You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: infrastructure/current-release-status.mdx
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ description: "A dated availability record for the independently released artifac
7
7
There is not yet a published, platform-wide known-good release set for the managed shared-router and private-PPB request path. The architecture pages describe the target contract, but they are not evidence that this integration is generally available. Do not change production DNS or infrastructure for that path until a later status record identifies every immutable artifact and its green end-to-end release gate.
8
8
</Warning>
9
9
10
-
This snapshot was reviewed on **July 19, 2026 at 01:15 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page.
10
+
This snapshot was reviewed on **July 19, 2026 at 10:52 UTC**. It is a release record, not a moving "latest" lookup. A later tag does not silently update the compatibility claims on this page.
11
11
12
12
## Status meanings
13
13
@@ -38,9 +38,9 @@ The table deliberately does not invent an image digest, template commit, signatu
38
38
39
39
| Integration | Status | Gate that remains |
40
40
| --- | --- | --- |
41
-
| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | PPB `0.5.1` is available, but the exact independently built site-router, edge-controller, and edge-provider-mutator image digests, ordered Pub/Sub mutation delivery, static Certificate Manager deny boundary, child-zone delegation lifecycle, two-phase organization DNS teardown with persisted TTL high-water and recursive-plus-parent-authority absence proof, exact-service-account state-gateway authentication, transactional observed-state outbox, managed Terraform pins, private-origin, client-IP, authorization-preservation, split timeout, Direct VPC, and hosted canaries still need promotion as one managed set. Cloud CDN remains disabled. |
41
+
| Cloud DNS and Certificate Manager through the global load balancer, Cloud Armor, shared Cloud Run router, and private per-site PPB | Blocked / preview | API commit [`1ffa3ee`](https://github.com/libops/api/commit/1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2) completed protected [Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) with bundle tag `sha-1ffa3ee5fd795d50844bf3594ffa8577cbd5dfb2-run-29667962498-attempt-3`. That run published signed, parity-checked GHCR and GAR manifests for `site-router@sha256:4bd36aad93e8d56ca2bdab090a5aba313bbdaf708cfc3c6a2eb8e83adf057cad`, `edge-controller@sha256:d5a2bbea2993a2d84730f66b6b09d8029f9c7daef5afd0d82f160c13eeb1af85`, and `edge-provider-mutator@sha256:c50e3de30b7d9fb3806557cfe6e57f6641bb556e4147a2565f945f8804e0d907`; signature claims and cross-registry manifest parity passed. Pin commit [`723ccaa`](https://github.com/libops/api/commit/723ccaa8d23ac0cdc0ba8833e5377fa22863fdc1) records those exact GAR digests as shared-infrastructure desired state. Production promotion still requires the shared-infrastructure Terraform apply and hosted canaries for DNS authorizations, certificates, and map entries; ordered Pub/Sub and dead-letter behavior; the static deny boundary; child-zone delegation and TTL-high-water teardown; exact-service-account state gateway and transactional outbox; private router-to-PPB origin; both Direct VPC egress paths; canonical client IP; application `Authorization` preservation; split timeouts; rollout; and rollback. Cloud CDN remains disabled. |
42
42
| Organization Vault three-image runtime | Blocked / preview | The shared publisher and verified WIF selector have passed protected-main publication for `vault-server`, released `vault-init``1.0.6`, and released `vault-proxy``2.0.3` through the cleanup-safe shared workflow. The aggregate runtime is still blocked until sitectl-admin's digest resolver and exact tag-commit/signature gate are released, all three independently built GAR manifests are pinned by digest, and the hosted API, Terraform, initialization, recovery, and rollback gates pass. Independently green image publications are not an aggregate runtime release. |
43
-
| Canonical API image set and production VM resolver | Blocked / preview |Merge the hosted post-CI publisher and `sitectl admin terraform api-compose-images`; publish the exact protected-main run to GHCR plus the appropriate private or public GAR repository; verify every digest's reusable-workflow identity, caller repository/ref/SHA, and caller-workflow annotation; and prove fresh VM bootstrap plus in-place refresh with the four verified private-GAR Compose images, the checkout detached at the publication commit, and legacy boot-disk discovery that fails on ambiguity. |
43
+
| Canonical API image set and production VM resolver | Blocked / preview |[Protected Images run 29667962498, attempt 3](https://github.com/libops/api/actions/runs/29667962498/attempts/3) published and verified `api`, `api-init`, `api-vault-agent`, and `control-plane`; `sitectl admin terraform libops-api` resolves the exact run tag to independent image digests. Production promotion still requires a deployment record naming the four private-GAR digests and their publication provenance, plus hosted proof of fresh VM bootstrap, detached same-SHA checkout, in-place refresh, rollback, and rejection of ambiguous legacy boot-disk discovery. |
44
44
| Separate request-serving API and `api-worker` Cloud Run services | Preview | Release the managed worker deployment and prove identity bootstrap, database connectivity, readiness, rollout, rollback, and removal of any temporary migration privilege. A process boundary in source or Compose is not proof of this Cloud Run topology. |
45
45
| Platform-wide image, template, CLI, plugin, and infrastructure compatibility manifest | Blocked | Generate the aggregate record from release automation and attach hosted CI evidence for the exact references. Until then, each operator owns a deployment-specific record. |
0 commit comments