Skip to content

Harden first public release path - #11

Merged
maincarry merged 2 commits into
mainfrom
first-release-readiness
Aug 12, 2026
Merged

maincarry merged 2 commits into
mainfrom
first-release-readiness

Conversation

@maincarry

Copy link
Copy Markdown
Contributor

Summary

  • add a staged Terraform evaluation path with one-target canary gates, account/Region/CIDR enforcement, public-egress validation, architecture-locked images, and an AWS-only emergency pause
  • bound and recover runtime work with namespace-scoped scanner quotas, per-destination serialization, generator claim recovery, DLQ redrive, and durable DynamoDB outbox replay
  • strengthen release confidence with hermetic migrator packaging, PostgreSQL/envtest/Terraform/Kubernetes/container gates, and end-to-end setup and finding-integration documentation

Test plan

  • make KUBECONFORM='go run github.com/yannh/kubeconform/cmd/kubeconform@v0.8.0' HELM='go run helm.sh/helm/v3/cmd/helm@v3.20.1' ci
  • uvx pre-commit run --all-files
  • git diff --check

Validation boundary

  • No AWS resources were created and no live network scan was performed.

Made with Cursor

maincarry and others added 2 commits August 12, 2026 11:29
Add staged canary deployment, runtime safety and recovery controls, and release validation so evaluators can prove one authorized target before broader activation.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use Bash-native matching so the Terraform Format job does not depend on an uninstalled ripgrep binary.

Co-authored-by: Cursor <cursoragent@cursor.com>
@maincarry
maincarry merged commit 7af62ea into main Aug 12, 2026
31 checks passed
@maincarry
maincarry deleted the first-release-readiness branch August 12, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants