Immutable
release. Only release title and notes can be modified.
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- 4dc1066 chore(deps): bump actions/checkout in the actions group
- 94d704b chore(deps): bump golang.org/x/term in the go-runtime group
- aea3f17 chore(deps): bump the actions group with 2 updates
- 949320b chore(deps): pin action release commits (#68)
- 6e2bc5b chore(deps): update x/term (#67)
- ad63031 ci(e1): gate multi-layer tenant isolation
- eb1692d ci(security): make isolation fuzz budget deterministic
- 7129d34 docs(ci): close isolation fuzz journal
- 7992456 docs(e0): close two-spoke OCM falsification
- a654acb docs(e1): checkpoint OIDC CI evidence
- 93fe683 docs(e1): close exec credential journal
- 424cc6a docs(e1): close postgres RLS journal
- a57ff09 docs(e1): close tenant-isolation journal
- 9d80592 docs(e1): close workspace auth journal
- b931225 docs(e1): finalize RLS preflight evidence
- 8b2455d docs(e1): record API key exchange evidence
- 3e9123c docs(e1): record AWS STS verification evidence
- 6a0fdff docs(e1): record Azure Entra verification evidence
- 71d0626 docs(e1): record OIDC federation evidence
- 27f8863 docs(e1): record RLS gate evidence
- ed7b41f docs(e1): record cloud identity seam evidence
- 024b099 docs(e1): record isolation-suite evidence
- f8e288e docs(release): prevent durable branch deletion
- 11c045e feat(e1): add cloud identity exchange seam
- 286d972 feat(e1): add forced postgres tenancy boundary
- f0071b5 feat(e1): add workspace tenancy contract
- 27ddb4b feat(e1): bind fleet reads to signed scope
- 68ec421 feat(e1): exchange API keys for signed sessions
- aff198a feat(e1): federate pinned OIDC identities
- 3530df4 feat(e1): verify AWS STS identity proofs
- 44660eb feat(e1): verify Azure Entra workload identities
- 7332864 feat(e1): verify Google service-account identities
- fbbf117 feat(e1): verify signed workspace sessions
- 44ae088 feat(e10): add bounded self-observability metrics
- c9e3737 feat(e10): add sanitized auth refusal logs
- 1ecfb56 feat(e10): add sanitized local trace context (#138)
- fef959f feat(e2): add direct ClusterProxy snapshot transport
- 096dca9 feat(e2): add immutable image digest search
- 5e5f426 feat(e2): collect bounded spoke snapshots
- 9a3911f feat(e2): correlate exact unhealthy workloads
- 658336f feat(e9): add fail-closed Helm hub chart
- 92bedb3 feat(e9): add fail-closed hub resource profiles
- 9e75a13 feat(e9): add immutable OCI image contract
- d29c8da feat(e9): add isolated hub migration command
- 64072f9 feat(fleet): add four-lens entity graph contract
- 75499b1 feat(hub): compose direct OCM runtime
- a4ec7db feat(pep): add structured policy audit logging
- d748b9d feat(pep): gate hub reads through policy hook
- 2f51151 fix(brain): normalize image evidence for fleet correlation
- 0a3dbca fix(brain): stabilize deterministic incident replays
- d76c975 fix(e0): harden OCM falsification evidence
- c23fcba fix(e1): harden signed workspace sessions
- 2721618 fix(e1): remove tenant-key existence oracle
- 2f35b11 fix(e1): require TLS for remote postgres
- a5f5ada fix(e2): harden portable M0 release checks
- 8b56a04 fix(security): pin secure Go toolchain
- b0a2553 refactor(e1): isolate hub network boundary
- 11d90dd test(e0): automate two-spoke OCM falsification
- c2f9641 test(e1): add destructive isolation controls
- 929be80 test(e1): prove exec credential isolation
- 6ce51ce test(e1): prove postgres RLS in CI
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.