Harden pre-release developer and qualification paths - #21
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
./scripts/vyral runnow executes generated apps, and CI proves citations, durable admission, restart recovery, replay, inspection, and reset under an isolated interpreter.Verification
./scripts/verify-release-artifacts.shpassed. The Python runtime completed 228 tests with mypy clean and verified wheel/sdist installs. The redacted local AWS gate passed through the existing least-privilege assumed role with S3, DynamoDB, SQS, and cleanup all successful.Public information review
Does this change expose new public information? Yes
Publication is intentional for the user-facing migration walkthrough, refreshed benchmark evidence, proposed build-only package cohort, and the redacted AWS qualification contract. The cohort remains explicitly unauthorized, raw provider logs and identities stay private, and no internal planning material is included.
Compatibility and operations
The new
vyral run PATHcommand is additive and fixes the documented zero-install source path. Publication remains disabled. The hosted AWS workflow will remain unable to authenticate until an AWS administrator adds the exact immutable GitHub environment subject to the existing least-privilege role trust; local assumed-role qualification is already passing.