Skip to content

Qualify the final v1.2 Candidate on physical amd64 and arm64 #131

Description

@BrettKinny

This was generated by AI during triage.

Type: HITL

Parent

What to build

Perform the final physical-hardware qualification of the protected v1.2.1
Candidate on amd64 and arm64, verify its signed Release assets and lifecycle
identity, and record the explicit promotion decision. Both machines must pull
the same multi-architecture digest and publication must reuse those exact
bytes.

Acceptance criteria

  • Record the final version, source SHA, multi-architecture digest, both host/runtime versions, and links to every completed v1.2 platform qualification issue.
  • Pull the Candidate by digest on physical amd64 and physical arm64 hardware and confirm both native images start.
  • On both architectures, release.json, version file, MOTD, checked-out source ref/SHA, repository, and digest agree.
  • Verify every asset against SHA256SUMS, the checksum Sigstore bundle against the exact workflow/tag identity, and the image identity signature.
  • Run fresh and retained-home Compose flows on both architectures; Workspace and Managed-home data survive force recreation.
  • Confirm stable installers cannot discover the draft before approval and that required assertion Evidence is complete.
  • Confirm the active release-tag ruleset still rejects update/deletion and the peeled tag SHA equals the Candidate source SHA.
  • Approve the protected stable environment only after all gates pass, publishing without rebuilding.
  • Verify the immutable GitHub Release attestation plus GitHub and GHCR latest identities.
  • Rerun an older stable workflow or equivalent dry-run and confirm neither latest pointer can rewind.
  • Record an explicit promote/no-promote decision and follow-up defects here.

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanRequires human implementation or judgment

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions