apiVersion: "catalog.confighub.com/v1alpha1"
kind: "AnonymousOciFluxProofReceipt"
metadata:
  name: "public-nginx-oci-work-oci-20260728-20z9"
spec:
  observedAt: "2026-07-28T09:07:05.692Z"
  pathway: "OCI -> work -> OCI"
  source:
    chart: "bitnami/nginx"
    version: "24.0.2"
    base: "http-clusterip"
    reference: "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-nginx:24.0.2"
    expectedManifestDigest: "sha256:08947210de607a6b9b8e7b8423b024e3fe89a0fc2b09581f80e2401008e445a1"
    expectedPackageLayerDigest: "sha256:2ad752b92ec7fe256da54a2b86fc0afde30d1f9afe38819587fb47c9cb9ecb8d"
    publicationReceipt: "runs/installer-oci/bitnami-nginx/24.0.2/installer-package-publication-receipt.yaml"
    anonymousManifestPull: "pass"
  localWork:
    command:
      - "cub"
      - "installer"
      - "setup"
      - "--pull"
      - "oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/bitnami-nginx:24.0.2"
      - "--base"
      - "http-clusterip"
      - "--work-dir"
      - "<temporary-work-dir>"
      - "--non-interactive"
      - "--namespace"
      - "nginx"
      - "--output-oci"
      - "<temporary-registry>/reviewed-nginx:24.0.2"
    configHubTokenFilePresent: false
    configHubOrganization: ""
    objectCount: 6
    objectKinds:
      - "Deployment"
      - "Namespace"
      - "NetworkPolicy"
      - "PodDisruptionBudget"
      - "Service"
      - "ServiceAccount"
    filesSha256: "sha256:567129a96b8a28ff096c9ad53818c03200ce6c0b5d9dcb23ba432999fbd40806"
  output:
    reference: "oci://127.0.0.1:32810/reviewed-nginx:24.0.2"
    digest: "sha256:ac000807c979534860947ea6876e848fa33af7d09230349fb55fdae91991b02a"
    anonymousPull: "pass"
    pulledFilesMatched: true
    filesSha256: "sha256:567129a96b8a28ff096c9ad53818c03200ce6c0b5d9dcb23ba432999fbd40806"
  flux:
    sourceReady: true
    kustomizationReady: true
    observedDigest: "sha256:ac000807c979534860947ea6876e848fa33af7d09230349fb55fdae91991b02a"
    contentDigest: "sha256:3db4f4f289eeb14aed9aed93a55f0455d4e68cee6c0eb4148b8433194e046668"
    deployment:
      namespace: "nginx"
      name: "nginx"
      readyReplicas: 1
      desiredReplicas: 1
      image: "registry-1.docker.io/bitnami/nginx@sha256:805bcc863fc3f602589fc75cae91eeedebad234d5ce5a476c96b03a747821e7f"
  run:
    cluster: "hx-anon-oci-20260728-20z9"
    registry: "temporary local registry with no authentication"
    cleanup:
      cluster: "pass"
      registry: "pass"
      localFiles: "pass"
  limits:
    - "The output OCI used a temporary local registry. A permanently hosted public workbench remains separate work."
    - "This NGINX configuration has no Helm hooks or CRDs. Charts with lifecycle work need their recorded routes."
    - "This run did not create or use ConfigHub records, variants, approvals, or releases."
status:
  result: "pass"
  claim: "Without a ConfigHub login, cub installer pulled the public NGINX installer OCI, wrote six Kubernetes objects, and used --output-oci to publish those exact files as a second OCI artifact. Flux pulled that output digest and NGINX reached one ready replica."
  error: ""
