release: promote demo-ready dev for v0.3.0-beta.5#317
Conversation
Add a pinned authorization-code and PKCE browser boundary that keeps upstream proofs and Sith session JWTs out of browser payloads. The Hub stores only a bounded, single-use transaction and returns the successful session in a strict host-only cookie. Keep the existing fleet API bearer-only, compose the optional provider through the hardened Hub runtime, and document the operator secret and Helm contract. GSTACK-Checkpoint: 2026-07-15/e8-browser-oidc-session#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…r-oidc-session feat(e8): broker browser-safe hub OIDC sessions
GSTACK-Checkpoint: 2026-07-15/e10-loopback-metrics#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…ack-metrics feat(hub): add loopback operator metrics
GSTACK-Checkpoint: 2026-07-15/e10-process-audit-sink#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…ss-audit-sink feat(hub): supervise auth audit delivery
Keep the common request-admission boundary as the only browser OIDC limiter debit. Add production-boundary coverage proving ten complete flows consume twenty requests and that rejection happens before transaction creation. Fixes #180 GSTACK-Checkpoint: 2026-07-16/browser-oidc-rate-limit#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…dc-rate-limit fix(hub): count browser OIDC requests once
GSTACK-Checkpoint: 2026-07-16/kubeconfig-timeout-bound#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…-timeout-bound fix(kubeconfig): quarantine timed-out operations
GSTACK-Checkpoint: 2026-07-16/brain-image-evidence#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com> Co-authored-by: Gnani Rahul <gnani.nutakki@gmail.com>
GSTACK-Checkpoint: 2026-07-16/fleetcache-workspace-scope#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com> Co-authored-by: Gnani Rahul <gnani.nutakki@gmail.com>
GSTACK-Checkpoint: 2026-07-16/kubeconfig-query-pagination#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com> Co-authored-by: Gnani Rahul <gnani.nutakki@gmail.com>
Qualify record identity, aliases, coverage, operational state, and change notifications by validated workspace boundaries. Reject mixed replace and watch inputs before mutation while preserving scoped query defense. Add race, fuzz, PostgreSQL isolation, and real two-cluster Kind proof for identical resource identities and independent failure paths. GSTACK-Checkpoint: 2026-07-16/fleetcache-workspace-mutations#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…-workspace-mutations fix(fleet): isolate workspace cache mutations
Bind directory traversal and reads to one validated os.Root, verify walked and opened identities, and reject replacement symlinks before parsing. Refuse deferred local credential and path-based exec references after the root closes, with deterministic root, file, symlink, and ancestor replacement coverage. GSTACK-Checkpoint: 2026-07-16/kubeconfig-directory-race#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…-directory-race fix(kubeconfig): anchor directory imports
Read cluster coverage state and persisted facts in one workspace-scoped repeatable-read, read-only transaction while preserving existing write semantics. Add deterministic PostgreSQL interleaving coverage that commits ReplaceSnapshot between reads, verifies transaction-local RLS, and rejects mixed freshness and fact generations. GSTACK-Checkpoint: 2026-07-16/hubdb-repeatable-read#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
Authorize every caller before joining one active refresh per workspace, then run shared collection on a detached internal trace so caller cancellation and request values cannot cross boundaries. Add deterministic race coverage for tenant isolation, cancellation, shared failures, panic cleanup, and defensive results. GSTACK-Checkpoint: 2026-07-16/hub-refresh-coalescing#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…atable-read fix(hubdb): keep fleet reads in one snapshot
…h-coalescing fix(hubfleet): coalesce workspace refreshes
Use one absolute deadline for current-object availability checks, tolerate delete/recreate transitions, and fail closed on terminal or malformed state without logging response bodies. GSTACK-Checkpoint: 2026-07-16/ocm-addon-wait-lifecycle#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…wait-lifecycle fix(ocm): make addon wait lifecycle-safe
Parallelize transport and validation behind a finite worker pool while serializing persistence and joining every worker on cancellation, store failure, or panic. GSTACK-Checkpoint: 2026-07-16/hub-spoke-worker-pool#2 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…worker-pool fix(hubfleet): bound spoke snapshot workers
Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…lignment fix(ci): align pinned Helm tooling
