v1.0.0-alpha.2
Pre-release
Pre-release
ainfra v1.0.0-alpha.2
This alpha release completes the Phase 2 local contracts-and-doctor slice. It
adds deterministic discovery and configuration, strict deployment and local
template validation, stable doctor diagnostics, minimal initialization, and
guarded local reconciliation.
Highlights
ainfra doctorsupports environment, deployment, template, retained-run,
and aggregate scopes with stable text and JSON results.- Deployment and template contracts reject unknown fields, traversal,
symlinks, special files, inline secrets, and prohibited runtime state. - Local reconciliation is plan-first, lock-protected, explicitly approved,
precondition-checked, contained, and followed by verification. ainfra initcreates only the minimal ainfra-owned deployment contract and
an idempotent.gitignoreblock.- Offline black-box, race, fuzz, schema, security, vulnerability, and
cross-platform validation cover the Phase 2 boundary.
This release deliberately does not acquire or lock template sources, execute
OpenTofu or Ansible lifecycle operations, or expose MCP mode. Those capabilities
remain assigned to later roadmap phases.
Verify the download
Download the platform archive, checksums.sha256, and
checksums.sha256.sigstore.json, then run:
sha256sum --check --ignore-missing checksums.sha256
cosign verify-blob checksums.sha256 \
--bundle checksums.sha256.sigstore.json \
--certificate-identity 'info@projectious.work' \
--certificate-oidc-issuer 'https://github.com/login/oauth'On macOS, use shasum -a 256 -c checksums.sha256 if sha256sum is not
installed.
See the
curated changelog
for the complete change summary.