You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The self-managed stable-stack follow-up produced several independently
reviewable pull requests across profile export, compute registration, routing,
API documentation, and BDD coverage. This issue provides one ranked review
queue so dependencies, readiness, and remaining gates are visible without
replacing the implementation issues linked from each pull request.
The order prioritizes direct installation and registration correctness, then
public API behavior, routing, and automated coverage.
test(bdd): single-cluster PKI feature with a secured LLM invoke #1075 exact head dcb58f71 merged as fc10e13b after approval. Its source
tree passed focused OpenBao, LLM-PKI wiring/render,
registration, full short BDD, full CLI test/build/vet, BDD vet/race, pinned
compute render/golden, Dash cleanup, Bash, ShellCheck, and diff checks.
Every automatic GitHub check on this exact head completed successfully or
was correctly skipped; no optional or manual job was triggered. No review
thread was unresolved.
A fresh validation-only integration of the same source content plus the
required standalone-path parameterization used released API 1.25.1,
Cassandra 0.20.1/migrations 0.16.0, and ESS 1.7.2/app 0.4.13. The bounded
BDD passed 4/4 scenarios and 69/69 steps in 14m34s. It verified the real
issuer/certificate, tokenless profile trust, compute registration, secure
NVCA settings, healthy backend, function creation/deployment, authenticated
routed fixed-response invocation, expected 401, and deployment deletion. No
live resource was patched or Pod manually deleted.
Keep implementation discussion and acceptance evidence on the owning pull
request or related issue.
Check an item here only after the pull request is approved and merged or
closed with a documented disposition. These checkboxes are manual; GitHub
does not automatically synchronize them with pull-request state.
Why
The self-managed stable-stack follow-up produced several independently
reviewable pull requests across profile export, compute registration, routing,
API documentation, and BDD coverage. This issue provides one ranked review
queue so dependencies, readiness, and remaining gates are visible without
replacing the implementation issues linked from each pull request.
The order prioritizes direct installation and registration correctness, then
public API behavior, routing, and automated coverage.
Ranked review queue
domain while preserving local behavior and explicit overrides. Related:
fix(cli): derive exported control-plane profile endpoints from selected environment #1231.
configuration, kube-context propagation, and LLM-disabled behavior. Related:
restore self-hosted compute CLI default config generation #1147.
exported profile while preserving genuine errors. Related: fix(cli): tolerate kubectl attach fallback diagnostics during profile export #1228.
OpenAI-compatible payloads, and echo-versus-token-generation distinction.
Related: docs(llm): clarify the function body-format contract for OpenAI-compatible routes #1227.
provider exposure, DNS/SNI/trust responsibilities, and partial-config guards.
gRPC mode without representing it as the permanent TLS solution.
destroy-all-ncp-localcleanup targetPOSIX-portable under Dash while preserving selective cluster deletion and
command-failure propagation. Related: fix(local-cluster): make destroy-all cleanup portable across POSIX shells #1261.
config-scoped CLI state, secure transport trust, and transient OpenBao
certificate-read handling. Related: Helmfile live BDDs fail because register-cluster requires an unexported profile #1254; prerequisite for test(bdd): single-cluster PKI feature with a secured LLM invoke #1075's merged
follow-on fix(bdd): use exported profile trust for PKI #1266.
worker registration, reverse QUIC, secured invocation, and cleanup. Related:
test(bdd): single-cluster PKI feature with a secured LLM invoke #1076.
authentication, and cleanup coverage without claiming secure gRPC or token
performance. Related: BDD suites: single and multi cluster with PKI and LLM function coverage #1019.
registration, and installation workflows. Related: docs(cli): document stack paths for source-built self-hosted CLI #1202.
Current readiness
main: fix(nvcf-cli): derive profile endpoints from stack domain #1234, fix(nvcf-compute-plane): use generated profile for registration #1236,fix(cli): tolerate kubectl attach fallback diagnostics #1233, docs(llm): clarify body format contract #1238, fix(self-managed): validate external LLM routing #1204, test(bdd): guard multi-cluster NVCF gRPC mode #1208, fix(local-cluster): make destroy-all cleanup POSIX-portable #1263, fix(self-managed): restore Helmfile profile registration #1262, test(bdd): single-cluster PKI feature with a secured LLM invoke #1075, test(bdd): cover multi-cluster LLM routing #1235, and docs(cli): document stack paths for source builds #1203.
4c100cf5merged as33a879e4after approval and allfocused Dash, broader Make, ShellCheck, root Bazel, and CodeRabbit checks
passed.
ef67bfbcmerged as12a56476after approval and allCodeRabbit, Go, Helm, docs, root Bazel, and release-helper checks passed.
parallel OpenBao rewrite and makes the BDD consume and validate canonical
exported-profile trust from merged fix(self-managed): restore Helmfile profile registration #1262.
dcb58f71merged asfc10e13bafter approval. Its sourcetree passed focused OpenBao, LLM-PKI wiring/render,
registration, full short BDD, full CLI test/build/vet, BDD vet/race, pinned
compute render/golden, Dash cleanup, Bash, ShellCheck, and diff checks.
Every automatic GitHub check on this exact head completed successfully or
was correctly skipped; no optional or manual job was triggered. No review
thread was unresolved.
required standalone-path parameterization used released API 1.25.1,
Cassandra 0.20.1/migrations 0.16.0, and ESS 1.7.2/app 0.4.13. The bounded
BDD passed 4/4 scenarios and 69/69 steps in 14m34s. It verified the real
issuer/certificate, tokenless profile trust, compute registration, secure
NVCA settings, healthy backend, function creation/deployment, authenticated
routed fixed-response invocation, expected 401, and deployment deletion. No
live resource was patched or Pod manually deleted.
validated compatible standalone stack input through a supported writable
release path remains separate delivery follow-up.
Completion
request or related issue.
closed with a documented disposition. These checkboxes are manual; GitHub
does not automatically synchronize them with pull-request state.