Skip to content

build(release): validate matched chart and artifacts for Kubernetes alpha - #253

Merged
yanpgwang merged 6 commits into
mainfrom
codex/alpha-distribution-acceptance
Oct 5, 2026
Merged

yanpgwang merged 6 commits into
mainfrom
codex/alpha-distribution-acceptance

Conversation

@yanpgwang

@yanpgwang yanpgwang commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Problem and result

A source chart passing tests does not establish that users can install the actual runtime and SDK distribution. This change packages the matching Helm chart with the clean-source candidate, records both validated OCI image index digests, and runs the existing Kubernetes lifecycle journey using the archived native supervisor, packaged chart and exported images. Only the explicitly simulated model fixture is source-built.

Artifact acceptance checks source/version alignment and streamed payload hashes before image import, rejects duplicate/missing roles, and extracts only the paired command archive's expected regular files. It exercises authenticated HTTP, external sandbox execution, pending-action replacement, workspace/Skill/Memory reuse, scoped orphan cleanup and independent quiesced restore with original Temporal Run ID/history continuation.

The manual read-only candidate workflow now uses tracked Git snapshots for OCI builds, a scoped containerd Docker image store, and verified shared Helm/kind/kubectl tools. It uploads only after actual-artifact installation/recovery passes. Required contributor CI retains its source-build path; publishing remains a separate maintainer action after review and acceptance.

Boundaries

  • Runtime, migrations, HTTP/OpenAPI and public SDK behavior are unchanged. This is distribution and independently authored acceptance infrastructure.
  • One reviewed source binds runtime/chart/TypeScript 0.1.0-alpha.2, Python 0.1.0a2 and Go sdk/go/v0.1.0-alpha.2.
  • Existing external state services, role-specific Secrets and operator sandbox ownership remain the release boundary. No cloud sandbox, general HA, live snapshots, cross-version upgrade/rollback or automatic registry publication.
  • Rationale: docs/design/alpha-distribution.md, approved docs/design/kubernetes-alpha.md, and docs/provenance.md. Standard Helm/Docker packaging is adopted; hosted-agent release constraints are not.

Validation

  • Clean 49a1941 candidate: four command archives, four SDK packages and packaged chart built; native CLI identity, Helm package/lint/render, fresh Go module, Python wheel/sdist sync+async, TypeScript declarations and six authenticated package HTTP requests passed.
  • Both tracked-snapshot Linux AMD64/ARM64 OCI exports passed identity checks; eleven-payload common manifest finalized. Actual-artifact Kubernetes 1.37.0 installation/restart/independent restore passed in 193.82s, including original Temporal execution/history and owned cleanup. These intermediate digests are evidence, not publication identities.
  • Distribution regressions: 18 passed; offline/race candidate checks cover same-length changed SDK bytes, wrong source, bad image digest, duplicate/missing role, archive traversal/symlink and existing-file preservation.
  • make verify lint/unit/race/vet passed; chart contracts and Actions validation passed; documentation: 64 pages passed.
  • Configured scripts/with-dev-env make test-self-hosted-live passed in 7.93s without credential output. Existing local stack and user edits remain intact.
  • Two independent subagent reviews approved the whole PR and final README delta with no actionable findings. All 12 required checks passed at d9dd5ddab674745fa40bd61dcc93bbaa66472120. The exact-head Release candidate run passed fresh package installation and Linux AMD64 actual-artifact Kubernetes restart/independent original-history restore before upload. Publication follows from a separately validated merged-revision candidate.

@yanpgwang
yanpgwang merged commit c56fc17 into main Oct 5, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant