Skip to content

feat: permanently allocate trusted release runs and retry attempts - #10

Merged
infraclaw-dash merged 3 commits into
mainfrom
feat/permanent-release-broker-20260929
Sep 29, 2026
Merged

infraclaw-dash merged 3 commits into
mainfrom
feat/permanent-release-broker-20260929

Conversation

@ktechmidas

Copy link
Copy Markdown
Contributor

What changes

Make the existing bounded release pool permanent across current and future Platform run IDs and retry attempts. The protected GitHub credential stays on the Gateway; the host gets only a scoped one-job JIT configuration. Keep the existing pinned-image/nonroot/fresh-workspace lifecycle and independent offline cleanup.

  • Discover the two approved release workflows and current attempts automatically.
  • Recheck repository/event/ref/head/labels, dedicated group6 visibility, and exact image manifest before admission.
  • Persist a pre-write registration receipt; never blindly replay an ambiguous GitHub write.
  • Serialize admission with the candidate pool and require its deployed lifetime capacity interlock.
  • Add queued/blocked alerts and a separate headless watchdog for disabled/failing schedules and stale receipts.
  • Package all runtime validation dependencies explicitly, with a standalone staged-bundle test.

Verification

101 tests pass, one opt-in Docker-runtime test skipped. Full source-image contract already passes against the actual immutable production image. Live plan discovered beta7 attempt2 Kotlin job109459417028 without any run-specific allowlist. Production activation and one-job lifecycle are being verified and recorded in the operator's private evidence; this does not alter release tags, publish packages manually, or touch contributor PR branches.

The Docker application-image cargo-binstall repair is separate: dashpay/platform#5203.

Prepared by infraclaw using the user-authorized internal-branch/PAT route; account attribution is not a personal approval.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b4de8e5f-7fa4-4899-8c34-5cc2125fdd2b

✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@infraclaw-dash
infraclaw-dash merged commit 683bb35 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants