Skip to content

AegisFlow v0.9.1: corrective runtime and installer release

Status: prepared candidate, not yet published. Do not expect v0.9.1 downloads or container images until the release workflow completes. Source and Helm version metadata are prepared together on the candidate branch.

Changes

  • MCP requests authenticate callers and bind sessions and approval retries to their identity. Tool discovery respects configured policy.
  • Optional SQLite state retains approvals, consumed state and signed session evidence across restart. Tampered state prevents startup.
  • Required evidence and approval persistence failures stop dispatch. An outcome failure after dispatch is uncertain execution, not proof that retrying is safe.
  • CLI requests use configured credentials, reject redirects and return nonzero for failed remote reads or invalid evidence verification. Local examples require explicit dry-run selection.
  • Response and stream write errors stop delivery. Plugin updates preserve permission bits, reject symlink destinations and roll back a binary update when config persistence fails.
  • Release builds validate the tag, chart, changelog and notes before producing artifacts. The installer verifies checksums and embedded versions for either binary.
  • Documentation distinguishes supported runtime boundaries, experimental libraries and hypothetical scenarios.

Required migration

  1. Stop workloads that depend on runtime upstream credential issuance. This candidate rejects credentials.enabled: true. Revoke or rotate existing provider tokens at the provider, then remove or disable the credentials block. Disabling the broker does not revoke old tokens.
  2. Replace demonstration caller keys with separate agent and reviewer credentials. Review MCP identity and migration before reconnecting clients.
  3. Export retained evidence before upgrading. For restart persistence, configure SQLite storage and retain the same evidence signing key outside that database. Memory-only state cannot be recovered after process shutdown. Downgrading persisted state to older binaries is unsupported.
  4. Recheck allow, block, review, matching retry and rejected replay against a disposable upstream. Verify evidence after restart.
  5. If plugin configuration uses a symlink, manage its actual regular file explicitly. Plugin commands reject non-regular replacement destinations.

Detailed configuration and limits: candidate migration, runtime support, production checklist.

Candidate verification

Run from the candidate checkout:

python3 scripts/release_metadata.py v0.9.1
python3 scripts/test_release_metadata.py
bash scripts/test_install.sh
bash scripts/build_release.sh v0.9.1 /tmp/aegisflow-v0.9.1-candidate
python3 scripts/e2e_release_install.py v0.9.1 /tmp/aegisflow-v0.9.1-candidate
python3 scripts/e2e_cli.py
bash scripts/e2e_approval_security.sh

Locally installed candidate artifacts test executable versions and installer behavior. They do not validate hosted signing, SBOM generation or provenance publication. Require those checks on the final release artifacts before declaring publication complete.

Limits

Only routed traffic is governed. Standalone execution gates remain experimental libraries; editor tools that bypass the gateway are not intercepted. Runtime upstream credential issuance remains disabled. Signed evidence cannot prove unobserved actions never occurred or independently detect every omitted session or removed tail. An operator with the signing key can forge records.