v0.7.0 — Verified Kubernetes and AWS Delivery Lifecycle
This release completes the seven-phase Advanced Distributed System with a reproducible delivery lifecycle spanning local Kubernetes and a controlled, temporary AWS EKS demonstration.
Highlights
- causal CRDT replication with explicit consistency boundaries
- SQLite WAL durability, etcd discovery, TLS 1.3 and mTLS identity checks
- Prometheus, OpenTelemetry, Tempo, Grafana, chaos and performance verification
- hardened non-root OCI image with Gitleaks, Trivy and SPDX SBOM gates
- three-replica Helm/kind verification, persistence restart and rollback
- reviewed Terraform plan, temporary AWS EKS verification and complete teardown
- GitHub Actions migrated to Node 24-compatible action majors
Immutable release identity
- Source commit:
7995d5342e5c40d83ee36beeed10ba50ce70f00f - Image:
ghcr.io/parmodk2310/distsys-node@sha256:c571c604cf310ddbf8c3c7ea1c9b605ffc8fdf1da5ec755422035643552e3a5f - SPDX SBOM SHA-256:
ba37ef2346f219b1b68468f24c56f9f1ae4f088df772d5b254e5762e9f69e4c9 - Image evidence SHA-256:
23291c9c93646a2466acc3a595dadd393509d5edff8f25c9826a191d16c314d8 - Image workflow:
35208700672 - Local Kubernetes workflow:
35208700515 - Quality workflow:
35208700539
The immutable digest passed secret scanning, vulnerability scanning, live kind verification, GHCR publication, provenance attestation and keyless signing.
Boundaries
This release does not claim consensus, linearizability, quorum durability, exactly-once distributed execution, multi-AZ high availability, production SLOs, or a permanently hosted service. The AWS demonstration used one worker and was destroyed after evidence capture.
See docs/releases/v0.7.0.md and docs/verification/phase7.md for the full evidence ledger.