Releases

A release is a signed manifest with compatibility metadata — platform versions, not image tags. Every component, chart, and image resolves from it; air-gap bundles carry the same guarantees offline.
Plan upgrade wave
0.1.91latest
2026-08-04 · signed ✓
6 environments
0.1.90stable
2026-07-28 · signed ✓
4 environments
0.1.88LTS
2026-07-14 · signed ✓
3 environments · air-gap default
0.1.86superseded
2026-07-02
1 environment
0.2.0rc
in validation
0 environments

Fleet version distribution

by release channel Plan upgrade wave
0.1.91 6 0.1.90 4 · wave 2 ready 0.1.88 LTS 3 · incl. 2 air-gapped 0.1.86 1 · below wave floor

Release manifest — 0.1.91

the artifact of record · what upgrade gates on
apiVersion: cf/v1
kind: Release
version: "0.1.91"
minUpgradableFrom: "0.1.1"

compat:
  kubernetes: [">=1.30 <1.34"]
  clouds:     [azure, aws]     # truthful per domain — see notes
  profiles:   [production, air-gap, development]

databases:               # backed up before any destructive stage
  - { name: identity,  hostVar: db_host }
  - { name: platform,  hostVar: db_host }
  - { name: workloads, hostVar: db_host }

migrations:              # expand-first; rollback-safety flagged
  - { id: 2026-08-01-search-index, backwardCompatible: true }
  - { id: 2026-08-02-quota-cols,   backwardCompatible: true }

rollback:
  strategy: helm
  forwardOnly: [migrations, infra]

signature:
  alg: cosign
  keyRef: converge-release-2026   # offline-verifiable at air-gapped sites

Supply-chain posture

Manifest signature
verified cosign · converge-release-2026
Image signatures
34 / 34 verified against the release key
SBOM
attached per image · SPDX
CVE scan
0 critical · 2 high (accepted, tracked) · scanned 2026-08-04
Provenance
git 4c1f9e2 · CI run #1847 · attested
Air-gapped verification: the signing key ships in the bundle's trust root, established at install — signature checks run fully offline.

Compatibility — honest per domain

Operational domainAzureAWS
Install / upgrade / backupfullfull
Drift reportfullfull
Reconcile cleanfullbest-effort
Teardown residual sweepfullbest-effort
A cloud is declared supported per domain only when the code actually covers it. Best-effort domains state their limits in the report.

Artifacts — 0.1.91

ArtifactTypeDigestSizeSignatureSBOM
converge-platform charthelmsha256:7d41…c9a02.1 MBsigned
platform-coreoci imagesha256:2b8e…11f7412 MBsignedSPDX
platform-identityoci imagesha256:9c02…7ab3287 MBsignedSPDX
platform-searchoci imagesha256:e5d9…30cc356 MBsignedSPDX
infrastructure moduleterraformsha256:44af…9e12180 KBsigned
air-gap bundle (private images only)bundlesha256:b7c3…52d81.8 GBsignedaggregate