Certify the AOS release-to-Station adapter
Author: joshuajbouwCreated Aug 26, 2026Updated Aug 26, 2026
Labelscampaign/station
Outcome
AOS releases can be transformed into fail-closed Station publication inputs using an immutable, fetchable Station-tools pin, without granting the adapter publication or runtime authority.
Parent
astrid-runtime/astrid#1563
Scope and ownership
Repository: unicity-aos/aos-ce. Release-to-Station adapter, immutable Git-object verification, hosted contract matrix, and Station v1 product terminology.
Dependencies
- The accepted Station publication interface in
astrid-runtime/station-tools. - AOS release evidence assets (
SHA256SUMS.txtand matching Capsules). - PR #87 review and required CI.
Exit gate
- PR #87 is merged to the intended protected branch.
- Hosted and local adapter matrices verify the immutable Station-tools object and reject replacement refs, dirt, ignored extras, mode drift, or unavailable pins before manifest generation.
- A real release evidence bundle produces deterministic unsigned Station inputs; publication remains a separate protected operation.
Claim boundary
This lands a release adapter. It does not publish an AOS Station generation, sign TUF metadata, or activate a Station source.
Verification
Adapter matrix, exact-head independent review, GitHub CI, and a release-asset dry run bound to the signed Station interface.
Source: unicity-aos/aos-ce