apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "InstallGate"
metadata:
  name: "cert-manager-crds-enabled-r001"
spec:
  variantRevision: "../variant-revision.yaml"
  renderedObjectSetSHA256: "e288b2413bd1919173bee6afcd823be61399f101cfe2cf61f8e0df56740fefe0"
  decision: "warn"
  allowedScopes:
    - "local-test"
  blockedScopes:
    - "production"
  reasons:
    - "Helm equivalence passed for crds-enabled"
    - "CRD install/upgrade behavior needs explicit lifecycle policy before production"
    - "Admission webhook availability needs a fresh observation receipt after apply"
    - "Helm startup API check hook Job needs explicit lifecycle policy before production"
    - "Cluster-scoped RBAC needs production review"
    - "adds the six cert-manager CRDs to the rendered revision"
