build(release): validate matched chart and artifacts for Kubernetes alpha - #253
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and result
A source chart passing tests does not establish that users can install the actual runtime and SDK distribution. This change packages the matching Helm chart with the clean-source candidate, records both validated OCI image index digests, and runs the existing Kubernetes lifecycle journey using the archived native supervisor, packaged chart and exported images. Only the explicitly simulated model fixture is source-built.
Artifact acceptance checks source/version alignment and streamed payload hashes before image import, rejects duplicate/missing roles, and extracts only the paired command archive's expected regular files. It exercises authenticated HTTP, external sandbox execution, pending-action replacement, workspace/Skill/Memory reuse, scoped orphan cleanup and independent quiesced restore with original Temporal Run ID/history continuation.
The manual read-only candidate workflow now uses tracked Git snapshots for OCI builds, a scoped containerd Docker image store, and verified shared Helm/kind/kubectl tools. It uploads only after actual-artifact installation/recovery passes. Required contributor CI retains its source-build path; publishing remains a separate maintainer action after review and acceptance.
Boundaries
0.1.0-alpha.2, Python0.1.0a2and Gosdk/go/v0.1.0-alpha.2.docs/design/alpha-distribution.md, approveddocs/design/kubernetes-alpha.md, anddocs/provenance.md. Standard Helm/Docker packaging is adopted; hosted-agent release constraints are not.Validation
49a1941candidate: four command archives, four SDK packages and packaged chart built; native CLI identity, Helm package/lint/render, fresh Go module, Python wheel/sdist sync+async, TypeScript declarations and six authenticated package HTTP requests passed.make verifylint/unit/race/vet passed; chart contracts and Actions validation passed; documentation: 64 pages passed.scripts/with-dev-env make test-self-hosted-livepassed in 7.93s without credential output. Existing local stack and user edits remain intact.d9dd5ddab674745fa40bd61dcc93bbaa66472120. The exact-head Release candidate run passed fresh package installation and Linux AMD64 actual-artifact Kubernetes restart/independent original-history restore before upload. Publication follows from a separately validated merged-revision candidate.