Skip to content

release: Hermes workload gateway, Rust 1.99 and approval broker - #69

Merged
ak5 merged 12 commits into
mainfrom
dev
Oct 3, 2026
Merged

ak5 merged 12 commits into
mainfrom
dev

Conversation

@ak5

@ak5 ak5 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Release

Included changes

Release checks

Risk and rollback

  • Risk: TLS interception and network-bound identity require exclusive isolation and installed client trust. The inherited approval broker/storage changes and scan bounds are included because release preserves the full dev ancestry.
  • Rollback: Infra must preserve the installed Compose layout, image pins and configuration revision and restore them while preserving egress isolation. Full platform convergence remains guarded until Infra validates real requests, bypass denial, config CD, tool admission, encrypted backups and obtains operator cutover authorization.
  • Publication: successful trusted main CI publishes immutable sha-<main-commit> GHCR images with provenance/SBOM. The actual registry digest will be recorded after publication.

ak5 and others added 11 commits August 17, 2026 14:57
Bumps library/rust from `14bc9c5` to `0e2bcae`.

---
updated-dependencies:
- dependency-name: library/rust
  dependency-version: 1.97.1-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps [futures-util](https://github.com/rust-lang/futures-rs) from 0.3.33 to 0.3.34.
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.33...0.3.34)

---
updated-dependencies:
- dependency-name: futures-util
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps [http-body-util](https://github.com/hyperium/http-body) from 0.1.4 to 0.1.5.
- [Release notes](https://github.com/hyperium/http-body/releases)
- [Commits](hyperium/http-body@http-body-util-v0.1.4...http-body-util-v0.1.5)

---
updated-dependencies:
- dependency-name: http-body-util
  dependency-version: 0.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps [hatchling](https://github.com/pypa/hatch) from 1.31.0 to 1.32.0.
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatchling-v1.31.0...hatchling-v1.32.0)

---
updated-dependencies:
- dependency-name: hatchling
  dependency-version: 1.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps [rcgen](https://github.com/rustls/rcgen) from 0.14.8 to 0.14.9.
- [Release notes](https://github.com/rustls/rcgen/releases)
- [Commits](rustls/rcgen@v0.14.8...v/0.14.9)

---
updated-dependencies:
- dependency-name: rcgen
  dependency-version: 0.14.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps [async-trait](https://github.com/dtolnay/async-trait) from 0.1.91 to 0.1.92.
- [Release notes](https://github.com/dtolnay/async-trait/releases)
- [Commits](dtolnay/async-trait@0.1.91...0.1.92)

---
updated-dependencies:
- dependency-name: async-trait
  dependency-version: 0.1.92
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
Bumps distroless/cc-debian12 from `fccdbb0` to `adcd20c`.

---
updated-dependencies:
- dependency-name: distroless/cc-debian12
  dependency-version: nonroot
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexander Ververis <alexander.ververis@gmail.com>
* feat: add exclusive workload TLS gateway for Hermes

* fix: refresh available gh fixture package pins

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release review of dev source 3d3a4d83619c228a2799efe0928a7d7df740b076: verified dev -> main path and exact tree equivalence with all-green implementation PR #68. Reviewed the complete main-to-dev file scope and listed inherited approval-broker, structured-scan and dependency changes in the release body rather than presenting this as gateway-only.

The new identity/credential/TLS boundary review is recorded in #68 and docs/security-review-workload-gateway.md. The final local mise run check, schema CLI validation, documentation parity and pinned Hermes compatibility pass. No unresolved source-review findings remain; this is an implementing-agent review, not an independent audit. Fresh release CI must also pass before merging.

Merge method must be a merge commit, with the source SHA verified as an ancestor afterward. Publication must wait for trusted main CI. No live deployment or operator cutover is part of this release; Infra retains the convergence guard and rollback pins until its completion checks pass.

@ak5 ak5 mentioned this pull request Oct 3, 2026
3 tasks done

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refreshed release review: source f1d11bb is tree-identical to all-green reviewed correction #70, built on implementation #68. Reviewed exact Codex quota grant and narrowed Nous OAuth paths against pinned Hermes source. Release body/source SHA updated. Fresh release checks on this head must pass before the merge commit; earlier checks/review do not substitute. No live Infra changes.

@ak5
ak5 merged commit d17a865 into main Oct 3, 2026
11 checks passed
@ak5

ak5 commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Release publication completed successfully after trusted main CI:

  • Main merge commit: d17a86506502aa517642cf2dfa265703798ba461.
  • Reviewed source: f1d11bbd59a7c80be0c731a565f8077993a5f841; verified ancestor of main, with matching trees.
  • Gateway immutable reference: ghcr.io/ak5/charon:sha-d17a86506502aa517642cf2dfa265703798ba461@sha256:f6568769ac4f713478941a233b5cb715bbeb57d6688b75a30a31f53a9a2d801c.
  • Separate Hermes integration reference: ghcr.io/ak5/charon-hermes:sha-d17a86506502aa517642cf2dfa265703798ba461@sha256:662d8962fb842cf87d4a061f0f517aaa10d696fdd8c3ae3c8c81658cdbbe8371.
  • Registry inspection confirms both OCI index digests, linux/amd64 manifests and attestation manifests. Digests are read from GHCR, not inferred from Git SHAs.
  • All final local gates, Linux PR/release/main CI and publication pass, including unmodified curl/gh mediation and pinned Hermes compatibility.
  • The actual digest-pinned gateway container validates the complete synthetic example (valid workload gateway v1) with --network none, read-only filesystem and dropped capabilities.

Schema/example: examples/hermes-gateway.toml. Contract and client CA/proxy/feature-test/rollback handoff: contracts/workload-gateway.md and docs/hermes-gateway.md. Required verification is the real TLS gateway fixture suite and deployment behavior proof; /readyz is not feature evidence.

No apps host deployment or convergence occurred. Infra retains its guard until isolation, real client trust and origin-side hydration, direct-egress/IPv6/QUIC/alternate-route denial, config CD, admission and encrypted backups are proven, then requests operator cutover authorization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant