Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
e3b313a
[minor] Add off-host backup and restore proof
libops-agent Aug 8, 2026
2361abf
[patch] Restore required DigitalOcean ISLE smoke
libops-agent Aug 8, 2026
67bc19a
[patch] Allow ISLE bootstrap to complete in smoke
joecorall Aug 8, 2026
909d6b4
[patch] Make provisioning readiness observable
joecorall Aug 8, 2026
df8868e
[patch] Promote first-customer application releases
joecorall Aug 8, 2026
d737965
[patch] Align config management release fixtures
joecorall Aug 8, 2026
6137153
[patch] Check in config management assertions
joecorall Aug 8, 2026
8591a50
[minor] Harden first-customer runtime recovery
joecorall Aug 8, 2026
b2057cf
[patch] Satisfy runtime shell lint
joecorall Aug 8, 2026
89f395b
[patch] Align Vault launcher contract
joecorall Aug 8, 2026
f0744ef
[patch] Make Salt rollout prerequisites explicit
joecorall Aug 8, 2026
fe03f10
[patch] Validate checked-in recovery programs
joecorall Aug 8, 2026
5e33a74
[patch] Cover checked-in backup manifest program
joecorall Aug 8, 2026
62896ba
[patch] Normalize rootfs archive ownership
joecorall Aug 8, 2026
38b8862
[patch] Support COS writable runtime paths
joecorall Aug 8, 2026
c6984fd
[patch] Use valid GCP contract name
joecorall Aug 8, 2026
b5a9f67
[patch] Normalize trusted bootstrap files
joecorall Aug 8, 2026
1025545
[patch] Apply shared bootstrap hardening to adapters
joecorall Aug 8, 2026
f6dc2f4
[patch] Assert root-owned cloud-init overlays
joecorall Aug 8, 2026
15a9275
[patch] Assert root-owned portable overlays
joecorall Aug 8, 2026
1712f2c
[patch] Preserve empty managed artifact manifest
joecorall Aug 8, 2026
d2e0f62
[patch] Restore noninteractive host bootstrap
joecorall Aug 9, 2026
c83bb6c
[patch] Discover secrets in Compose Specification files
joecorall Aug 9, 2026
15c52fd
[patch] Invoke Compose secret parser from file
joecorall Aug 9, 2026
8aad96d
[minor] Harden first-customer provisioning runtime
libops-agent Aug 9, 2026
91daa24
[patch] Surface configuration smoke failures
libops-agent Aug 9, 2026
3dee4a6
[patch] Repair hosted contract expectations
libops-agent Aug 9, 2026
5badc2f
[patch] Cover both rootfs archive trust paths
libops-agent Aug 9, 2026
f956455
[patch] Exercise checked lifecycle executor in CI
libops-agent Aug 9, 2026
7bce652
[patch] Use checked lifecycle fixture in CI
libops-agent Aug 9, 2026
7adeeaf
[patch] Invoke lifecycle fixture with Bash
libops-agent Aug 9, 2026
d094455
[patch] Reuse checked executor fixture in contracts
libops-agent Aug 9, 2026
166df9b
[patch] Refresh hosted smoke contracts
libops-agent Aug 9, 2026
df3a69c
[patch] Keep template tests offline
libops-agent Aug 9, 2026
e8bc5cc
[patch] Isolate provider tests from release network
libops-agent Aug 9, 2026
8bdc89a
[patch] Keep DigitalOcean tests in archive mode
libops-agent Aug 9, 2026
cbf6656
[patch] Make the GCP archive contract test hermetic
libops-agent Aug 9, 2026
01daec8
[patch] Correct the rootfs release sidecar contract
libops-agent Aug 9, 2026
770edcc
[patch] Scope the GCP bootstrap order contract
libops-agent Aug 9, 2026
aea3600
[patch] Exercise Linode contracts in archive mode
libops-agent Aug 9, 2026
216a15d
[patch] Refresh rootfs contract fixture
libops-agent Aug 9, 2026
d9d6f31
[patch] Keep provider contracts in archive mode
libops-agent Aug 9, 2026
54bb577
[patch] Override nested provider contract data
libops-agent Aug 9, 2026
73a12f6
[patch] Keep Linode provider contracts in archive mode
joecorall Aug 9, 2026
2eca1e5
[patch] Promote hardened compose templates
joecorall Aug 9, 2026
54cb265
[patch] Align promoted template contracts
joecorall Aug 9, 2026
6300d66
[patch] Align Salt template contract
joecorall Aug 9, 2026
9f354dd
[patch] Align Drupal Salt contract
joecorall Aug 9, 2026
1803186
[patch] Initialize default component state
joecorall Aug 9, 2026
3294224
[patch] Refresh rootfs contract fixtures
joecorall Aug 9, 2026
274f255
[patch] Fence managed Compose reconciliation
joecorall Aug 9, 2026
41aaa8c
[patch] Repin rootfs contract fixtures
joecorall Aug 9, 2026
ed1e716
[patch] Make GCP smoke zone selectable
joecorall Aug 9, 2026
fadd0ab
[patch] Isolate fresh GCP smoke location
joecorall Aug 9, 2026
908b8be
[patch] Run built-in lifecycle on noexec hosts
libops-agent Aug 9, 2026
1b1872b
[patch] Repin lifecycle rootfs contract fixtures
libops-agent Aug 9, 2026
2698a12
[patch] Use executable Compose plugin for diagnostics
libops-agent Aug 9, 2026
4627b00
[patch] Repin diagnostic rootfs contract fixtures
libops-agent Aug 9, 2026
bf363ce
[patch] Stage hosted contracts on executable disk
libops-agent Aug 9, 2026
e627c1c
[patch] Avoid noexec lifecycle contract preflight
libops-agent Aug 9, 2026
e4e7372
[patch] Pin final sitectl release catalog
libops-agent Aug 9, 2026
94aba41
[patch] Align release catalog contract fixtures
libops-agent Aug 9, 2026
9a3c8f6
[patch] Align inherited config catalog assertions
libops-agent Aug 9, 2026
52f1e22
[patch] Pin sitectl ownership fix release
libops-agent Aug 9, 2026
9e296bc
[patch] Invoke reviewed runtime programs by path
joecorall Aug 9, 2026
7357502
[patch] Follow checked key validation program
joecorall Aug 9, 2026
9e4d05c
[patch] Preserve GCP bootstrap metadata headroom
joecorall Aug 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 17 additions & 1 deletion .github/workflows/cloud-smoke-cleanup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,12 @@ jobs:
fail-fast: false
matrix:
include:
- name: DigitalOcean ISLE
kind: app
provider: digitalocean
template: isle
environment: cloud-smoke-cleanup-digitalocean
concurrency_group: cloud-compose-smoke-digitalocean-isle
- name: DigitalOcean WordPress
kind: app
provider: digitalocean
Expand Down Expand Up @@ -93,7 +99,10 @@ jobs:
CLOUD_COMPOSE_SMOKE_RUN_ID: ${{ github.event.workflow_run.id }}
GCLOUD_OIDC_POOL: ${{ vars.GCLOUD_OIDC_POOL || secrets.GCLOUD_OIDC_POOL }}
GCLOUD_PROJECT: ${{ vars.GCLOUD_PROJECT || secrets.GCLOUD_PROJECT }}
GCLOUD_FRESH_REGION: ${{ vars.GCLOUD_FRESH_REGION || secrets.GCLOUD_FRESH_REGION }}
GCLOUD_FRESH_ZONE: ${{ vars.GCLOUD_FRESH_ZONE || secrets.GCLOUD_FRESH_ZONE }}
GCLOUD_REGION: ${{ vars.GCLOUD_REGION || secrets.GCLOUD_REGION }}
GCLOUD_ZONE: ${{ vars.GCLOUD_ZONE || secrets.GCLOUD_ZONE }}
GSA: ${{ vars.GSA || secrets.GSA }}
steps:
- name: Checkout repository
Expand Down Expand Up @@ -127,5 +136,12 @@ jobs:
- name: Install gcloud
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db # v3

- name: Sweep GCP smoke resources
- name: Sweep GCP upgrade-region resources
run: ci/cloud-smoke.sh sweep-gcp-wp

- name: Sweep GCP fresh-smoke region
if: ${{ env.GCLOUD_FRESH_REGION != '' && env.GCLOUD_FRESH_REGION != env.GCLOUD_REGION }}
env:
GCLOUD_REGION: ${{ env.GCLOUD_FRESH_REGION }}
GCLOUD_ZONE: ${{ env.GCLOUD_FRESH_ZONE }}
run: ci/cloud-smoke.sh sweep-gcp-wp
28 changes: 25 additions & 3 deletions .github/workflows/cloud-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,9 @@ jobs:
cancel-in-progress: false
env:
CLOUD_COMPOSE_SMOKE_AUTO_APPROVE: "true"
CLOUD_COMPOSE_SMOKE_DESTROY_TIMEOUT: "1800"
CLOUD_COMPOSE_SMOKE_BOOT_TIMEOUT: "900"
CLOUD_COMPOSE_SMOKE_CONFIG_MANAGEMENT_TIMEOUT: "2400"
CLOUD_COMPOSE_SMOKE_DESTROY_TIMEOUT: "900"
CLOUD_COMPOSE_SMOKE_SWEEP_ORPHANS: "true"
CLOUD_COMPOSE_SMOKE_RUN_ID: ${{ github.run_id }}
steps:
Expand All @@ -103,12 +105,14 @@ jobs:
terraform_wrapper: false

- name: Run Linode config-management smoke test
timeout-minutes: 100
env:
LINODE_TOKEN: ${{ secrets.LINODE_TOKEN }}
run: make config-management-cloud-smoke METHOD=${{ matrix.method }}

- name: Destroy Linode config-management smoke resources
if: always()
timeout-minutes: 20
env:
LINODE_TOKEN: ${{ secrets.LINODE_TOKEN }}
run: ci/config-management-cloud-smoke.sh destroy-${{ matrix.method }}-drupal
Expand All @@ -126,21 +130,30 @@ jobs:
fail-fast: false
matrix:
include:
- name: DigitalOcean ISLE
provider: digitalocean
template: isle
# Exceed the 90-minute application service ceiling with enough
# room to observe the terminal unit state before cleanup.
boot_timeout: "6000"
- name: DigitalOcean WordPress
provider: digitalocean
template: wp
boot_timeout: "1200"
- name: Linode WordPress
provider: linode
template: wp
boot_timeout: "1200"
concurrency:
group: cloud-compose-smoke-${{ matrix.provider }}-${{ matrix.template }}
cancel-in-progress: false
env:
CLOUD_COMPOSE_SMOKE_AUTO_APPROVE: "true"
CLOUD_COMPOSE_SMOKE_BOOT_TIMEOUT: ${{ matrix.boot_timeout }}
CLOUD_COMPOSE_SMOKE_DESTROY_TIMEOUT: "1800"
CLOUD_COMPOSE_SMOKE_SWEEP_ORPHANS: "true"
CLOUD_COMPOSE_SMOKE_RUN_ID: ${{ github.run_id }}
CLOUD_COMPOSE_SOURCE_REF: ${{ github.event.pull_request.head.sha }}
CLOUD_COMPOSE_SOURCE_REF: ${{ github.sha }}

