apiVersion: "catalog.confighub.com/v1alpha1"
kind: "RedisPublicWalkthroughProofReceipt"
metadata:
  name: "redis-25-5-3-to-27-0-0"
spec:
  observedAt: "2026-07-29T07:28:25.252Z"
  chart: "bitnami/redis"
  execution:
    configHubAccountUsed: false
    registryLoginUsed: false
    kubernetesClusterUsed: false
    isolatedHome: true
  selectedBase: "reuse-existing-secret"
  namespace: "redis"
  versions:
    -
      version: "25.5.3"
      appVersion: "8.6.3"
      packageReference: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-redis:25.5.3"
      publicationReceipt: "runs/installer-oci/bitnami-redis/25.5.3/installer-package-publication-receipt.yaml"
      sourceManifestDigest: "sha256:7ad5fa6de0aa9c29df8cd26650893ebae6ad149a7c5ac33a8beedf5b02e2ac33"
      anonymousPull: "pass"
      selectedBase: "reuse-existing-secret"
      objectCount: 14
      secretObjectCount: 0
      renderedOci:
        destination: "temporary local OCI layout"
        manifestDigest: "sha256:ceb2afe39c3eeff54b70e1c3e83a8c805f389c0f331ce2fefbff4ed69daa4fca"
        objectSetDigest: "sha256:518db60ad92b59818c9e84042b12cc7b3d850a583ab7ca565bbf09f6806e4324"
        pullBack: "pass"
    -
      version: "27.0.0"
      appVersion: "8.8.0"
      packageReference: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-redis:27.0.0"
      publicationReceipt: "runs/installer-oci/bitnami-redis/27.0.0/installer-package-publication-receipt.yaml"
      sourceManifestDigest: "sha256:f7abbebaa196753028c1ece5c24a32a0f40ac08aeda7ad3a5ec225e019a90780"
      anonymousPull: "pass"
      selectedBase: "reuse-existing-secret"
      objectCount: 14
      secretObjectCount: 0
      renderedOci:
        destination: "temporary local OCI layout"
        manifestDigest: "sha256:f94516849e8dd8ab8cc71500cff0d34c96fca925a1491f710eb399727d33bb1b"
        objectSetDigest: "sha256:222cdae547665b7be00a61001ee6789582ff387e687890a46da9112232bd1ebc"
        pullBack: "pass"
  retainedChoice:
    field: "Selection.spec.base"
    before: "reuse-existing-secret"
    after: "reuse-existing-secret"
    result: "pass"
  managedContinuation:
    summary: "data/redis-upgrade-app-proof/summary.md"
    receipt: "runs/redis-upgrade-app-proof/receipt.yaml"
  limits:
    - "This public run proves anonymous package pulls, local rendering, local OCI output, OCI pull-back verification, and retention of the selected base across a package upgrade."
    - "The selected existing-Secret base keeps credential bytes out of the rendered files and OCI. A deployer still has to create or bind redis/redis-existing-secret."
    - "The no-account run does not keep arbitrary edits to rendered Kubernetes objects. The separate ConfigHub proof covers a post-render replica edit, promotion, two-cluster rollout, and rollback."
    - "This run does not apply either version to Kubernetes. The separate serverless install parity proof covers live Helm and cub installs."
status:
  result: "pass"
  claim: "With no ConfigHub account, registry login, or Kubernetes cluster, cub installer anonymously pulled Redis 25.5.3, rendered the existing-Secret base as 14 non-secret objects, wrote and verified a local OCI, upgraded the same work directory to 27.0.0, retained the selected base, and wrote and verified the newer 14-object OCI."
  error: ""
