Skip to content

tracking: installer implementation after manifest-first foundation #436

Description

@YoneRai12

Summary

This is the single parent tracker for installer implementation work after the manifest-first foundation in #313.

#313 is closed as the original definition tracker. This issue keeps the remaining implementation checklist visible without recreating noisy child issues.

Current public repository scope

Allowed in the public repo:

  • local manifest verification
  • SHA256 and artifact naming validation
  • dry-run install/update planning
  • deterministic non-production/test trust fixtures
  • local verification and docs

Not allowed in the public repo:

  • production signing keys
  • production trust stores
  • production key rotation service
  • release signing service
  • network download-and-execute installer
  • irm ... | iex
  • PATH/package/service/registry mutation by default

Remaining public-repo tasks

  • PowerShell dry-run installer skeleton that validates local inputs and prints planned actions only.
  • Manifest-to-release-asset hash and naming consistency check.
  • Safe install, rollback, update, and uninstall docs.
  • Future install.yonerai.com / yonerai.com/install onboarding copy that clearly avoids remote-execution claims.
  • Keep production signing/trust/key rotation/release signing service documented as private/official future work only.

Acceptance boundary

This tracker is not a production installer completion claim. Close it only when the public-safe installer implementation lane has either shipped the above items or intentionally moved them into a narrower owner-approved tracker.

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions