Lifecycle phase map · doc-wide · engineer
Reviewed decommission lifecycle
Reviewed decommission lifecycle
State diagram showing the retain-default exit and the separately reviewed deletion stages. Git Sync credential decommission is platform-authorized, removes the Connection before the Securevalue, and records completion through claim status instead of inferred child disappearance.
REVIEWED STAGES
WAIT FOR EVIDENCE
DEFAULT EXIT
REVIEW 1
ARMED, NOT DELETED
READY TRUE
REVIEW 2
REVIEW 3
PRUNE UNARMED
REQUEST
Request active
Retain by default
INTENT
Arm Delete
exact authorization
WAIT
Evidence
observed state
READY
Deletion ready
both conditions observed
CLAIMS
Clear access claims
objects and finalizers gone
REQUEST
Remove from Git
armed deletion
DELETE
External state retained
Stack-local content is orphaned
Readiness: observed deleteProtection=false; ESO finalizes and syncs current-generation PushSecrets.
Git Sync retains its external Connection and Securevalue by default.
An authorized Delete removes Connection before Securevalue;
status.decommission.phase records Armed through Complete from observed child state.
SCOPE
review boundary
wait for observed evidence
Delete covers the Stack and credential output documents, not stack-local Grafana content.