Release assurance
Release assurance, without pretending provenance is complete.
This page combines the current Artax release-evidence registry, explicit release-approval records, canary rules, provenance-attestation policy, release-attestation-artifact policy, release-tracking policy, release-evidence-linkage policy, release-record-adoption policy, release-approval-authority policy, release-promotion policy, release-smoke-verification policy, release-rollback policy, release-target launch gates, and provenance-baseline posture in one public-safe view. It is a real assurance surface, not a production launch approval or signed provenance statement.
Release evidence and approval records
This page gathers release evidence, rollout gates, approval records, provenance posture, smoke checks, promotion records, and rollback targets in one place. It explains what is documented and what is still missing without turning policy files, pre-production wiring, or local evidence into a production approval claim.
Evidence records
Release evidence records tracked in the release registry.
14
Approval records
Release-target gates with explicit approval and provenance records.
2/2
Signed provenance
Release approval records that report signing artifacts or external attestation.
0/2
Canary rules
Bounded canary-rule records tied to production rollout posture.
1
Attestation policies
Provenance-attestation policy records defining required lineage and production verification posture.
2
Attestation records
Checked-in attestation artifact records. Live workflow-backed: 0. Local or synthetic proof: 2.
2
Authority records
Checked-in approval-authority records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Tracked releases
Checked-in tracked release records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Linkage records
Checked-in release evidence linkage records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Adoption records
Checked-in release record adoption records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Promotion records
Checked-in promotion records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Smoke records
Checked-in smoke verification records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Rollback targets
Checked-in trusted rollback target records. Live workflow-backed: 0. Local or synthetic proof: 1.
1
Production approvals
Release approval records that grant production launch approval.
0
Release posture
What is documented
Guarded rollout
Staging Rollout Gated Not Production. Approval state: Staging Bundle Backed Manual Rollout Only. Deployment allowed: yes.
Production launch
Production Rollout Workflow Defined Launch Blocked. Approval state: Production Rollout Workflow Defined Launch Blocked. Production ready: no.
Production timing
A healthy pre-production or production-candidate posture does not force an immediate production launch. Artax can keep validating on pre-production and devnet until the production milestone is met.
Provenance posture
Formal release approval records exist for the release targets, but only 0 records report signed provenance artifacts.
Attestation posture
2 attestation policy records define the provenance requirements, but only 0 report recorded attestation evidence.
Attestation artifact posture
3 release-attestation-artifact policy records define checked-in artifact expectations, and 2 checked-in attestation artifact records exist. Live workflow-backed: 0. Local or synthetic proof: 2.
Authority posture
2 release-approval-authority policy records define human approval and automation-reference requirements, and 1 checked-in approval-authority record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Release identity posture
2 release-tracking policy records define stable artifact-set identity rules, and 1 checked-in tracked release record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Release coherence posture
2 release-evidence-linkage policy records define cross-record artifact identity coherence, and 1 checked-in release evidence linkage record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Release adoption posture
2 release-record-adoption policy records define how generated bundle artifacts are promoted into checked-in release truth, and 1 checked-in adoption record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Promotion posture
2 release-promotion policy records define staged release promotion requirements, and 1 checked-in promotion record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Smoke posture
2 release-smoke-verification policy records define required post-deploy checks, and 1 checked-in smoke verification record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Rollback posture
2 release-rollback policy records define rollback-target expectations, and 1 checked-in trusted rollback target record exist. Live workflow-backed: 0. Local or synthetic proof: 1.
Canary posture
1 bounded canary rule describe the current production rollout ring. Approval status: Canary Rules Defined No Live Canary Smoke Or Dashboard Environment Key Record.
Release approval boundary
These records, canary rules, attestation policies, attestation-artifact policies, release-tracking policies, release-evidence-linkage policies, release-record-adoption policies, release-approval-authority policies, release-promotion policies, release-smoke-verification policies, and release-rollback policies describe current approval posture, rollout boundaries, bundle expectations, and blockers. They do not approve a production release, widen compatibility claims, or replace the actual launch gates.
Release approval records
release_approval.render_staging_rollout.bundle_backed_manual_staging
Staging approval posture
Current state
Staging Bundle Backed Manual Rollout Only
Approval mode
Manual Workflow Dispatch With Human Initiation. Scope: Staging Rollout Only.
Release and artifact identity
Release version source: Workflow Dispatch Ref Resolved To Checked Out Commit Sha. Artifact set source: Workflow Run Or Local Commit Scoped Release Artifact Set. Source revision source: Checked Out Commit Sha After Actions Checkout.
Provenance and signing
Digest source: Generated Release Evidence Bundle Sha256 Snapshots. Provenance: Per Run Bundle Generated Not Signed. Signing: Unsigned No External Attestation.
