apiVersion: "catalog.confighub.com/v1alpha1"
kind: "RbacReviewLiveProofReceipt"
metadata:
  name: "namespaced-secret-read-correction"
spec:
  recordedAt: "2026-07-27T02:34:28.984Z"
  source:
    before:
      path: "examples/apps/rbac-review/before.yaml"
      sha256: "295dbd1488d15655015dae02027b6711f07f43b195857881c7e17b06e2c29697"
      objectCount: 5
      findings:
        -
          id: "secret-read"
          object: "rbac.authorization.k8s.io/v1|Role|rbac-review|report-reader"
          ruleIndex: 0
          resources:
            - "configmaps"
            - "secrets"
          verbs:
            - "get"
            - "list"
            - "watch"
    after:
      path: "examples/apps/rbac-review/after.yaml"
      sha256: "3d110795dbe1cbf4d2e97f1223136db257ff779d0ae0fe04bb39ebc2d11bd83a"
      objectCount: 5
      findings:
        []
    proposedChange:
      object: "rbac.authorization.k8s.io/v1|Role|rbac-review|report-reader"
      path: "/rules/0/resources"
      removed:
        - "secrets"
      retained:
        - "configmaps"
      otherFieldsChanged: false
  configHubReview:
    organization: "helm-catalog"
    space: "hx-rbac-review-20260727023428"
    unit: "rbac-review-example"
    unitId: "663b6374-a62c-43a7-b840-2a150d51bd09"
    target:
      ref: "bitnami-redis-27-0-0-stage-pilot-live-20260705/oci-target"
      id: "7d32ab9b-6259-40e6-871d-e78f84761d2b"
      provider: "OCI"
      usedForDryRunAndReleasePublish: true
    policy:
      profile: "catalog-standard"
      resourceClass: "system-configuration"
      filter:
        ref: "platform/helm-catalog-prod-gates"
        id: "8784a447-0e4d-4471-b924-eae5377778a2"
        hash: "53b704e063e156905f5b7f56e7a001cdacd8d300506981e9f6ce97167a0d0b5b"
        triggerRefs:
          - "platform/digest-pinned-images"
          - "platform/lifecycle-route-evidence"
          - "platform/probes-declared"
          - "platform/require-approval"
          - "platform/vet-placeholders"
          - "platform/vet-schemas"
        triggerIds:
          - "04746183-327b-484e-b061-91d2c7753a76"
          - "2651b7cc-31a2-4833-adde-11e018656dee"
          - "3f5dd412-1cf2-4583-a73a-12817f899c87"
          - "4d7664a3-9ac0-4160-868f-95eaa0b59f8f"
          - "5ce74cb1-7129-43c8-a48c-a0ba4322de3d"
          - "9d281daf-79f4-4244-84cc-fbde411e3c11"
      approvalGate: "platform/require-approval/vet-approvedby"
    revisions:
      imported: 2
      corrected: 4
      importedContentHash: -866092711
      correctedContentHash: 1306112189
    beforeApproval:
      result: "blocked"
      exitCode: 1
      gate: "platform/require-approval/vet-approvedby"
      dryRun: true
    approval:
      revisionSelector: "HeadRevisionNum"
      recordedApprovals: 1
      approverIdentityRecordedInReceipt: false
      contentHashUnchanged: true
      gateCleared: true
    afterApproval:
      result: "allowed"
      exitCode: 0
      dryRun: true
    approvedDataMatchesReviewedFile: true
    release:
      space: "hx-rbac-review-20260727023428"
      reference: "oci://oci.hub.confighub.com:443/space/hx-rbac-review-20260727023428:latest"
      manifestDigest: "sha256:9a1c9b52efaf39493d783fe3d9674102bef18ab1c2ccee7a95f951c276144ebf"
      bundleDigest: "sha256:d31850ea6de1ca172e8ec743df5cb7879ee6a202e483e4c62c311ffdca0c7261"
      releaseId: "0e722c4a-39bc-4dcc-97f8-c03c72e151f5"
    portableRelease:
      reference: "oci://127.0.0.1:32793/rbac-review-correction:latest"
      clusterReference: "oci://host.docker.internal:32793/rbac-review-correction"
