Repository navigation
v0.1.1
[0.1.1] — 2026-10-02
Added
Deployment & Release Channels (DEVELOPMENT vs PRODUCTION)
- One core runtime, two isolated deployment channels: production (
m31a,
default build) and development (m31a-dev,--features development).
Channel is compile-time artifact identity — no runtime environment switch
can re-channel a binary. - New
src/deployment/subsystem:DeploymentChannel/UpdateChannel,
immutableDeploymentContext(version, build ID, commit, branch, timestamp,
target, dirty, artifact ID),ReleaseArtifactmodel, versioned
DeploymentManifest(schema v1, shared by both channels), transactional
Installer(stage → verify → atomic replace, previous binary preserved),
channel-safe update discovery,rollbackseam, centralizedFeatureGate
for development-only affordances, andDeploymentPathsisolation. - CLI:
m31a version [--verbose],m31a deployment [--verbose],
m31a update --manifest <file> [--check],m31a rollback;
channel-awarem31a --version(m31a X.Y.Zvsm31a-dev X.Y.Z-dev+<build>);
m31a doctorincludes a deployment probe;m31a config sourcesreports
channel and config source. - Cockpit header shows an unobtrusive
vX.Y.Z PRODUCTION/
vX.Y.Z DEVELOPMENT · build <short>label at all terminal widths. - Release tooling:
scripts/build-release.sh --channel, channel-aware
packaging/identity validation/deployment manifest, dirty-tree refusal for
production; newscripts/install-local.shfor user-local installs. - CI: new development pipeline (
.github/workflows/development.yml;
nightly/branch builds, 7-day artifact retention, never publishes releases);
production pipeline gated on clean source, version==tag, and identity checks.
Changed
PlatformPathsand persistence paths are channel-aware: development uses
isolatedm31a-devglobal state; production paths are unchanged
(backward compatible). Project-local.m31a/stays shared with
deployment-scoped runtime state (m31a.dbvsm31a-dev.db,
.m31a/state/<channel>/, per-channel sockets/PIDs/credentials).- Production promotion reuses the existing release-candidate state machine
with explicit dirty/blocker/approval gates (deployment::evaluate_promotion).
Security
- Both channels enforce identical policy, sandbox, capability, approval,
containment, and secret controls. Development diagnostics can never bypass
security gates. Production rejects development artifacts on the normal
update path; updates verify SHA-256 before replacing any binary.