Required tracking policies
release_tracking_policy.render_staging_rollout.bundle_identity
Required authority policies
release_approval_authority.render_staging_rollout.manual_dispatch
Required promotion policies
release_promotion_policy.render_staging_rollout.explicit_stage_ladder
Required rollback policies
release_rollback_policy.render_staging_rollout.documented_ref
Required smoke policies
release_smoke_verification.render_staging_rollout.web_edge
Required attestation policies
attestation_policy.release_bundle_minimum_lineage
Required attestation-artifact policies
release_attestation_artifact.render_staging_rollout.bundle_lineage_snapshot
Execution posture
Test: Repo Devnet And Staging Checks Linked. Canary: No Separate Canary Stage Recorded. Production: Staging Only Not Production.
Required canary rules
none
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Bundle output
artifacts/release-evidence/staging/<github.run_id>/{pre-deploy,post-deploy}
Rollback target
docs/render-deployment-contract.md and docs/deployment-runbook.md
Current blockers
Attestation policy now defines required lineage fields, but current per-run release-evidence bundles are still unsigned and local-snapshot based rather than externally attested provenance.; Formal staging attestation-artifact policy now exists, but no checked-in staging attestation artifact record exists yet.; Formal staging release-evidence-linkage policy now exists, but no checked-in staging linkage record exists yet.; Formal staging release-record-adoption policy now exists, but no checked-in staging adoption record exists yet.; Formal staging approval-authority policy now exists, but no checked-in staging authority record exists yet.; Formal staging promotion policy now exists, but no checked-in staging promotion record exists yet.; Formal staging rollback policy now exists, but no checked-in trusted staging rollback target record exists yet.; Formal staging smoke-verification policy now exists, but no checked-in staging smoke verification record exists yet.; This record only documents the guarded staging rollout path and must not be used as a production launch approval.
release_approval.render_production_launch.rollout_workflow_defined_launch_blocked
Production approval posture
Current state
Production Rollout Workflow Defined Launch Blocked
Approval mode
Manual Rollout Workflow With Explicit Human Approval. Scope: Guarded Production Rollout Defined But Not Approved.
Release and artifact identity
Release version source: Workflow Dispatch Ref Resolved To Checked Out Commit Sha. Artifact set source: Workflow Run Or Local Commit Scoped Release Artifact Set. Source revision source: Checked Out Commit Sha After Actions Checkout.
Provenance and signing
Digest source: Generated Release Evidence Bundle Sha256 Snapshots. Provenance: Pre And Post Deploy Bundles Defined Not Signed. Signing: Unsigned No Production Attestation.
Required tracking policies
release_tracking_policy.render_production_launch.bundle_identity
Required authority policies
release_approval_authority.render_production_launch.manual_rollout
Required promotion policies
release_promotion_policy.render_production_launch.explicit_stage_ladder
Required rollback policies
release_rollback_policy.render_production_launch.documented_ref
Required smoke policies
release_smoke_verification.render_production_launch.web_edge
Required attestation policies
attestation_policy.release_bundle_minimum_lineage; attestation_policy.render_production_launch_signed_or_attested_release
Required attestation-artifact policies
release_attestation_artifact.render_production_launch.bundle_lineage_snapshot; release_attestation_artifact.render_production_launch.signed_or_attested_release
Execution posture
Test: Repo Devnet Production Contract Smoke And Private Dashboard Environment Key Path Linked. Canary: Canary Rules Defined No Live Canary Smoke Or Dashboard Environment Key Record. Production: Rollout Workflow Defined Launch Blocked.
Required canary rules
canary_rule.render_production_allowlisted_web_edge_rollout
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Bundle output
artifacts/release-evidence/production/<github.run_id>/{pre-deploy,post-deploy}
Rollback target
docs/render-deployment-contract.md and docs/deployment-runbook.md
Current blockers
Guarded production-candidate and production rollout workflows now exist, but no live production canary or smoke record exists yet.; The private dashboard environment-key proof is now a production launch-window requirement: production web must route devnet and mainnet-beta requests through the one production API, one signed-in account and one project must create separate cluster-bound keys, and no devnet key may be mutated into a mainnet-beta key before live approval.; Formal production attestation, release-attestation-artifact, release-tracking, release-evidence-linkage, release-record-adoption, release-approval-authority, release-smoke-verification, release-rollback, and release-promotion policies now exist, and first checked-in local or synthetic proof records now exist across the production attestation, tracking, linkage, adoption, authority, promotion, smoke-verification, and rollback families, but no signed provenance, live workflow-backed production release evidence, or nonzero production approval record exists yet.; No production compatibility certification evidence exists yet.
Canary rules
canary_rule.render_production_allowlisted_web_edge_rollout
Production canary boundary
Ring
Bounded Operator Initiated Canary
Traffic boundary
Allowlisted Review And Operator Checks Only
Rollout strategy
Manual Ref Pinned Render Hook Rollout With Post Deploy Web Smoke
Surfaces
Web Review Page; Web Operator Page; Web Dashboard Projects Page
Required evidence
evidence.production.cloud_preflight; evidence.production.render_candidate_workflow; evidence.production.dashboard_environment_key_flow_private; evidence.production.web_edge_smoke_path; evidence.production.render_rollout_workflow
Verification notes
Use the public web edge for a narrow review and operator verification ring after deploy rather than widening traffic by default.; Privately prove the dashboard environment-key path through the production web service after the one production API multi-cluster routing is configured and verified.; Treat this as a manual operator-initiated canary rule for the current production rollout path, not as proof of general production approval.
Prohibited claims
No signed provenance, formal production approval, or universal production support claim is allowed from this rule alone.; No broader compatibility or partner-support claim may be inferred from a bounded canary rule.
Attestation policies
attestation_policy.release_bundle_minimum_lineage
All Release Targets attestation policy
Stages
Staging; Production
Fulfillment
Policy Defined Release Bundles Still Unsigned
Required identity claims
Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot
Required promotion stages
Build Complete; Artifact Verified
Verification requirement
Release Bundle Digests And Selected Ref Context Must Be Recorded And Checkable Before Rollout
Rollback requirement
Rollback Targets Must Stay Versioned And Documented Until Signed Or Attested Artifacts Exist
Required before production approval
no
Attestation evidence recorded
no
Current blockers
Required lineage fields are now explicit, but no release bundle is currently signed or externally attested.
attestation_policy.render_production_launch_signed_or_attested_release
Single Release Target attestation policy
Stages
Production
Fulfillment
Policy Defined Zero Signed Or Attested Production Records
Required identity claims
Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot
Required promotion stages
Build Complete; Artifact Verified; Artifact Signed Or Attested; Candidate Tested; Canary Approved; Production Approved; Production Deployed; Post Deploy Verified
Verification requirement
Production Artifacts Must Be Signed Or Cryptographically Verifiable And Match The Intended Release Artifact
Rollback requirement
Rollback Targets Must Be Known Good Versioned Signed Or Attested Artifacts
Required before production approval
yes
Attestation evidence recorded
no
Current blockers
No signed provenance or external attestation artifact is currently recorded for production.; Production approval must remain zero until operators can verify the deployed artifact against the intended signed or attested release.
Release attestation artifact policies
release_attestation_artifact.render_staging_rollout.bundle_lineage_snapshot
Staging attestation artifact policy
Current artifact status
Artifact Policy Defined No Checked In Staging Attestation Records
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required identity claims
Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot
Verification required
no
Required before production approval
no
release_attestation_artifact.render_production_launch.bundle_lineage_snapshot
Production attestation artifact policy
Current artifact status
Artifact Policy Defined Checked In Local Or Synthetic Production Lineage Attestation Records Present
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required identity claims
Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot
Verification required
no
Required before production approval
no
release_attestation_artifact.render_production_launch.signed_or_attested_release
Production attestation artifact policy
Current artifact status
Artifact Policy Defined Zero Checked In Signed Or Attested Production Records
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required identity claims
Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot
Verification required
yes
Required before production approval
yes
Checked-in attestation artifact records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_attestation_artifact.render_production_launch.bundle_lineage_snapshot
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Kind: Release Bundle Snapshot Only. Status: Local Bundle Lineage Snapshot Recorded For Post Deploy Smoke Verified. Verification: Local Lineage Only Not Cryptographically Verified. Reference: release_bundle:production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified.
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_attestation_artifact.render_production_launch.signed_or_attested_release
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Kind: Missing Required Attestation Material. Status: Required Attestation Artifact Missing For Post Deploy Smoke Verified. Verification: Cryptographic Verification Required Not Recorded. Reference: release_bundle:production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified.
Release tracking policies
release_tracking_policy.render_staging_rollout.bundle_identity
Staging release tracking
Artifact name
render_staging_rollout_release_evidence_bundle
Artifact type
Release Evidence Bundle
Current tracking status
Tracking Policy Defined No Checked In Release Records
Required identity fields
Artifact Name; Artifact Type; Artifact Version; Source Revision; Release Evidence Origin Class; Build Pipeline Identifier; Build Timestamp; Artifact Digest; Release Channel; Signing Status; Provenance Status; Dependency Snapshot Reference
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Artifact set strategy
Stage Gate Release Ref Workflow Run Identity Without Phase
Release identity rule
One Release Version Maps To One Artifact Set Within Gate And Release Channel
Hotfix rule
Distinct Release Version Required With Documented Bypass Notes If Any
Notes
Current checked-in automation can generate phase-specific staging release-evidence bundles keyed to a stable artifact-set identity, but no checked-in staging release record ledger exists yet.
release_tracking_policy.render_production_launch.bundle_identity
Production release tracking
Artifact name
render_production_launch_release_evidence_bundle
Artifact type
Release Evidence Bundle
Current tracking status
Tracking Policy Defined Checked In Local Or Synthetic Production Release Records Present
Required identity fields
Artifact Name; Artifact Type; Artifact Version; Source Revision; Release Evidence Origin Class; Build Pipeline Identifier; Build Timestamp; Artifact Digest; Release Channel; Signing Status; Provenance Status; Dependency Snapshot Reference
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Artifact set strategy
Stage Gate Release Ref Workflow Run Identity Without Phase
Release identity rule
One Release Version Maps To One Artifact Set Within Gate And Release Channel
Hotfix rule
Distinct Release Version Required With Documented Bypass Notes If Any
Notes
Current checked-in automation can generate phase-specific production candidate or rollout bundles keyed to a stable artifact-set identity, and one checked-in local or synthetic proof production release record now exists, but no live workflow-backed production release record or signed artifact record exists yet.
Checked-in tracked release records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Bundle Generated For Post Deploy Smoke Verified. Recorded phases: Post Deploy Smoke Verified.
Release evidence linkage policies
release_evidence_linkage.render_staging_rollout.bundle_phase_consistency
Staging release evidence linkage
Current linkage status
Linkage Policy Defined No Checked In Staging Linkage Records
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required shared identity fields
Approval Record Id; Gate Id; Artifact Version; Artifact Set Id; Source Revision; Release Evidence Origin Class; Deployment Stage; Release Channel
Shared identity strategy
Approval Record Gate Artifact Version Artifact Set Source Revision Origin Class Stage And Channel Must Match Across Linked Record Families
Approval-ready bundle phase
not applicable
Linked record families
Pre Deploy Candidate: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record
Notes
Current staging bundle generation can emit phase-specific linkage records tying tracking, attestation, approval-authority, promotion, rollback, and smoke record families to one artifact set, but no checked-in staging linkage record ledger exists yet.
release_evidence_linkage.render_production_launch.bundle_phase_consistency
Production release evidence linkage
Current linkage status
Linkage Policy Defined Checked In Local Or Synthetic Production Linkage Records Present
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required shared identity fields
Approval Record Id; Gate Id; Artifact Version; Artifact Set Id; Source Revision; Release Evidence Origin Class; Deployment Stage; Release Channel
Shared identity strategy
Approval Record Gate Artifact Version Artifact Set Source Revision Origin Class Stage And Channel Must Match Across Linked Record Families
Approval-ready bundle phase
Post Deploy Smoke Verified
Linked record families
Pre Deploy Candidate: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record
Notes
Current production candidate and rollout bundle generation can emit phase-specific linkage records tying tracking, attestation, approval-authority, promotion, rollback, and smoke record families to one artifact set, and one checked-in local or synthetic proof production linkage record now exists, but no live workflow-backed production linkage record exists yet.
Checked-in release evidence linkage records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_evidence_linkage.render_production_launch.bundle_phase_consistency
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Phase: Post Deploy Smoke Verified. Families present: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record. Consistency: Linked Record Families Share Artifact Identity For Post Deploy Smoke Verified.
Release record adoption policies
release_record_adoption.render_staging_rollout.generated_bundle_import
Staging release record adoption
Current adoption status
Adoption Policy Defined No Checked In Staging Adoption Records
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required adoption evidence
Source Bundle Artifact Reference; Review Contract Artifact Reference; Generated Record Artifact References; Release Evidence Origin Class; Adoption Review Reference; Adopter Identity; Adopted Record Ids; Source Bundle Policy Version Dependencies; Current Policy Version Dependencies; Policy Version Dependency Status
Adopted record families
Pre Deploy Candidate: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record
Source artifact SHA strategy
Source Bundle And Generated Record Artifact Sha256 Must Match Before Checked In Adoption
Policy snapshot match strategy
Source Bundle Release Assurance Policy Version Dependencies Must Match Current Registry Snapshot Sha256 Before Checked In Adoption
Adoption review strategy
Human Review Reference Named Adopter And Review Contract Artifact Reference Required Before Generated Records Are Treated As Checked In Release Truth
Importer script
scripts/import-release-record-adoption.mjs
Reviewed apply script
scripts/apply-release-record-adoption.mjs
Approval-ready bundle phase
not applicable
Notes
Current staging bundle generation can emit machine-readable adoption candidates with exact bundle, record-artifact sha256, and live-versus-proof origin references, and canonical importer plus reviewed-apply paths now enforce current policy snapshot matching plus reviewed-contract artifact traceability before checked-in adoption, but no checked-in staging adoption ledger exists yet.
release_record_adoption.render_production_launch.generated_bundle_import
Production release record adoption
Current adoption status
Adoption Policy Defined Checked In Local Or Synthetic Production Adoption Records Present
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required adoption evidence
Source Bundle Artifact Reference; Review Contract Artifact Reference; Generated Record Artifact References; Release Evidence Origin Class; Adoption Review Reference; Adopter Identity; Adopted Record Ids; Source Bundle Policy Version Dependencies; Current Policy Version Dependencies; Policy Version Dependency Status
Adopted record families
Pre Deploy Candidate: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record
Source artifact SHA strategy
Source Bundle And Generated Record Artifact Sha256 Must Match Before Checked In Adoption
Policy snapshot match strategy
Source Bundle Release Assurance Policy Version Dependencies Must Match Current Registry Snapshot Sha256 Before Checked In Adoption
Adoption review strategy
Human Review Reference Named Adopter And Review Contract Artifact Reference Required Before Generated Records Are Treated As Checked In Release Truth
Importer script
scripts/import-release-record-adoption.mjs
Reviewed apply script
scripts/apply-release-record-adoption.mjs
Approval-ready bundle phase
Post Deploy Smoke Verified
Notes
Current production candidate and rollout bundle generation can emit machine-readable adoption candidates with exact bundle, record-artifact sha256, and live-versus-proof origin references, and canonical importer plus reviewed-apply paths now enforce current policy snapshot matching plus reviewed-contract artifact traceability before checked-in adoption. One checked-in local or synthetic proof production adoption record now exists, but no live workflow-backed production adoption record exists yet.
Checked-in release record adoption records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_record_adoption.render_production_launch.generated_bundle_import
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Phase: Post Deploy Smoke Verified. Adopted families: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record. Adopter: codex_user_directed. Review reference: terminal-review.user-directed-next-step.2026-04-10. Review contract: artifacts/release-evidence/synthetic/post-deploy/release-record-adoption.review.json#sha256=16c525ca0e33e66270ac55731b73687dda8e3fc9f205f9add3af852acf1dd35c. Status: Human Reviewed Generated Bundle Candidate Checked In For Post Deploy Smoke Verified.
Release approval authority policies
release_approval_authority.render_staging_rollout.manual_dispatch
Staging approval authority
Current authority status
Authority Policy Defined No Checked In Staging Authority Records
Human approval required
yes
Approver identity required before production approval
no
Approved automation reference allowed
yes
Allowed authority kinds
Workflow Dispatch Actor And Workflow Reference; Approved Workflow Reference Only; Local Manual Reference Only
Required authority evidence
Approval Mode; Approval Scope; Approval Reference; Authority Kind; Approver Identity Or Automation Reference
Authority reference strategy
Github Actor If Present Else Workflow Name And Run Id Else Local Trigger Source
Promotion policy linkage
release_promotion_policy.render_staging_rollout.explicit_stage_ladder
Notes
Current automation can snapshot staging workflow reference and optional actor identity into release bundles, but no checked-in staging approval-authority record ledger exists yet.
release_approval_authority.render_production_launch.manual_rollout
Production approval authority
Current authority status
Authority Policy Defined Checked In Local Or Synthetic Production Authority Records Present
Human approval required
yes
Approver identity required before production approval
yes
Approved automation reference allowed
yes
Allowed authority kinds
Workflow Dispatch Actor And Workflow Reference; Approved Workflow Reference Only; Local Manual Reference Only
Required authority evidence
Approval Mode; Approval Scope; Approval Reference; Authority Kind; Approver Identity Or Automation Reference
Authority reference strategy
Github Actor If Present Else Workflow Name And Run Id Else Local Trigger Source
Promotion policy linkage
release_promotion_policy.render_production_launch.explicit_stage_ladder
Notes
Current automation can snapshot production workflow reference and optional actor identity into release bundles, and one checked-in local or synthetic proof production approval-authority record now exists, but no live workflow-backed production authority record or production approval exists yet.
Checked-in approval authority records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_approval_authority.render_production_launch.manual_rollout
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Local Manual Authority Reference Captured For Post Deploy Smoke Verified. Authority reference: trigger_source:local_manual. Approval reference: trigger_source:local_manual.
Release promotion policies
release_promotion_policy.render_staging_rollout.explicit_stage_ladder
Staging promotion policy
Current promotion status
Promotion Policy Defined No Checked In Staging Promotion Records
Required promotion stages
Build Complete; Artifact Verified; Candidate Tested; Post Deploy Verified
Manual promotion stages
Artifact Signed Or Attested; Canary Approved; Production Approved; Production Deployed
Approval reference strategy
Workflow Name And Run Id Or Local Manual Trigger Source
Compatibility matrix strategy
Generated Compatibility Matrix Snapshot Reference
Policy dependency strategy
Registry Snapshot Sha256 References For Attestation Tracking Smoke Rollback And Promotion Policies
Attestation policies
attestation_policy.release_bundle_minimum_lineage
Notes
Current checked-in automation can snapshot explicit staging promotion-stage state into release bundles, but no checked-in staging promotion record ledger exists yet.
release_promotion_policy.render_production_launch.explicit_stage_ladder
Production promotion policy
Current promotion status
Promotion Policy Defined Checked In Local Or Synthetic Production Promotion Records Present
Required promotion stages
Build Complete; Artifact Verified; Artifact Signed Or Attested; Candidate Tested; Canary Approved; Production Approved; Production Deployed; Post Deploy Verified
Manual promotion stages
Artifact Signed Or Attested; Canary Approved; Production Approved
Approval reference strategy
Workflow Name And Run Id Or Local Manual Trigger Source
Compatibility matrix strategy
Generated Compatibility Matrix Snapshot Reference
Policy dependency strategy
Registry Snapshot Sha256 References For Attestation Tracking Smoke Rollback And Promotion Policies
Attestation policies
attestation_policy.release_bundle_minimum_lineage; attestation_policy.render_production_launch_signed_or_attested_release
Notes
Current checked-in automation can snapshot explicit production promotion-stage state into candidate or rollout bundles, and one checked-in local or synthetic proof production promotion record now exists, but no live workflow-backed production promotion record exists yet.
Checked-in promotion records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_promotion_policy.render_production_launch.explicit_stage_ladder
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Promotion Snapshot Generated For Post Deploy Smoke Verified. Completed stages: Build Complete; Artifact Verified; Candidate Tested; Production Deployed; Post Deploy Verified.
Release rollback policies
release_rollback_policy.render_staging_rollout.documented_ref
Staging rollback policy
Rollback target kind
Documented Release Ref And Runbook Reference
Current rollback status
Rollback Policy Defined No Checked In Trusted Staging Rollback Targets
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required rollback fields
Artifact Version; Artifact Set Id; Rollback Target Reference; Source Revision; Rollback Preparation Reference; Rollback Verification Status; Trusted Artifact Status; Rollback Operator Confirmation; Dependency Snapshot Reference
Reference strategy
Selected Release Ref Plus Checked In Staging Runbook Paths
Verification strategy
Manual Workflow Dispatch And Operator Confirmation Before Use
Trusted artifact requirement
Known Good Versioned Documented Ref Until Signed Or Attested Artifacts Exist
Rollback references
docs/render-deployment-contract.md; docs/deployment-runbook.md
Notes
Current checked-in automation can snapshot rollback references into staging release-evidence bundles, but no checked-in trusted staging rollback target records exist yet.
release_rollback_policy.render_production_launch.documented_ref
Production rollback policy
Rollback target kind
Documented Release Ref And Runbook Reference
Current rollback status
Rollback Policy Defined Checked In Local Or Synthetic Production Rollback Targets Present
Required bundle phases
Pre Deploy Candidate; Post Deploy Smoke Verified
Required rollback fields
Artifact Version; Artifact Set Id; Rollback Target Reference; Source Revision; Rollback Preparation Reference; Rollback Verification Status; Trusted Artifact Status; Rollback Operator Confirmation; Dependency Snapshot Reference
Reference strategy
Selected Release Ref Plus Checked In Production Runbook Paths
Verification strategy
Manual Workflow Dispatch And Operator Confirmation Before Use
Trusted artifact requirement
Known Good Versioned Signed Or Attested Artifact Before Production Approval
Rollback references
docs/render-deployment-contract.md; docs/deployment-runbook.md
Notes
Current checked-in automation can snapshot rollback references into production candidate or rollout release-evidence bundles, and one checked-in local or synthetic proof production rollback-target record now exists, but no live workflow-backed trusted production rollback target record or signed rollback artifact exists yet.
Checked-in trusted rollback target records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_rollback_policy.render_production_launch.documented_ref
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Rollback Reference Documented After Post Deploy Verification. Trusted artifact: Documented Ref Only Not Signed Or Attested. Reference: docs/render-deployment-contract.md and docs/deployment-runbook.md; selected_release_ref=synthetic-proof-2026-04-10.
Release smoke verification policies
release_smoke_verification.render_staging_rollout.web_edge
Staging smoke verification
Smoke evidence
evidence.staging.web_edge_smoke
Verification kind
Web Edge Post Deploy Smoke
Current verification status
Policy Defined No Checked In Staging Smoke Records
Required bundle phases
Post Deploy Smoke Verified
Required smoke checks
Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available
Operator session required
yes
Notes
Current checked-in automation can run staging web-edge smoke and emit a per-run smoke summary artifact, but no checked-in staging smoke verification records exist yet.
release_smoke_verification.render_production_launch.web_edge
Production smoke verification
Smoke evidence
evidence.production.web_edge_smoke_path
Verification kind
Web Edge Post Deploy Smoke
Current verification status
Policy Defined Checked In Local Or Synthetic Production Smoke Records Present
Required bundle phases
Post Deploy Smoke Verified
Required smoke checks
Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available
Operator session required
yes
Notes
Current checked-in automation can run production web-edge smoke and emit a per-run smoke summary artifact, and one checked-in local or synthetic proof production smoke verification record now exists, but no live workflow-backed production smoke verification record exists yet.
Checked-in smoke verification records
production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_smoke_verification.render_production_launch.web_edge
Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Post Deploy Smoke Verified. Web base URL: https://staging.example.invalid. Verified checks: Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available.
Current release-evidence records
evidence.repo.ci_monorepo_validation
Monorepo CI validation
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
repo; staging; production
Provenance status
Preproduction Workflow Only
Production grade
no
Notes
This proves repo integrity and generated-doc freshness for a checked-out commit. It is not a production release bundle.
evidence.repo.provenance_baseline_generation
Generated provenance baseline for build and rollout inputs
Kind
Generated Provenance Baseline
Status
Implemented Initial
Stages
repo; staging; production
Provenance status
Local Hash Baseline Only
Production grade
no
Notes
This captures exact hashes of the checked-in build and rollout inputs. It improves traceability, but it is not a signed or externally attested provenance bundle.
evidence.local.production_like_rehearsal
Local production-like Docker rehearsal
Kind
Local Rehearsal
Status
Implemented Initial
Stages
local
Provenance status
Not A Release Bundle
Production grade
no
Notes
This is the strongest localhost rehearsal path and should stay local-first, but it does not certify staging or production support.
evidence.devnet.live_verification
Live devnet verification workflow
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
devnet; staging; production
Provenance status
Preproduction Workflow Only
Production grade
no
Notes
This captures live rehearsal of the supported transfer ladder and current swap-review boundaries on Solana devnet.
evidence.staging.cloud_preflight
Cloud env-contract preflight for staging
Kind
Preflight Script
Status
Implemented Initial
Stages
staging
Provenance status
Pre Deploy Contract Check Only
Production grade
no
Notes
This validates the checked-in staging env contract before any Render deploy hooks are triggered.
evidence.staging.web_edge_smoke
Public web-edge staging smoke verification
Kind
Post Deploy Smoke
Status
Implemented Initial
Stages
staging
Provenance status
Post Deploy Smoke Only
Production grade
no
Notes
This verifies the intended private-API web-edge topology after a staging deploy and now unlocks the deliberate staging site-access gate before checking the bounded public-looking surfaces.
evidence.staging.extension_popup_runtime_acceptance
Extension popup runtime acceptance export
Kind
Browser Runtime Acceptance Export
Status
Implemented Initial
Stages
local; staging
Provenance status
Manual Browser Runtime Export Only
Production grade
no
Notes
This captures trusted browser-side runtime evidence for the preview extension popup-review surface from the install runtime lab. It improves local and staging acceptance truth, but it is not a production-grade workflow or broad browser-device certification.
evidence.staging.render_rollout_workflow
Render staging rollout workflow
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
staging
Provenance status
Staging Rollout Only
Production grade
no
Notes
This is a guarded staging rollout path. It is not a production launch workflow and must not be described as production release evidence.
evidence.production.cloud_preflight
Cloud env-contract preflight for production
Kind
Preflight Script
Status
Implemented Initial
Stages
production
Provenance status
Pre Deploy Contract Check Only
Production grade
no
Notes
This validates the checked-in production env contract before any future production deploy path is considered. It does not prove a live production rollout.
evidence.production.render_candidate_workflow
Render production-candidate verification workflow
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
production
Provenance status
Production Candidate Bundle Only
Production grade
no
Notes
This is a guarded production-candidate verification path. It validates the checked-in production contract and generates a release-evidence bundle, but it does not trigger production deploy hooks, prove live smoke, or grant production launch approval.
evidence.production.dashboard_environment_key_flow_private
Private production dashboard environment-key proof
Kind
Private Dashboard Acceptance Proof
Status
Defined Launch Window Manual Proof Pending
Stages
production
Provenance status
Production Manual Private Acceptance Defined Not Executed
Production grade
no
Notes
This proof is intentionally launch-window only because it exercises the one production API multi-cluster dashboard architecture. It must verify one-login project-level key management, separate devnet and mainnet-beta API-key scope, and no cross-cluster key mutation. It must not be treated as satisfied by docs alone or by a direct staging-web test.
evidence.platform.signer_boundary_workflow
Signer-boundary verification workflow
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
staging; production
Provenance status
Live Runtime Boundary Proof Only
Production grade
no
Notes
This workflow captures workflow-backed signer-boundary evidence for the selected environment by proving live signer `/health` and authenticated `/v1/solana/keys` consistency against the expected key reference and signer address. It does not deploy the signer, prove web-edge rollout health, or grant production launch approval.
evidence.production.web_edge_smoke_path
Production web-edge smoke verification path
Kind
Post Deploy Smoke Path
Status
Implemented Initial
Stages
production
Provenance status
Production Smoke Path Defined Not Executed
Production grade
no
Notes
This defines the intended production web-edge smoke contract for a guarded rollout workflow, but it is not itself a recorded live production smoke result or launch approval.
evidence.production.render_rollout_workflow
Render production rollout workflow
Kind
Github Actions Workflow
Status
Implemented Initial
Stages
production
Provenance status
Production Rollout Workflow Defined Not Approved
Production grade
no
Notes
This is a guarded production rollout path with pre-deploy bundle generation, deploy-hook triggering, and post-deploy web-edge smoke steps. It does not by itself grant production approval, live canary approval, or signed provenance.
Release-target gates
gate.release_target.render_staging_rollout (staging)
Readiness: Staging Rollout Gated Not Production. Deployment allowed: yes. Production ready: no. Approval: Staging Bundle Backed Manual Rollout Only. Blockers: none.
gate.release_target.render_production_launch (production)
Readiness: Production Rollout Workflow Defined Launch Blocked. Deployment allowed: no. Production ready: no. Approval: Production Rollout Workflow Defined Launch Blocked. Blockers: Guarded production-candidate and production rollout workflows now exist, but no live production canary or smoke evidence exists yet.; Private dashboard environment-key proof is launch-window work: it must be run through the production web service against the one production API multi-cluster architecture, and it must prove one signed-in account and one project can hold separate devnet and mainnet-beta keys without cross-cluster key mutation.; A formal production approval record, canary rule, attestation policy, release-attestation-artifact policy, release-tracking policy, release-evidence-linkage policy, release-record-adoption policy, release-approval-authority policy, release-promotion policy, release-smoke-verification policy, and release-rollback policy now exist, and first checked-in local or synthetic proof records now exist across the production attestation, tracking, linkage, adoption, authority, promotion, smoke-verification, and rollback families, but no signed provenance, live workflow-backed production release evidence, or nonzero production approval record exists yet.; No production compatibility certification evidence exists yet.; Before live public production, a full repo security review must cover every checked-in line of code and unresolved trust-critical findings must block launch..
Provenance baseline scope
supply_chain.root_npm_workspace_lockfile
Scope: Repo Build. Control state: Lockfile Pinned Known Audit Advisories Reviewed Not Attested. Criticality: Critical. Workspace dependency resolution is anchored by package-lock.json. npm audit still reports transitive moderate/high advisories through the Solana client stack, Next's nested PostCSS dependency, and rpc-websockets/uuid without a non-breaking npm audit fix path. Those advisories are now recorded in registries/supply-chain/npm-audit-advisory-exceptions.registry.json and checked by npm run check:npm-audit-posture; any unknown, expired, or critical advisory remains a launch blocker. This is still not a signed production provenance bundle.
supply_chain.github_actions_workflows
Scope: Repo Validation And Release. Control state: Workflow Defined Not Attested. Criticality: Critical. These workflows currently define CI, devnet verification, staging rollout, signer-boundary verification, production-candidate verification, and a guarded production rollout path. They are versioned and reviewable, but not yet backed by signed release provenance.
supply_chain.node20_alpine_container_bases
Scope: Container Build. Control state: Tag Pinned Not Digest Pinned. Criticality: Critical. Current build and runtime images use node:20-alpine by tag. That is consistent and local-first, but production provenance should pin digests.
supply_chain.local_compose_infra_images
Scope: Local Rehearsal. Control state: Tag Pinned Local Rehearsal Only. Criticality: High. Local rehearsal currently depends on postgres:16-alpine and redis:7-alpine images. This is acceptable for localhost rehearsal, not production provenance.
supply_chain.render_blueprint_and_env_contract
Scope: Staging And Production Rollout. Control state: Versioned Contract Preflight Checked. Criticality: Critical. This is the real checked-in cloud contract, including the separate signer env contract. It is gated before staging rollout, signer-boundary verification, the production-candidate workflow, and the guarded production rollout workflow, but it is not yet a signed production release-evidence bundle.
supply_chain.release_gate_and_provenance_scripts
Scope: Staging And Production Rollout. Control state: Repo Local Controls Only. Criticality: Critical. These scripts keep registry truth, generated support truth, provenance baseline generation, release bundle generation, canary rule checks, attestation-policy checks, release-tracking checks, release-promotion checks, release-smoke-verification checks, release-rollback checks, and rollout or approval gate checks executable in local and CI flows.
Read next
Trust
Return to the public-safe trust overview that links to this bounded release-assurance layer.
OpenRead next
Compatibility
See how compatibility certification remains blocked alongside production release readiness.
OpenRead next
Status
Read the bounded public status page without confusing runtime posture with release assurance.
OpenRead next
Support
Use the current support and disclosure path if you need to report release or trust-surface issues.
OpenRead next
Developers
Inspect the current API, SDK, and rollout docs that these assurance records still bound.
Open