Repository navigation
Releases: TheAgentHealth/agenthealth
Release list
AgentHealth v0.12.0
AgentHealth v0.12.0 — Synchronized distribution
v0.12.0 adopts one software version and source tag for the CLI, Docker image,
Helm chart, Linux packages and registry bundles. It supersedes CLI v0.11.1 and
chart 0.1.0 without modifying their published tags or downloads.
Changes
- Coordinate one GitHub Release containing five archives, five CycloneDX SBOMs,
four DEB/RPM packages, Homebrew/Scoop manifests, chart package and checksums. - Publish three linked GHCR packages: Docker image, OCI Helm chart and an
additional OCI binary bundle containing the complete signed release asset set. - Set chart version 0.12.0, appVersion v0.12.0 and matching CLI image defaults.
- Sign downloadable assets, archive-bound SBOMs and all three OCI identities.
- Publish the release only after container/package jobs and anonymous package
access checks succeed. Failed first-package visibility checks leave a draft. - Preserve existing CLI commands, health exit codes, schemas and AHS/AHP contracts.
No separate local source test suite was rerun during preparation, as requested.
The release workflow passed source validation and all five native platform smoke
checks. Published downloads and packages passed post-publication verification;
see the verification record.
The initial v0.12.0 attempt stopped before building or publishing artifacts
because a Kubernetes test still expected v0.11.1. That test now derives its
expected version from chart metadata. The maintainer explicitly authorized
recreating the unpublished v0.12.0 tag at the corrected source commit. The
intermediate v0.12.1 attempt was canceled before publication.
Installation
Docker references:
ghcr.io/theagenthealth/agenthealth:v0.12.0docker.io/theagenthealth/agenthealth:v0.12.0when the configured mirror succeeds
Helm from Packages:
helm upgrade --install agenthealth \
oci://ghcr.io/theagenthealth/charts/agenthealth --version 0.12.0 \
--namespace agenthealth --create-namespace \
--set-file config=./agenthealth.yamlThe configuration describes your services; the chart does not install the
fixture's demo Service. Direct chart download/installation remains available:
helm pull https://github.com/TheAgentHealth/agenthealth/releases/download/v0.12.0/agenthealth-0.12.0.tgz
gh attestation verify agenthealth-0.12.0.tgz --repo TheAgentHealth/agenthealth \
--signer-workflow TheAgentHealth/agenthealth/.github/workflows/release.yml
helm upgrade --install agenthealth ./agenthealth-0.12.0.tgz \
--set-file config=./agenthealth.yamlStandalone Linux AMD64:
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.12.0/agenthealth_v0.12.0_linux_amd64.tar.gz
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.12.0/checksums.txt
gh attestation verify agenthealth_v0.12.0_linux_amd64.tar.gz --repo TheAgentHealth/agenthealth \
--signer-workflow TheAgentHealth/agenthealth/.github/workflows/release.yml
sha256sum --check --ignore-missing checksums.txt
tar -xzf agenthealth_v0.12.0_linux_amd64.tar.gz
./agenthealth versionRetrieve the additional full asset bundle with ORAS:
oras pull ghcr.io/theagenthealth/agenthealth-binaries:v0.12.0 \
--output ./agenthealth-v0.12.0Verify the bundle's signed OCI provenance at its published digest, then verify
all downloaded file signatures/checksums before selecting an archive/package.
The bundle includes the chart so the shared checksum manifest covers every
bundled file. This OCI artifact is not a runnable container or an SDK.
Source and verification
The package manifest digests below were verified after publication. The Kubernetes
API floor is 1.29; this release's public OCI chart was installed in all three
workload modes on Kubernetes 1.32.2/Linux AMD64 with Helm 3.17.3. All 18 anonymous
release downloads matched the verified signed files and ORAS bundle. Verification
covered 17 checksums and 26 file/SBOM/OCI attestations, Linux CLI behavior, archive
and package contents, and both registries' AMD64/ARM64 binary identities.
Native OS signing/notarization, Helm GPG .prov, APT/YUM repositories and public
Homebrew/Scoop hosting remain deferred. GitHub keyless provenance is supplied.
Published package digests
All entries identify this release source revision. Repository Packages.
| Package | Immutable reference |
|---|---|
| Docker GHCR | ghcr.io/theagenthealth/agenthealth@sha256:ad568974f50b11e4c9342b6dd17816e9f391397501ff922197d99f60ea70cd31 |
| Helm OCI | ghcr.io/theagenthealth/charts/agenthealth@sha256:abb80ced1bc0a60a5c087a482ce35c7540877297fb11d22527a93c744dd1df43 |
| Binary OCI bundle | ghcr.io/theagenthealth/agenthealth-binaries@sha256:86e357192c00cf75440b8e0d83ad4c4db1ed22893045927301318ac1d882a143 |
| Docker Hub mirror | docker.io/theagenthealth/agenthealth@sha256:f9ae3e1ceda1738d4b445504eed1ba155b1aa343988e7c1aefc3c186fd9ab7d2 |
AgentHealth v0.11.1
AgentHealth v0.11.1 — Security rebuild and Kubernetes integration
v0.11.1 rebuilds every CLI distribution with Go 1.27.2, fixing
GO-2026-6617, an HTTP/2 HPACK encoder race
in the standard library. Existing CLI commands, AHS/AHP contracts, configuration
schemas, adapter behavior and health exit codes remain unchanged.
Changes
- Update the digest-pinned Go container builder and release/CI toolchains to 1.27.2.
- Include Phase 14 manifests, Kustomize overlays, bounded readiness/init/Job
scenarios, Secret references and conventional AHP sidecar examples in source. - Quote Helm labels and ConfigMap names, use process health for startup, and bound
each configured dependency independently of its parent. - Target Kubernetes 1.32.2 explicitly during offline Helm validation; local and
CI runtime scenarios use kind 0.27.0. Kubernetes 1.29 is the declared floor,
not a separately runtime-tested version. - Prepare independently versioned chart 0.1.0, with
appVersion: v0.11.1and
GitHub-signed package/checksum provenance. Chart publication useshelm-v0.1.0
and is separate from this CLI release.
Installation and verification
The CLI release contains five archives with CycloneDX SBOMs, four AMD64/ARM64
DEB/RPM packages, Homebrew/Scoop manifests and checksums. Build provenance covers
all downloadable assets; archive SBOM attestations describe each executable.
Linux AMD64 example:
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.11.1/agenthealth_v0.11.1_linux_amd64.tar.gz
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.11.1/checksums.txt
gh attestation verify agenthealth_v0.11.1_linux_amd64.tar.gz --repo TheAgentHealth/agenthealth \
--signer-workflow TheAgentHealth/agenthealth/.github/workflows/release.yml
sha256sum --check --ignore-missing checksums.txt
tar -xzf agenthealth_v0.11.1_linux_amd64.tar.gz
./agenthealth versionBoth registry references for this CLI release are:
- GHCR:
ghcr.io/theagenthealth/agenthealth:v0.11.1 - Docker Hub mirror:
docker.io/theagenthealth/agenthealth:v0.11.1
Confirm both are anonymously accessible before choosing either registry.
CLI archives, packages and both configured image registries share this version.
Kubernetes artifacts
From a checkout of this tag with your disposable cluster selected:
kubectl create namespace agenthealth-demo
kubectl -n agenthealth-demo apply -k examples/kubernetes
kubectl -n agenthealth-demo wait --for=condition=complete job/agenthealth-check --timeout=90s
kubectl -n agenthealth-demo logs job/agenthealth-check
kubectl -n agenthealth-demo delete namespace agenthealth-demoSee the independent chart release notes for the packaged
chart download and Helm installation. Selected Kubernetes patterns credit
Sharath K (sharath568) through PR #15.
Limitations
Only CLI exit 0 passes exec readiness and validation Jobs. AHP readiness uses
its existing snapshot contract; process startup/liveness remain independent of
dependency outages. The nginx fixtures are not real agent/gateway/router
interoperability certification. Native OS executable signing/notarization,
package repository signatures and Helm GPG .prov files remain deferred.
GitHub keyless provenance signatures are provided instead. No operator/CRDs or
admission automation is included.
Post-release verification
All published downloads passed signature, checksum, SBOM and content checks. Linux CLI behavior, both public registries and published Kubernetes/chart scenarios also passed. See the verification record for evidence and validation limits.
