Lifecycle phase map · doc-wide · engineer

Reviewed decommission lifecycle

Reviewed decommission lifecycleState diagram showing the retain-default exit and the separately reviewed deletion stages. Git Sync credential decommission is platform-authorized, removes the Connection before the Securevalue, and records completion through claim status instead of inferred child disappearance.REVIEWED STAGESWAIT FOR EVIDENCEDEFAULT EXITREVIEW 1ARMED, NOT DELETEDREADY TRUEREVIEW 2REVIEW 3PRUNE UNARMEDREQUESTRequest activeRetain by defaultINTENTArm Deleteexact authorizationWAITEvidenceobserved stateREADYDeletion readyboth conditions observedCLAIMSClear access claimsobjects and finalizers goneREQUESTRemove from Gitarmed deletionDELETEExternal state retainedStack-local content is orphanedReadiness: observed deleteProtection=false; ESO finalizes and syncs current-generation PushSecrets. Git Sync retains its external Connection and Securevalue by default. An authorized Delete removes Connection before Securevalue; status.decommission.phase records Armed through Complete from observed child state.SCOPEreview boundarywait for observed evidenceDelete covers the Stack and credential output documents, not stack-local Grafana content.