Skip to content

Design release attestation and reproducible builds for all adapters - #1262

Open
prk-Jr wants to merge 5 commits into
mainfrom
spec/1235-release-attestation
Open

prk-Jr wants to merge 5 commits into
mainfrom
spec/1235-release-attestation

Conversation

@prk-Jr

@prk-Jr prk-Jr commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Define how publishers and vendors verify that release artifacts were built from reviewed source, and how operators submit those verified bytes without rebuilding.
  • Require reproducible recipes, retained authenticated inputs, separate clean A/B builds and operator replay, alongside SLSA provenance, artifact-specific SPDX SBOMs and immutable release publication.
  • Define contracts for Fastly, Cloudflare, Spin and Axum, with typed EdgeZero integration and future publisher/configuration/runtime attestation boundaries.

Changes

File Change
docs/superpowers/specs/2026-10-09-1235-release-attestation-design.md Add the reviewed design, complete build-input inventory, online/offline verification policy, byte-preserving consumption contracts, reproducibility gates, test plan and phased rollout.

Phase 1 ships Fastly wasm and three native CLI assets. The cumulative Phase 2 cohort adds Cloudflare's processed module archive, a validated Spin WASIp2 component and three Axum executables, for nine canonical assets. Each enabled artifact needs its own composition, reproducibility and consumption proofs. Spin target/SDK/runtime alignment is an explicit enablement prerequisite; unsupported provider operations fail before side effects.

Publisher groundwork separates artifact identity, the configuration snapshot actually loaded, provider/process observations and publisher authority. Enrollment, signing protocols, freshness and independent remote execution assurance remain with #161. The specification does not implement runtime behavior or claim that the proposed release pipeline already exists.

Closes

Refs #1235. This PR fulfills its separate specification-review prerequisite; #1235 remains open until implementation and its remaining acceptance criteria are complete.

Test plan

  • Independent full-spec and adapter reviews; resolve Spin OCI secret/configuration leakage and Axum runtime-selector consistency findings.
  • cargo fmt --all -- --check and all eight target-matched Rust clippy aliases.
  • JS build, npx vitest run (1,185 tests; no type errors), and JS formatting using pinned Node 24.12.0.
  • Documentation formatting/lint, repository Markdown formatting, domain lint, relative-link checks, shell-example syntax and diff checks.
  • All four adapter test aliases plus Fastly reusable-sandbox tests, 17 parity tests, native build-digest tests/lint and ./scripts/test-cli.sh (including required browser fixtures).

Viceroy certificate loading and localhost fixture listeners needed execution outside the sandbox; those retries passed without code changes or TLS weakening.

Checklist

  • Changes follow AGENTS.md conventions and stay limited to the specification.
  • No secrets or credentials committed.
  • Implementation verification and acceptance requirements are documented; no production code, logging or regex/pattern compilation changes are included.
  • Maintainer approval is required before an implementation PR, as requested by Publish attested release binaries with build provenance and SBOMs #1235.

@prk-Jr prk-Jr self-assigned this Oct 9, 2026
@prk-Jr
prk-Jr requested review from aram356 and jevansnyc October 9, 2026 07:54

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants