Skip to content

feat(installer): support prerelease installations - #3364

Merged
drew merged 17 commits into
mainfrom
codex/prerelease-install-guidance
Sep 18, 2026
Merged

drew merged 17 commits into
mainfrom
codex/prerelease-install-guidance

Conversation

@drew

@drew drew commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Add first-class prerelease installation support for local and Kubernetes users, and announce the upcoming OpenShell 0.1.0 release in the README and Fern documentation. Prerelease packages are retained as authenticated GitHub Actions artifacts rather than published as GitHub Releases; Kubernetes installs reuse the exact image and Helm chart versions the Release Tag workflow already publishes.

Related Issue

Related to #2860

Changes

  • publish architecture- and package-manager-specific prerelease Actions artifacts with 90-day retention, including the generated Homebrew formula and its macOS assets
  • resolve OPENSHELL_VERSION=pre to the latest current-platform artifact from a completed, successful Release Tag workflow run
  • avoid workflow headBranch assumptions and reject expired artifacts during discovery and exact-version installation
  • keep prerelease tags out of GitHub Releases and remove the rolling prerelease tag/release lifecycle
  • reuse the existing exact prerelease image tags and <version>-pre.N Helm chart versions for Kubernetes installs
  • add focused installer and Homebrew-formula tests for artifact selection, expiration filtering, failure handling, and local Homebrew asset URLs
  • add the 0.1.0 notice, prerelease/dev guidance for local and Kubernetes installs, and dedicated Python, TypeScript, Go, and Rust SDK sections
  • add a version-specific 0.1.0 announcement to the latest Fern documentation
  • document prerelease installation in the published installation guide and Helm chart documentation

Testing

  • mise run pre-commit
  • mise run test:install-sh
  • mise run docs (0 errors; 3 existing warnings)
  • uv run pytest python/release_tooling_test.py python/openshell/release_formula_test.py -q
  • mise run helm:docs:check
  • mise x github:rhysd/actionlint@v1.7.12 -- actionlint -shellcheck= .github/workflows/release-tag.yml
  • mise run test (all relevant suites passed; the unrelated test:e2e-parity harness failed because its synthetic baseline/candidate launchers did not emit retained manifests)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (not applicable; no architecture boundaries changed)
  • Related release workflow skills reviewed; no updates are required for prerelease packaging alone

@github-actions

Copy link
Copy Markdown

pimlock
pimlock previously approved these changes Sep 16, 2026
Comment thread install.sh Outdated
@elezar

This comment was marked as outdated.

elezar
elezar previously approved these changes Sep 16, 2026

@elezar elezar left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's get this in and iterate.

@drew
drew force-pushed the codex/prerelease-install-guidance branch from 45c2d17 to 3e553f8 Compare September 16, 2026 15:51
@elezar

elezar commented Sep 17, 2026

Copy link
Copy Markdown
Member

One remaining blocker is that prerelease aliases can expose an unqualified candidate:

  • pre / pre-X.Y.Z currently discover any unexpired platform artifact, including artifacts from failed or still-running Release Tag workflows.
  • The rolling Helm chart and pre-X.Y.Z image tags are published before the canary completes. A later failure can therefore leave those channels pointing at an unqualified or partially published candidate.

Could we make qualification explicit with this ordering?

  1. Publish immutable X.Y.Z-pre.N artifacts, images, and Helm chart.
  2. Run the canary against those exact versions, using the current workflow run ID to access its in-progress Actions artifacts.
  3. After the canary passes, promote the rolling pre-X.Y.Z image tags and X.Y.Z-pre Helm chart.
  4. Have installer aliases consider only artifacts whose parent Release Tag workflow completed successfully.

I'd also have the rolling Helm chart pin the qualified candidate's exact image version. That prevents a later image-channel update from silently changing an already-published chart.

This preserves the current Actions-artifact approach while ensuring every rolling prerelease entry point means "latest qualified candidate."

drew added 12 commits September 17, 2026 14:54
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew force-pushed the codex/prerelease-install-guidance branch from 4ba363d to 79f7fd4 Compare September 17, 2026 21:59
@drew

drew commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator Author

Thanks — addressed by simplifying the prerelease model instead of adding a rolling promotion stage.

  • Removed pre-X.Y.Z and the rolling prerelease image and Helm aliases.
  • Release Tag continues publishing immutable X.Y.Z-pre.N images and Helm charts.
  • The canary installs that exact prerelease, including the exact Helm chart, while using artifacts from the current workflow run.
  • OPENSHELL_VERSION=pre now intersects unexpired platform artifacts with completed, successful Release Tag runs. A candidate therefore becomes discoverable through pre only after its entire workflow, including the canary, succeeds.

With no rolling prerelease images or charts remaining, there is no separate promotion step or mutable chart-to-image mapping to qualify.

pimlock
pimlock previously approved these changes Sep 17, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
pimlock and others added 2 commits September 17, 2026 17:05
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
pimlock
pimlock previously approved these changes Sep 18, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
pimlock
pimlock previously approved these changes Sep 18, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew enabled auto-merge September 18, 2026 00:45
@drew
drew added this pull request to the merge queue Sep 18, 2026
Merged via the queue into main with commit 8b77925 Sep 18, 2026
58 checks passed
@drew
drew deleted the codex/prerelease-install-guidance branch September 18, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants