Releases: projectious-work/ainfra
Release list
v1.0.0-alpha.9
ainfra v1.0.0-alpha.9
This alpha release completes Phase 9 with a live-certified, provider-backed
Hetzner private K3s baseline.
Highlights
- Provisions a private Hetzner network and an odd-sized K3s control plane with
optional workers and no public administrative dependency after bootstrap. - Uses pinned OpenTofu, Ansible, K3s, and Cloudflare Tunnel boundaries while
keeping credentials out of plans, standardized output, and retained logs. - Bootstraps the first K3s server before joining the remaining nodes, uses
non-overlapping pod and service CIDRs, and binds node identities to their
private addresses. - Supports a source-restricted temporary bastion that can be removed after
Cloudflare Service Auth tunnel-only SSH is verified. - Passes immutable no-op planning, exact-host Ansible check mode, bastion
removal, post-removal cluster health, exact destruction, and independent
provider-side leak detection.
Roadmap
The next contract phase will evolve the single standardized infrastructure
result with a closed, non-secret consumer-target projection and optional signed
deployment provenance. It keeps symbolic credential and trust references
unresolved and does not treat discovery or a signed deployment claim as proof
of current live infrastructure state. Confidential-computing and live
attestation work remains a separate later phase.
Security boundary
The baseline disables root and password SSH, requires operator-supplied keys
and independently verified host keys, and accepts the Cloudflare connector
token only through protected Ansible input. Its local OpenTofu backend is for
disposable certification; production operators must lock a derivative with a
capability-tested encrypted remote backend.
The live test used explicitly approved, time-bounded Hetzner resources. All
resources were destroyed, and independent API queries confirmed that no test
servers, networks, firewalls, placement groups, or SSH keys remained.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.8
ainfra v1.0.0-alpha.8
This alpha release completes Phase 8's template-authoring and conformance
contract for infrastructure engineers and AI coding agents.
Highlights
ainfra doctor templatechecks the portable authoring layout, standard
variable reference, lifecycle documentation, and applicable output fixture.- Conformance failures produce typed diagnostics and a non-zero dependency
exit code. - Native OpenTofu and Ansible validation remains engine-owned and is explicitly
delegated to each template's clean-room validation script. - The human guide and self-contained AI entry point cover manifests, native
variables, dependencies, standardized output, security, validation, live
acceptance, teardown, and sanitized evidence. - A second provider-free template proves clean-room authoring with a complete
local OpenTofu plan, apply, destroy-plan, and destroy lifecycle. - Inventory-free templates remain conforming without artificial output files
or output fixtures.
Security boundary
The authoring doctor reads only beneath the validated template root and does
not inspect provider credentials, backends, connectivity, topology, DNS, hosts,
or application health. A local conformance pass does not authorize a billable
lifecycle or prove provider support.
Live support requires explicit approval for the provider account, region, cost
ceiling, and teardown window, followed by disposable lifecycle evidence and
independent provider-side teardown confirmation.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.7
ainfra v1.0.0-alpha.7
This alpha release completes Phase 7's guarded Model Context Protocol server
mode for MCP-capable agents and editors.
Highlights
ainfra mcp serve --stdiofixes one canonical project root for the lifetime
of the server and keeps protocol frames isolated on stdout.- The default registry is read-only: diagnostics, status, sanitized retained
output and inventory, and bundled v1 contract resources. - Saved plan creation is available only through the explicit
planning
capability group. - Apply, configure, convergence check, deploy, reconciliation, template lock,
and migration execution require thedeploymentcapability plus an
independently issued, operation-bound approval artifact. - Destroy additionally requires the separate
destructioncapability and a
destroy-intent approval. - Ed25519-signed approval artifacts bind the canonical root, operation, plan
ID and digest, intent, caller, independent issuer, and validity window.
ainfra exposes no signing path. - Lifecycle handlers reuse the same typed application use cases as the CLI,
retaining exact-plan checks, locks, evidence, cancellation, and ambiguous
state recovery. - MCP frames are limited to 4 MiB and tool/resource execution is capped at
eight concurrent requests.
Security boundary
Capability enablement makes a tool discoverable but never authorizes a
mutation. Requests cannot override the fixed root, configuration path,
executables, environment, caches, run storage, or logging destinations. Raw
engine streams are not exposed through MCP.
Compiled-binary tests cover capability separation, missing authorization,
stale and self-issued approvals, binding mismatches, malformed and oversized
frames, unknown tools, concurrency, cancellation, stdout purity, and clean
shutdown.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.6
ainfra v1.0.0-alpha.6
This alpha release completes Phase 6's destructive lifecycle, interruption
recovery, retained-evidence browsing, operational logging, and security
hardening boundaries.
Highlights
ainfra plan --destroycreates a separately bound destroy-intent plan;
ainfra destroy --plan RUN_IDapplies only those exact reviewed bytes.- Apply and destroy record durable started and terminal events. Ambiguous
interruption records inspection-required evidence and prohibits automatic
retry. ainfra statusderives lifecycle and recovery guidance solely from retained
ainfra records without reading or interpreting OpenTofu state.ainfra logsprovides combined chronological ainfra and Ansible Runner
evidence, typed error filtering, and explicit source selection.- Guarded raw child-stream access requires a child source, exact stream, and
interactive confirmation or both non-interactive approval flags. - Operational logging supports
-vthrough-vvv, explicit levels, text or
JSON sinks, private rotating files, and local syslog independently of command
output format. - Exact secrets and common credential shapes are redacted before sinks;
concurrent structured records retain their run correlation. - Template cache consumers reverify content, owner-only permissions, and
immutable plan bindings before mutation. Retained evidence rejects public,
special, replaced, and symlinked files. - Certified templates must document an authenticated provider-side teardown
query. A successful OpenTofu destroy exit is not independent cleanup proof.
Recovery boundary
An interrupted mutation is intentionally not resumable by repeating the
command. Preserve the private run directory, inspect it with ainfra status,
ainfra logs, and ainfra doctor run, then use provider-native read-only
inspection before deciding whether a new reviewed plan is safe.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.5
ainfra v1.0.0-alpha.5
This alpha release completes Phase 5's reviewed infrastructure-to-
configuration handoff. It collects one declared non-sensitive OpenTofu output,
derives deterministic Ansible inventory, runs the declared native playbook,
and independently verifies exact-host zero-change convergence.
Highlights
ainfra output --run RUN_IDextracts only the manifest-declared OpenTofu
output, refuses sensitive or invalid values, and publishes private atomic
output.jsonevidence.ainfra inventory --run RUN_IDstrictly validates the closed v1 handoff and
generates stable, sortedinventory.yamlwithout reading provider state.ainfra configure --run RUN_IDinvokes Ansible Runner without a shell and
preserves the declared order and opaque bytes of native variable files.ainfra configure --run RUN_ID --checkrequires Runner evidence for the
exact expected hosts with zero changed, failed, or unreachable outcomes.ainfra deploy --plan RUN_IDcomposes reviewed apply, output, inventory,
configure, and verification without creating an implicit plan.- Infrastructure-only deployments report all skipped post-apply stages as
typednot-applicableresults and do not require Ansible Runner. - SSH configuration forces host-key checking and requires a populated
known_hostsfile whose bytes were bound into the reviewed plan. - Adversarial coverage refuses secret-shaped output, unsafe connections,
changed bindings, replayed configuration, corrupt or symlinked Runner
evidence, duplicate terminal summaries, and concurrent mutations.
Destruction, teardown verification, consolidated retained-run browsing, and
broader interruption recovery remain planned for Phase 6.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.4
ainfra v1.0.0-alpha.4
This alpha release completes Phase 4's reviewed OpenTofu plan boundary. It
creates immutable saved plans from locked templates, binds every relevant
input and executable identity, and applies only the exact plan the operator
reviewed.
Highlights
ainfra plancreates a collision-resistant private run, snapshots native
backend and variable inputs, and publishes a sanitized structural summary.- Plan records bind deployment and template content, ordered inputs, OpenTofu
executable bytes and version, and the final saved-plan digest. ainfra apply --plan RUN_IDacquires the deployment operation lock and
immediately reverifies every immutable binding before execution.- Apply invokes only the reviewed
plan.tfplan; stale, changed, replayed, or
destroy-intent plans fail before OpenTofu can mutate infrastructure. - Durable evidence distinguishes started, succeeded, failed, cancelled, and
inspection-required outcomes. Ambiguous interruption disables automatic
retry and directs the operator to retained evidence. - Stable text and v1 JSON results expose plan intent, digests, engine status,
evidence, recovery state, and exact next commands without persisting raw
plan values in the structural summary. - Compiled black-box coverage verifies the complete lock-plan-apply boundary,
tampering refusal, and concurrent apply serialization.
Destroy execution, standardized output and inventory, Ansible configuration,
and MCP mode are not part of this release. Phase 5 will derive standardized
non-secret output and deterministic inventory before adding Ansible execution.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.3
ainfra v1.0.0-alpha.3
This alpha release completes Phase 3's immutable template-source boundary. It
resolves local and Git-subdirectory sources, records immutable identities and
tree digests, materializes verified private cache entries, and diagnoses lock,
source, digest, or cache drift.
Highlights
ainfra template lockcreates a canonical source binding and
ainfra template updateexplicitly replaces a changed binding.- Git acquisition uses argument arrays, private staging, immutable commit
resolution, and sanitized diagnostics without shell evaluation. - Local and Git content share a normative SHA-256 tree digest and a contained,
digest-addressed cache that verifies every hit. - Deployment and aggregate doctor scopes verify lock structure, source
binding, cache safety, digest equality, and local source drift. - Trusted configuration can select cache and Git paths, while
repository-controlled trust redirection fails closed. - Credentials are available only to ephemeral Git acquisition and are redacted
from lockfiles, recorded invocations, diagnostics, and machine output.
OpenTofu planning and apply, Ansible execution, destruction, and MCP mode are
not part of this release. Phase 4 will bind reviewed saved OpenTofu plans to
the immutable template content established here.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.2
ainfra v1.0.0-alpha.2
This alpha release completes the Phase 2 local contracts-and-doctor slice. It
adds deterministic discovery and configuration, strict deployment and local
template validation, stable doctor diagnostics, minimal initialization, and
guarded local reconciliation.
Highlights
ainfra doctorsupports environment, deployment, template, retained-run,
and aggregate scopes with stable text and JSON results.- Deployment and template contracts reject unknown fields, traversal,
symlinks, special files, inline secrets, and prohibited runtime state. - Local reconciliation is plan-first, lock-protected, explicitly approved,
precondition-checked, contained, and followed by verification. ainfra initcreates only the minimal ainfra-owned deployment contract and
an idempotent.gitignoreblock.- Offline black-box, race, fuzz, schema, security, vulnerability, and
cross-platform validation cover the Phase 2 boundary.
This release deliberately does not acquire or lock template sources, execute
OpenTofu or Ansible lifecycle operations, or expose MCP mode. Those capabilities
remain assigned to later roadmap phases.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v1.0.0-alpha.1
ainfra v1.0.0-alpha.1
This alpha release delivers the Phase 1 foundation of ainfra v1: the Go CLI,
normative contracts, guarded lifecycle behavior, release-quality validation,
and cross-platform packaging.
Highlights
- Linux and macOS binaries for amd64 and arm64.
- Versioned JSON result contracts and offline schema validation.
- Guarded planning, execution, and MCP server lifecycle foundations.
- SPDX JSON SBOM for every platform archive.
- SHA-256 checksum manifest signed keylessly with Sigstore as
info@projectious.workthrough GitHub OIDC. - Owner-reviewed Docker build/runtime, hardening, SBOM, vulnerability-scan,
and cleanup evidence.
This is an alpha release. Interfaces covered by the published v1 contracts are
stable within the documented compatibility policy; broader provider and
template capabilities remain roadmap work.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.
v0.1.0
What's Changed
- feat: complete security gates and live Hetzner verification by @projectious in #2
- docs: add branded Hugo and Docsy site by @projectious in #3
- chore: reconcile project state by @projectious in #4
- docs: adopt v0 branching strategy by @projectious in #5
- docs: promote Hugo versioning to release by @projectious in #8
- docs: promote consolidated documentation to release by @projectious in #13
- docs: promote Hetzner How-to to release by @projectious in #17
- chore: promote issue 19 milestone to release by @projectious in #22
- chore: promote v0.1.0 candidate to release by @projectious in #27
- fix: prepare v0.1.0 release metadata by @projectious in #28
Full Changelog: https://github.com/projectious-work/ainfra/commits/v0.1.0