You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Scope is registry-only: the component exists in recipes/registry.yaml, custom and external recipes may opt in explicitly, and no stock recipe references it. Stock adoption and any runtime-observation evidence predicate are separate future decisions, explicitly out of scope here.
Acceptance bar: a user can add k8s-aibom to a custom recipe and get a digest-pinned, secure-by-default, health-checked deployment that renders identically through every supported deployer, while every stock recipe resolves to the same bytes it does today.
Status: complete
All seven sub-issues are closed. Both phases are delivered.ADR-019 moved from Proposed to Accepted on 2026-08-19.
Phase 2 landed atomically in #2259, merged 2026-08-19 at af9099fd.
The acceptance bar is met on main:
Acceptance claim
Where it is proven
Registry entry, digest-pinned to the qualified set
oci://ghcr.io/googlecloudplatform/charts/k8s-aibom:1.2.0 at sha256:164ba4eeb8b2d3e817917cd3e312994030e4cda24046419d899fdcad4bcf6244; archive SHA-256 534d05b540bf82a0d8279e342a82606be187bca9480ff25e274d4f11bae00097
Attestations
Image: SLSA provenance + CycloneDX SBOM; chart: SLSA provenance. Subjects bind the exact digests, use the upstream release workflow on a GitHub-hosted runner, and are transparency-logged. Observed SLSA Build Level 2.
Verification
gh attestation verify constrained by upstream repo, release workflow, refs/tags/v1.2.0, source digest, predicate type, and --deny-self-hosted-runners
1.27-1.35. AICR's Kind 1.36.1 run is additional observed evidence, not an extension of upstream support. Registry documentation states this boundary.
Per ADR-019 Decision 4, AICR qualifies chart, image, CRDs, and the public status contract as one versioned set. A change to any of them requires requalification against the new exact release and digests.
The supply-chain gate established the exact artifact identity every later gate reviewed, so it ran first. The other three gates were then independent and parallel. No implementation issue started until all four closed, per ADR-019.
Phase 2 - AICR implementation: complete. All three closed by #2259, landed as one PR so registry admission, cross-deployer qualification, and behavioral proof are atomic.
AICR releases every other Monday. Target was the Sep 7 train. The work landed on main 2026-08-19, one train early, and rides the next release.
Surfaced by this epic, deliberately not fixed here
Qualification exercised bundler, mirror, and docs paths hard enough to expose three pre-existing AICR gaps. None is a k8s-aibom defect and none blocks this epic. Filed separately so the trail is not lost:
#2264 - Flux HelmRelease omits spec.upgrade, so existing CRDs are never updated on upgrade. Affects every component delivered via Flux, helm, and helmfile; Argo CD diverges. Elevated impact for the hasSelfRefCRDs set, which now includes k8s-aibom. feat(recipes): add qualified k8s-aibom component #2259 documented the behavior in one component's catalog entry, which is the wrong altitude for a fleet-wide property.
Goal
Admit
GoogleCloudPlatform/k8s-aibominto the AICR component registry as an optional, provider-neutral Helm component, per ADR-019.Scope is registry-only: the component exists in
recipes/registry.yaml, custom and external recipes may opt in explicitly, and no stock recipe references it. Stock adoption and any runtime-observation evidence predicate are separate future decisions, explicitly out of scope here.Acceptance bar: a user can add
k8s-aibomto a custom recipe and get a digest-pinned, secure-by-default, health-checked deployment that renders identically through every supported deployer, while every stock recipe resolves to the same bytes it does today.Status: complete
All seven sub-issues are closed. Both phases are delivered. ADR-019 moved from Proposed to Accepted on 2026-08-19.
Phase 2 landed atomically in #2259, merged 2026-08-19 at
af9099fd.The acceptance bar is met on
main:recipes/registry.yaml(chart1.2.0,oci://ghcr.io/googlecloudplatform/charts, namespacek8s-aibom-system, aliasesk8saibom/aibom)recipes/components/k8s-aibom/values.yaml(no sink, no credentials, label-gated namespace discovery,readiness.strictConfig: true, non-root, read-only rootfs, all capabilities dropped)recipes/checks/k8s-aibom/health-check.yaml, gated onupdatedReplicasandobservedGenerationrather thanavailableReplicasalonepkg/bundler/k8s_aibom_render_parity_test.go;hasSelfRefCRDs: truehandles the helm-diff REST-mapper case for Helmfilepkg/bundler/testdata/stock_render_golden.yaml,pkg/recipe/testdata/catalog_parity_golden.yaml; no overlay or mixin referencesk8s-aibomtools/k8s-aibom-test/Kind integration test withvalidate-bompkg/mirror/k8s_aibom_discover_test.godocs/user/component-catalog.md,docs/user/container-images.md,THIRD_PARTY_NOTICES.mdNothing further is outstanding. The three issues this work surfaced are pre-existing AICR gaps, tracked separately, and listed below.
Qualified release
All four ADR-019 upstream gates passed on 2026-08-19 against this final immutable artifact set:
v1.2.0at4aa7638b08ab9927bfa8df85c46c80234b9996f9ghcr.io/googlecloudplatform/k8s-aibom@sha256:b5040d14a20b4e890956d5f47b78445dac6c871eb5799586d9011c48ce71c198, multi-arch amd64/arm64oci://ghcr.io/googlecloudplatform/charts/k8s-aibom:1.2.0atsha256:164ba4eeb8b2d3e817917cd3e312994030e4cda24046419d899fdcad4bcf6244; archive SHA-256534d05b540bf82a0d8279e342a82606be187bca9480ff25e274d4f11bae00097gh attestation verifyconstrained by upstream repo, release workflow,refs/tags/v1.2.0, source digest, predicate type, and--deny-self-hosted-runnersaibom.k8saibom.dev/v1alpha1, experimentalk8s-aibom-systemreadiness.strictConfig: true50m/128Mi, limits1 CPU/256Mi.Per ADR-019 Decision 4, AICR qualifies chart, image, CRDs, and the public status contract as one versioned set. A change to any of them requires requalification against the new exact release and digests.
Phase 1 findings and upstream responses are recorded in
GoogleCloudPlatform/k8s-aibom#8.Sequence
The supply-chain gate established the exact artifact identity every later gate reviewed, so it ran first. The other three gates were then independent and parallel. No implementation issue started until all four closed, per ADR-019.
Sub-issues
Phase 1 - upstream qualification gates: complete. Findings work, no AICR code. Each closed with a recorded verdict and the commands that produced it.
Phase 2 - AICR implementation: complete. All three closed by #2259, landed as one PR so registry admission, cross-deployer qualification, and behavioral proof are atomic.
Target
AICR releases every other Monday. Target was the Sep 7 train. The work landed on
main2026-08-19, one train early, and rides the next release.Surfaced by this epic, deliberately not fixed here
Qualification exercised bundler, mirror, and docs paths hard enough to expose three pre-existing AICR gaps. None is a
k8s-aibomdefect and none blocks this epic. Filed separately so the trail is not lost:HelmReleaseomitsspec.upgrade, so existing CRDs are never updated on upgrade. Affects every component delivered via Flux,helm, andhelmfile; Argo CD diverges. Elevated impact for thehasSelfRefCRDsset, which now includesk8s-aibom. feat(recipes): add qualified k8s-aibom component #2259 documented the behavior in one component's catalog entry, which is the wrong altitude for a fleet-wide property.pkg/mirror'sLister.Discovertreats a values-load failure as a warning, so a component can contribute zero images to an air-gap mirror list while the command exits 0. Found while adding mirror coverage in k8s-aibom: prove deployer, vendoring, mirror, and stock-recipe parity #2240.<placeholder>syntax that bash lexes as redirection.Out of scope
Per ADR-019 Non-Goals:
k8s-aibomtorecipes/overlays/base.yaml, a leaf overlay, a mixin, or any stock recipe.--set k8s-aibom:enabled=falseas a recipe selection contract.