v1.1.0
Summary
- Add the supported attestation-free
production.SoftwareOnlyProfilewith a distinct request type and replay domain. - Add live mTLS protected-change E2E and negative coverage through a non-Split-Knowledge consumer.
- Add optional same-connection Redis/Valkey
WAITacknowledgement and the supported two-phase failover qualification tools.
Qualification
- Release commit
754b348e6e463ce7807be18b29fac050b51f5cb2is GitHub verified-signed. - CI run
30877005508passed, including product-security, race, E2E, bounded fuzz, andgovulncheck. - Security Red Team run
30877005526passed. - Redis Sentinel Failover run
30877005523passed with TLS 1.3, one primary, two replicas, and three Sentinels. The seeded replay remained rejected after automatic promotion and an ASB process restart; a fresh post-promotion write received replica acknowledgement.
Supported compatibility
The Direct-Agent v1 token shape remains unchanged. The supported v1.1 surface is defined in docs/API_COMPATIBILITY.md and includes pkg/production software-only composition plus replica-acknowledged replay and the documented failover qualification helpers.
Boundaries
- The Redis result qualifies the tested self-operated Sentinel topology only. It does not qualify a managed-provider endpoint, persistence configuration, network-partition behavior, RTO, or SLA.
- The Azure SEV-SNP bridge remains experimental. Live hardware attestation and managed KMS/HSM custody are optional deployment qualifications and are not required by the software-only profile.
- This is a stable verifier-side library/substrate release, not a claim that a complete end-user SaaS product or managed HA service has been delivered.