Documentation/Install
Install · v0.0.1

Production-readiness gate

A fail-closed decision record for dependencies, security, operations, live-provider evidence and exact-release approval.

AudienceChange authority · platform · security · SREReading time18 minutesCommands in context1 guided stepsReviewed sourcefcc5871 · 30 July 2026
RC

Exact release scope. This page documents the reviewed v0.0.1 source at fcc5871. Check release status before enabling a gated capability.

Current truth

Not GA

No v0.0.1 capability is GA-ready.

Production-gated means implementation exists but customer production use still requires explicit environment validation and approval.

Documentation sourcerelease/v0.0.1fcc5871Reviewed 30 July 2026

Control-plane gate

  • Signed, immutable release identity and retained SBOM/provenance/CVE evidence
  • Durable external PostgreSQL with tested backup and restore
  • Durable artifact storage; shared or S3-compatible for multi-replica
  • Customer-managed 32-byte protection key stored separately from backup
  • Leader election and failure testing for more than one API/worker replica
  • Health, readiness, clock, metrics, logs and alert ownership accepted

Execution gate

  • Every enabled provider/operation has live evidence for this exact release
  • Every lifecycle agent passes trust, clock, runtime and N/N-1 compatibility
  • Create, scale, replace, upgrade, cancellation, restart and cleanup are exercised
  • Registry/private-CA/no-egress paths are validated where used
  • Sensitive Kubernetes mutations, exec and port-forward remain disabled
  • Add-on upgrade and uninstall contract stubs are not treated as features

Recovery gate

  • RPO and RTO are measured from a clean restore exercise
  • Database, artifacts, master key and release metadata form a complete recovery set
  • Artifact loss, database loss and key-rotation scenarios have named runbooks
  • Provider partial failure and stale OperationRun recovery are tested
  • Emergency disablement and rollback/restore authority are named

Decision record

FieldRequired value
CandidateVersion, branch, full commit SHA, image digests and bundle checksum
EnvironmentProfile, region/site, dependency identities and network zone
Enabled capabilityExact feature flags, provider operations and roles
EvidenceAutomated checks plus controlled live-environment proof
ExceptionsOwner, risk, compensating control and expiry
ApprovalNamed environment-specific authority and date
RollbackDisable, restore and communication trigger