steps:
- name: Checkout repository
Expand Down Expand Up @@ -199,12 +212,15 @@ jobs:
CLOUD_COMPOSE_SMOKE_DESTROY_TIMEOUT: "1800"
CLOUD_COMPOSE_SMOKE_SWEEP_ORPHANS: "true"
CLOUD_COMPOSE_SMOKE_RUN_ID: ${{ github.run_id }}
CLOUD_COMPOSE_SOURCE_REF: ${{ github.event.pull_request.head.sha }}
CLOUD_COMPOSE_SOURCE_REF: ${{ github.sha }}
CLOUD_COMPOSE_UPGRADE_BASE_SHA: f33117cdbbf4a9c7d59006a4db986baef118e6bb
CLOUD_COMPOSE_UPGRADE_CURRENT_REF: ${{ github.sha }}
GCLOUD_OIDC_POOL: ${{ vars.GCLOUD_OIDC_POOL || secrets.GCLOUD_OIDC_POOL }}
GCLOUD_PROJECT: ${{ vars.GCLOUD_PROJECT || secrets.GCLOUD_PROJECT }}
GCLOUD_FRESH_REGION: ${{ vars.GCLOUD_FRESH_REGION || secrets.GCLOUD_FRESH_REGION }}
GCLOUD_FRESH_ZONE: ${{ vars.GCLOUD_FRESH_ZONE || secrets.GCLOUD_FRESH_ZONE }}
GCLOUD_REGION: ${{ vars.GCLOUD_REGION || secrets.GCLOUD_REGION }}
GCLOUD_ZONE: ${{ vars.GCLOUD_ZONE || secrets.GCLOUD_ZONE }}
GCLOUD_NETWORK_PROJECT_ID: ${{ vars.GCLOUD_NETWORK_PROJECT_ID || secrets.GCLOUD_NETWORK_PROJECT_ID }}
GCLOUD_NETWORK_NAME: ${{ vars.GCLOUD_NETWORK_NAME || secrets.GCLOUD_NETWORK_NAME }}
GCLOUD_SUBNETWORK_NAME: ${{ vars.GCLOUD_SUBNETWORK_NAME || secrets.GCLOUD_SUBNETWORK_NAME }}
Expand Down Expand Up @@ -264,6 +280,9 @@ jobs:

- name: Run fresh smoke test
if: ${{ !startsWith(github.event.pull_request.title, '[major]') }}
env:
GCLOUD_REGION: ${{ vars.GCLOUD_FRESH_REGION || secrets.GCLOUD_FRESH_REGION || vars.GCLOUD_REGION || secrets.GCLOUD_REGION }}
GCLOUD_ZONE: ${{ vars.GCLOUD_FRESH_ZONE || secrets.GCLOUD_FRESH_ZONE || vars.GCLOUD_ZONE || secrets.GCLOUD_ZONE }}
run: make smoke-test PROVIDER=gcp TEMPLATE=wp

- name: Run 0.10.2 upgrade smoke test
Expand All @@ -272,6 +291,9 @@ jobs:

- name: Destroy fresh smoke resources
if: ${{ always() && !startsWith(github.event.pull_request.title, '[major]') && env.GCLOUD_OIDC_POOL != '' && env.GSA != '' && env.GCLOUD_PROJECT != '' }}
env:
GCLOUD_REGION: ${{ vars.GCLOUD_FRESH_REGION || secrets.GCLOUD_FRESH_REGION || vars.GCLOUD_REGION || secrets.GCLOUD_REGION }}
GCLOUD_ZONE: ${{ vars.GCLOUD_FRESH_ZONE || secrets.GCLOUD_FRESH_ZONE || vars.GCLOUD_ZONE || secrets.GCLOUD_ZONE }}
run: ci/cloud-smoke.sh destroy-gcp-wp

- name: Destroy upgrade smoke resources
Expand Down
21 changes: 21 additions & 0 deletions .github/workflows/github-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,24 @@ jobs:
contents: write
actions: write
secrets: inherit

verify-rootfs-assets:
name: Verify rootfs release assets
needs: release
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- name: Checkout merged source
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
fetch-depth: 0
persist-credentials: false
ref: ${{ github.event.pull_request.merge_commit_sha }}

- name: Wait for and verify immutable rootfs assets
env:
GH_TOKEN: ${{ github.token }}
run: >-
ci/verify-rootfs-release.sh commit
"${{ github.event.pull_request.merge_commit_sha }}"
8 changes: 7 additions & 1 deletion .github/workflows/publish-rootfs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,11 +20,17 @@ jobs:
ci/rootfs-package-contract.sh
ci/package-rootfs.sh dist