Paginate server-side Table lists with opaque continuation tokens, row and byte budgets, and retain only display fields for selected facts. Sanitize non-success bodies at the reviewed kubeconfig HTTP boundary without losing status classification. GSTACK-Checkpoint: 2026-07-16/table-materialization#1 Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…rialization fix(fleet): bound generic table materialization
Signed-off-by: Gnani Rahul <gnani.nutakki@gmail.com>
…-20260721 fix(deps): remediate x/text normalization loop
Align the desktop CLI gate with the Wails module, reject lookalike or failed version probes, and exercise the policy in the standard script suite. GSTACK-Checkpoint: 2026-07-21/wails-policy#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…0260721 fix(desktop): enforce exact Wails tool version
Upgrade Syft and Cosign to current stable fixes, synchronize CI and release pins with operator documentation, and enforce the compatibility contract in the standard policy suite. GSTACK-Checkpoint: 2026-07-21/release-tooling#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…g-20260721 fix(release): refresh supply-chain tooling
Mint one immutable database-clock expiry for every new approval, enforce the half-open lifetime in the single-use consume update, and bind expiry into versioned audit evidence. Retain legacy rows fail closed, preserve mixed-format offline verification, and document the transactional migration and rolling-upgrade contract. GSTACK-Checkpoint: 2026-07-21/approval-grant-expiry#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…y-20260721 feat(approvals): expire grants after ten minutes
Add an immutable GitOps provenance bundle and pure fail-closed resolver for confirmed entity-local R2/R4 candidates. Bind readiness to one fresh source claim and the exact live GitHub handler adapter and schema. Reuse handler-owned canonicalization, preserve every source-owned Git precondition, close descriptor/freshness/cancellation drift windows, and keep PEP, credentials, network, mutation, and execution structurally absent. GSTACK-Checkpoint: 2026-07-22/e14-gitops-provenance#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…nce-20260722 feat(remediation): resolve source-owned GitOps provenance
Add the observed-only git-source-snapshot/v1 contract for one canonical repository file observation. Bind exact current bytes to their Git blob identity, one object format, stable source and subject identity, attached evidence, and a bounded validity interval. Keep DesiredChange, Brain and resolver wiring, authority, credentials, I/O, persistence, mutation, and execution structurally absent so R2/R4 remain advisory-only. GSTACK-Checkpoint: 2026-07-22/e14-git-source-snapshot#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…pshot-20260722 feat(remediation): define immutable Git source snapshot
Seed temporal approval controls from PostgreSQL statement time with safe future and expired margins. Assert the database-observed sides and exact ten-minute lifetimes before refusal checks without changing production behavior. GSTACK-Checkpoint: 2026-07-22/approval-expiry-clock#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…xpiry-clock-20260722 test(hubdb): eliminate approval-expiry clock-boundary flake
Add desired-change/v1 as an opaque exact binding between one validated Git source snapshot, one canonical transformer version, cited evidence, and exact proposed bytes. Reject forged, ambiguous, oversized, and no-op claims while preserving deterministic mutation-isolated state. Keep construction package-private and leave R2/R4, renderer policy, resolver wiring, authority, credentials, I/O, persistence, mutation, and execution structurally absent. GSTACK-Checkpoint: 2026-07-22/e14-desired-change#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…-20260722 feat(remediation): bind immutable desired changes
Use an explicit Lax final session cookie so the safe console redirect receives the newly issued session after the cross-site IdP callback. Retain the host-only Secure and HttpOnly boundary, reject unsafe methods, and document the exact CSRF trade-off. GSTACK-Checkpoint: 2026-07-22/e8-oidc-session-handoff#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…on-handoff-20260722 fix(hub): preserve browser OIDC session handoff
Copy the validated Ed25519 key into runtime-owned memory, then clear the parser-owned allocation before returning. Lock the ownership transfer with a focused non-aliasing and signing regression. GSTACK-Checkpoint: 2026-07-22/e3-session-key-lifetime#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…key-copy-20260722 fix(hub): clear parser-owned session key bytes
Align operator, architecture, ADR, specification, alert annotation, and session records with implemented bounds and live landing proof. Clarify evidence semantics without changing alert evaluation, connector-wave scope, IAM, or runtime behavior. GSTACK-Checkpoint: 2026-07-22/deep-audit-contract-drift#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
…tract-drift-20260722 docs: reconcile deep-audit evidence contracts
Route auto mode to the native desktop on macOS and the loopback-only UI elsewhere. Reuse the bounded directory importer, reject UI-only flags in desktop mode, and allow an explicit demo directory without a default kubeconfig backend. Document the first-run path and cover platform selection, command registration, safe dependency failures, loopback startup, and explicit-directory bootstrap. GSTACK-Checkpoint: 2026-07-23/demo-launch#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
feat(cli): add one-command local demo launcher
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (293)
Disabled knowledge base sources:
📝 WalkthroughWalkthroughThis large PR spans CI/release tooling updates, Helm chart/runtime enhancements (browser OIDC, metrics, health probes), new Investigation Brain rules (R7–R9) with graph facts and remediation candidates, connector wire-version negotiation with several new adapters, hardened kubeconfig pagination, hub audit-chain/approval-grant persistence, a new hub console/browser-OIDC/audit-export/probes surface, hubfleet concurrency/observability, PEP proposal binding, remediation GitOps contracts, extensive documentation, monitoring rules, and e2e/script tests. ChangesSith platform hardening release
Estimated code review effort: 5 (Critical) | ~180+ minutes Possibly related issues
Possibly related PRs
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Release-gate checkpoint before merge:
Proceeding with the merge-only promotion. Any late automated finding will be triaged before the beta tag is created; tagging remains separately fail-closed on anonymous GHCR digest access. |
There was a problem hiding this comment.
Actionable comments posted: 7
🧹 Nitpick comments (4)
internal/connector/argocd/boundary_test.go (1)
30-39: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winWeaker import denylist than sibling projectors.
This guard only rejects two exact
k8s.io/client-gosubpackages (dynamic,rest) andnet/http/os/exec. The equivalentprometheus/boundary_test.godenies anyk8s.io/client-go/*(prefix), plussyscall,plugin,net,net/*, and gRPC. As written, an argocd projector could importk8s.io/client-go/kubernetes,tools/clientcmd,syscall, etc. and still pass this boundary gate. Consider aligning with the prometheus prefix-based denylist (or an allowlist as in github/dcgm) for consistent seam protection.♻️ Suggested alignment with prometheus denylist
for _, imported := range file.Imports { path, err := strconv.Unquote(imported.Path.Value) if err != nil { t.Fatalf("unquote import: %v", err) } - switch path { - case "net/http", "os/exec", "k8s.io/client-go/dynamic", "k8s.io/client-go/rest": - t.Fatalf("projector imports network or execution package %q", path) - } + if path == "os/exec" || path == "syscall" || path == "plugin" || path == "net" || + strings.HasPrefix(path, "net/") || strings.HasPrefix(path, "google.golang.org/grpc") || + strings.HasPrefix(path, "k8s.io/client-go") { + t.Fatalf("projector imports network or execution package %q", path) + } }🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@internal/connector/argocd/boundary_test.go` around lines 30 - 39, Strengthen the import validation in the boundary test’s loop over file.Imports to match the sibling prometheus projector denylist: reject any k8s.io/client-go/ subpackage, syscall, plugin, net, net/*, and gRPC imports rather than only the current exact paths. Preserve the existing fatal reporting and unquote error handling while applying prefix matching where required.internal/hubdb/migrations/0011_approval_lifecycle_audit.sql (1)
10-40: 🧹 Nitpick | 🔵 TrivialMigration may lock the audit log during rollout.
sith.policy_audit_entriesis an append-only audit table that can grow large. Settingevent_kind/evidence_digestNOT NULLand adding the new validatingCHECKconstraints in-line forces full-table scans that block writes for the duration on a populated table. If zero-write-downtime matters here, prefer adding the columns nullable, backfilling in batches, and adding constraints asNOT VALIDfollowed by a separateVALIDATE CONSTRAINT.The backfill/constraint logic itself is correct; this is purely about lock duration on large deployments.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@internal/hubdb/migrations/0011_approval_lifecycle_audit.sql` around lines 10 - 40, Update the migration’s ALTER TABLE for sith.policy_audit_entries to avoid long blocking scans: add or retain event_kind and evidence_digest as nullable during rollout, backfill existing rows in batches, and add the validating CHECK constraints with NOT VALID before validating them separately via VALIDATE CONSTRAINT. Apply NOT NULL only after the backfill is complete, preserving the existing validation rules and append-only write availability.Source: Linters/SAST tools
internal/brain/graph.go (1)
410-425: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winReject duplicate JSON members in the Argo payload decoder.
decodeArgoChangePayloadonly disallows unknown fields; addingrejectDuplicateGraphJSON(raw)here would match the GitHub and Elasticsearch paths and avoid last-write-wins ambiguity on duplicate keys.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@internal/brain/graph.go` around lines 410 - 425, Update decodeArgoChangePayload to call rejectDuplicateGraphJSON(raw) before decoding the payload, returning any validation error through the existing error-wrapping pattern. Preserve the current unknown-field and single-JSON-value checks.internal/brain/rules.go (1)
74-79: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low valueR7 lacks the sourceKind/resourceKind allowlist applied to R8/R9.
RuleArgoSyncFailandRuleWorkflowFaildeliberately pinsourceKind/resourceKind/exactTriggerto prevent ambiguous cross-source matches (per the adversarial "fails closed" tests ingraph_test.go).RuleImagePulltriggers on anylive/pod.reasonobservation with no such restriction, relying implicitly on today's fact that only the kubeconfig connector emits this key. If a future connector reuses this key/lens, R7 could fire on unintended sources.Consider adding
sourceKind: "kubeconfig", resourceKind: "Pod"for defense-in-depth consistency with the pattern just introduced for R8/R9.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@internal/brain/rules.go` around lines 74 - 79, The RuleImagePull trigger is missing source and resource restrictions, allowing unintended connectors to match it. Update RuleImagePull’s predicate to require sourceKind “kubeconfig” and resourceKind “Pod”, preserving its existing live lens, pod.reason key, and trigger values.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/SITH-NOTION.md`:
- Around line 2551-2552: Update the F10.1 federation metrics description and
adjacent diagram to describe unlabeled, request-time aggregate outcomes—fresh,
stale, unknown, empty, and error—instead of per-spoke freshness metrics. Ensure
the text does not imply per-spoke labels or nonexistent per-spoke alert
dimensions.
In `@docs/specs/E2-readfed-brain-integrations.md`:
- Around line 710-713: The GitHub row must not present gitops.open-pr as
shipped: update its pl/ex capability and description to explicitly mark the
governed write as planned/future P2, or remove ex until the resolver is wired
through the Brain, PEP, and Hub. Keep the existing read capabilities unchanged.
In `@internal/connector/argocd/project.go`:
- Around line 340-367: Update the history projection loop so HistoryTruncated is
assigned to the first emitted projectedChange, not based on raw history index ==
0. Preserve skipping entries without deployedAt, and track whether a change has
already been emitted so truncated remains true when the oldest retained entry is
skipped.
In `@internal/hubserver/console_assets/console.css`:
- Around line 497-499: Resolve the Stylelint violations in the console
stylesheet: change all currentColor values at the referenced declarations to
lowercase currentcolor, remove quotes from SFMono-Regular in each listed
font-family declaration while preserving quotes for names that require them, and
handle the deprecated clip declaration by adding a narrowly scoped Stylelint
disable comment if it remains necessary for the visually-hidden pattern.
In `@sessions/2026-07-15-e10-loopback-metrics.md`:
- Line 4: Update the status metadata at
sessions/2026-07-15-e10-loopback-metrics.md:4 to the repository’s
completed/ready-for-commit status; update
sessions/2026-07-15-e10-process-audit-sink.md:4 to indicate implementation and
local validation are complete with only fresh PR CI pending; and update
sessions/2026-07-15-e8-browser-oidc-session.md:4 to match its completed
checkpoint and ready-for-review close.
In `@sessions/2026-07-16-fleetcache-workspace-scope.md`:
- Around line 23-26: Make the verification commands environment-neutral in
sessions/2026-07-16-fleetcache-workspace-scope.md lines 23-26 by removing
developer-specific PATH, GOPATH, and tool locations, using repository-relative
commands or clearly marked placeholders. Apply the same cleanup to
sessions/2026-07-16-brain-image-evidence.md lines 26-27, replacing hard-coded
GOPATH and tool paths with portable commands or placeholders.
