Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
88 commits
Select commit Hold shift + click to select a range
bbb504a
chore(packaging): add validated packaging wrappers and preflight checks
krishna-santosh Sep 4, 2026
a91eb88
fix(packaging): correct deb and rpm dependencies and recommendations
krishna-santosh Sep 4, 2026
a765924
fix(packaging): overhaul systemd lifecycle handling in maintainer scr…
krishna-santosh Sep 4, 2026
24e2aa8
test(packaging): add maintainer script unit and vm lifecycle harnesses
krishna-santosh Sep 4, 2026
c8098fd
fix(packaging): harden smoke test for static units and failed state
krishna-santosh Sep 4, 2026
544c06c
docs(packaging): document packaging requirements and lifecycle behavior
krishna-santosh Sep 4, 2026
ee029c4
build: introduce distro-aware Go wrapper
krishna-santosh Sep 4, 2026
8f56070
feat(platform)!: replace PackageKit with distro-native update providers
krishna-santosh Sep 4, 2026
f055d23
feat!: wire UpdateService through sessiond, bridge and gateway
krishna-santosh Sep 4, 2026
696567e
feat(api)!: revise update contracts for full-system preview and SSE l…
krishna-santosh Sep 4, 2026
7efb3d9
refactor(dashboard)!: adopt full-system updates and SSE progress stream
krishna-santosh Sep 4, 2026
9d1108d
chore(packaging): emit eight distro-specific packages with per-distro…
krishna-santosh Sep 4, 2026
eed525c
docs: describe distro-native update and multi-distro packaging
krishna-santosh Sep 4, 2026
44dac96
feat(platform)!: root file operations with openat2, paginated list, s…
krishna-santosh Sep 5, 2026
6f60c3e
feat(platform): split firewall runtime and persistent inventory
krishna-santosh Sep 5, 2026
1fb706a
fix(platform): harden SELinux and AppArmor reads and mutations
krishna-santosh Sep 5, 2026
8c2486d
feat(network): gate mutations behind D-Bus checkpoints with reconnect…
krishna-santosh Sep 5, 2026
0ea1a83
fix(platform): reap journal children, stabilize log IDs, track mount …
krishna-santosh Sep 5, 2026
9947da4
fix(sessiond): bound journal queries and follows per UID
krishna-santosh Sep 5, 2026
baacefb
feat(gateway): scope file access, stream downloads, bound login attempts
krishna-santosh Sep 5, 2026
c626235
fix(metrics): harden sampler concurrency and subscription intervals
krishna-santosh Sep 5, 2026
fb1032a
style(dashboard): align advisory markdown spacing with flex convention
krishna-santosh Sep 5, 2026
36123a5
fix(dashboard): virtualize only large tables and expose scroll position
krishna-santosh Sep 5, 2026
0699a67
feat(dashboard): scoped file browser with pagination, search, resumab…
krishna-santosh Sep 5, 2026
683b2df
fix(dashboard): harden journal live stream with dedup and filter UX
krishna-santosh Sep 5, 2026
80b7d05
feat(dashboard): reliable update SSE with async preview and live panel
krishna-santosh Sep 5, 2026
5042486
refactor(dashboard): responsive advisory package table
krishna-santosh Sep 5, 2026
09c3f90
test(dashboard): cover update SSE settle, cancel, and package grouping
krishna-santosh Sep 5, 2026
1401574
feat(packaging): versioned multi-arch native matrix
krishna-santosh Sep 5, 2026
84de082
docs(packaging): describe native beta build and release process
krishna-santosh Sep 5, 2026
b71f0ca
feat(ci): add native package, VM validation, and beta release pipeline
krishna-santosh Sep 5, 2026
641b3ca
chore(dashboard): rebuild embedded frontend bundle
krishna-santosh Sep 5, 2026
2e54c4f
feat(storage): add UDisks2 inventory with mount operations
krishna-santosh Sep 6, 2026
177b130
feat(files): harden file operations with resume and safe copy
krishna-santosh Sep 6, 2026
ab37c94
feat(network): add durable checkpoints and ownership detection
krishna-santosh Sep 6, 2026
a1d51b5
feat(firewall): add timed rollback guard with coordinator
krishna-santosh Sep 6, 2026
f410e24
feat(security): preview narrow remediations with verification
krishna-santosh Sep 6, 2026
e679e1a
refactor(dashboard): extract route pages to components
krishna-santosh Sep 6, 2026
3cdbcd4
feat(packaging): support cross-distro all-target builds
krishna-santosh Sep 6, 2026
5c78d08
fix(host): harden socket restart order
krishna-santosh Sep 6, 2026
44f5d96
chore(dashboard): rebuild embedded frontend bundle
krishna-santosh Sep 6, 2026
71b3067
feat(dashboard): add tabbed network views with overview summary
krishna-santosh Sep 6, 2026
64abc1b
refactor(dashboard): migrate firewall, security and network controls …
krishna-santosh Sep 6, 2026
4b6e814
fix(dashboard): defer login render until session resolves
krishna-santosh Sep 6, 2026
e1aad5b
style(dashboard): align directional metrics skeleton with flex layout
krishna-santosh Sep 6, 2026
c8c16e6
chore(dashboard): rebuild embedded frontend bundle
krishna-santosh Sep 6, 2026
0b02a99
add Mascot assets
krishna-santosh Sep 10, 2026
41d7e01
init web
krishna-santosh Sep 10, 2026
2df060e
add TakoMascot-1
krishna-santosh Sep 11, 2026
9b68075
feat: update hero section mascot image
krishna-santosh Sep 11, 2026
7a996a8
fix(platform): distinguish active and activatable D-Bus names
krishna-santosh Sep 11, 2026
0299e0e
refactor(platform): base network ownership on active D-Bus owners
krishna-santosh Sep 11, 2026
2310a79
feat(dashboard): gate network mutations on NetworkManager ownership
krishna-santosh Sep 11, 2026
041bd8f
docs: remove stale Cockpit references
krishna-santosh Sep 11, 2026
260bc85
chore(dashboard): rebuild embedded frontend bundle
krishna-santosh Sep 11, 2026
cae3a17
chore(web): migrate formatting from Prettier to Biome
krishna-santosh Sep 11, 2026
fc8bc5c
chore: add web task aliases to root package.json
krishna-santosh Sep 11, 2026
823c57f
style(web): format with Biome
krishna-santosh Sep 11, 2026
123149f
fix(web): add explicit button types to dashboard preview
krishna-santosh Sep 11, 2026
ab28788
fix(web): use fieldset for workflow choices
krishna-santosh Sep 11, 2026
b671a60
fix(web): harden site header accessibility
krishna-santosh Sep 11, 2026
40ba2ed
fix(web): correct footer back-to-top target
krishna-santosh Sep 11, 2026
51ad2d8
style(web): satisfy Biome lint in compatibility constellation
krishna-santosh Sep 11, 2026
6641a02
chore(ci): extract Linux backend setup to composite action
krishna-santosh Sep 11, 2026
2941a00
feat(ci): expand CI into parallel quality, coverage and contract gates
krishna-santosh Sep 11, 2026
65807ae
feat(ci): add disposable VM integration and lifecycle workflows
krishna-santosh Sep 11, 2026
a0c1d1f
feat(test): add integration harness for disposable VMs
krishna-santosh Sep 11, 2026
79bad6e
test: harden backend and bridge with fuzz and surface tests
krishna-santosh Sep 11, 2026
d6ec62d
feat(dashboard): wire V8 coverage reporting
krishna-santosh Sep 11, 2026
6081f02
fix(openapi): quote descriptions for Redocly contract lint
krishna-santosh Sep 11, 2026
afc1608
feat(dashboard): add Tako light and dark themes
krishna-santosh Sep 11, 2026
c097376
feat(dashboard): add Tako theme picker to site header
krishna-santosh Sep 11, 2026
e1d9299
feat(dashboard): make system terminal theme reactive
krishna-santosh Sep 11, 2026
179bca4
test(dashboard): cover Tako theme provider
krishna-santosh Sep 11, 2026
91fae64
chore(dashboard): rebuild embedded frontend bundle
krishna-santosh Sep 11, 2026
2886aec
feat(web): add overview navigation entry and explicit numbering
krishna-santosh Sep 11, 2026
f8ef7db
fix(packaging): stub tako binary for systemd unit verification
krishna-santosh Sep 11, 2026
71c3f39
ci(packaging): use goreleaser action for static checks
krishna-santosh Sep 11, 2026
2aa3469
test(release): add release-gate evidence checks
krishna-santosh Sep 11, 2026
8153ca1
ci(packaging): run release-gate tests and decouple VM integration
krishna-santosh Sep 11, 2026
bc75367
fix(ci): mask generated integration passwords
krishna-santosh Sep 11, 2026
dc98bd9
ci(vm): harden VM validation trigger and timeout
krishna-santosh Sep 11, 2026
0ff350d
feat(packaging): make native builds tag-aware and harden verification
krishna-santosh Sep 11, 2026
5d7553f
feat(release): require VM integration in beta and fix evidence handling
krishna-santosh Sep 11, 2026
eb8ff52
docs(packaging): clarify VM runner contract and release versioning
krishna-santosh Sep 11, 2026
fd7efd4
fix(release): atomically write beta checksums manifest
krishna-santosh Sep 11, 2026
f588658
docs: update README.md
krishna-santosh Sep 11, 2026
4dfca7b
docs: update README.md
krishna-santosh Sep 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
self-hosted-runner:
labels:
- tako-vm-*-amd64
- tako-vm-*-arm64
config-variables: null
15 changes: 15 additions & 0 deletions .github/actions/setup-linux-backend/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: Set up Linux backend dependencies
description: Install the native libraries required to build and test Tako's Go backend
runs:
using: composite
steps:
- name: Install Linux backend dependencies
shell: bash
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install --yes --no-install-recommends \
gcc \
libpam0g-dev \
libsystemd-dev \
systemd
2 changes: 2 additions & 0 deletions .github/coverage-baseline.env
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# Informational until the first stable CI run records the hosted-runner value.
GO_STATEMENT_COVERAGE_BASELINE=42.6
131 changes: 131 additions & 0 deletions .github/workflows/beta-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,131 @@
name: Beta release

on:
push:
tags:
- "v*-beta*"
workflow_dispatch:

permissions:
contents: read

jobs:
ci:
name: Required CI gates
uses: ./.github/workflows/ci.yml
permissions:
contents: read

integration:
name: Required VM integration
needs: ci
uses: ./.github/workflows/integration.yml
permissions:
contents: read

native-packages:
name: Native package matrix
needs: ci
uses: ./.github/workflows/native-packages.yml
permissions:
contents: read

lifecycle-validation:
name: Representative lifecycle validation
needs: ci
uses: ./.github/workflows/packaging-lifecycle.yml
permissions:
contents: read

vm-validation:
name: Disposable VM validation matrix
needs: native-packages
uses: ./.github/workflows/vm-validation.yml
permissions:
contents: read
actions: read

evidence-gate:
name: Verify all VM evidence
needs: [ci, integration, native-packages, vm-validation, lifecycle-validation]
runs-on: ubuntu-24.04
permissions:
contents: read
actions: read
id-token: write
attestations: write
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: apps/backend/go.mod
cache: true
cache-dependency-path: |
apps/backend/go.sum
go.work.sum
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.4.0
- uses: actions/download-artifact@v4
with:
pattern: package-*
path: incoming
merge-multiple: true
- uses: actions/download-artifact@v4
with:
pattern: vm-evidence-*
path: incoming
merge-multiple: true
- name: Fail closed unless every manifest target passed in a VM
run: TAKO_VM_COMMIT="$GITHUB_SHA" ./tools/release-gate incoming incoming
- name: Assemble packages from the manifest
run: bun tools/release-assemble incoming release
- name: Record dependency inventory
run: bun tools/release-dependencies release/dependency-inventory.json
- name: Generate release checksums
run: |
set -euo pipefail
checksums_tmp=$(mktemp)
trap 'rm -f "$checksums_tmp"' EXIT
cd release
find . -maxdepth 1 -type f ! -name checksums.txt -print0 \
| sort -z \
| xargs -0 sha256sum > "$checksums_tmp"
mv "$checksums_tmp" checksums.txt
- uses: sigstore/cosign-installer@v3
- name: Sign the release checksum manifest
run: |
cosign sign-blob --yes \
--output-signature release/checksums.txt.sig \
--output-certificate release/checksums.txt.pem \
release/checksums.txt
- name: Attest release provenance
uses: actions/attest-build-provenance@v2
with:
subject-path: release/*
- uses: actions/upload-artifact@v4
with:
name: beta-release-inputs
path: release/
if-no-files-found: error
retention-days: 30

publish:
name: Publish beta release
needs: evidence-gate
if: startsWith(github.ref, 'refs/tags/v') && contains(github.ref_name, '-beta')
runs-on: ubuntu-24.04
permissions:
contents: write
steps:
- uses: actions/download-artifact@v4
with:
name: beta-release-inputs
path: release
- name: Publish only after CI, native builds, and every VM evidence gate passed
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
prerelease: true
generate_release_notes: true
files: release/*
Loading
Loading