Conversation
…le-finish-graph-reader-20260914
…le-finish-ui-policy-parity-20260914
…60914 fix(topology): validate scoped IP ownership and inventory evidence
…ce-proof-prerequisites-20260915
…le-finish-graph-reader-20260914
…le-finish-ui-policy-parity-20260914
…le-finish-graph-publication-20260914
…le-finish-graph-reader-20260914
…le-finish-ui-policy-parity-20260914
* fix(deps): patch documentation and presentation dependencies * ci: require documentation build and presentation provenance checks * docs: document required documentation and presentation merge checks * docs: synchronize root CI commands with the documentation gate
* fix(eks): preserve account and region through registration and views * fix(eks): align dashboard fleet and API contracts * docs(eks): explain cross-account registration across locales * docs(eks): align dashboard and connection guidance across locales * docs(eks): distinguish configured access from successful reads * fix(eks): isolate member authentication and align scoped guides * fix(eks): preserve CloudWatch read quality and scope guidance * fix(eks): minimize member grants and allow offboarded cleanup * fix(eks): sanitize upstream errors across member reads * test(eks): await-compatible route params in metrics and registration fixtures * docs(eks): preserve shared member grants during network-path cleanup * fix(eks): distinguish missing metric envelopes from confirmed no data
…136) * test: retain collector uncertainty and deployment STS regressions * test: await populated EKS fleet summary before assertions * test: keep malformed registration allowlists fail-closed
* docs: preserve SRE blog draft and architecture sources * docs: fix blog setup, evidence boundaries and fresh diagram exports * docs: distinguish historical editorial checks from current validation * docs: align log-query windows and identify archived author notes * docs: disclose diagnosis samples and SDK inventory quality
* docs: preserve blog preview and historical review evidence * docs: bind archived blog evidence to the reviewed source
🤖 AI Code Review (two independent reviewers)Reviewer responses: none Status: BLOCKED — input coverage incomplete; models were not called Review input incomplete: diff exceeds 128 KiB; split the change or implement complete bounded review batches. No models were called; no code verdict is available. Triggered by commit |
* release: prepare AWSops 0.10.0 for main promotion * docs: reconcile release cut with immutable migration labels * docs: disclose legacy and apply-time migration version labels
* fix: consolidate PR reviewers and reject incomplete review inputs * fix: preserve incomplete review findings and bound chair input * test: identify redaction fixture as a synthetic sentinel * fix: enforce shared review budgets before synthesis * fix: publish fixed review diagnostics and deduplicate prompts * fix: normalize failure diagnostic markers before counting * fix: require substantive checklist reports and preserve diff bytes * fix: merge repeated checklist sections without losing reviews * fix: accept review heading variants and prove stdin budget boundary * fix: isolate review imports and publish keyword-presence diagnostics * fix: exclude hidden and placeholder checklist content
* release: prepare AWSops 0.10.1 promotion metadata * docs: align promotion candidate with final release preparation * release: consolidate unpublished preparation into AWSops 0.10.1
Direct release review — PR #137Reviewed by Codex on 2026-09-20. This is an interactive, risk-focused code review, Scope and candidate
AssessmentNo new merge-blocking implementation defect was found in the reviewed areas. Authentication and authorization: examined changed route guards and the common auth Account/region boundaries: examined EKS context resolution, registration, role identity, Data and topology: examined graph transaction/read paths, parameterized traversal and AWS/IaC boundaries: reviewed runtime-read scope, AgentCore IAM narrowing, private Migrations: all 55 SQL migrations already on main are byte-identical. The promotion Release metadata: #140 landed after the 0.10.0 preparation, leaving its entry in Verification
Approved one-promotion exceptionThe owner explicitly approved this exception on 2026-09-20. Final reviewed HEAD: |
Promote AWSops 0.10.1 from
devtomainthrough the standing-branch release path. The unpublished 0.10.0 preparation and subsequent review hardening are consolidated into one 0.10.1 release by merged PR #141; no SQL migration checksum or dependency resolution was changed by that preparation.Release-prepared source:
4134838c7c45a6e004f0d12a8be31e5c08018838. Main base:ab091a2d1c87c5be8d9e43d75553cec0342f4bf7. The simulated main merge tree equals the prepared dev tree.This promotion includes accumulated account onboarding, cross-account EKS/inventory, topology/evidence and runtime-release work, dependency updates, documentation/blog source and evidence, regression fixes, and release metadata. An interactive Codex review examined authentication/ownership, account and region scope, IAM/frozen boundaries, graph data/partial evidence, migration immutability and release/deployment controls. It found no new blocking implementation defect in those reviewed areas. Independently rerun checks passed 493 targeted web tests, 417 Python policy/readiness/collector tests and six release-note tests; the 55 migrations already on main are byte-identical. This is a risk-focused direct review, not a claim that every line was manually inspected or that the automated AI workflow completed coverage.
The normal required AI check remains blocked by input size. The accumulated diff exceeds the automated review's 128 KiB admission bound, so that job does not invoke reviewers. Code review findings and this workflow capacity failure are separate. Existing ruleset
protect-main-devrequires that AI check and grants no administrator bypass. No protection rule has been changed and no automated-review success has been fabricated. Any one-promotion replacement with an explicitly named direct-review status requires a separate policy-exception decision while retaining all other checks and restoring the normal protection afterward.Before merging, verify this exact HEAD's current CodeQL, Merge Verify, Plan, dev-only main guard and deployment/runtime readiness. Production deployment and Terraform apply remain separately approved operations. Merge with a merge commit to preserve branch ancestry; only after an approved merge and confirmed protection state create annotated v0.10.1 on the actual main merge SHA and push that tag explicitly to
samples. No release tag has been created by this preparation.