In `@sessions/2026-07-21-deep-quality-audit.md`:
- Around line 18-28: Update the audit summary’s API-surface statement to say
there are no externally visible API changes, while acknowledging the mandatory
collector lifecycle context contract change within internal/hubfleet. Keep the
qualification limited to clarifying scope and leave the listed implementation
changes unchanged.
---
Nitpick comments:
In `@internal/brain/graph.go`:
- Around line 410-425: Update decodeArgoChangePayload to call
rejectDuplicateGraphJSON(raw) before decoding the payload, returning any
validation error through the existing error-wrapping pattern. Preserve the
current unknown-field and single-JSON-value checks.
In `@internal/brain/rules.go`:
- Around line 74-79: The RuleImagePull trigger is missing source and resource
restrictions, allowing unintended connectors to match it. Update RuleImagePull’s
predicate to require sourceKind “kubeconfig” and resourceKind “Pod”, preserving
its existing live lens, pod.reason key, and trigger values.
In `@internal/connector/argocd/boundary_test.go`:
- Around line 30-39: Strengthen the import validation in the boundary test’s
loop over file.Imports to match the sibling prometheus projector denylist:
reject any k8s.io/client-go/ subpackage, syscall, plugin, net, net/*, and gRPC
imports rather than only the current exact paths. Preserve the existing fatal
reporting and unquote error handling while applying prefix matching where
required.
In `@internal/hubdb/migrations/0011_approval_lifecycle_audit.sql`:
- Around line 10-40: Update the migration’s ALTER TABLE for
sith.policy_audit_entries to avoid long blocking scans: add or retain event_kind
and evidence_digest as nullable during rollout, backfill existing rows in
batches, and add the validating CHECK constraints with NOT VALID before
validating them separately via VALIDATE CONSTRAINT. Apply NOT NULL only after
the backfill is complete, preserving the existing validation rules and
append-only write availability.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 1ba1489a-52dd-4ad7-a5db-e915527ca3fe
⛔ Files ignored due to path filters (1)
go.sumis excluded by!**/*.sum
📒 Files selected for processing (293)
.github/workflows/ci.yml.github/workflows/release.ymlMakefileREADME.mdcharts/sith-hub/README.mdcharts/sith-hub/templates/deployment.yamlcharts/sith-hub/values.schema.jsoncharts/sith-hub/values.yamldocs/ARCHITECTURE.mddocs/EPICS.mddocs/ROADMAP.mddocs/SITH-NOTION.mddocs/adr/0005-ai-mcp-ardur-pdp.mddocs/adr/0008-deterministic-advisory-brain.mddocs/adr/0009-release-supply-chain.mddocs/adr/0011-opencost-namespace-cost-facts.mddocs/adr/0012-opencost-coverage-aware-workspace-rollup.mddocs/adr/0013-dcgm-gpu-utilization-facts.mddocs/adr/0014-connector-wire-adapter-version-split.mddocs/adr/README.mddocs/experiments/M0-ocm-falsification.mddocs/runbooks/hub-alerts.mddocs/specs/E2-readfed-brain-integrations.mddocs/specs/F2.1-source-adapter-contract.mdgo.modhack/experiments/m0-ocm-falsification.shhack/verify-release-hub-image.shhack/verify-wails-version.shinternal/auditdelivery/process.gointernal/auditdelivery/process_test.gointernal/auditrecord/export.gointernal/auditrecord/export_test.gointernal/auditrecord/page.gointernal/auditrecord/page_test.gointernal/brain/boundary_test.gointernal/brain/cache.gointernal/brain/cache_test.gointernal/brain/evaluate.gointernal/brain/evaluate_test.gointernal/brain/graph.gointernal/brain/graph_elasticsearch_test.gointernal/brain/graph_test.gointernal/brain/model.gointernal/brain/remediation.gointernal/brain/remediation_test.gointernal/brain/replay_test.gointernal/brain/rules.gointernal/brain/testdata/replays/README.mdinternal/brain/testdata/replays/r1-bad-deploy-causes-crashloop.jsoninternal/brain/testdata/replays/r1-stale-timeline-unconfirmed.jsoninternal/brain/testdata/replays/r2-oomkilled.jsoninternal/brain/testdata/replays/r3-elasticsearch-log-cause.jsoninternal/brain/testdata/replays/r3-fleet-image-correlation.jsoninternal/brain/testdata/replays/r4-config-drift.jsoninternal/brain/testdata/replays/r7-image-pull-backoff.jsoninternal/brain/testdata/replays/r8-argocd-sync-failed.jsoninternal/brain/testdata/replays/r9-github-actions-workflow-failed.jsoninternal/cli/audit.gointernal/cli/audit_test.gointernal/cli/audit_unix_test.gointernal/cli/cached_test.gointernal/cli/desktop.gointernal/cli/investigate_test.gointernal/cli/launch.gointernal/cli/launch_test.gointernal/cli/root.gointernal/cli/ui.gointernal/connector/argocd/boundary_test.gointernal/connector/argocd/project.gointernal/connector/argocd/project_test.gointernal/connector/awseks/boundary_test.gointernal/connector/awseks/project.gointernal/connector/awseks/project_test.gointernal/connector/contract.gointernal/connector/dcgm/boundary_test.gointernal/connector/dcgm/project.gointernal/connector/dcgm/project_test.gointernal/connector/elasticsearch/boundary_test.gointernal/connector/elasticsearch/project.gointernal/connector/elasticsearch/project_test.gointernal/connector/github/action_plan.gointernal/connector/github/action_plan_test.gointernal/connector/github/boundary_test.gointernal/connector/github/project.gointernal/connector/github/project_test.gointernal/connector/github/workflow_run.gointernal/connector/github/workflow_run_test.gointernal/connector/kubeconfig/adapter.gointernal/connector/kubeconfig/adapter_test.gointernal/connector/kubeconfig/directory.gointernal/connector/kubeconfig/directory_test.gointernal/connector/kubeconfig/local_objects.gointernal/connector/kubeconfig/local_streams.gointernal/connector/kubeconfig/resources.gointernal/connector/kubeconfig/table.gointernal/connector/kubeconfig/table_test.gointernal/connector/kubeconfig/watch.gointernal/connector/kubeconfig/watch_bootstrap_test.gointernal/connector/opencost/boundary_test.gointernal/connector/opencost/project.gointernal/connector/opencost/project_test.gointernal/connector/opencost/rollup.gointernal/connector/opencost/rollup_test.gointernal/connector/prometheus/boundary_test.gointernal/connector/prometheus/project.gointernal/connector/prometheus/project_test.gointernal/connector/registry.gointernal/connector/registry_test.gointernal/connector/source.gointernal/connector/source_test.gointernal/connector/version.gointernal/connector/version_boundary_test.gointernal/connector/version_test.gointernal/fleet/coverage_test.gointernal/fleet/model.gointernal/fleet/resource.gointernal/fleetcache/scoped_test.gointernal/fleetcache/store.gointernal/fleetcache/store_test.gointernal/fleetcache/workspace_mutation_test.gointernal/fleetrender/table.gointernal/fleetrender/table_test.gointernal/hubauth/oidc.gointernal/hubauth/oidc_browser_test.gointernal/hubauth/oidc_test.gointernal/hubdb/app.gointernal/hubdb/app_test.gointernal/hubdb/approvals.gointernal/hubdb/approvals_test.gointernal/hubdb/audit.gointernal/hubdb/doc.gointernal/hubdb/fleet.gointernal/hubdb/migrate.gointernal/hubdb/migrations/0009_policy_audit_chain.sqlinternal/hubdb/migrations/0010_approval_grants.sqlinternal/hubdb/migrations/0011_approval_lifecycle_audit.sqlinternal/hubdb/migrations/0012_audit_export_action.sqlinternal/hubdb/migrations/0013_approval_grant_expiry.sqlinternal/hubdb/policy_audit.gointernal/hubdb/policy_audit_test.gointernal/hubdb/postgres_integration_test.gointernal/hubfleet/collector.gointernal/hubfleet/collector_concurrency_test.gointernal/hubfleet/collector_test.gointernal/hubfleet/correlation.gointernal/hubfleet/inventory_search.gointernal/hubfleet/inventory_search_test.gointernal/hubfleet/metrics_test.gointernal/hubfleet/policy_test.gointernal/hubfleet/refresh_coordinator.gointernal/hubfleet/refresh_coordinator_test.gointernal/hubfleet/source.gointernal/hubfleet/source_observability_test.gointernal/hubfleet/tracing_test.gointernal/hubruntime/config.gointernal/hubruntime/metrics.gointernal/hubruntime/metrics_test.gointernal/hubruntime/ocm_integration_test.gointernal/hubruntime/policy_audit.gointernal/hubruntime/policy_audit_test.gointernal/hubruntime/runtime_test.gointernal/hubserver/audit_export.gointernal/hubserver/audit_export_test.gointernal/hubserver/auth.gointernal/hubserver/auth_observability.gointernal/hubserver/auth_observability_test.gointernal/hubserver/browser_oidc.gointernal/hubserver/browser_oidc_test.gointernal/hubserver/console.gointernal/hubserver/console_assets/console.cssinternal/hubserver/console_assets/console.htmlinternal/hubserver/console_assets/console.jsinternal/hubserver/console_boundary_test.gointernal/hubserver/console_correlation_test.gointernal/hubserver/console_cve_test.gointernal/hubserver/console_inventory_test.gointernal/hubserver/console_test.gointernal/hubserver/fleet.gointernal/hubserver/fleet_test.gointernal/hubserver/probes.gointernal/hubserver/probes_test.gointernal/hydrate/hydrator.gointernal/hydrate/hydrator_test.gointernal/intent/boundary_test.gointernal/intent/verb.gointernal/intent/verb_test.gointernal/intentargs/boundary_test.gointernal/intentargs/schema.gointernal/intentargs/schema_test.gointernal/mcpserver/server_test.gointernal/observability/alert_rules_contract_test.gointernal/observability/auth.gointernal/observability/auth_test.gointernal/observability/metrics.gointernal/observability/metrics_test.gointernal/pep/approval_test.gointernal/pep/audit.gointernal/pep/audit_metrics.gointernal/pep/audit_metrics_test.gointernal/pep/audit_test.gointernal/pep/boundary_test.gointernal/pep/metrics.gointernal/pep/metrics_test.gointernal/pep/pep.gointernal/pep/pep_test.gointernal/pep/proposal_test.gointernal/privacy/boundary_test.gointernal/remediation/boundary_test.gointernal/remediation/desired_change.gointernal/remediation/desired_change_test.gointernal/remediation/git_snapshot.gointernal/remediation/git_snapshot_test.gointernal/remediation/gitops.gointernal/remediation/gitops_test.gointernal/tenancy/model.gointernal/tenancy/model_test.gointernal/tui/model.gointernal/tui/model_test.gointernal/webui/server_test.gomonitoring/sith-hub.rules.test.ymlmonitoring/sith-hub.rules.ymlsessions/2026-07-15-e10-loopback-metrics.mdsessions/2026-07-15-e10-process-audit-sink.mdsessions/2026-07-15-e8-browser-oidc-session.mdsessions/2026-07-16-argocd-application-facts.mdsessions/2026-07-16-brain-image-evidence.mdsessions/2026-07-16-browser-oidc-rate-limit.mdsessions/2026-07-16-fleetcache-workspace-mutations.mdsessions/2026-07-16-fleetcache-workspace-scope.mdsessions/2026-07-16-github-merged-pr-facts.mdsessions/2026-07-16-helm-pin-alignment.mdsessions/2026-07-16-hub-refresh-coalescing.mdsessions/2026-07-16-hub-spoke-worker-pool.mdsessions/2026-07-16-hubdb-repeatable-read.mdsessions/2026-07-16-kubeconfig-directory-race.mdsessions/2026-07-16-kubeconfig-query-pagination.mdsessions/2026-07-16-kubeconfig-timeout-bound.mdsessions/2026-07-16-ocm-addon-wait-lifecycle.mdsessions/2026-07-16-prometheus-alert-facts.mdsessions/2026-07-16-table-materialization.mdsessions/2026-07-16-watch-bootstrap.mdsessions/2026-07-17-e10-database-readiness.mdsessions/2026-07-17-e10-fleet-read-coverage-alert.mdsessions/2026-07-17-e10-fleet-read-outcomes.mdsessions/2026-07-17-e10-policy-audit-metrics.mdsessions/2026-07-17-e10-portable-alert-rules.mdsessions/2026-07-17-e10-readiness-alert.mdsessions/2026-07-17-e10-readiness-metrics.mdsessions/2026-07-17-e5-single-use-approvals.mdsessions/2026-07-17-elasticsearch-log-causes.mdsessions/2026-07-17-hub-cve-evidence-console.mdsessions/2026-07-17-hub-fleet-console.mdsessions/2026-07-17-hub-health-correlation.mdsessions/2026-07-18-approval-lifecycle-audit.mdsessions/2026-07-18-e10-auth-outcome-counter.mdsessions/2026-07-18-e10-auth-refusal-metric.mdsessions/2026-07-18-e10-auth-refusal-only-alert.mdsessions/2026-07-18-e10-fleet-read-freshness.mdsessions/2026-07-18-e10-missing-telemetry-alert.mdsessions/2026-07-18-e10-policy-error-alert.mdsessions/2026-07-18-e10-stale-read-alert.mdsessions/2026-07-18-e13-dcgm-gpu-utilization.mdsessions/2026-07-18-e13-opencost-namespace-costs.mdsessions/2026-07-18-e13-opencost-workspace-rollup.mdsessions/2026-07-18-e14-argocd-sync-failure-rule.mdsessions/2026-07-18-e14-elasticsearch-r3-bridge.mdsessions/2026-07-18-e14-github-actions-failure-rule.mdsessions/2026-07-18-e14-image-pull-rule.mdsessions/2026-07-18-e6-bounded-audit-export.mdsessions/2026-07-18-e6-offline-audit-verifier.mdsessions/2026-07-18-e6-snapshot-audit-pages.mdsessions/2026-07-19-e12-wire-adapter-version-split.mdsessions/2026-07-20-e14-remediation-candidate-contract.mdsessions/2026-07-21-approval-grant-expiry.mdsessions/2026-07-21-ci-release-policy-sync.mdsessions/2026-07-21-deep-quality-audit.mdsessions/2026-07-21-release-tooling.mdsessions/2026-07-21-wails-version-policy.mdsessions/2026-07-21-xtext-security.mdsessions/2026-07-22-e14-desired-change.mdsessions/2026-07-22-e14-git-source-snapshot.mdsessions/2026-07-22-e14-gitops-provenance-resolver.mdsessions/2026-07-23-demo-launch.mdtests/e2e/helm_chart_test.gotests/e2e/kind_argocd_projection_test.gotests/e2e/kind_fanout_test.gotests/e2e/kind_read_federation_test.gotests/scripts/helm_tooling_policy_test.shtests/scripts/m0_ocm_falsification_safety_test.shtests/scripts/prometheus_tooling_policy_test.shtests/scripts/release_hub_image_policy_test.shtests/scripts/release_tooling_policy_test.shtests/scripts/wails_tooling_policy_test.sh
Summary
Promote the current green
devtree tomainas the source commit for the next immutable beta. This promotion includes the complete current Phase-L local client and the accumulated read/governance foundations sincev0.3.0-beta.4, including the new one-commandsith launchgraphical entry point.Demo outcome
sith launchopens the native desktop on macOS and the loopback browser UI elsewhere.--kubeconfig-dirsupports bounded, in-memory demo hydration without requiring a default kubeconfig.Release boundary
v0.3.0-beta.5must not be cut until P1 E9: Make released hub OCI package publicly pullable #172 is resolved by an explicit package-admin decision and the existing beta.4 Hub digest is anonymously pullable.dev; do not delete the release source branch.Verification
Exact
devmergec77176454d4fe66555f443f9625699ee56c53d5f:0 / 0 / 0Summary by CodeRabbit
New Features
sith launchfor one-command UI or desktop startup, including kubeconfig-directory support./healthzand/readyzendpoints.Bug Fixes