      manifestDigest: "sha256:92c3fa146b7b510d047a459ad9402177ae696405137fcca4d7fd234120c448d8"
      objectCount: 5
      approvedDataSha256: "7c0ca0e20a30a4bccc6ad58bba7760306e83a15b365e59a54e5b7b555061cded"
      pulledDataSha256: "7c0ca0e20a30a4bccc6ad58bba7760306e83a15b365e59a54e5b7b555061cded"
      objectsMatchApprovedData: true
      anonymousPull: true
      registryLifetime: "temporary"
  liveCluster:
    organization: "DP1-Sandbox"
    creationCommand: "cub cluster up"
    name: "hx-rbac-review-20260727023428"
    namespace: "rbac-review"
    serviceAccount: "report-reader"
    startingPermissions:
      secrets:
        verb: "list"
        resource: "secrets"
        allowed: true
      configmaps:
        verb: "list"
        resource: "configmaps"
        allowed: true
    correctedPermissions:
      secrets:
        verb: "list"
        resource: "secrets"
        allowed: false
      configmaps:
        verb: "list"
        resource: "configmaps"
        allowed: true
    liveRoleMatchesApprovedData: true
    handoff:
      source: "approved ConfigHub Unit data"
      method: "Argo CD"
      applicationDelivery: "ConfigHub cluster Space release OCI"
      workloadDelivery: "temporary portable OCI"
      portablePackaging: "scripted from the approved Unit data"
      automatedArgoDelivery: true
      application:
        name: "rbac-review-20260727023428"
        unit: "hx-rbac-review-20260727023428-cluster/rbac-review-application"
        source: "oci://host.docker.internal:32793/rbac-review-correction"
        approvedConfigHubSpace: "hx-rbac-review-20260727023428"
        destinationNamespace: "rbac-review"
        clusterRootReleaseDigest: "sha256:9f200524af85316f3cdab7adc81b7eace266fb4cda6b8e68893c5ae5ca80beac"
      delivery:
        result: "pass"
        sync: "Synced"
        health: "Healthy"
        revision: "sha256:92c3fa146b7b510d047a459ad9402177ae696405137fcca4d7fd234120c448d8"
        expectedRevision: "sha256:92c3fa146b7b510d047a459ad9402177ae696405137fcca4d7fd234120c448d8"
        digestMatchesPortableOci: true
  cleanup:
    policySpace: "pass"
    namespace: "pass"
    cluster: "pass"
    clusterSpace: "pass"
    registry: "pass"
    localFiles: "pass"
  limits:
    - "The scanner uses conservative RBAC rules. A finding asks for review; it does not prove that a permission is unnecessary."
    - "This fixture is deliberately small and namespaced. It does not resolve RoleBinding graphs across a fleet or change a production chart."
    - "The existing catalog OCI target was used for the blocked and allowed dry-run checks and to publish the approved Space release."
    - "kubectl created the deliberately unsafe starting state. The reviewed correction was packaged from the approved ConfigHub Unit data and delivered as portable OCI through Argo CD."
    - "The disposable cluster's target-scoped OCI credential was not copied into another organization. Argo CD consumed a temporary anonymous OCI containing the same approved objects."
    - "This run proves one ConfigHub-to-Argo correction on one throwaway cluster. It does not prove Flux delivery, a fleet rollout, or every RBAC change."
    - "The temporary ConfigHub Space, namespace, kind cluster, cluster Space, OCI registry, and local files were removed."
status:
  result: "pass"
  claim: "ConfigHub stored an exact RBAC correction, blocked it until its head revision was approved, and published its private release OCI. The same approved objects were packaged as a portable OCI, and Argo CD reconciled that portable digest on an isolated cluster. Secret access was removed while ConfigMap access remained."
