diff --git a/infrastructure/current-release-status.mdx b/infrastructure/current-release-status.mdx index 6cf4a81..5b994f8 100644 --- a/infrastructure/current-release-status.mdx +++ b/infrastructure/current-release-status.mdx @@ -7,7 +7,7 @@ description: "A dated availability record for the independently released artifac There is not yet a published, platform-wide known-good release set for the managed shared-router and private-PPB request path. The architecture pages describe the target contract, but they are not evidence that this integration is generally available. Do not change production DNS or infrastructure for that path until a later status record identifies every immutable artifact and its green end-to-end release gate. -This snapshot was reviewed on **July 19, 2026 at 01:15 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page. +This snapshot was reviewed on **July 19, 2026 at 10:52 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page. ## Status meanings @@ -38,9 +38,9 @@ The table deliberately does not invent an image digest, template commit, signatu | Integration | Status | Gate that remains | | --- | --- | --- | -| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | PPB `0.5.1` is available, but the exact independently built site-router, edge-controller, and edge-provider-mutator image digests, ordered Pub/Sub mutation delivery, static Certificate Manager deny boundary, child-zone delegation lifecycle, two-phase organization DNS teardown with persisted TTL high-water and recursive-plus-parent-authority absence proof, exact-service-account state-gateway authentication, transactional observed-state outbox, managed Terraform pins, private-origin, client-IP, authorization-preservation, split timeout, Direct VPC, and hosted canaries still need promotion as one managed set. Cloud CDN remains disabled. | +| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | API commit [`1ffa3ee`](https://github.com/libops/api/commit/1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2) completed protected [Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) with bundle tag `sha-1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2-run-29667962498-attempt-3`. That run published signed, parity-checked GHCR and GAR manifests for `site-router@sha256:4bd36aad93e8d56ca2bdab090a5aba313bbdaf708cfc3c6a2eb8e83adf057cad`, `edge-controller@sha256:d5a2bbea2993a2d84730f66b6b09d8029f9c7daef5afd0d82f160c13eeb1af85`, and `edge-provider-mutator@sha256:c50e3de30b7d9fb3806557cfe6e57f6641bb556e4147a2565f945f8804e0d907`; signature claims and cross-registry manifest parity passed. Pin commit [`723ccaa`](https://github.com/libops/api/commit/723ccaa8d23ac0cdc0ba8833e5377fa22863fdc1) records those exact GAR digests as shared-infrastructure desired state. Production promotion still requires the shared-infrastructure Terraform apply and hosted canaries for DNS authorizations, certificates, and map entries; ordered Pub/Sub and dead-letter behavior; the static deny boundary; child-zone delegation and TTL-high-water teardown; exact-service-account state gateway and transactional outbox; private router-to-PPB origin; both Direct VPC egress paths; canonical client IP; application `Authorization` preservation; split timeouts; rollout; and rollback. Cloud CDN remains disabled. | | Organization Vault three-image runtime | Blocked / preview | The shared publisher and verified WIF selector have passed protected-main publication for `vault-server`, released `vault-init` `1.0.6`, and released `vault-proxy` `2.0.3` through the cleanup-safe shared workflow. The aggregate runtime is still blocked until sitectl-admin's digest resolver and exact tag-commit/signature gate are released, all three independently built GAR manifests are pinned by digest, and the hosted API, Terraform, initialization, recovery, and rollback gates pass. Independently green image publications are not an aggregate runtime release. | -| Canonical API image set and production VM resolver | Blocked / preview | Merge the hosted post-CI publisher and `sitectl admin terraform api-compose-images`; publish the exact protected-main run to GHCR plus the appropriate private or public GAR repository; verify every digest's reusable-workflow identity, caller repository/ref/SHA, and caller-workflow annotation; and prove fresh VM bootstrap plus in-place refresh with the four verified private-GAR Compose images, the checkout detached at the publication commit, and legacy boot-disk discovery that fails on ambiguity. | +| Canonical API image set and production VM resolver | Blocked / preview | [Protected Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) published and verified `api`, `api-init`, `api-vault-agent`, and `control-plane`; `sitectl admin terraform libops-api` resolves the exact run tag to independent image digests. Production promotion still requires a deployment record naming the four private-GAR digests and their publication provenance, plus hosted proof of fresh VM bootstrap, detached same-SHA checkout, in-place refresh, rollback, and rejection of ambiguous legacy boot-disk discovery. | | Separate request-serving API and `api-worker` Cloud Run services | Preview | Release the managed worker deployment and prove identity bootstrap, database connectivity, readiness, rollout, rollback, and removal of any temporary migration privilege. A process boundary in source or Compose is not proof of this Cloud Run topology. | | Platform-wide image, template, CLI, plugin, and infrastructure compatibility manifest | Blocked | Generate the aggregate record from release automation and attach hosted CI evidence for the exact references. Until then, each operator owns a deployment-specific record. | diff --git a/infrastructure/release-compatibility.mdx b/infrastructure/release-compatibility.mdx index 9097daa..165612e 100644 --- a/infrastructure/release-compatibility.mdx +++ b/infrastructure/release-compatibility.mdx @@ -120,12 +120,13 @@ gate fails for malformed, empty, failed, cancelled, or skipped dependencies and has no checkout, package, OIDC, secret, or registry permission. The main-only publisher remains a separate caller job. -The target API repository publication gives every deployable image a GHCR +The protected API repository publication path gives every deployable image a GHCR copy. Images consumed by LibOps GCP runtimes also receive a GAR copy: `api` (also tagged as `dash`), `api-init`, `api-vault-agent`, and `control-plane` use the private API-project repository; `terraform-runner`, `gcp-vm-ip-controller`, `controller-ingress`, and `site-controller` use shared -public GAR; and `site-router` uses the separate +public GAR; and `site-router`, `edge-controller`, and `edge-provider-mutator` +use the separate shared-infrastructure GAR repository. The independently owned `vault-server` image is not built or published by the API workflow. @@ -162,16 +163,18 @@ passes only digest references. These signatures bind the reviewed publisher identity to the published digests. They are not SLSA provenance or an attestation of the full build-material graph. -Before this API publication path can be promoted, the admin plugin must resolve -every selected API bundle image and the independently released Vault server to -fail-closed GAR digest references. The VM must record the canonical API -selector and detach its Compose checkout at the embedded commit before -starting services. Only an explicitly configured development branch or -`local` may follow a branch pull. Local Compose build fallbacks remain useful -for development; they are not a production substitute for this verified source -and image handoff. Publish the exact commands and current image-to-variable -mapping in the sitectl documentation only when that resolver is released; an -architecture page must not act as an unreleased CLI reference. +The admin plugin resolves every selected API bundle image and the independently +released Vault server to fail-closed GAR digest references. Production +promotion still requires a deployment record naming the four private-GAR API +digests and their publication provenance, plus hosted proof that the VM records +the canonical API selector, detaches its Compose checkout at the embedded +commit before starting services, handles a fresh bootstrap and in-place +refresh, rolls back safely, and rejects ambiguous legacy-disk discovery. Only +an explicitly configured development branch or `local` may follow a branch +pull. Local Compose build fallbacks remain useful for development; they are not +a production substitute for this verified source and image handoff. The +published sitectl documentation is the command and image-to-variable reference; +an architecture page does not replace it. Keep similarly named images in their actual ownership boundary. The following organization Vault runtime is a target promotion contract until the