Restore signed Nest production releases after the namespace change - #11
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The breaking Nest rename left production release jobs pointing at nonexistent GitHub credentials, runner labels, and a renamed repository. Preserve those existing infrastructure identities while passing the new Tiaris process inputs.
Authenticate the immutable James 0.2.41 descriptors under their original signature domain and an exact, current-authority namespace-transition authorization for Nest 0.2.42. This history is reinstall-only; a separately signed Nest predecessor and the existing warm/cold qualification gates remain mandatory. Publication also verifies production origin, advancing runtime identity, and nondecreasing compatibility/state versions. Original signed artifacts and the earlier recovery authorization remain unchanged.
Validation: 398 release-tool tests passed (11 skipped), 23 appliance contract tests passed, shell syntax/ShellCheck and Nix parsing passed. The cache eviction test now specifies its LRU ordering instead of relying on distinct filesystem timestamps. Recovery media build and qualification are in progress; neither production lab VM has been modified.