gameplane / docs
DEVELOP

CI, releases, and signing

Understand the gates from pull request through edge images, tagged releases, Helm publication, and Cosign verification.

Testing & Releasev0.217 MIN
Edge channel is beta software

The rolling :edge channel is test software; production installs should pin a tagged chart and immutable image digests.

Continuous integration

CI covers Go modules, envtest, web build/coverage, browser tests, Helm rendering, and disjoint Kind E2E buckets.

Matrix testsEvery Go module and required build tag is tested.
Coverage gatesCoverage is merged and enforced per component.
E2E completenessHelm and bucket-coverage checks protect generated and E2E completeness.

Edge channel

Changes on main publish rolling :edge images and immutable sha-<short> tags for all released components.

Multi-architectureImages are multi-architecture and optionally signed by digest.
Immutable pinningCommit-based sha tags provide immutable commit pinning.
Docs/design-onlyDocs and design-only changes require direct review because code CI may skip them.

Tagged release

A v tag builds and signs images, packages the OCI chart, creates release notes, and publishes official modules.

RELEASE PATH

01   01 go build ./... && npx tsc --noEmit # Lightweight local compile checks
02   02 git tag vX.Y.Z && git push origin vX.Y.Z
03   03 cosign verify --key cosign.pub ghcr.io/gameplanepanel/gameplane/<image>@<digest>

Release images carry Cosign signatures recorded in the public Sigstore Rekor transparency log. Verify any released or edge image with the cosign.pub key at the repo root. Pre-rotation releases (v0.2.0-beta.7 and earlier) used the retired Ed25519 key and require cosign-legacy.pub with the --insecure-ignore-tlog=true flag (see Key Rotation for trust continuity).

Signing is mandatory and fail-closed: without COSIGN_PRIVATE_KEY the release job fails before anything is pushed. Every signing job (release.yaml, publish-edge.yaml, images.yaml and republish-modules.yaml) runs in the release-signing environment, whose deployment policy admits only master and v* tags, so a run on any other ref never receives the key. Images are pushed by digest, signed and verified, and only then tagged, so a published tag always names a signed image.


Next guide

Extension services