Skip to content

Release Verification

Use this checklist before trusting a public release in a customer-owned cluster.

Set the release and repository once:

export RELEASE=v0.5.1
export REPOSITORY=RamazanKara/agentworkflows
export IMAGE_REPO=ghcr.io/ramazankara/agentworkflows
export RELEASE_IDENTITY="https://github.com/$REPOSITORY/.github/workflows/release.yml@refs/tags/$RELEASE"

Helm OCI Charts

Tag builds publish each chart to oci://$IMAGE_REPO/charts.

helm pull "oci://$IMAGE_REPO/charts/inference-gateway" --version "${RELEASE#v}"
helm pull "oci://$IMAGE_REPO/charts/rag-service" --version "${RELEASE#v}"
helm pull "oci://$IMAGE_REPO/charts/agent-workspace" --version "${RELEASE#v}"

Render the downloaded chart before installing:

helm template verify-inference "inference-gateway-${RELEASE#v}.tgz" \
  --values deploy/clusters/customer/values/inference-gateway.yaml >/tmp/inference.yaml

Image Signatures

Release images are signed by digest with Cosign in GitHub Actions.

cosign verify "$IMAGE_REPO/inference-gateway:$RELEASE" \
  --certificate-identity "$RELEASE_IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

cosign verify "$IMAGE_REPO/rag-service:$RELEASE" \
  --certificate-identity "$RELEASE_IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Release images are also multi-arch (linux/amd64 and linux/arm64); the signature covers the manifest list, so the same cosign verify works on Apple Silicon and arm64 (Graviton/Ampere) clusters.

Chart Signatures

Helm chart OCI artifacts are cosign-signed by digest in the same release workflow as the images.

cosign verify "$IMAGE_REPO/charts/inference-gateway:${RELEASE#v}" \
  --certificate-identity "$RELEASE_IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

cosign verify "$IMAGE_REPO/charts/rag-service:${RELEASE#v}" \
  --certificate-identity "$RELEASE_IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

cosign verify "$IMAGE_REPO/charts/agent-workspace:${RELEASE#v}" \
  --certificate-identity "$RELEASE_IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Chart OCI tags drop the leading v (${RELEASE#v}) to match the chart version, while runtime image tags keep it.

Release Files

Download the release files into a new directory and check them:

mkdir -p "release-files/$RELEASE"
gh release download "$RELEASE" --repo "$REPOSITORY" --dir "release-files/$RELEASE"
(
  cd "release-files/$RELEASE"
  sha256sum --check sdk-checksums.txt
  cosign verify-blob chart-release-manifest.json \
    --bundle chart-release-manifest.sigstore.json \
    --certificate-identity "$RELEASE_IDENTITY" \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com
)

sdk-checksums.txt covers the Python wheel, source archive and TypeScript package. The signed chart manifest records each chart package and the image digests it embeds. Images are built from the tagged commit on GitHub-hosted runners; the release workflow does not publish SBOM or provenance attestations. Run make image-scan locally if you need a vulnerability report before deploying.

Strict Evidence

Strict release evidence must be generated from current artifacts, not sample evidence:

make validate-full
make image-scan
make supply-chain-check
make loadtest-local
make evidence
make release-gate-strict

For a live customer-style validation path, run the local cluster checks and generate live evidence:

QUICKSTART_DIRECT_APPLY=1 make quickstart
make trace-smoke
make tenant-smoke
make agent-smoke
make evidence LIVE=1

Record the command output, generated evidence paths under results/, image digests, chart versions, and GitHub Actions run URL in the release notes.