AgentHealth chart 0.1.0
AgentHealth Helm chart 0.1.0
Chart component release; published independently of the CLI.
Chart 0.1.0 pins CLI v0.11.1 (appVersion) and supports AHP Deployment,
one-shot Job and CronJob modes, read-only ConfigMap configuration and existing
Secret references. Kubernetes runtime scenarios were validated on kind 1.32.2
with Helm 3.17.3 on Linux AMD64. The declared manifest floor is Kubernetes 1.29;
other cluster versions have not been runtime validated.
CLI image references (verify both before chart publication):
- Default:
ghcr.io/theagenthealth/agenthealth:v0.11.1 - Optional mirror:
docker.io/theagenthealth/agenthealth:v0.11.1
Kustomize source examples and an optional application-image exec-probe pattern
are also included. Selected operational patterns credit Sharath K (sharath568)
from PR #15.
Source paths at the intended component release revision:
These tag-pinned links become available only after the authorized chart release.
Verify that they resolve before announcing publication. This release does not
republish the CLI or container images.
After publication, download the chart and checksums.txt from the component
release, verify the checksum, and use a reviewed configuration:
gh attestation verify agenthealth-0.1.0.tgz --repo TheAgentHealth/agenthealth \
--signer-workflow TheAgentHealth/agenthealth/.github/workflows/helm-release.yml
sha256sum --check checksums.txt
helm upgrade --install agenthealth ./agenthealth-0.1.0.tgz \
--set-file config=./agenthealth.yamlFor a runnable fixture scenario, check out the component tag and follow
the usage examples. Set
image.repository=docker.io/theagenthealth/agenthealth to choose the mirror.
Only CLI exit 0 passes exec probes and validation Jobs. AHP readiness uses its
existing aggregate contract and snapshot interval. The chart exposes no Service
or Ingress; configure network isolation and HTTPS when needed. Completed Jobs
need a new release name for reruns or a deliberate workload deletion for updates.
No CRDs, operator, admission policy, real product interoperability certification,
or GPG-signed Helm .prov files are included. Chart package and checksum
provenance is signed through GitHub Actions attestations.
Post-release verification
All published downloads passed signature, checksum, SBOM and content checks. Linux CLI behavior, both public registries and published Kubernetes/chart scenarios also passed. See the verification record for evidence and validation limits.
AgentHealth v0.11.0
AgentHealth v0.11.0 — Standalone package distribution
v0.11.0 implements the package-channel source scope of
Phase 13.
CLI distribution formats share a version; this release includes matching binary
archives, Linux packages and container images. SDKs and Helm charts remain
planned and will use independent component versions.
Changes
- Add Linux AMD64/ARM64 DEB and RPM release assets with a
ca-certificates
dependency, reusing executable and documentation bytes from the verified archive
with normalized executable/document modes. - Generate
agenthealth.rbfor Homebrew (Linux/macOS AMD64/ARM64) and
agenthealth.jsonfor Scoop (Windows AMD64). Each manifest pins a tagged
archive URL and its SHA-256. - Extend checksums and GitHub-signed build provenance to every package and
manifest. Retain five platform archives and their CycloneDX SBOM attestations. - Build and smoke-test native archives on all five platforms in CI and gate
binary publication on the same checks in the release workflow. - Document component release policy, distribution preparation examples and
earlier-phase alignment. Correct current documentation of parallel binary
and container release jobs.
Compatibility and migration
No AHS, configuration/result schema, CLI command, exit-code, core or adapter
changes. Existing configurations work without migration. DEB/RPM packages install
/usr/bin/agenthealth and documentation under /usr/share/doc/agenthealth;
no service, configuration, credentials or install hooks are created. Avoid
multiple installation methods writing to the same PATH location.
Installation
Download the appropriate assets from this release and verify their checksums
and GitHub build provenance before installation. For Linux AMD64:
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.11.0/agenthealth_v0.11.0_linux_amd64.tar.gz
curl -fLO https://github.com/TheAgentHealth/agenthealth/releases/download/v0.11.0/checksums.txt
sha256sum --check --ignore-missing checksums.txt
gh attestation verify agenthealth_v0.11.0_linux_amd64.tar.gz --repo TheAgentHealth/agenthealth
tar -xzf agenthealth_v0.11.0_linux_amd64.tar.gz
./agenthealth versionFor verified local DEB/RPM downloads, use sudo apt install ./<package>.deb
or sudo dnf install ./<package>.rpm. Scoop can install a verified downloaded
manifest with scoop install ./agenthealth.json. Maintainers can place the
verified formula in their Homebrew tap's Formula/agenthealth.rb.
Both GHCR and Docker Hub images are published for this release:
# GitHub Container Registry
docker run --rm ghcr.io/theagenthealth/agenthealth:v0.11.0 version
# Docker Hub
docker run --rm theagenthealth/agenthealth:v0.11.0 versionSee installation
and component policy.
Validation and limitations
Local Go vet/race tests, Python regressions, markdown links and marked/standalone
configuration examples pass. Archives for all five platforms and all four Linux
packages build locally. Linux AMD64 archive/DEB smoke checks and both DEB payload
comparisons pass. CI checks native version/help and tool-failure exit behavior
on each of the five platforms; local cross-compilation alone does not establish
native runtime coverage on other platforms.
There is no public Homebrew tap, Scoop bucket, APT or YUM repository. Native
executable signing/macOS notarization, package repository signatures,
package-manager installation/upgrade/removal matrices, and package-specific SBOM
attestations remain future work. Archive SBOMs describe the reused executable;
packages and manifests have signed build provenance. Container publishing remains
required for CLI releases; Docker Hub is optional when its credentials are absent.
AgentHealth v0.10.0
AgentHealth v0.10.0 — Docker distribution
v0.10.0 implements Phase 12:
an official container image published to GitHub Container Registry, with an
optional Docker Hub mirror. See issue #12,
PR #38 and the
Docker guide.
Changes
- Add a multi-stage Dockerfile: a digest-pinned
golang:1.27.1-bookwormbuilder compiles a static binary with the same
flags as scripts/build_release.py, onto a
digest-pinnedgcr.io/distroless/static-debian12:nonrootruntime (no shell,
fixed non-root user65532:65532). - CI (
ci.yml) buildslinux/amd64andlinux/arm64, then smoke-tests the
image via scripts/test_container.py
(version, help, non-root user, entrypoint, and an actual HTTP health check
run from inside the container). tests/test_container_image.py
statically checks digest pinning, the non-root distroless base, and that
build flags stay in sync with the release builder. release.ymladds acontainerjob that runs only after the binary
release succeeds, verifies (viacmp) that each platform's image binary is
byte-identical to that tag's attested archive, then publishes
ghcr.io/theagenthealth/agenthealthwith BuildKit provenance, an SBOM, and
a keyless GitHub-signed attestation pushed to the registry. Tags are
vX.Y.Z, with floatingvXandlatestfor plain releases; suffixed
pre-release tags publish only their exact tag.- The published image is smoke-tested as an unauthenticated user (logged out
of GHCR first), so a release fails loudly instead of silently passing if
the package is still private. - Add an optional Docker Hub mirror (
theagenthealth/agenthealth) with the
same tags, gated onDOCKERHUB_USERNAME/DOCKERHUB_ACCESS_TOKENrepository
secrets; the step is skipped until they exist. - No AHS, schema, core, CLI, or adapter contract changes.
Compatibility and migration
This is an additive distribution channel only. Configuration/result schemas,
health states, exit codes, and existing CLI behavior are unchanged; no
migration is needed. Standalone binary archives remain the same as earlier
releases.
Installation
docker run --rm ghcr.io/theagenthealth/agenthealth:v0.10.0 version
docker run --rm ghcr.io/theagenthealth/agenthealth:v0.10.0 ping http https://example.comA Docker Hub mirror is also published with the same tags:
docker pull theagenthealth/agenthealth:v0.10.0
docker pull theagenthealth/agenthealth:latestSee container usage for mounting
configuration files, credentials, and provenance verification, and
installation.md for standalone archives, which are
unchanged from v0.9.0.
Limitations
GitHub creates a new organization package as private by default; the first
publish needs a one-time manual visibility change (documented in
RELEASING.md) before unauthenticated pulls succeed. MCP
stdio targets need their server executable in a derived image.
agenthealth login's browser callback is a workstation flow, not supported
in this minimal image. The Docker Hub mirror only publishes once its secrets
are configured. Kubernetes integration, SDK packages, and remaining adapters
are still planned. OS-native executable signing and macOS notarization remain
planned; the release uses keyless signed attestations.
Validation
Go vet/race tests, Python schema/integration tests (100 passed, 3 skipped),
markdown links, and all marked/standalone configuration examples pass locally.
The Dockerfile was built and smoke-tested locally for both linux/amd64 and
multi-platform (linux/amd64,linux/arm64) targets with Docker Buildx. The
release workflow validates the tagged source, builds five binary archives,
verifies image binaries are byte-identical to those archives, and publishes
the container image only after that verification succeeds.
AgentHealth v0.9.0
AgentHealth v0.9.0 — Experimental AHP HTTP serving
v0.9.0 implements Phase 11's experimental Agent Health Protocol HTTP v1
binding and agenthealth serve. See the wire contract,
serving guide, impact review and
earlier-phase alignment audit.
Changes
- Add GET
/health,/readyand/livepublic summaries and bearer-authorized
/health/dependenciesand/health/capabilitiesrecursive evidence. - Refresh checks in the background without request-triggered probes or
overlapping runs. Refresh starts 30 seconds after each completed run;
snapshots expire after two minutes. - Keep liveness independent of target health. Readiness accepts HEALTHY and
DEGRADED evidence; cold, stale, stopped or impaired results return 503. - Preserve graph IDs, relationship and critical edge policies, and separate
capability, declared readiness and completed functional/path evidence. - Default to loopback, reference bearer credentials through
--token-env,
validate token grammar and compare fixed-size digests in constant time. - Add protocol envelope schema/fixtures, serving and CLI tests, examples,
documentation and phase-by-phase alignment.
Compatibility and migration
AHP ahp_version: v1 is separate from AHS spec_version: v1. Existing
configuration/result schemas, health states, target vocabulary and health
command exit codes remain unchanged. Existing nested and graph configurations
need no migration. Serving exits 0 after graceful shutdown and 6 on tool failure;
it does not exit when targets are unhealthy. Earlier binaries do not support serve.
Installation
Download your archive and matching CycloneDX SBOM from the
v0.9.0 release.
Linux AMD64/ARM64, macOS AMD64/ARM64 and Windows AMD64 are packaged with
checksums and keyless signed build provenance/SBOM attestations. Follow
installation and verification.
agenthealth versionThe serving example path requires a v0.9.0 or newer repository checkout.
From its root, run:
agenthealth serve examples/ahp-check/agenthealth.yamlThe example requires your HTTP application on port 9000. Query port 8080 for
public summaries. Configure a private random token through AHP_TOKEN and
--token-env AHP_TOKEN to enable authorized details.
Limitations
Experimental HTTP JSON only, one configuration and bearer scope, no vendor
extension fields or automatic discovery. Independent implementation
interoperability is unverified. Remote serving requires proxy HTTPS termination,
network restrictions and per-client rate limiting. No built-in TLS or client
limiter is provided. Explicit functional probes repeat with each refresh; review
these before serving. AHP is not an AHP-specific client adapter, and a healthy
peer, gateway or router does not establish direct-agent communication.
Docker, Kubernetes, SDK packages and remaining adapters are still planned.
OS-native executable signing and macOS notarization remain planned; the release
uses keyless signed attestations. Only Linux AMD64 runtime behavior is
smoke-tested locally; other platform archives are cross-compiled.
Validation
Go vet/race tests, Python schema/integration tests, markdown links and all
marked/standalone configuration examples pass locally. Optional interoperability
cases require their CI environment. CI includes Linux/macOS/Windows Go tests,
Go 1.23 compatibility, vulnerability scanning and current/legacy official SDK
interoperability. The release workflow validates the tagged source and builds
five archives, five SBOMs and checksums before publication.
AgentHealth v0.8.0
AgentHealth v0.8.0 — Dependency graph
v0.8.0 implements Phase 10 with explicit shared-node references, independent
edge policies and relationship evidence, bounded parallel execution, and
ordered recursive output. See RFC #26,
the graph contract,
usage guide, and earlier-phase alignment.
Changes
- Add globally unique target/inline dependency
idand dependencyref.
References select explicitly configured nodes without overriding their
endpoint, checks, credentials or policies. - Evaluate each explicit ID once per run, including opted-in active checks
and cleanup. Anonymous nested targets remain independent. - Preserve critical/optional policy per edge and distinguish
supporting,
downstream,path,gatewayandrouterrelationship evidence. - Execute targets and dependencies in parallel while preserving output order.
Add per-runconcurrency(1–16, default 16) under the engine-wide 16-call
bound, including cleanup and uncooperative adapter calls. - Add
budget_ms(1–60000) for a node's own checks, retries and queue waits.
Parent budgets do not cancel independently budgeted shared dependencies. - Reject duplicate IDs, missing references, cycles, depth above 64 and more
than 10000 result projections before adapter execution. - Extend JSON/YAML results with
target.idand dependency-edge metadata.
Terminal output labels node IDs, relationships and optional edges. - Resolve agent-advertised dependency names only against explicit inline or
referenced nodes. Keep peer and first-runtime communication evidence separate. - Redact final results after all graph nodes register dynamically acquired secrets.
- Align earlier phase contracts and guides, add graph examples, schema fixtures,
graph/CLI regressions and real-output schema validation.
Compatibility and migration
Configuration/result v1, health states, dimensions, target types and exit codes
remain unchanged. Existing nested configurations require no migration.
Older binaries reject the new graph fields; upgrade before using them.
Parallel scheduling changes request timing, while declaration-order output stays
stable. Trusted custom adapters must tolerate concurrent calls across nodes.
Closed downstream result schemas should allow target.id, relationship
and critical. Incoming-edge policy belongs to each dependency projection;
a root result has no incoming-edge policy. Repeated IDs indicate shared evidence,
not repeated probes. Known secrets in IDs become redacted, which may collapse
identities; do not infer shared identity from that placeholder.
Installation
Download the matching archive and SBOM from the
v0.8.0 release.
Platforms: Linux AMD64/ARM64, macOS AMD64/ARM64 and Windows AMD64, with
five matching CycloneDX SBOMs and checksums. Follow
installation and attestation verification.
agenthealth version
agenthealth check examples/graph-check/agenthealth.yaml --format json
agenthealth doctor examples/graph-check/agenthealth.yamlThe example requires compatible running services and a safe first-agent handler
that contacts the selected peer. See setup requirements.
Limitations
No automatic topology discovery, product certification, root-cause inference,
new adapter protocols, AHP server, SDK packages, Docker or Kubernetes support
is introduced. A healthy backend or router does not establish a working
first-runtime path. Graph metadata can expose topology; restrict access to
results. Active probes remain explicit, bounded, non-destructive and non-retrying.
The existing independent one-second cleanup budget is separate from node budgets.
Validation
Local Go vet/race tests and Python schema/integration tests pass. Optional
SDK interoperability cases require their configured test environment. CI
runs platform Go race tests, current/legacy SDK interoperability, vulnerability
scanning, schema and documentation checks. The release workflow builds five
archives and smoke-tests Linux AMD64; other platforms are cross-compiled
without a claim of local runtime validation. Signed provenance and SBOM
attestations accompany the release; OS-native signing/notarization remains planned.
Cleanup hooks remain serialized across nodes, runs and engines sharing a registry. Waiting for the serialization gate honors the cleanup deadline; an uncooperative hook holds the gate and its adapter-call slots until it actually returns.
AgentHealth v0.7.0
AgentHealth v0.7.0 — Agent Router integration
v0.7.0 implements Phase 9 with a vendor-neutral router target for explicitly
configured read-only HTTP signals. See PR #24,
RFC #23 and the
impact review.
Changes
- Add router support to
ping,checkanddoctor, retaining terminal, JSON
and YAML output and the existing health exit codes. - Add
routerto configuration/result type schemas and allow HTTP expectations
on top-level router targets and nested dependencies. - Use GET for read-only router signals, retaining HTTP/API HEAD and gateway GET.
- Preserve named router, direct-backend and routed-path results independently,
including critical failure propagation and optional dependency degradation. - Reuse bearer environment references, verified TLS, redirect rejection,
deadlines and bounded response matching. Functional probes require explicit
opt-in and never retry; reachability/authentication preflight GETs mean every
configured probe endpoint must be read-only. - Add failure-isolation, aggregation, functional-bound and CLI tests; schema
fixtures; a direct-agent/router/backend/path example; and phase documentation.
Compatibility and migration
This additive release retains configuration/result v1, existing result structure,
health states and exit codes. Existing supported checks keep their behavior.
Older binaries reject the new router type; upgrade before using router targets.
Configure actual health signals and each routed endpoint explicitly. Credentials,
checks and dependency policies are not inherited. A healthy router signal does
not establish backend or path health, and a failed route alone cannot identify
its cause. Aggregate status includes dependency results.
Installation
Download the matching archive and SBOM from the v0.7.0 release,
verify checksums.txt, signed provenance and SBOM attestations using the
installation guide, for the v0.7.0 download commands. Archives cover Linux AMD64/ARM64,
macOS AMD64/ARM64 and Windows AMD64, with five matching CycloneDX SBOMs.
agenthealth version
agenthealth ping router http://localhost:8081/ready
agenthealth doctor examples/router-check/agenthealth.yamlThe endpoint and example require your running services. Adjust them to match
your deployment; sample ports/paths are not product defaults. See the
router guide and example setup.
Limitations
This generic HTTP interface integration does not certify a router product or
version. No admin inventory, inferred endpoints, discovery, failover probes,
model generation or arbitrary mutations are supported. HTTP/MCP/A2A paths use
their existing adapters. External CLI route probes do not prove communication
from the direct agent runtime; Phase 7 safe downstream handlers remain required.
Shared graph identity, AHP serving, SDK packages, Docker and Kubernetes remain
future work. Real product interoperability remains Phase 25 work. OS-native
signing and macOS notarization are not provided.
Validation
Phase 9 implementation CI passed all nine checks, including Linux/macOS/Windows
Go race tests, current/legacy official SDK interoperability, vulnerability scanning,
schemas and documentation. The implementation review recommended approval with
zero findings; a non-blocking result-fixture suggestion was addressed separately.
Local Go vet/race tests passed with Go 1.26.0. Python tests with Go on PATH reported
88 passed and three optional SDK tests skipped; those SDK suites passed in CI.
The release workflow uses Go 1.27.1 and smoke-tests Linux AMD64. Other archives
are cross-compiled, without local runtime validation on other platforms.
AgentHealth v0.6.0
AgentHealth v0.6.0 — Agentgateway integration
v0.6.0 implements Phase 8 using read-only GET health signals for the existing
gateway target type. See PR #21
and the impact RFC.
Changes
- Register gateway support for
ping,checkanddoctor, with terminal,
JSON and YAML output and existing health exit codes. - Allow HTTP status/header expectations and bounded, explicitly opted-in
functional body matching on gateway targets and nested gateway dependencies. - Preserve independent gateway, backend and configured protocol-path evidence
through named dependencies, critical/optional aggregation and redaction. - Add gateway/CLI regression tests, collected schema fixtures, an agent/gateway/
downstream example and an all-phase documentation status index. - Preserve HTTP/API HEAD behavior; gateway read-only signals use GET.
Compatibility and migration
This is an additive release retaining configuration/result v1. Existing supported
agent, HTTP/API, MCP and A2A checks keep their behavior. Previously unsupported
gateway targets now execute HTTP checks: point them at an explicitly configured
read-only health endpoint. Credentials and policies are not inherited by dependencies.
Functional probes remain opt-in, bounded, non-destructive and non-retrying.
Installation
Download the matching archive and SBOM from this release and verify
checksums.txt, signed provenance and SBOM attestations using the
installation guide. Archives cover Linux AMD64/ARM64,
macOS AMD64/ARM64 and Windows AMD64.
agenthealth version
agenthealth ping gateway http://localhost:15021/healthz/ready
agenthealth doctor examples/gateway-check/agenthealth.yamlThe endpoint and example require your running services; adjust addresses to
match your deployment. See the gateway guide.
Limitations
HTTP health signals do not establish backend membership, load-balancer eviction
state or route configuration. Backends and proxied HTTP/MCP/A2A paths must be
configured explicitly. A failed proxied request alone cannot identify its cause.
CLI probes do not prove first-agent runtime communication; Phase 7 runtime path
handlers remain required for that evidence. Product-version Agentgateway
interoperability remains untested. No admin inventory parsing, automatic discovery,
model generation or mutating health operations are added.
Router integration, graph extensions, AHP serving, SDK packages, Docker and
Kubernetes remain planned. OS-native signing and macOS notarization are not provided.
Validation
Phase 8 PR CI passed all nine checks, including Linux/macOS/Windows Go race tests,
current/legacy official SDK tests, vulnerability scanning, schemas and documentation.
Both review findings were fixed; follow-up review recommended approval with no open
findings. Local Go vet/race tests passed using Go 1.26.0; the Python suite reported
84 passed and 4 optional tests skipped. Release CI uses Go 1.27.1 and smoke-tests
Linux AMD64; other release archives are cross-compiled, not locally runtime-tested.
AgentHealth v0.5.0
AgentHealth v0.5.0 — Agent health
v0.5.0 implements Phase 7 direct and composite agent health through a bounded,
framework-neutral health-resource interface. See PR #19
and RFC #18.
Changes
- Add
agentandmulti-agentsupport toping,checkanddoctorwith
consistent terminal/JSON/YAML output and existing health exit codes. - Validate agent metadata, declared liveness/readiness, required capabilities
and names-only dependency discovery. Share the passive document per target. - Add explicitly safe, opt-in task probes and selected downstream communication
probes. Keep first-agent, peer, path and supporting dependency evidence in
separate named results; retain independent critical/optional aggregation. - Add optional v1 agent configuration, strict validation, stable diagnostic
codes, schema fixtures, examples and affected-phase impact reviews. - Align downstream selectors with the 1024-Unicode-character schema limit;
allow empty selectors as omission and reject whitespace-only selectors.
Retain the separate 64 KiB UTF-8 byte limit for task text. - Update CLI help for supported agent types and the A2A 1.0 default.
- Drain MCP OAuth browser callback responses before server shutdown, fixing an
intermittent EOF on rejected callbacks. Bound graceful cleanup to one second.
Runtime prerequisite and limitations
Your agent application must expose the documented HEAD/GET health resource
and implement the safe POST probe handler. For a first-to-downstream path
probe, the first agent must actually contact the selected peer directly or
through A2A before reporting completion. AgentHealth sends/evaluates probes;
it does not install a handler into your application or trace remote execution.
It trusts runtime completion reports. Peer endpoint health alone does not
prove a working path. See the adapter contract and
setup example.
Discovery matches advertised names against explicitly configured dependencies;
it never creates targets or follows remote addresses. Functional probes run
once without polling or retries. Incomplete evidence is UNKNOWN. Passive
readiness is a runtime declaration, not proof of task execution.
Framework-specific integrations, Agentgateway/Agent Router adapters, graph
scheduling, AHP serving, SDK packages, Docker and Kubernetes remain roadmap
work. Existing A2A JSON-RPC limitations still apply. OS-native executable
signing and macOS notarization are not provided.
Migration and compatibility
The configuration and JSON/YAML result envelopes retain v1. Existing supported
HTTP/API, MCP and A2A targets preserve their behavior. Previously unsupported
agent targets now execute checks against the health-resource interface.
Legacy agent configurations listing functional without task options remain
syntactically valid but produce MISCONFIGURED before networking. Add
agent.functional with safe: true and a bounded nonempty text to enable
functional execution. Dependencies do not inherit credentials or check policy.
Consumers should tolerate new engine-owned diagnostic code identifiers.
Installation and verification
Download the matching platform archive and CycloneDX SBOM from this release;
verify their hashes with checksums.txt. The five platform archives cover Linux
AMD64/ARM64, macOS AMD64/ARM64 and Windows AMD64. Build provenance and SBOM
attestations use GitHub keyless signing. Follow the
installation and attestation instructions.
Validation
Local Go vet/race tests and Python suite passed (83 passed, 3 optional SDK
interoperability tests skipped locally); marked documentation examples,
standalone configurations and links validated. The OAuth callback test passed
100 repetitions under the race detector. PR CI passed Linux/macOS/Windows Go
checks, current/legacy official SDK interoperability, schema/documentation
checks and vulnerability scanning. Release CI validates the tagged source,
uses Go 1.27.1, builds all platforms and smoke-tests Linux AMD64; other archive
platforms are cross-compiled. CI runtime checks are separate from archive
runtime testing.