Argus
Contributing

Releases

Publish an immutable signed Argus release, verify it on clean hosts, promote the stable manifest, and deploy the public site through its Git-connected Vercel project.

Releases are immutable signed GitHub releases. Start from a reviewed commit that passes the root quality gates, then create a SemVer tag beginning with v, such as v0.1.10. The Signed release workflow validates the tag and toolchain, reserves a draft release, and only publishes it after every asset is built and verified.

Signed release contents

The workflow builds and pushes digest-pinned Linux AMD64 and ARM64 application, management, and VPS FxEmbed images; builds the pinned Cloudflare FxEmbed worker; renders the wrapper; and creates manifest.json and manifest.sig with the Ed25519 release key. It verifies the manifest signature and shell syntax before publishing the immutable GitHub release with the installer, wrapper, manifest, public key, and FxEmbed assets.

Do not rerun a tag that already has a release and do not replace its files. A failed release needs a new reviewed commit and a new version tag.

Smoke before stable promotion

The Installer smoke workflow consumes a published signed release and tests the signed wrapper, onboarding, and argus doctor --json on isolated clean hosts across the supported OS, architecture, and Docker-present/absent matrix. The manual VPS smoke workflow verifies a selected immutable release against a controlled Web target.

Only after the required smoke evidence is green may a maintainer promote the release by updating the reviewed stable bundle together: install.sh, manifest.json, and manifest.sig under apps/web/public/releases/stable/. Preserve the exact signed manifest and signature bytes, render the stable installer through the promotion tooling, and run the stable-release web tests. CI rejects a partial bundle change or an extra file under that directory; unrelated repository changes may coexist. The stable channel is intentionally mutable; each GitHub release is not.

Public site deployment

The public site is the Next.js project rooted at apps/web, with its Vercel configuration in apps/web/vercel.json. Its Git-connected Vercel project deploys the committed site source; do not deploy generated output or edit site assets out of band. Before merging the promotion or documentation change, run:

pnpm --filter @argus/web generate
pnpm vitest run apps/web/test
pnpm --filter @argus/web build
pnpm --filter @argus/web check:links

After the connected deployment completes, verify the public release link, stable manifest URL, installer, docs, and machine-readable routes from https://argus.gpsxtre.me.

On this page