Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 8 additions & 5 deletions FORK.md
Original file line number Diff line number Diff line change
Expand Up @@ -249,11 +249,13 @@ version is built from is documented here ("Pin") and carried by every image as t
(the tag without `v`; `appVersion` the same). **`1.0.0`** is the first release of the scheme — the next major
above the `0.0.30-gs.N` releases, which were coupled to upstream's next patch and are superseded. Consumers
follow a Flux `OCIRepository` range, `semver: ">=1.0.0 <2.0.0"`.
- Dev build, on every push to `giantswarm`: gitsemver's dev version — the next patch above the last release and a
pre-release identifier from the branch, the commit's committer time (UTC) and its short hash — so a rebuild of a
commit yields the same version, dev builds sort chronologically within the branch and below the release they
anticipate. The dev channel is selected with `semverFilter` on that pre-release shape; exact pins name the full
string.
- Dev build, on every push to `giantswarm`: gitsemver's dev version, `<next patch>-dev.<branch>.<YYYY-MM-DD>.<HH-MM-SS>.h<sha7>`
as the orb's gitsemver emits it today (`0.0.0-dev.giantswarm.2026-09-19.13-38-12.h171b9e4` for the commit `1.0.0` was cut
from — the base is `0.0.0` until a stable tag exists — `1.0.1-dev.giantswarm.…` from `1.0.0` on): committer time in UTC,
so a rebuild of a commit yields the same version and dev builds sort chronologically within the branch and below the
release they anticipate. The dev channel is a Flux `OCIRepository` with `semver: ">=1.0.0-0 <2.0.0-0"` and
`semverFilter: ".*-dev\.giantswarm\..*"` (the filter follows gitsemver's shape when it moves to the RFC's
`-r<crc>t<time>h<sha>` form); exact pins name the full string.
- Image tags carry no `v`, as every Giant Swarm image tag does.

**Signatures.** Every index and chart is signed keyless with cosign under the pipeline's CircleCI OIDC identity
Expand Down Expand Up @@ -283,6 +285,7 @@ here:
| **v0.0.30-gs.3** (2026-09-15, tag on `653de64e` = gs.2 + #34: every pause durable — the pause snapshot uploaded in the background and recorded as the actor's external snapshot marked with its source, the snapshot's node a placement preference once the copy exists, a suspend adopting the copy without the node (`653de64e`)) | v0.0.29 | images `ateapi` `sha256:4bb59829…`, `atecontroller` `sha256:9de1965d…`, `atelet` `sha256:8079258f…`, `atenet` `sha256:515de099…`, `podcertcontroller` `sha256:19e628ae…`, `ateom-gvisor` `sha256:4ad380f2…` (linux/amd64 + arm64); charts `substrate` `sha256:c08d9122…`, `substrate-crds` `sha256:71cf502e…`; dataplane `ghcr.io/giantswarm/agentgateway-upstream/agentgateway:v1.5.1-gs.4`; [run 34981525932](https://github.com/giantswarm/substrate/actions/runs/34981525932). Consumers: the agent-platform meta chart's range `>=0.0.30-gs.1 <0.0.31-0` admits it without a re-pin — gazelle rolled it at the next 10-minute reconcile of its OCIRepository (chart pushed 14:28Z, HelmRelease Ready on gs.3 with every pod and all 16 atelets updated at 14:40Z); its one `PAUSED` actor is the incident's dead session, which the resync reports every minute as `No atelet on the node holding the pause snapshot; not uploaded` until #35 crashes it |
| **v0.0.30-gs.4** (2026-09-15, annotated tag on `d8a2d5e4` = gs.3 + #39: the golden boot a workload keeps failing is bounded — three boots counted in `GoldenSnapshotStatus.workload_boot_failures`, then the golden actor crashed (its worker freed) and the template failed with `GoldenActorNotReady`, the bound and the last boot's error — and ateom's readiness-deadline error quotes the workload's last output lines (`7a11e479`, with its ledger row `d8a2d5e4`; giantswarm/giantswarm#37801, #37742 row 47); cut after the agentlab proof of the branch's dev build `0.0.30-dev.fork-golden-boot-bound.2026-09-15.18-17-09.he684b13`: the released images loop a private-skill template without end, the patch fails it 3 min 8 s after creation with `could not read Username for 'https://github.com'` in kagent's condition message, the spec fix reaches Ready in 20 s and the failed revision is collected; `platform-test` green) | v0.0.29 | images `ateapi` `sha256:1703b848…`, `atecontroller` `sha256:4ae8e4ac…`, `atelet` `sha256:d36093c3…`, `atenet` `sha256:ddb41ec3…`, `podcertcontroller` `sha256:0fc2e4b6…`, `ateom-gvisor` `sha256:6e086b8c…` (linux/amd64 + arm64); charts `substrate` `sha256:5dfa7ae1…`, `substrate-crds` `sha256:bc5b90aa…`; dataplane `ghcr.io/giantswarm/agentgateway-upstream/agentgateway:v1.5.1-gs.4`; [run 35009210132](https://github.com/giantswarm/substrate/actions/runs/35009210132), every scan clean. Consumers: the agent-platform meta chart's range `>=0.0.30-gs.2 <0.0.31-0` admits it without a re-pin (the control plane's bound); the worker image — the quoted output — comes with the kagent line's stamp (giantswarm/kagent-upstream#49, `SUBSTRATE_VERSION 0.0.30-gs.1 → 0.0.30-gs.4`) through the kagent range `>=0.11.0-gs.16 <0.11.1-0` |
| **v0.0.30-gs.5** (2026-09-19, annotated tag on `ea00cfce` = gs.4 + #42/#43: every Docker Hub image default names its registry (`images.awsCli` kept a short name for the immutable bucket-init Job) + #45: the third-party image defaults are their gsoci copies, `images.agentgateway` the agentgateway line's release on gsoci + #46: the line publishes its images and charts to gsoci from CircleCI — **the first release published natively to `gsoci.azurecr.io/giantswarm/substrate`, each index and chart signed with the organisation's CircleCI identity**; cut after the agentlab proof of #46's dev build `0.0.30-dev.fork-circleci-gsoci.2026-09-19.04-30-17.hab9aa1f` from gsoci: the control plane, the atelet and the four workers on the new images, `platform-test` 13/13, `agents-test` 6/6 with the golden boot Ready in 12 s) | v0.0.29 | images `ateapi` `sha256:6692117e…`, `atecontroller` `sha256:27f95c3e…`, `atelet` `sha256:8ad7a4ec…`, `atenet` `sha256:da4e699d…`, `podcertcontroller` `sha256:6a314e07…`, `ateom-gvisor` `sha256:cf816037…` (linux/amd64 + arm64); charts `substrate` `sha256:943f8a95…`, `substrate-crds` `sha256:ebe2b126…`; dataplane `gsoci.azurecr.io/giantswarm/agentgateway:v1.5.1-gs.4` (`sha256:f3d4b52c…`); [CircleCI pipeline 6](https://app.circleci.com/pipelines/github/giantswarm/substrate/6) (`images` 1 min 57 s, `scan` 31 s, `charts` 17 s), every scan clean, every reference `cosign verify`-ed under the pipeline's identity. Consumers: the agent-platform meta chart's chart sources move to the gsoci path (giantswarm/agent-platform#580) — until then no installation follows this release, its chart range still reads the ghcr path; the kagent line's `SUBSTRATE_REPO`/`SUBSTRATE_VERSION` move together at its re-pin; agentlab's defaults (giantswarm/agentlab#229); retagger's `renamed-substrate.yaml` mirror entries are retired now that a native release exists (giantswarm/retagger#1238, open) |
| **1.0.0** (2026-09-19, annotated tag on `171b9e44` = gs.5 + #48: the six images built by the architect orb's `push-to-registries` jobs from `.circleci/Dockerfile` (ko's result; each index annotated `io.giantswarm.upstream.version=v0.0.29`, with provenance and an SPDX SBOM), the versions decoupled from upstream's — **the first release of the scheme**, the next major above `0.0.30-gs.5` — and `images.agentgateway` the agentgateway line's own release `agentgateway-upstream/agentgateway:2.0.0`) | v0.0.29 | images `ateapi` `sha256:d99a5316…`, `atecontroller` `sha256:bdb0b08f…`, `atelet` `sha256:0c647af8…`, `atenet` `sha256:44335714…`, `podcertcontroller` `sha256:9df643a6…`, `ateom-gvisor` `sha256:1ea67204…` (linux/amd64 + arm64; each index and its per-platform SPDX attestation signed); charts `substrate` `sha256:291e1b41…`, `substrate-crds` `sha256:99d8211e…` (signed); dataplane `gsoci.azurecr.io/giantswarm/agentgateway-upstream/agentgateway:2.0.0` (`sha256:63deaa67…`); [CircleCI pipeline 13](https://app.circleci.com/pipelines/github/giantswarm/substrate/13) (pushes 1 min 55 s – 4 min 29 s, `scan` 22 s, `charts` 24 s), every scan clean, every reference `cosign verify`-ed under the pipeline's identity; the orb also moves the images' `latest` tag to the release. The dev build of the same commit is `0.0.0-dev.giantswarm.2026-09-19.13-38-12.h171b9e4` (pipeline 12). Consumers: the agent-platform meta chart's ranges (giantswarm/agent-platform#580), the kagent line's `SUBSTRATE_VERSION` at its re-pin (giantswarm/giantswarm#37872), agentlab's defaults (giantswarm/agentlab#229), retagger's `renamed-substrate.yaml` entries retired (giantswarm/retagger#1238) |
| **v0.0.27-gs.9** (2026-09-13, tag on `36d00f80` = gs.8 + #30: the gVisor worker's terminate collects a workload whose runsc containers are already gone (`1dd5d1fb` — `cleanupContainers` lists the containers runsc knows and checks and deletes only those; a delete that fails after removing its container counts as done), with its ledger row; giantswarm/giantswarm#37773) | v0.0.26 | images `ateapi` `sha256:cb267526…`, `atecontroller` `sha256:f2c845ab…`, `atelet` `sha256:0882ecb1…`, `atenet` `sha256:72939cda…`, `podcertcontroller` `sha256:d3eab8cc…`, `ateom-gvisor` `sha256:2240d996…` (linux/amd64 + arm64); charts `substrate` `sha256:bb6ba693…`, `substrate-crds` `sha256:09e363c6…`; dataplane `ghcr.io/giantswarm/agentgateway-upstream/agentgateway:v1.5.1-gs.2`; [run 34783226348](https://github.com/giantswarm/substrate/actions/runs/34783226348), every scan clean |
**Scans.** Every own image is scanned with Trivy (HIGH and CRITICAL, fixable only) after the push and before the
charts that reference it are published. A fixable finding fails the publish: bump the module (upstream first) or,
Expand Down
Loading