Skip to content

Releases: projectious-work/ainfra

v1.0.0-alpha.9

v1.0.0-alpha.9 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 22 Aug 19:44

ainfra v1.0.0-alpha.9

This alpha release completes Phase 9 with a live-certified, provider-backed
Hetzner private K3s baseline.

Highlights

  • Provisions a private Hetzner network and an odd-sized K3s control plane with
    optional workers and no public administrative dependency after bootstrap.
  • Uses pinned OpenTofu, Ansible, K3s, and Cloudflare Tunnel boundaries while
    keeping credentials out of plans, standardized output, and retained logs.
  • Bootstraps the first K3s server before joining the remaining nodes, uses
    non-overlapping pod and service CIDRs, and binds node identities to their
    private addresses.
  • Supports a source-restricted temporary bastion that can be removed after
    Cloudflare Service Auth tunnel-only SSH is verified.
  • Passes immutable no-op planning, exact-host Ansible check mode, bastion
    removal, post-removal cluster health, exact destruction, and independent
    provider-side leak detection.

Roadmap

The next contract phase will evolve the single standardized infrastructure
result with a closed, non-secret consumer-target projection and optional signed
deployment provenance. It keeps symbolic credential and trust references
unresolved and does not treat discovery or a signed deployment claim as proof
of current live infrastructure state. Confidential-computing and live
attestation work remains a separate later phase.

Security boundary

The baseline disables root and password SSH, requires operator-supplied keys
and independently verified host keys, and accepts the Cloudflare connector
token only through protected Ansible input. Its local OpenTofu backend is for
disposable certification; production operators must lock a derivative with a
capability-tested encrypted remote backend.

The live test used explicitly approved, time-bounded Hetzner resources. All
resources were destroyed, and independent API queries confirmed that no test
servers, networks, firewalls, placement groups, or SSH keys remained.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.8

v1.0.0-alpha.8 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 20 Aug 17:20

ainfra v1.0.0-alpha.8

This alpha release completes Phase 8's template-authoring and conformance
contract for infrastructure engineers and AI coding agents.

Highlights

  • ainfra doctor template checks the portable authoring layout, standard
    variable reference, lifecycle documentation, and applicable output fixture.
  • Conformance failures produce typed diagnostics and a non-zero dependency
    exit code.
  • Native OpenTofu and Ansible validation remains engine-owned and is explicitly
    delegated to each template's clean-room validation script.
  • The human guide and self-contained AI entry point cover manifests, native
    variables, dependencies, standardized output, security, validation, live
    acceptance, teardown, and sanitized evidence.
  • A second provider-free template proves clean-room authoring with a complete
    local OpenTofu plan, apply, destroy-plan, and destroy lifecycle.
  • Inventory-free templates remain conforming without artificial output files
    or output fixtures.

Security boundary

The authoring doctor reads only beneath the validated template root and does
not inspect provider credentials, backends, connectivity, topology, DNS, hosts,
or application health. A local conformance pass does not authorize a billable
lifecycle or prove provider support.

Live support requires explicit approval for the provider account, region, cost
ceiling, and teardown window, followed by disposable lifecycle evidence and
independent provider-side teardown confirmation.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.7

v1.0.0-alpha.7 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 17 Aug 13:54
097f294

ainfra v1.0.0-alpha.7

This alpha release completes Phase 7's guarded Model Context Protocol server
mode for MCP-capable agents and editors.

Highlights

  • ainfra mcp serve --stdio fixes one canonical project root for the lifetime
    of the server and keeps protocol frames isolated on stdout.
  • The default registry is read-only: diagnostics, status, sanitized retained
    output and inventory, and bundled v1 contract resources.
  • Saved plan creation is available only through the explicit planning
    capability group.
  • Apply, configure, convergence check, deploy, reconciliation, template lock,
    and migration execution require the deployment capability plus an
    independently issued, operation-bound approval artifact.
  • Destroy additionally requires the separate destruction capability and a
    destroy-intent approval.
  • Ed25519-signed approval artifacts bind the canonical root, operation, plan
    ID and digest, intent, caller, independent issuer, and validity window.
    ainfra exposes no signing path.
  • Lifecycle handlers reuse the same typed application use cases as the CLI,
    retaining exact-plan checks, locks, evidence, cancellation, and ambiguous
    state recovery.
  • MCP frames are limited to 4 MiB and tool/resource execution is capped at
    eight concurrent requests.

Security boundary

Capability enablement makes a tool discoverable but never authorizes a
mutation. Requests cannot override the fixed root, configuration path,
executables, environment, caches, run storage, or logging destinations. Raw
engine streams are not exposed through MCP.

Compiled-binary tests cover capability separation, missing authorization,
stale and self-issued approvals, binding mismatches, malformed and oversized
frames, unknown tools, concurrency, cancellation, stdout purity, and clean
shutdown.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.6

v1.0.0-alpha.6 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 15 Aug 20:52
62a35fb

ainfra v1.0.0-alpha.6

This alpha release completes Phase 6's destructive lifecycle, interruption
recovery, retained-evidence browsing, operational logging, and security
hardening boundaries.

Highlights

  • ainfra plan --destroy creates a separately bound destroy-intent plan;
    ainfra destroy --plan RUN_ID applies only those exact reviewed bytes.
  • Apply and destroy record durable started and terminal events. Ambiguous
    interruption records inspection-required evidence and prohibits automatic
    retry.
  • ainfra status derives lifecycle and recovery guidance solely from retained
    ainfra records without reading or interpreting OpenTofu state.
  • ainfra logs provides combined chronological ainfra and Ansible Runner
    evidence, typed error filtering, and explicit source selection.
  • Guarded raw child-stream access requires a child source, exact stream, and
    interactive confirmation or both non-interactive approval flags.
  • Operational logging supports -v through -vvv, explicit levels, text or
    JSON sinks, private rotating files, and local syslog independently of command
    output format.
  • Exact secrets and common credential shapes are redacted before sinks;
    concurrent structured records retain their run correlation.
  • Template cache consumers reverify content, owner-only permissions, and
    immutable plan bindings before mutation. Retained evidence rejects public,
    special, replaced, and symlinked files.
  • Certified templates must document an authenticated provider-side teardown
    query. A successful OpenTofu destroy exit is not independent cleanup proof.

Recovery boundary

An interrupted mutation is intentionally not resumable by repeating the
command. Preserve the private run directory, inspect it with ainfra status,
ainfra logs, and ainfra doctor run, then use provider-native read-only
inspection before deciding whether a new reviewed plan is safe.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.5

v1.0.0-alpha.5 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 14 Aug 14:51
7bf9447

ainfra v1.0.0-alpha.5

This alpha release completes Phase 5's reviewed infrastructure-to-
configuration handoff. It collects one declared non-sensitive OpenTofu output,
derives deterministic Ansible inventory, runs the declared native playbook,
and independently verifies exact-host zero-change convergence.

Highlights

  • ainfra output --run RUN_ID extracts only the manifest-declared OpenTofu
    output, refuses sensitive or invalid values, and publishes private atomic
    output.json evidence.
  • ainfra inventory --run RUN_ID strictly validates the closed v1 handoff and
    generates stable, sorted inventory.yaml without reading provider state.
  • ainfra configure --run RUN_ID invokes Ansible Runner without a shell and
    preserves the declared order and opaque bytes of native variable files.
  • ainfra configure --run RUN_ID --check requires Runner evidence for the
    exact expected hosts with zero changed, failed, or unreachable outcomes.
  • ainfra deploy --plan RUN_ID composes reviewed apply, output, inventory,
    configure, and verification without creating an implicit plan.
  • Infrastructure-only deployments report all skipped post-apply stages as
    typed not-applicable results and do not require Ansible Runner.
  • SSH configuration forces host-key checking and requires a populated
    known_hosts file whose bytes were bound into the reviewed plan.
  • Adversarial coverage refuses secret-shaped output, unsafe connections,
    changed bindings, replayed configuration, corrupt or symlinked Runner
    evidence, duplicate terminal summaries, and concurrent mutations.

Destruction, teardown verification, consolidated retained-run browsing, and
broader interruption recovery remain planned for Phase 6.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.4

v1.0.0-alpha.4 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 14 Aug 10:12

ainfra v1.0.0-alpha.4

This alpha release completes Phase 4's reviewed OpenTofu plan boundary. It
creates immutable saved plans from locked templates, binds every relevant
input and executable identity, and applies only the exact plan the operator
reviewed.

Highlights

  • ainfra plan creates a collision-resistant private run, snapshots native
    backend and variable inputs, and publishes a sanitized structural summary.
  • Plan records bind deployment and template content, ordered inputs, OpenTofu
    executable bytes and version, and the final saved-plan digest.
  • ainfra apply --plan RUN_ID acquires the deployment operation lock and
    immediately reverifies every immutable binding before execution.
  • Apply invokes only the reviewed plan.tfplan; stale, changed, replayed, or
    destroy-intent plans fail before OpenTofu can mutate infrastructure.
  • Durable evidence distinguishes started, succeeded, failed, cancelled, and
    inspection-required outcomes. Ambiguous interruption disables automatic
    retry and directs the operator to retained evidence.
  • Stable text and v1 JSON results expose plan intent, digests, engine status,
    evidence, recovery state, and exact next commands without persisting raw
    plan values in the structural summary.
  • Compiled black-box coverage verifies the complete lock-plan-apply boundary,
    tampering refusal, and concurrent apply serialization.

Destroy execution, standardized output and inventory, Ansible configuration,
and MCP mode are not part of this release. Phase 5 will derive standardized
non-secret output and deterministic inventory before adding Ansible execution.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.3

v1.0.0-alpha.3 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 13 Aug 17:36

ainfra v1.0.0-alpha.3

This alpha release completes Phase 3's immutable template-source boundary. It
resolves local and Git-subdirectory sources, records immutable identities and
tree digests, materializes verified private cache entries, and diagnoses lock,
source, digest, or cache drift.

Highlights

  • ainfra template lock creates a canonical source binding and
    ainfra template update explicitly replaces a changed binding.
  • Git acquisition uses argument arrays, private staging, immutable commit
    resolution, and sanitized diagnostics without shell evaluation.
  • Local and Git content share a normative SHA-256 tree digest and a contained,
    digest-addressed cache that verifies every hit.
  • Deployment and aggregate doctor scopes verify lock structure, source
    binding, cache safety, digest equality, and local source drift.
  • Trusted configuration can select cache and Git paths, while
    repository-controlled trust redirection fails closed.
  • Credentials are available only to ephemeral Git acquisition and are redacted
    from lockfiles, recorded invocations, diagnostics, and machine output.

OpenTofu planning and apply, Ansible execution, destruction, and MCP mode are
not part of this release. Phase 4 will bind reviewed saved OpenTofu plans to
the immutable template content established here.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.2

v1.0.0-alpha.2 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 13 Aug 10:49
34eab1a

ainfra v1.0.0-alpha.2

This alpha release completes the Phase 2 local contracts-and-doctor slice. It
adds deterministic discovery and configuration, strict deployment and local
template validation, stable doctor diagnostics, minimal initialization, and
guarded local reconciliation.

Highlights

  • ainfra doctor supports environment, deployment, template, retained-run,
    and aggregate scopes with stable text and JSON results.
  • Deployment and template contracts reject unknown fields, traversal,
    symlinks, special files, inline secrets, and prohibited runtime state.
  • Local reconciliation is plan-first, lock-protected, explicitly approved,
    precondition-checked, contained, and followed by verification.
  • ainfra init creates only the minimal ainfra-owned deployment contract and
    an idempotent .gitignore block.
  • Offline black-box, race, fuzz, schema, security, vulnerability, and
    cross-platform validation cover the Phase 2 boundary.

This release deliberately does not acquire or lock template sources, execute
OpenTofu or Ansible lifecycle operations, or expose MCP mode. Those capabilities
remain assigned to later roadmap phases.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v1.0.0-alpha.1

v1.0.0-alpha.1 Pre-release
Pre-release

Choose a tag to compare

@projectious projectious released this 12 Aug 07:39

ainfra v1.0.0-alpha.1

This alpha release delivers the Phase 1 foundation of ainfra v1: the Go CLI,
normative contracts, guarded lifecycle behavior, release-quality validation,
and cross-platform packaging.

Highlights

  • Linux and macOS binaries for amd64 and arm64.
  • Versioned JSON result contracts and offline schema validation.
  • Guarded planning, execution, and MCP server lifecycle foundations.
  • SPDX JSON SBOM for every platform archive.
  • SHA-256 checksum manifest signed keylessly with Sigstore as
    info@projectious.work through GitHub OIDC.
  • Owner-reviewed Docker build/runtime, hardening, SBOM, vulnerability-scan,
    and cleanup evidence.

This is an alpha release. Interfaces covered by the published v1 contracts are
stable within the documented compatibility policy; broader provider and
template capabilities remain roadmap work.

Verify the download

Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:

sha256sum --check --ignore-missing checksums.sha256

cosign verify-blob checksums.sha256 \
  --bundle checksums.sha256.sigstore.json \
  --certificate-identity 'info@projectious.work' \
  --certificate-oidc-issuer 'https://github.com/login/oauth'

On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.

See the
curated changelog
for the complete change summary.

v0.1.0

Choose a tag to compare

@projectious projectious released this 28 Jul 21:01
9f90698

What's Changed

Full Changelog: https://github.com/projectious-work/ainfra/commits/v0.1.0