Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions infrastructure/current-release-status.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: "A dated availability record for the independently released artifac
There is not yet a published, platform-wide known-good release set for the managed shared-router and private-PPB request path. The architecture pages describe the target contract, but they are not evidence that this integration is generally available. Do not change production DNS or infrastructure for that path until a later status record identifies every immutable artifact and its green end-to-end release gate.
</Warning>

This snapshot was reviewed on **July 19, 2026 at 01:15 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page.
This snapshot was reviewed on **July 19, 2026 at 10:52 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page.

## Status meanings

Expand Down Expand Up @@ -38,9 +38,9 @@ The table deliberately does not invent an image digest, template commit, signatu

| Integration | Status | Gate that remains |
| --- | --- | --- |
| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | PPB `0.5.1` is available, but the exact independently built site-router, edge-controller, and edge-provider-mutator image digests, ordered Pub/Sub mutation delivery, static Certificate Manager deny boundary, child-zone delegation lifecycle, two-phase organization DNS teardown with persisted TTL high-water and recursive-plus-parent-authority absence proof, exact-service-account state-gateway authentication, transactional observed-state outbox, managed Terraform pins, private-origin, client-IP, authorization-preservation, split timeout, Direct VPC, and hosted canaries still need promotion as one managed set. Cloud CDN remains disabled. |
| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | API commit [`1ffa3ee`](https://github.com/libops/api/commit/1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2) completed protected [Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) with bundle tag `sha-1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2-run-29667962498-attempt-3`. That run published signed, parity-checked GHCR and GAR manifests for `site-router@sha256:4bd36aad93e8d56ca2bdab090a5aba313bbdaf708cfc3c6a2eb8e83adf057cad`, `edge-controller@sha256:d5a2bbea2993a2d84730f66b6b09d8029f9c7daef5afd0d82f160c13eeb1af85`, and `edge-provider-mutator@sha256:c50e3de30b7d9fb3806557cfe6e57f6641bb556e4147a2565f945f8804e0d907`; signature claims and cross-registry manifest parity passed. Pin commit [`723ccaa`](https://github.com/libops/api/commit/723ccaa8d23ac0cdc0ba8833e5377fa22863fdc1) records those exact GAR digests as shared-infrastructure desired state. Production promotion still requires the shared-infrastructure Terraform apply and hosted canaries for DNS authorizations, certificates, and map entries; ordered Pub/Sub and dead-letter behavior; the static deny boundary; child-zone delegation and TTL-high-water teardown; exact-service-account state gateway and transactional outbox; private router-to-PPB origin; both Direct VPC egress paths; canonical client IP; application `Authorization` preservation; split timeouts; rollout; and rollback. Cloud CDN remains disabled. |
| Organization Vault three-image runtime | Blocked / preview | The shared publisher and verified WIF selector have passed protected-main publication for `vault-server`, released `vault-init` `1.0.6`, and released `vault-proxy` `2.0.3` through the cleanup-safe shared workflow. The aggregate runtime is still blocked until sitectl-admin's digest resolver and exact tag-commit/signature gate are released, all three independently built GAR manifests are pinned by digest, and the hosted API, Terraform, initialization, recovery, and rollback gates pass. Independently green image publications are not an aggregate runtime release. |
| Canonical API image set and production VM resolver | Blocked / preview | Merge the hosted post-CI publisher and `sitectl admin terraform api-compose-images`; publish the exact protected-main run to GHCR plus the appropriate private or public GAR repository; verify every digest's reusable-workflow identity, caller repository/ref/SHA, and caller-workflow annotation; and prove fresh VM bootstrap plus in-place refresh with the four verified private-GAR Compose images, the checkout detached at the publication commit, and legacy boot-disk discovery that fails on ambiguity. |
| Canonical API image set and production VM resolver | Blocked / preview | [Protected Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) published and verified `api`, `api-init`, `api-vault-agent`, and `control-plane`; `sitectl admin terraform libops-api` resolves the exact run tag to independent image digests. Production promotion still requires a deployment record naming the four private-GAR digests and their publication provenance, plus hosted proof of fresh VM bootstrap, detached same-SHA checkout, in-place refresh, rollback, and rejection of ambiguous legacy boot-disk discovery. |
| Separate request-serving API and `api-worker` Cloud Run services | Preview | Release the managed worker deployment and prove identity bootstrap, database connectivity, readiness, rollout, rollback, and removal of any temporary migration privilege. A process boundary in source or Compose is not proof of this Cloud Run topology. |
| Platform-wide image, template, CLI, plugin, and infrastructure compatibility manifest | Blocked | Generate the aggregate record from release automation and attach hosted CI evidence for the exact references. Until then, each operator owns a deployment-specific record. |

Expand Down
27 changes: 15 additions & 12 deletions infrastructure/release-compatibility.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -120,12 +120,13 @@ gate fails for malformed, empty, failed, cancelled, or skipped dependencies and
has no checkout, package, OIDC, secret, or registry permission. The main-only
publisher remains a separate caller job.

The target API repository publication gives every deployable image a GHCR
The protected API repository publication path gives every deployable image a GHCR
copy. Images consumed by LibOps GCP runtimes also receive a GAR copy:
`api` (also tagged as `dash`), `api-init`, `api-vault-agent`, and
`control-plane` use the private API-project repository; `terraform-runner`,
`gcp-vm-ip-controller`, `controller-ingress`, and `site-controller` use shared
public GAR; and `site-router` uses the separate
public GAR; and `site-router`, `edge-controller`, and `edge-provider-mutator`
use the separate
shared-infrastructure GAR repository. The independently owned `vault-server`
image is not built or published by the API workflow.

Expand Down Expand Up @@ -162,16 +163,18 @@ passes only digest references. These signatures bind the reviewed publisher
identity to the published digests. They are not SLSA provenance or an
attestation of the full build-material graph.

Before this API publication path can be promoted, the admin plugin must resolve
every selected API bundle image and the independently released Vault server to
fail-closed GAR digest references. The VM must record the canonical API
selector and detach its Compose checkout at the embedded commit before
starting services. Only an explicitly configured development branch or
`local` may follow a branch pull. Local Compose build fallbacks remain useful
for development; they are not a production substitute for this verified source
and image handoff. Publish the exact commands and current image-to-variable
mapping in the sitectl documentation only when that resolver is released; an
architecture page must not act as an unreleased CLI reference.
The admin plugin resolves every selected API bundle image and the independently
released Vault server to fail-closed GAR digest references. Production
promotion still requires a deployment record naming the four private-GAR API
digests and their publication provenance, plus hosted proof that the VM records
the canonical API selector, detaches its Compose checkout at the embedded
commit before starting services, handles a fresh bootstrap and in-place
refresh, rolls back safely, and rejects ambiguous legacy-disk discovery. Only
an explicitly configured development branch or `local` may follow a branch
pull. Local Compose build fallbacks remain useful for development; they are not
a production substitute for this verified source and image handoff. The
published sitectl documentation is the command and image-to-variable reference;
an architecture page does not replace it.

Keep similarly named images in their actual ownership boundary. The following
organization Vault runtime is a target promotion contract until the
Expand Down