Skip to content

Prepare signed release inventories and verify installation inputs - #308

Merged
ctfbruce merged 4 commits into
mainfrom
feat/verified-release-bundles
Oct 2, 2026
Merged

ctfbruce merged 4 commits into
mainfrom
feat/verified-release-bundles

Conversation

@ctfbruce

@ctfbruce ctfbruce commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Prepare signed release bundles that bind installers, all four component archives, compatibility metadata, checksums, source/build identities, CycloneDX inventory and provenance. Signed installation verifies the selected files with independently provisioned OpenSSH trust before execution. The existing checksum-only installation command remains usable while signing is unprovisioned and prints a warning; either trust setting or DEBUGLET_REQUIRE_SIGNATURE=1 requires complete trust and successful signature verification, with no fallback. Explicit unsigned mode cannot override configured trust or a signature requirement. Related to #137, #138, #139 and #140.

The manually dispatched workflow consumes packages from successful CI on an exact protected version tag. It requires all 16 current CI checks, verifies independent approval protection for the signing environment, and keeps signing in a separate job that checks out no source and executes no candidate payload. The compatibility record is bound to the package source, version and OpenAPI digest. First-tag secret scans include the reachable history instead of silently selecting a one-commit range.

The integration prerequisite #354 is merged and this PR now targets main. #322 adds retained evidence and private archive promotion separately.

Validation: 56 focused release, inventory, bootstrap, CI and scanner checks pass on Aspire. Independent source review found no issues. All 16 checks pass in CI 36980153683 on ea1aaaa39034756e8c7563d061264c3157abe1d4. The current package inventory/provenance logic was also checked against the actual 14-file CI package, including the compatibility sidecar. The bootstrap compatibility revision additionally passes all 19 focused tests; its fresh full CI run is 37001062695 on a81463c3289d50739456a6c94ea95ab051579be7.

The first full-history scan surfaced two previously retired localhost TLS fixtures. Their existing removal record establishes that the disabled local configs gave them no runtime authority; two exceptions bind only to the original commit, exact path, rule and line. The real full-history scan then passed, with current files and future commits still covered.

No release, signing key, trust anchor or repository setting is activated here. Actual protected version tags, an independently reviewed signing environment, operator trust distribution and real release acceptance remain required. A signed Actions artifact alone does not establish durable retention; #141 remains open. Runtime base-image pins are not a complete OS package inventory, and BPF regeneration metadata does not establish the historical compiler for inherited objects.

@ctfbruce ctfbruce added the Ready for review Reviewed, green candidate; maintainer review and dependency checks still required. label Sep 28, 2026
@ctfbruce
ctfbruce marked this pull request as ready for review September 28, 2026 11:20
@vincent10400094

Copy link
Copy Markdown
Member

Deferring pending the package and CI foundations. The signed-release preparation work is valuable; please rebase onto current main and submit only its release-signing commits.

@vincent10400094 vincent10400094 added Deferred Intentionally deferred; see the issue for its activation condition. Operator experience and releases Configuration, services, recovery, observability and reproducible releases. and removed Ready for review Reviewed, green candidate; maintainer review and dependency checks still required. labels Sep 28, 2026
@vincent10400094

Copy link
Copy Markdown
Member

Keeping this deferred. Its prerequisites are now merged, and the release-signing commit rebases onto current main with two small conflicts in scripts/bootstrap.sh and tools/test_bootstrap.py. It stays inert until an administrator configures a signing key and environment. Until then, scripts/bootstrap.sh would refuse to install unless DEBUGLET_ALLOW_UNSIGNED=1 or trust is provisioned. We'll revisit once signing is set up, so that the default install path keeps working.

@ctfbruce
ctfbruce marked this pull request as draft October 2, 2026 07:34
@ctfbruce
ctfbruce changed the base branch from main to feat/measurement-workflows-and-limits October 2, 2026 07:34
@ctfbruce
ctfbruce force-pushed the feat/verified-release-bundles branch from 01e3331 to 70b0fbe Compare October 2, 2026 07:34
@ctfbruce ctfbruce removed the Deferred Intentionally deferred; see the issue for its activation condition. label Oct 2, 2026
@ctfbruce
ctfbruce changed the base branch from feat/measurement-workflows-and-limits to main October 2, 2026 11:26
@ctfbruce
ctfbruce marked this pull request as ready for review October 2, 2026 11:40
@ctfbruce
ctfbruce merged commit f0305fc into main Oct 2, 2026
16 checks passed
@vincent10400094
vincent10400094 deleted the feat/verified-release-bundles branch October 8, 2026 00:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Operator experience and releases Configuration, services, recovery, observability and reproducible releases.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants