v1.0.0
Agent Secure Binding v1.0.0 establishes the supported Direct-Agent verifier surface.
Highlights:
- Production verifier profile with role-separated trust keys and current trust/revocation snapshots.
- Signed attestation-result policy bound to the accepted TLS session and exact action.
- TLS-only Redis/Valkey SETNX replay adapter with fail-closed behavior.
- Independent protected-change consumer application with real TLS 1.3 mTLS E2E and negative tests.
- Published API compatibility and support policy for pkg/production, the Direct-Agent v1 subset of pkg/clients, and pkg/atls/identitypolicy.
Evidence:
- Signed source commit: f29de34 (GitHub verification: valid).
- Final main CI: 30784814370 (success).
- Final main Security Red Team: 30784814359 (success).
- Proto Consistency: 30782322014 (success on the last protobuf-changing product merge).
Boundaries:
- Hardware evidence acquisition, multi-node replay-store operations/failover, draft-06 v2 adapters, gateway runtime wiring, and inherited agent/manager runtime are not part of the supported v1 surface.
- This release is a verifier component and reference deployment profile, not a complete standalone agent-security platform.