evidence:
        - "value-model.yaml"
      configHubHome: "value-model"
      disposition: "absorbed-into-value-model"
      linkedReceipt: "value-model.yaml"
      supportedVariantStatus: "unknown=not-checked; dead=not-checked; ignored=not-checked"
  answerForSkepticalHelmUser: "hashicorp/vault@0.32.0 maps its detected Helm pain to 10 ConfigHub control areas: source-lock, dependency-lock, capability-profile, operate-policy, lifecycle-policy, recipe, scan-gate, target-fact-requirement, extension-slot, value-model. Supported scopes have explicit variants, receipts, scans/gates, and control-point dispositions; production readiness remains production-review-ready."
