diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml index 742deec4..5ba85c3b 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.yml +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -29,7 +29,7 @@ body: id: version attributes: label: Brewlet version - placeholder: v0.4.0 + placeholder: v0.5.0 validations: required: true - type: textarea diff --git a/.github/workflows/site-pages.yml b/.github/workflows/site-pages.yml index b263efa1..5ec365bb 100644 --- a/.github/workflows/site-pages.yml +++ b/.github/workflows/site-pages.yml @@ -60,7 +60,7 @@ jobs: # registry pulls; the smoke script isolates saved registry credentials. env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: ./site/scripts/verify-release-artifacts.sh 0.4.0 + run: ./site/scripts/verify-release-artifacts.sh 0.5.0 deploy: needs: [release-smoke, site-contracts] diff --git a/README.md b/README.md index 9666d681..ae259dbc 100644 --- a/README.md +++ b/README.md @@ -108,7 +108,7 @@ installs `brewlet` to `$HOME/.local/bin` by default. No Go toolchain or GitHub authentication is required: ```bash -export BREWLET_VERSION="0.4.0" +export BREWLET_VERSION="0.5.0" curl -fsSL https://brewlet.sh/install.sh | sh export PATH="$HOME/.local/bin:$PATH" brewlet version @@ -160,7 +160,7 @@ Install the published chart on your disposable cluster: ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 \ + --version 0.5.0 \ --namespace brewlet \ --create-namespace \ --set provisioner.pools="{java-workers}" \ diff --git a/docs/building-and-publishing.md b/docs/building-and-publishing.md index 84be81e3..da2bd83d 100644 --- a/docs/building-and-publishing.md +++ b/docs/building-and-publishing.md @@ -157,7 +157,7 @@ exact packaged `BOOT-INF/lib/*.jar` entries, not a second dependency resolution: ```bash # One-off: enable layering on the command line -mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \ +mvn clean package sh.brewlet:brewlet-maven-plugin:0.5.0:push \ -Dbrewlet.image=registry.example.com/team/app:1.4.2 \ -Dbrewlet.layered=true ``` @@ -166,7 +166,7 @@ mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \ sh.brewlet brewlet-maven-plugin - 0.4.0 + 0.5.0 registry.example.com/team/app:${project.version} true @@ -323,20 +323,20 @@ with override guidance instead of silently selecting the build machine's JDK. See the [complete inference precedence](https://github.com/microsoft/brewlet/blob/main/maven-plugin/README.md#jdk-inference). Download the released plugin JAR and POM from -the [GitHub release](https://github.com/microsoft/brewlet/releases/tag/v0.4.0) and +the [GitHub release](https://github.com/microsoft/brewlet/releases/tag/v0.5.0) and install them once in your local Maven repository: ```bash -curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.4.0/brewlet-maven-plugin-0.4.0.jar -curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.4.0/brewlet-maven-plugin-0.4.0.pom +curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.5.0/brewlet-maven-plugin-0.5.0.jar +curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.5.0/brewlet-maven-plugin-0.5.0.pom mvn org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \ - -Dfile=brewlet-maven-plugin-0.4.0.jar \ - -DpomFile=brewlet-maven-plugin-0.4.0.pom + -Dfile=brewlet-maven-plugin-0.5.0.jar \ + -DpomFile=brewlet-maven-plugin-0.5.0.pom ``` ```bash # Build the fat JAR and push it as a Brewlet OCI artifact in one line: -mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \ +mvn clean package sh.brewlet:brewlet-maven-plugin:0.5.0:push \ -Dbrewlet.image=registry.example.com/team/app:1.4.2 ``` @@ -346,7 +346,7 @@ Or configure publishing once in `pom.xml` and bind `push` to the lifecycle: sh.brewlet brewlet-maven-plugin - 0.4.0 + 0.5.0 registry.example.com/team/app:${project.version} 21 diff --git a/docs/cli-reference.md b/docs/cli-reference.md index fafe2c4d..fb55a51a 100644 --- a/docs/cli-reference.md +++ b/docs/cli-reference.md @@ -11,7 +11,7 @@ export PATH="$HOME/.local/bin:$PATH" brewlet version ``` -The installer selects the latest release by default. Set `BREWLET_VERSION=0.4.0` +The installer selects the latest release by default. Set `BREWLET_VERSION=0.5.0` to pin a release or `BREWLET_INSTALL_DIR=/custom/bin` to change the destination. You can instead build the CLI with `make binaries` (producing `./bin/brewlet`). @@ -337,7 +337,7 @@ Print the release version embedded in the binary: ```bash brewlet version -# 0.4.0 +# 0.5.0 ``` Source builds without release linker flags print `dev`. diff --git a/docs/configuration.md b/docs/configuration.md index 7386ff16..dae2a83d 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -113,7 +113,7 @@ provisioner: ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 -f values-production.yaml + --version 0.5.0 -f values-production.yaml ``` > JDKs and launchers are always obtained **copy-from-image** from explicit, @@ -208,7 +208,7 @@ When you install via Helm, the chart populates them for you. | Flag | Default | Meaning | |---|---|---| | `--namespace` | `brewlet` | Namespace the provisioner DaemonSet is managed in. | -| `--provisioner-image` | `ghcr.io/microsoft/brewlet-node-provisioner:0.4.0` | Image the DaemonSet runs. | +| `--provisioner-image` | `ghcr.io/microsoft/brewlet-node-provisioner:0.1.0` | Image the DaemonSet runs. Published Helm charts override this with the release image digest. | | `--allowed-source-mirror-hosts` | *(empty)* | Comma-separated exact destination registry hosts approved for NodeProfile runtime-source rewrites. Configure the same value on manager and admission; empty disables mirrors. | | `--leader-elect` | `false` | Enable leader election for HA. | | `--metrics-bind-address` | `0` | Metrics endpoint; `0` disables it. | @@ -218,7 +218,7 @@ When you install via Helm, the chart populates them for you. ```bash ./bin/operator --namespace=brewlet \ - --provisioner-image=ghcr.io/microsoft/brewlet-node-provisioner:0.4.0 \ + --provisioner-image=ghcr.io/microsoft/brewlet-node-provisioner:0.5.0 \ --allowed-source-mirror-hosts=registry.internal.example.com kubectl apply -f nodeprofile.yaml ``` diff --git a/docs/getting-started.md b/docs/getting-started.md index cc317be2..41b57174 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -33,14 +33,14 @@ the matching release archive, and verifies its SHA-256 checksum before installing it: ```bash -export BREWLET_VERSION="0.4.0" +export BREWLET_VERSION="0.5.0" curl -fsSL https://brewlet.sh/install.sh | sh export PATH="$HOME/.local/bin:$PATH" brewlet version ``` -The last command must print `0.4.0`. +The last command must print `0.5.0`. Without `BREWLET_VERSION`, the installer selects the latest release. Set `BREWLET_INSTALL_DIR` to choose a directory other than `$HOME/.local/bin`. @@ -78,7 +78,7 @@ mkdir -p "$BREWLET_WORK" brewlet version ``` -The CLI reports the source build's version, which need not be `0.4.0`. Continue +The CLI reports the source build's version, which need not be `0.5.0`. Continue at step 2 from this checkout. ## 2. Build the example @@ -163,7 +163,7 @@ and Linux; executing the bundle with `runc` is a Linux node operation. ## What you proved -- Brewlet came from the checksum-verified v0.4.0 release or your optional +- Brewlet came from the checksum-verified v0.5.0 release or your optional source build. - The application payload contains only the JAR and launch metadata. - A node-resident JDK can run the packaged application directly. diff --git a/docs/installation.md b/docs/installation.md index 10bd9cd5..6e56312a 100644 --- a/docs/installation.md +++ b/docs/installation.md @@ -46,7 +46,7 @@ section. Brewlet publishes version-aligned multi-architecture component images and an OCI Helm chart. A published chart records the **immutable digest** of each component -image it was built against, so installing chart `0.4.0` resolves +image it was built against, so installing chart `0.5.0` resolves `ghcr.io/microsoft/brewlet-operator@sha256:…` rather than a tag that could later be repointed. Charts packaged from a source checkout have no recorded digests and fall back to the shared `images.tag`. @@ -113,7 +113,7 @@ store, verify everything for a release in one step: ```bash git clone https://github.com/microsoft/brewlet.git cd brewlet -./scripts/verify-release-provenance.sh 0.4.0 +./scripts/verify-release-provenance.sh 0.5.0 ``` The script checks that each image, the chart, and every release asset was built @@ -125,12 +125,12 @@ To verify a single artifact directly: ```bash # A component image, straight from the registry. -gh attestation verify oci://ghcr.io/microsoft/brewlet-operator:0.4.0 \ +gh attestation verify oci://ghcr.io/microsoft/brewlet-operator:0.5.0 \ --repo microsoft/brewlet \ --signer-workflow microsoft/brewlet/.github/workflows/release.yml # A downloaded CLI archive. -gh attestation verify brewlet_0.4.0_linux_amd64.tar.gz \ +gh attestation verify brewlet_0.5.0_linux_amd64.tar.gz \ --repo microsoft/brewlet \ --signer-workflow microsoft/brewlet/.github/workflows/release.yml ``` @@ -183,7 +183,7 @@ Install the released chart: ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 \ + --version 0.5.0 \ --namespace brewlet \ --create-namespace \ --set provisioner.pools="{java-workers}" \ diff --git a/docs/managed-dependency-bundles.md b/docs/managed-dependency-bundles.md index 4af4a597..d441252d 100644 --- a/docs/managed-dependency-bundles.md +++ b/docs/managed-dependency-bundles.md @@ -90,7 +90,7 @@ owned by the application team. sh.brewlet brewlet-maven-plugin - 0.4.0 + 0.5.0 registry.example.com/platform/java-deps/spring-web:2026.08 com.example.platform:approved-spring-bom:2026.08 @@ -130,7 +130,7 @@ owned by the application team. sh.brewlet brewlet-maven-plugin - 0.4.0 + 0.5.0 registry.example.com/apps/orders:${project.version} registry.example.com/platform/java-deps/spring-web:2026.08 diff --git a/docs/runtime-metrics.md b/docs/runtime-metrics.md index 6b06e8d6..eb90072c 100644 --- a/docs/runtime-metrics.md +++ b/docs/runtime-metrics.md @@ -41,7 +41,7 @@ Install or upgrade Brewlet with the values file: ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 \ + --version 0.5.0 \ --values metrics-values.yaml \ --set provisioner.pools="{java-workers}" ``` diff --git a/docs/workshops/developers.md b/docs/workshops/developers.md index e6deba58..68e96a8b 100644 --- a/docs/workshops/developers.md +++ b/docs/workshops/developers.md @@ -14,7 +14,7 @@ Ask the Ops participant for: export BREWLET_CONTEXT="" export BREWLET_NAMESPACE="" export BREWLET_JDK="21" -export BREWLET_VERSION="0.4.0" +export BREWLET_VERSION="0.5.0" export BREWLET_REGISTRY="/" ``` diff --git a/docs/workshops/index.md b/docs/workshops/index.md index 6b324e2e..4a2ca7ea 100644 --- a/docs/workshops/index.md +++ b/docs/workshops/index.md @@ -25,7 +25,7 @@ The Ops workshop installs the released chart and CLI directly. The Dev workshop uses the example application from the matching release tag: ```bash -git clone --depth 1 --branch v0.4.0 https://github.com/microsoft/brewlet.git +git clone --depth 1 --branch v0.5.0 https://github.com/microsoft/brewlet.git cd brewlet ``` diff --git a/docs/workshops/operations.md b/docs/workshops/operations.md index b25c20fa..3132ab4c 100644 --- a/docs/workshops/operations.md +++ b/docs/workshops/operations.md @@ -29,7 +29,7 @@ Do not use a production or shared cluster for this preproduction workshop. Set the Brewlet release and application registry used by both workshop parts: ```bash -export BREWLET_VERSION="0.4.0" +export BREWLET_VERSION="0.5.0" export BREWLET_REGISTRY="/" ``` @@ -168,7 +168,7 @@ Give the developer: | Namespace | Namespace where the developer may deploy | | RuntimeClass | `brewlet` | | Supported JDK | `21` in this workshop | -| Brewlet version | `0.4.0` | +| Brewlet version | `0.5.0` | | Registry prefix | Repository where the developer can push OCI images | | Pull secret | Required only when the registry is private | diff --git a/kubernetes/README.md b/kubernetes/README.md index f1a99b79..c1116d19 100644 --- a/kubernetes/README.md +++ b/kubernetes/README.md @@ -19,7 +19,7 @@ documentation lives in [`docs/`](../docs/). ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 \ + --version 0.5.0 \ --namespace brewlet \ --create-namespace \ --set provisioner.pools="{java-workers}" diff --git a/kubernetes/charts/brewlet/README.md b/kubernetes/charts/brewlet/README.md index 87d1dd52..a4464595 100644 --- a/kubernetes/charts/brewlet/README.md +++ b/kubernetes/charts/brewlet/README.md @@ -50,7 +50,7 @@ runtime catalog. Name the node pool the privileged provisioner may modify: ```bash helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \ - --version 0.4.0 \ + --version 0.5.0 \ --namespace brewlet \ --create-namespace \ --set provisioner.pools="{java-workers}" \ diff --git a/scripts/verify-release-provenance.sh b/scripts/verify-release-provenance.sh index 24fd52d2..bebcc9db 100755 --- a/scripts/verify-release-provenance.sh +++ b/scripts/verify-release-provenance.sh @@ -7,7 +7,7 @@ # # Consumers can run this against any published release: # -# ./scripts/verify-release-provenance.sh 0.4.0 +# ./scripts/verify-release-provenance.sh 0.5.0 # # It is also the release smoke test: the release workflow runs it against the # version it just published, so a release that fails to produce verifiable @@ -23,7 +23,7 @@ IMAGES=(brewlet-operator brewlet-admission brewlet-node-provisioner) usage() { echo "usage: $0 " >&2 - echo " version: release version without the v prefix, e.g. 0.4.0" >&2 + echo " version: release version without the v prefix, e.g. 0.5.0" >&2 } version="${1:-}" diff --git a/site/README.md b/site/README.md index 5454d8f2..4ffa2dd5 100644 --- a/site/README.md +++ b/site/README.md @@ -77,7 +77,7 @@ Before publishing installation guidance, run the same release smoke test as the Pages workflow: ```bash -./site/scripts/verify-release-artifacts.sh 0.4.0 +./site/scripts/verify-release-artifacts.sh 0.5.0 ``` It requires `curl`, Maven, JDK 21+, Helm, Docker CLI, and an authenticated diff --git a/site/index.html b/site/index.html index 661248bc..f0fb455c 100644 --- a/site/index.html +++ b/site/index.html @@ -123,7 +123,7 @@

Ship the JAR, not the runtime

$ brewlet push target/app.jar demo/app:1.4.2 --store ./oci --format image # Publish with the released plugin installed in the quick start below: -$ mvn package sh.brewlet:brewlet-maven-plugin:0.4.0:push \ +$ mvn package sh.brewlet:brewlet-maven-plugin:0.5.0:push \ -Dbrewlet.image=registry.example.com/team/app:1.4.2 # Deploy it — one Brewlet-specific line. @@ -408,7 +408,7 @@

Try Brewlet locally

terminal
# Install the CLI (the installer verifies the release checksum)
-$ export BREWLET_VERSION="0.4.0"
+$ export BREWLET_VERSION="0.5.0"
 $ curl -fsSL https://brewlet.sh/install.sh | sh
 $ export PATH="$HOME/.local/bin:$PATH"
 $ brewlet version
@@ -420,9 +420,9 @@ 

Try Brewlet locally

# Package, inspect, and run from a local OCI store $ brewlet push integration-tests/fixtures/demo-app/target/app.jar \ - demo/hello:0.4.0 --store ./oci --format artifact -$ brewlet inspect demo/hello:0.4.0 --store ./oci -$ brewlet run demo/hello:0.4.0 --store ./oci
+ demo/hello:0.5.0 --store ./oci --format artifact +$ brewlet inspect demo/hello:0.5.0 --store ./oci +$ brewlet run demo/hello:0.5.0 --store ./oci

Stop the app with Ctrl+C, then install the released Maven plugin to package a local image. See release verification for checksums and build provenance. Use the plugin's push goal with a registry you control when you are ready to publish.

@@ -437,7 +437,7 @@

Try Brewlet locally

# Build a local OCI layout for the example app $ mvn -f integration-tests/fixtures/demo-app/pom.xml package \ "sh.brewlet:brewlet-maven-plugin:${BREWLET_VERSION}:build" \ - -Dbrewlet.image=demo/hello:0.4.0 + -Dbrewlet.image=demo/hello:0.5.0
Open the full quick start diff --git a/site/scripts/test_release_artifacts.py b/site/scripts/test_release_artifacts.py index a11c1897..5c9dcd1a 100644 --- a/site/scripts/test_release_artifacts.py +++ b/site/scripts/test_release_artifacts.py @@ -15,7 +15,7 @@ ROOT = Path(__file__).resolve().parents[2] DIGEST = "0123456789abcdef" * 4 -VERSION = "0.4.0" +VERSION = "0.5.0" # Transport/workload stand-ins fail on unrecognized commands. Helm still # reads/renders the actual packaged chart, with synthetic release image pins. diff --git a/site/scripts/test_site_contracts.py b/site/scripts/test_site_contracts.py index 9aacebd4..400f0a68 100644 --- a/site/scripts/test_site_contracts.py +++ b/site/scripts/test_site_contracts.py @@ -119,7 +119,7 @@ def test_cli_examples_explicitly_use_local_stores(self): def test_quickstart_uses_released_cli_plugin_and_matching_example_source(self): blocks = "\n".join(block for section, block in self.page.blocks if section == "quickstart") - self.assertIn('export BREWLET_VERSION="0.4.0"', blocks) + self.assertIn('export BREWLET_VERSION="0.5.0"', blocks) self.assertIn("curl -fsSL https://brewlet.sh/install.sh | sh", blocks) self.assertLess(blocks.index("export BREWLET_VERSION"), blocks.index("install.sh")) self.assertIn('export PATH="$HOME/.local/bin:$PATH"', blocks) @@ -143,7 +143,7 @@ def test_documented_quickstarts_use_the_release_installer_by_default(self): with self.subTest(document=filename): document = (ROOT / filename).read_text(encoding="utf-8") primary_path = document.split("### Alternative: build from source")[0] - self.assertIn('export BREWLET_VERSION="0.4.0"', primary_path) + self.assertIn('export BREWLET_VERSION="0.5.0"', primary_path) self.assertIn("curl -fsSL https://brewlet.sh/install.sh | sh", primary_path) self.assertLess(primary_path.index("export BREWLET_VERSION"), primary_path.index("install.sh")) diff --git a/site/scripts/verify-release-artifacts.sh b/site/scripts/verify-release-artifacts.sh index 087236cb..b9f603a5 100755 --- a/site/scripts/verify-release-artifacts.sh +++ b/site/scripts/verify-release-artifacts.sh @@ -4,7 +4,7 @@ set -euo pipefail -version="${1:-0.4.0}" +version="${1:-0.5.0}" # Releases from this version on publish build provenance and a digest-pinned # chart. Older releases predate that workflow and are verified by checksum only. # Keep this at or below the version the Pages workflow verifies, otherwise diff --git a/specs/README.md b/specs/README.md index 0ba53705..ff14862d 100644 --- a/specs/README.md +++ b/specs/README.md @@ -16,9 +16,9 @@ requirements by section using the existing `§N` convention (for example, `§4.2 The `**Version:**` header in `SPECIFICATION.md` tracks the Brewlet release version without the `v` prefix, including any prerelease suffix. Before creating a release tag or dispatching the release workflow, update and commit this header to match -the intended release (for example, `0.4.0` for `v0.4.0`). Check it locally with -`bash scripts/check-release-version.sh 0.4.0` from the repository root, replacing -`0.4.0` with the intended version. The release workflow refuses to publish if the +the intended release (for example, `0.5.0` for `v0.5.0`). Check it locally with +`bash scripts/check-release-version.sh 0.5.0` from the repository root, replacing +`0.5.0` with the intended version. The release workflow refuses to publish if the checked-out specification does not match. Public reference contracts: diff --git a/specs/SPECIFICATION.md b/specs/SPECIFICATION.md index fcdc54f2..71862759 100644 --- a/specs/SPECIFICATION.md +++ b/specs/SPECIFICATION.md @@ -1,6 +1,6 @@ # Brewlet — The JVM analogue to SpinKube -**Version:** 0.4.0 +**Version:** 0.5.0 **Audience:** Platform engineers, Kubernetes operators, JVM platform owners