Harness Intelligence Wiki
SpecsCLIIssue 94 Durable Stable Baseline Promotion

Implementation Notes

Implementation Notes

Summary

  • Replaced deployment-scoped stable identity with immutable baseline_release rows and an append-only stable_baseline_promotion head in Postgres.
  • Made verified GitHub publication promote through the API with one publisher credential, deterministic retry reconciliation, and no baseline identity environment rewrite or API redeployment.
  • Completed the seeded production cutover, published durable revision 2, removed exactly nine obsolete identity variables, and kept the production deployment unchanged after the one capability deployment.

Execution Mode

Parallel delivery waves with disjoint package, API, CLI, runtime, and documentation ownership, followed by parent integration and production validation.

Deviations From the Plan

  • The initial capability configuration had to be corrected so the publisher secret reached Vercel as the exact stdin bytes. The final deployment was dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRf; no secret value was recorded.
  • A deterministic publisher/build regression was fixed before the live release, producing the v2 tag from commit c910c9edf656e96d7b818e9ff052dd5cc2b50a1f.
  • The CLI remote authority timeout was retained at 5 seconds after production latency exceeded the shorter boundary.

Sanity Checks

CheckResultNotes
Production seed and capability deploymentPassed2026.07.30-security-pack, revision 1, manifest a324..., archive febf...; final capability deployment dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRf.
Production v2 publication and retryPassedRelease ID 364190218; publisher ran twice with exit 0 and durable revision remained 2.
Stable and artifact readbackPassedStable, manifest, and archive endpoints returned HTTP 200 for v2.
Merged CLI 3.1 checkPassedResolved v2 and reported expected drift-detected, with no authority-unavailable result.
Obsolete environment cleanup and retryPassedExactly nine names removed; retry was a no-op; publisher token and public origin remained.
Documentation format/diff/mirrorPassedFormatting, diff hygiene, and exact runbook body parity passed.
Full wiki content checkPre-existing failureReported only stale generated spec meta.json files outside the issue-94 documentation slice.

Not applicable. This delivery changed API, CLI, persistence, release automation, configuration, and documentation surfaces; it added no UI.

Runtime Validation Evidence

TaskScenario and targetPublic actionCorrelation or provenanceExpected resultObserved result and durable evidenceCleanupStatus or exact blocker
T9Seeded production cutover on Postgres and canonical Vercel APIDeploy the ledger capability and read stable plus both artifactsSeed 2026.07.30-security-pack; revision 1; deployment dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRfSeed is readable before identity-env removal and the credential is never disclosedSeed manifest a324... and archive febf... read back after the exact secret-stdin correction; no credential value entered artifactsPreserve seed, capability deployment, and audit historyComplete
T10No-redeploy production publication across GitHub, API, Postgres, CLI, and VercelPublish v2 twice, read stable/artifacts, then run merged CLI 3.1 hi checkRelease ID 364190218; tag baseline/stable/2026.08.03-durable-stable-authority-v2; commit c910c9edf656e96d7b818e9ff052dd5cc2b50a1f; revision 2One durable promotion, retry reconciliation, HTTP 200 readbacks, actionable CLI result, unchanged deploymentPublisher exited 0 twice; a live exact idempotent POST returned HTTP 200, already-committed, revision 2, previous revision 1, previous release 362549177, committedAt: 2026-08-03T12:16:58.981Z, and publication identity baseline-release:364190218; manifest 6095... and archive f7e4...; stable and both artifacts returned HTTP 200; CLI resolved v2 and reported expected drift; deployment stayed dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRfPreserve legitimate release and append-only ledger; remove only run-owned temporary filesComplete
T11Canonical production environment cleanupRemove the exact obsolete-name allowlist, rerun cleanup, and read authority/deployment stateDurable revision 2; deployment dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRfNine names absent, retry no-op, required capability/origin retained, no deploymentExactly nine names were removed; retry issued no removals; token/public origin remained; stable and deployment were unchangedIntentional configuration deletion retained; no other environment value removedComplete

Acceptance Criteria Status

CriterionStatusNotes
Verified publication is the stable promotion without identity-env mutation or deploymentMetv2 committed at durable revision 2 and deployment identity did not change.
Durable commit is atomic, shared, restart-safe, and retry-reconcilableMetAdvisory-locked Postgres ledger, process reconstruction coverage, and two successful same-release publisher runs.
Normal publish ordering and conflicts fail closedMetImmutable release evidence, newest-only policy, CAS/conflict tests, and deterministic publication identity.
Controlled rollback is explicit and append-onlyMetRequires expected revision, prior committed target, and audit reason; history is immutable.
Stable, exact, artifact, and typed failure contracts remain intactMetStable/artifact HTTP 200 proof, exact-selector coverage, CLI authority-error precedence, and expected drift presentation.
Publisher credential stays scoped and secretMetOne token, constant-time API boundary, exact secret stdin, redacted evidence, and no recorded value.
Obsolete environment authority is removed safelyMetExactly nine names removed after durable proof; retry no-op; token/public origin and deployment retained.
Operator documentation matches the shipped lifecycleMetThree docs updated with format, diff, and mirror checks passing.

Manual Review Checklist

AreaCheckHow to performExpected result
CLIReconfirm merged CLI authority presentationRun hi check --json in a repository still pinned before v2resolvedVersion is v2; expected scaffold drift is drift-detected; authority is not unavailable.
AuthorityReconfirm stable and artifact metadataRequest /api/baselines/stable and both /api/baselines/stable/artifacts/{manifest,archive} endpointsAll return HTTP 200 with v2 identity; manifest begins 6095... and archive begins f7e4....
DeploymentReconfirm no-redeploy stateInspect the canonical production deployment IDIt remains dpl_CVSWHsq8bDiE7MCSv7tPE5JrCzRf.
EnvironmentReconfirm the bounded cleanupList production environment names without retrieving valuesThe nine obsolete identity names are absent; publisher token and public origin remain.
DocsReview the operator lifecycleRead the repository and mirrored hi-cli-scaffolding runbooksSeed, publish, retry, rollback, cleanup, and no-redeploy guidance agree.

Pre-existing Issues

  • The full wiki content check reports stale generated meta.json files across existing spec routes. This did not affect issue-94 runbook parity or the focused documentation checks.

Remaining Work

  • None for issue #94 delivery. Route to final review/PR handling, or mark the delivery complete.

On this page