Skip to content

Production VM gates and browser custom image builder - #11

Merged
tifycloud merged 1 commit into
mainfrom
codex/production-builder
Jul 21, 2026
Merged

tifycloud merged 1 commit into
mainfrom
codex/production-builder

Conversation

@tifycloud

Copy link
Copy Markdown
Owner

Summary

  • harden the x86_64 VM candidate with a deterministic two-NIC LAN/WAN layout, HTTPS redirect, firewall runtime gate, per-install first-boot password, disabled SSH, and raw/VMDK persistence validation
  • add a strict component catalog plus browser selector and authenticated GitHub Actions custom builds for x86_64 and Xiaomi AX9000 official/NSS flavors
  • add committed human ESXi evidence validation and byte-identical RC-to-stable promotion
  • allow strictly verified stable VM releases to appear on the GitHub Pages download site

Security and release policy

  • component IDs are allowlisted; arbitrary package names, paths, or commands are rejected
  • browser request hashes bind catalog version, target, flavor, components, and resolved packages and are recomputed by the workflow
  • stable promotion requires immutable RC assets, exact checksums, committed real ESXi evidence, and re-download byte comparison
  • interrupted stable draft promotion is recoverable only when every trusted identity field matches

Verification

  • ./tests/test_static.sh
  • targeted component, custom-build, Pages provenance/UI, VM release, and VM promotion tests
  • ShellCheck, Python compile checks, Node syntax check, actionlint, and git diff --check
  • independent final audit: no P0/P1 blockers

Remaining acceptance boundary

A stable x86_64 release is intentionally blocked until the new RC is tested on real VMware ESXi and its evidence is committed. AX9000 remains a RAM-test candidate until real hardware acceptance is completed.

@tifycloud
tifycloud merged commit 798d0aa into main Jul 21, 2026
7 checks passed
@tifycloud
tifycloud deleted the codex/production-builder branch July 21, 2026 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant