You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Perform the final physical-hardware qualification of the protected v1.2.1
Candidate on amd64 and arm64, verify its signed Release assets and lifecycle
identity, and record the explicit promotion decision. Both machines must pull
the same multi-architecture digest and publication must reuse those exact
bytes.
Acceptance criteria
Record the final version, source SHA, multi-architecture digest, both host/runtime versions, and links to every completed v1.2 platform qualification issue.
Pull the Candidate by digest on physical amd64 and physical arm64 hardware and confirm both native images start.
On both architectures, release.json, version file, MOTD, checked-out source ref/SHA, repository, and digest agree.
Verify every asset against SHA256SUMS, the checksum Sigstore bundle against the exact workflow/tag identity, and the image identity signature.
Run fresh and retained-home Compose flows on both architectures; Workspace and Managed-home data survive force recreation.
Confirm stable installers cannot discover the draft before approval and that required assertion Evidence is complete.
Confirm the active release-tag ruleset still rejects update/deletion and the peeled tag SHA equals the Candidate source SHA.
Approve the protected stable environment only after all gates pass, publishing without rebuilding.
Verify the immutable GitHub Release attestation plus GitHub and GHCR latest identities.
Rerun an older stable workflow or equivalent dry-run and confirm neither latest pointer can rewind.
Record an explicit promote/no-promote decision and follow-up defects here.
Type: HITL
Parent
What to build
Perform the final physical-hardware qualification of the protected v1.2.1
Candidate on amd64 and arm64, verify its signed Release assets and lifecycle
identity, and record the explicit promotion decision. Both machines must pull
the same multi-architecture digest and publication must reuse those exact
bytes.
Acceptance criteria
release.json, version file, MOTD, checked-out source ref/SHA, repository, and digest agree.SHA256SUMS, the checksum Sigstore bundle against the exact workflow/tag identity, and the image identity signature.latestidentities.latestpointer can rewind.Blocked by