- name: Upload rootfs asset and checksum
- name: Upload rootfs asset, archive checksum, and source contract
env:
GH_TOKEN: ${{ github.token }}
run: >-
gh release upload "$GITHUB_REF_NAME"
dist/cloud-compose-rootfs.tar.gz
dist/cloud-compose-rootfs.tar.gz.sha256
dist/cloud-compose-rootfs.contract.sha256
--clobber

- name: Verify published rootfs release assets
env:
GH_TOKEN: ${{ github.token }}
run: ci/verify-rootfs-release.sh tag "$GITHUB_REF_NAME"
12 changes: 9 additions & 3 deletions Makefile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
.PHONY: lint lint-check actionlint shell-lint runtime-config-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract sitectl-version-contract go-fmt-check go-vet go-contracts template-version-contract rollout-parity-contract rootfs-package-contract host-runtime-security cos-jq-portability-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract artifact-install-contract config-management-smoke cloud-compose-ci
.PHONY: lint lint-check actionlint shell-lint runtime-config-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract disaster-recovery-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract sitectl-version-contract go-fmt-check go-vet go-contracts template-version-contract rollout-parity-contract rootfs-package-contract host-runtime-security inline-data-program-contract cos-jq-portability-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract artifact-install-contract config-management-smoke cloud-compose-ci
.PHONY: terraform-fmt terraform-fmt-check terraform-validate terraform-validate-contract terraform-lint-check terraform-docs terraform-docs-check
.PHONY: config-management-cloud-smoke config-management-cloud-smoke-ansible-drupal config-management-cloud-smoke-salt-drupal
.PHONY: destroy-config-management-cloud-smoke destroy-config-management-cloud-smoke-ansible-drupal destroy-config-management-cloud-smoke-salt-drupal
Expand All @@ -16,9 +16,9 @@ export CLOUD_COMPOSE_CI_BIN
GO_MODULE_FILES := $(wildcard go.mod go.sum)
GO_SOURCES := $(shell find cmd internal -type f -name '*.go')

lint: terraform-fmt actionlint shell-lint host-runtime-security cos-jq-portability-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract sitectl-version-contract template-version-contract rollout-parity-contract rootfs-package-contract artifact-install-contract terraform-validate terraform-docs-check
lint: terraform-fmt actionlint shell-lint host-runtime-security inline-data-program-contract cos-jq-portability-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract disaster-recovery-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract sitectl-version-contract template-version-contract rollout-parity-contract rootfs-package-contract artifact-install-contract terraform-validate terraform-docs-check

lint-check: terraform-fmt-check actionlint shell-lint host-runtime-security cos-jq-portability-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract sitectl-version-contract template-version-contract rollout-parity-contract rootfs-package-contract artifact-install-contract terraform-validate terraform-docs-check
lint-check: terraform-fmt-check actionlint shell-lint host-runtime-security inline-data-program-contract cos-jq-portability-contract application-env-contract compose-runtime-contract app-filesystem-convergence-contract backup-contract disaster-recovery-contract overlay-contract filesystem-prep-contract key-rotation-contract vault-runtime-contract managed-artifact-contract config-management-input-contract systemd-contract bootstrap-recovery-contract source-trust-contract cloud-smoke-cleanup-contract hosted-cleanup-retry-contract gcp-upgrade-smoke-contract sitectl-version-contract template-version-contract rollout-parity-contract rootfs-package-contract artifact-install-contract terraform-validate terraform-docs-check

actionlint:
go run github.com/rhysd/actionlint/cmd/actionlint@$(ACTIONLINT_VERSION)
Expand Down Expand Up @@ -58,6 +58,9 @@ app-filesystem-convergence-contract:
backup-contract:
bash ci/backup-contract.sh

disaster-recovery-contract:
bash ci/disaster-recovery-contract.sh

overlay-contract:
bash ci/overlay-contract.sh

Expand Down Expand Up @@ -102,6 +105,9 @@ rootfs-package-contract:
host-runtime-security:
bash ci/host-runtime-security.sh

inline-data-program-contract:
bash ci/inline-data-program-contract.sh

cos-jq-portability-contract:
bash ci/cos-jq-portability-contract.sh

Expand Down
Loading
Loading