cast/drills/0.2.0.md

62 lines
2.7 KiB
Markdown

# cast 0.2.0 — release drill
**WAIVED. No drill was run for this release.**
Waived by the maintainer (@danmt) on 2026-07-21. This file exists because the
gate requires a *record*, not a passing result — so a skip is a line in a diff
somebody reviewed, rather than a silence nobody notices.
## Why
The drill harness is not in a state to produce a trustworthy run, and cast is
the least automated of the three: **cast has no drill harness of its own**, and
its legs are the heaviest to stand up. The A→B promotion path needs two live
Coolify instances, working credentials, an age store and a registered GitHub
App. In the 2026-07-19 drill, instance B had to be built from a hand-written
compose file.
A run improvised under those conditions produces numbers nobody should rely on,
and `drills/` is worth nothing if it fills with records like that.
Deferred deliberately, and tracked: #142.
## What this release therefore does NOT prove
Stated plainly so it is not rediscovered as a surprise:
- **The A→B promotion path** against two genuinely live instances: `team`,
`apply`, an idempotent re-diff, `smoke` (the bulk-upsert contract),
`inventory`, `emit-draft`, `fleet --all`, `destroy` behind its typed gate with
the orphan preserved, and the read-only guard refusing.
- **The two headline features of this release under real use.** Declarative
HTTP basic auth (#76) writes to a live Coolify and is only partly readable
back — the password is deliberately never compared, so a drill is the only
place the write is observed end to end. And `cast github-app create` (#7) runs
GitHub's App Manifest flow, whose `redirect_url` on `127.0.0.1` is documented
in that PR as **unvalidated and load-bearing** — no automated test covers it,
and this release does not either.
- **The `### Removed` breaking change in practice** — `scripts/register-github-app.sh`
is gone; the replacement path is exercised only by unit tests.
## What CI did prove on this tree
Not nothing, and worth recording so the gap is precise rather than total:
| Job | Result |
|---|---|
| `install` — real `install.sh` against throwaway roots | pass |
| `scope` | pass |
| `reconcile` | pass |
| `npm test` | 784 passed, 0 failed (39 files) |
| `npm run check` (biome, `--error-on-warnings`) | clean |
| `npm run build` (tsc) | clean |
| `shellcheck-all.sh` | clean |
The command surface, the schema and the installer are covered. Nothing that
requires a live Coolify is.
## The commitment
The next release carries a real drill record at `drills/<version>.md` — what
ran, on what host, the pinned refs and SHAs, the numbers, and what failed. A
failed drill is a valid record; another waiver is not. Tracked in #142.