Skip to content

Commit f7341fa

Browse files
author
ocx-test
committed
chore(release): mark 1.5.1 live-release evidence
Sync the place-lock version/SHA pins (container unit, OIDC checklist, README, docs-site, .env.example, build-info) with the 1.5.1 release commit so the health -smoke contract test tracks the live artifact.
1 parent c88648f commit f7341fa

9 files changed

Lines changed: 28 additions & 28 deletions

File tree

‎.env.example‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@
33
#
44
# Live place lock (do not change from this checkout):
55
# systemd unit: opencodex-proxy
6-
# version: 1.5.0
7-
# source SHA: f5cc348b7f0b7a48a9241cac17714399c2777c0f
6+
# version: 1.5.1
7+
# source SHA: c88648fa87001d04beedc8df853bee7700253422
88
# health: http://<tailscale-ipv4>:10100/healthz
99
# The immutable GHCR digest lives only on the live host `.env` as OPENCODEX_IMAGE.
1010

@@ -15,10 +15,10 @@
1515
OPENCODEX_API_TOKEN_FILE=deploy/container/.secrets/api-token
1616
OPENCODEX_STATE_DIR=./.tmp/opencodex-state
1717
OPENCODEX_GIT_SHA=
18-
OPENCODEX_VERSION=1.5.0
18+
OPENCODEX_VERSION=1.5.1
1919

2020
# --- Production compose.example.yml (digest-pinned; not used by local compose) ---
21-
# OPENCODEX_IMAGE=ghcr.io/groeponline/opencodex:1.5.0@sha256:<immutable-digest>
21+
# OPENCODEX_IMAGE=ghcr.io/groeponline/opencodex:1.5.1@sha256:<immutable-digest>
2222
# OPENCODEX_BIND_IP= # host Tailscale IPv4; required only for prod compose
2323

2424
# --- Cloudflare Access (live public-host gate; optional locally) ---
@@ -49,5 +49,5 @@ OIDC_REDIRECT_URI=http://127.0.0.1:10100/oauth/callback
4949

5050
# --- Healthz smoke (scripts/healthz-smoke.sh) ---
5151
# OPENCODEX_HEALTH_URL=http://127.0.0.1:10100/healthz
52-
# OPENCODEX_SMOKE_EXPECT_SHA=f5cc348b7f0b7a48a9241cac17714399c2777c0f
53-
# OPENCODEX_SMOKE_EXPECT_VERSION=1.5.0
52+
# OPENCODEX_SMOKE_EXPECT_SHA=c88648fa87001d04beedc8df853bee7700253422
53+
# OPENCODEX_SMOKE_EXPECT_VERSION=1.5.1

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -528,7 +528,7 @@ mirrors that path:
528528
| Dev Container | `.devcontainer/` (Bun 1.4.0) |
529529
| Health smoke | `bash scripts/healthz-smoke.sh` → `http://127.0.0.1:10100/healthz` |
530530

531-
Operator notes, the live `1.5.0` / `f5cc348b7` place lock, and Authentik OIDC
531+
Operator notes, the live `1.5.1` / `c88648fa8` place lock, and Authentik OIDC
532532
(`chefgroep-ocx-oidc`; issuer APPLY DONE 2026-09-18; consumer JWKS +
533533
`/oauth/login`) are in
534534
[`deploy/container/README.md`](./deploy/container/README.md). Cloudflare Access

‎compose.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ services:
1515
dockerfile: Dockerfile
1616
args:
1717
VCS_REF: ${OPENCODEX_GIT_SHA:-dev}
18-
VERSION: ${OPENCODEX_VERSION:-1.5.0}
18+
VERSION: ${OPENCODEX_VERSION:-1.5.1}
1919
restart: unless-stopped
2020
read_only: true
2121
environment:

‎deploy/container/README.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,8 @@ change. Reported live identity:
2424
| ---------- | --------------------------------------------------------- |
2525
| Unit | `opencodex-proxy.service` |
2626
| Unit state | Non-serving; a separate npm process owns port `10100` |
27-
| Version | `1.5.0` |
28-
| Source SHA | `f5cc348b7f0b7a48a9241cac17714399c2777c0f` (tag `v1.5.0`) |
27+
| Version | `1.5.1` |
28+
| Source SHA | `c88648fa87001d04beedc8df853bee7700253422` (tag `v1.5.1`) |
2929
| Health | `GET /healthz` on the host Tailscale IPv4, port `10100` |
3030

3131
The live bc-scan-2 service runs the published npm package from
@@ -107,7 +107,7 @@ the existing `providers` map instead.
107107
1. Authentik issuer public apply is done (2026-09-18). The consumer is wired,
108108
but Cloudflare Access remains the live public-host gate until the cutover
109109
checklist is executed. Client secret is not in git.
110-
2. This change documents the `1.5.0` / `f5cc348b7` live release and does not
110+
2. This change documents the `1.5.1` / `c88648fa8` live release and does not
111111
move it. Do not deploy this PR to bc-scan-2.
112112
3. The former Azure `deploy.yml` route is retired fail-closed; do not treat a
113113
merge here as a live cutover.

‎deploy/container/opencodex-proxy.service‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
Description=OpenCodex proxy (Docker Compose)
33
Documentation=https://github.com/GroepOnline/opencodex
44
# Live place lock (docs only — this unit does not embed a version or digest):
5-
# version 1.5.0 / source SHA f5cc348b7f0b7a48a9241cac17714399c2777c0f
5+
# version 1.5.1 / source SHA c88648fa87001d04beedc8df853bee7700253422
66
# image pin is OPENCODEX_IMAGE in EnvironmentFile (immutable digest)
77
# health: GET :10100/healthz on the host Tailscale IPv4
88
# Do not retarget the pin from a docs or local/dev change.

‎deploy/oidc/CUTOVER-CHECKLIST.md‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -36,13 +36,13 @@ hostname. It is not a second identity provider.
3636
- [x] Host `.env` names set (values not recorded): `OIDC_ISSUER`, `OIDC_CLIENT_ID`,
3737
`OIDC_CLIENT_SECRET_FILE`, `OIDC_REDIRECT_URI`, `OIDC_ALLOWED_HOSTS`, plus
3838
`CF_ACCESS_TEAM_DOMAIN`, `CF_ACCESS_AUD`, `CF_ACCESS_ALLOWED_HOSTS`.
39-
- [x] Actual running artifact is npm package **1.5.0** from
40-
`/home/joep/.opencodex/releases/f5cc348b7f0b7a48a9241cac17714399c2777c0f`
39+
- [x] Actual running artifact is npm package **1.5.1** from
40+
`/home/joep/.opencodex/releases/c88648fa87001d04beedc8df853bee7700253422`
4141
(`start-service.sh` → `src/cli/index.ts start --port 10100`). The unit-file
42-
comment and runtime health identity cite tag `v1.5.0` / source SHA
43-
`f5cc348b7f0b7a48a9241cac17714399c2777c0f`.
42+
comment and runtime health identity cite tag `v1.5.1` / source SHA
43+
`c88648fa87001d04beedc8df853bee7700253422`.
4444
- [x] `GET http://100.65.83.86:10100/healthz` returns `status=ok`,
45-
`service=opencodex`, `version=1.5.0`, and source SHA `f5cc348b7…`.
45+
`service=opencodex`, `version=1.5.1`, and source SHA `c88648fa8…`.
4646
Bind is the Tailscale IPv4, not 127.0.0.1. Public
4747
`https://ocx.chefgroep.online/` is still a Cloudflare Access 302.
4848
- [ ] systemd `opencodex-proxy.service` is **not** healthy: `ActiveState=activating`,
@@ -56,7 +56,7 @@ hostname. It is not a second identity provider.
5656
- [x] Issuer `https://auth.chefgroep.online/application/o/ocx/` discovery and JWKS return 200 (APPLY DONE 2026-09-18; not DNS HOLD).
5757
- [x] Client id is `chefgroep-ocx-oidc`. Client secret exists only in `OIDC_CLIENT_SECRET_FILE` on the host (never git, never ChefFactory catalog).
5858
- [x] Redirect URIs required by `deploy/oidc/authentik-ocx-client.placeholder.json` are present. Extra unused URIs remain; leave them.
59-
- [x] Live package version is `1.5.0`. Running tree SHA is `f5cc348b7`. This checklist does not retarget the pin.
59+
- [x] Live package version is `1.5.1`. Running tree SHA is `c88648fa8`. This checklist does not retarget the pin.
6060
- [x] `GET http://100.65.83.86:10100/healthz` still returns `status=ok`, `service=opencodex`.
6161

6262
## Authorize canary (no live cutover)

‎docs-site/src/content/docs/guides/access-vs-authentik.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ OPENCODEX_OIDC_CANARY_URL=http://127.0.0.1:10100 bash scripts/oidc-authorize-can
4747

4848
The operator checklist for dual-run and Cloudflare Access cutover is
4949
[`deploy/oidc/CUTOVER-CHECKLIST.md`](https://github.com/GroepOnline/opencodex/blob/main/deploy/oidc/CUTOVER-CHECKLIST.md).
50-
Merging the consumer does not move the live `1.5.0` place lock and is not a
50+
Merging the consumer does not move the live `1.5.1` place lock and is not a
5151
cutover.
5252

5353
## See also

‎src/build-info.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
2-
"git_sha": "f5cc348b7f0b7a48a9241cac17714399c2777c0f",
2+
"git_sha": "c88648fa87001d04beedc8df853bee7700253422",
33
"built_at": "2026-09-24T09:30:48.055Z",
44
"release": "v1.5.0",
5-
"gui_version": "1.5.0"
5+
"gui_version": "1.5.1"
66
}

‎tests/local-dev-contract.test.ts‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ describe("local/dev complete path", () => {
9595
expect(compose).not.toContain("OIDC_CLIENT_SECRET_FILE:?");
9696
});
9797

98-
test("systemd unit keeps the compose place lock and documents 1.5.0 / f5cc348b7", async () => {
98+
test("systemd unit keeps the compose place lock and documents 1.5.1 / c88648fa8", async () => {
9999
const unit = await readRepo("deploy/container/opencodex-proxy.service");
100100
expect(unit).toContain(
101101
"ExecStart=/usr/bin/docker compose up -d --remove-orphans",
@@ -106,8 +106,8 @@ describe("local/dev complete path", () => {
106106
expect(unit).toContain(
107107
"After=docker.service network-online.target tailscaled.service",
108108
);
109-
expect(unit).toContain("1.5.0");
110-
expect(unit).toContain("f5cc348b7f0b7a48a9241cac17714399c2777c0f");
109+
expect(unit).toContain("1.5.1");
110+
expect(unit).toContain("c88648fa87001d04beedc8df853bee7700253422");
111111
expect(unit).toContain("GET :10100/healthz");
112112
});
113113

@@ -125,7 +125,7 @@ describe("local/dev complete path", () => {
125125
"OIDC_REDIRECT_URI=http://127.0.0.1:10100/oauth/callback",
126126
);
127127
expect(envExample).toContain("https://ocx.chefgroep.online/oauth/callback");
128-
expect(envExample).toContain("f5cc348b7f0b7a48a9241cac17714399c2777c0f");
128+
expect(envExample).toContain("c88648fa87001d04beedc8df853bee7700253422");
129129
expect(envExample).not.toMatch(/OIDC_CLIENT_SECRET=/);
130130
expect(envExample).not.toMatch(/\bsk-[A-Za-z0-9_-]{20,}\b/);
131131
expect(envExample).not.toMatch(/\bghp_[A-Za-z0-9_]{20,}\b/);
@@ -230,7 +230,7 @@ describe("local/dev complete path", () => {
230230
expect(checklist).toContain("GET /oauth/login");
231231
expect(checklist).toContain("Do not apply Cloudflare DNS");
232232
expect(checklist).toContain("ChefFactory");
233-
expect(checklist).toContain("1.5.0");
233+
expect(checklist).toContain("1.5.1");
234234
expect(checklist).toContain(":10100");
235235
});
236236
});
@@ -243,11 +243,11 @@ describe("healthz-smoke against a live proxy", () => {
243243
try {
244244
const ok = await runHealthzSmoke({
245245
OPENCODEX_HEALTH_URL: `http://127.0.0.1:${server.port}/healthz`,
246-
OPENCODEX_SMOKE_EXPECT_VERSION: "1.5.0",
246+
OPENCODEX_SMOKE_EXPECT_VERSION: "1.5.1",
247247
});
248248
expect(ok.exitCode).toBe(0);
249249
expect(ok.stdout).toContain('"service": "opencodex"');
250-
expect(ok.stdout).toContain('"version": "1.5.0"');
250+
expect(ok.stdout).toContain('"version": "1.5.1"');
251251
} finally {
252252
await server.stop(true);
253253
}

0 commit comments

Comments
 (0)