Skip to content

Operate / Releases and evidence

Know what you are deploying.

Immutable references, explicit test scope, and known limits. A signature proves publication identity and integrity; it is not an uptime or security guarantee.

v0.2.0 · September 4, 2026

ComponentPublished reference
Controllerghcr.io/gondola-build/gondola@sha256:18517fe57b69420ddcbdf93c621a9cce3c88ad758387c347cdef3a700e3c866c
Modulegondola-build/gondola/aws · 0.2.2
Release source revision5fafcebd7b57a8852152e58297456c7c943a6d00
Public artifact bundleghcr.io/gondola-build/gondola:v0.2.0-artifacts

Verify the image and release bundle before applying your organization's delivery policy. The controller source and its CI logs are private; the public module, compiled artifacts, signatures, checksums, provenance, and SBOMs are available independently.

What this release covers

Linux x64 and ARM64 EC2 runner fleets on GitHub.com; Terraform/OpenTofu installation; active/passive controller coordination; one-job runners; lifetime cleanup; offline signed entitlements; and customer-owned CloudWatch operations.

Acceptance scope

The release-source AWS acceptance run completed on September 5, 2026 UTC. It exercised six runner jobs across x64 and ARM64, controller restart, upgrade, deliberate bad-image rollback, same-ARN secret rotation, metrics, and resource cleanup.

For this release, AWS acceptance used separate images built from the release commit, the local infrastructure module, and licensing disabled. Published-image signatures and checksums were verified separately. This evidence does not establish a complete paid-checkout-to-build or renewed-entitlement rollout on the shipped digest.

Known limits

  • No Windows, macOS, GitHub Enterprise Server, Azure, or GCP execution.
  • No built-in managed cache. Minimum runner capacity can keep idle runners available; a richer stopped-standby service is not included.
  • Spot launch fallback is distinct from retrying a job interrupted after launch.
  • Paid entitlement renewal requires a secret update and controller rollout. Use the renewal checklist.
  • No published customer-usage benchmark, independent security assessment, or uptime SLA is asserted by this release record.

Before an upgrade

Pin the next image digest and module version in a private pilot first. Retain the prior working digest and protected state, review the plan and release notes, run a representative job on each fleet, and verify termination. A running ECS task is not enough: confirm the expected deployment generation and fleet readiness.

Upgrade and rollback procedures · Trust and assurance status · Report a release problem