genesis: refresh seed (agents 0.7.3 + mcp 0.23.15) + seed GITOPS_REF override #56
No reviewers
Labels
No labels
bug
discussion
duplicate
enhancement
goal
help wanted
horizon:backlog
horizon:governance
horizon:mvp
invalid
operator-decision
question
roadmap
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
open-platform/mitosis!56
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/robust-seed-refresh"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Wave-1 ROBUSTNESS — the seed refresh so a fresh germination ships apps first-try.
Refreshed
genesis/seed.tar.gznow carries:prime branch/PR setup failedfallback while keeping the #16 exfil property).agent-dev-env-readRole/RoleBinding the agents SA needs (0.23.9 predated the dev overlay entirely → 403).bin/seed: addGITOPS_REF(defaultHEAD) so a coordinated release can be seeded from a not-yet-merged gitops pin-bump branch (--mirrorcarries every ref). This seed was built withGITOPS_REF=feat/robust-devenv-pins; after plat/gitops#5 merges, a default re-seed (GITOPS_REF=HEAD) reproduces the same artifact.Depends on: plat/agents#7 (v0.7.3 tag/image), plat/mcp v0.23.15 tag/image, plat/gitops#5 (pins). Merge order: agents+mcp tags build → gitops#5 → this.
Validation: germinated an isolated platform (CLUSTER=wb-robust) from this seed on vxrail; result in the PR thread / handoff.
Prime-protection decision: fix lives in the dispatcher (agents#7), not germinate — the dispatcher owns both the protection and the prime setup for new apps, so reordering there is self-contained and provably safe (deploy key is minted only in spawnBuilder, after the rule is applied). germinate’s seeded-repo protection (admin, migration path) is unchanged.
🤖 Generated with Claude Code