Usable Aegis 0.9 journey¶
This historical audit record describes the 2026-09-18 release journey. For current customer instructions, use Quickstart.
Observed on 2026-09-18 for the GCP integration sandbox. This record binds the installed package, human authentication, ordinary Nexus request, Git publication, and Forge deployment/update/rollback.
The record omits credentials, account identifiers, tenant identifiers, installation identifiers, session identifiers, and private paths. The coordinator retains the original evidence for identity comparison.
Package identity and installation¶
Source commit:
9ff382f4c61e54376f3e39d8629b42f561147829
Package: Aegis-signed.pkg.
Package SHA-256:
0383d8b857317e0ce5001b7088985c965282b98d52204116296049dbdf904b19
Software delivery channel: GitHub Release
dogfood/2026-09-18.123755.
Producer workflow: https://github.com/mithran-hq/aegis/actions/runs/35279230432
The producer workflow concluded with failure in a later legacy ACM diagnostic. The following retained-package observations are separate. They do not establish a successful complete producer workflow.
The clean Apple Silicon VM had no installed Aegis product state. Package and app assessment used normal Gatekeeper policy. The table substitutes the public filename for the private package path.
| Observed command or operation | Result |
|---|---|
| Package SHA-256 comparison | Exact digest matched. |
pkgutil --check-signature Aegis-signed.pkg |
Exit 0; trusted installer signature. |
xcrun stapler validate Aegis-signed.pkg |
Exit 0; notarization ticket valid. |
spctl --assess --type install --verbose=4 Aegis-signed.pkg |
Exit 0; accepted. |
sudo -n /usr/sbin/installer -pkg Aegis-signed.pkg -target / |
Exit 0; installation succeeded. |
codesign --verify --deep --strict --verbose=4 /Applications/Aegis.app |
Exit 0. |
spctl --assess --type execute --verbose=4 /Applications/Aegis.app |
Exit 0; accepted. |
| Installed component manifest and hashes | 34 examined; 34 existing; all matched. |
Human sign-in and continuity¶
The installed CLI completed the human email-link flow:
Sign-in returned exit zero. Two separate status processes returned the same valid account identity. Neither identity value appears here.
An initial wrapper stopped after input delay, before email-link navigation. The completed attempt used normal authentication and exited zero. Both attempts remain in private evidence; no product timeout is claimed.
Current-account hosted renewal was not observed; renewal behavior is supported by deterministic CLI/local-issuer proof.
The deterministic command was:
cargo test -p aegis-cli --test setup_cli_e2e interactive_setup_refreshes_expired_auth_without_reopening_browser -- --exact --nocapture
It passed one test with zero failures. The test used a local issuer and expired fixture sessions; no browser reopened during renewal. The canonical local gate ran the test through its CLI proof group. All 30 of 30 gate groups returned zero.
The canonical and candidate commits have the same complete source tree:
fc26ed5482f46fb2f0a083c43baf8e550a7cb0ca
Canonical source:
7e1de5933bbf9fe117d3e11f48c957917730e5a9
This establishes deterministic renewal behavior at the candidate's source tree. It does not establish renewal of the hosted human account.
Standalone Nexus request¶
The installed CLI configured and inspected ordinary Codex:
aegis codex enable --model nexus --json
aegis codex status --model nexus --json
codex exec --skip-git-repo-check "Reply with exactly NEXUS-09-OK"
Enable and status returned exit zero. Status reported enabled with
pending_recovery: false. Codex 0.141.0 returned NEXUS-09-OK and exit
zero, using no provider override or copied credentials.
The client warned that model-catalog metadata was missing and used fallback metadata. This result does not establish complete catalog compatibility.
The request began at 2026-09-18T11:38:06.924392+00:00 and completed at
2026-09-18T11:38:17.573975+00:00.
Ordinary Git publication¶
Repository: mithran-hq/forge-smoke-fixture.
Source A:
276d85a3e75f753841bf2df5b05db73d608f11bb
Source B:
9f4f90938199215cbff64e57b153ea8e9f36ba12
The handwritten fixture retained its app response and source-identity endpoint. Each revision changed its qualification marker. The coordinator published each committed revision from the workstation:
Each fixture gate passed nine tests and returned zero. Both ordinary Git pushes returned zero. The final VM received the published commits as a Git bundle. No Git credentials were copied into that VM.
Manifest blob shared by both revisions:
40d9c561eb1d8096d26b8b25c521a047beebc1f1
Repository authorization¶
An earlier ordinary deployment opened the browser authorization flow.
The authorized user renewed the existing repository deploy grant at
2026-09-18T06:25:32.150114+00:00.
The browser reported a linked identity, installed App, valid repository
grant, and valid deploy grant.
This proves renewal of existing authority. It did not observe a new GitHub App installation or a new repository grant. The final source A deployment matched the authenticated account and tenant. Its authorization record contained one grant and exposed no raw secret values. The deployment worker received no write credentials.
Forge deployment, update, and rollback¶
The installed CLI selected the published fixture commit explicitly.
The command below uses the installed executable's name on PATH:
aegis forge deploy --repo mithran-hq/forge-smoke-fixture --sha 276d85a3e75f753841bf2df5b05db73d608f11bb
aegis forge status deployment://sandbox/preview/15dcef6f3ddd3a30 --json
aegis forge versions forge-smoke-fixture --json
The source A deployment command returned exit zero. Status and versions returned exit zero. The deployment succeeded with runtime and route readiness. Its source snapshot matched source A. The deployment record established GitHub source authority. All 12 of 12 readiness assertions passed.
Source A deployment reference:
deployment://sandbox/preview/15dcef6f3ddd3a30
Source A artifact digest:
sha256:ef1dc662662bdd58bcf244167f38271d5c2bf4cd3dfe87c100df0edc76f5aca8
The trusted HTTPS probe used normal certificate verification:
curl --fail-with-body --silent --show-error \
--proto '=https' --tlsv1.2 --connect-timeout 5 --max-time 30 \
--write-out '\nHTTP=%{http_code};TLS=%{ssl_verify_result}\n' \
https://forge-smoke-fixture-preview.apps.sandbox.mithran.cloud/__proof/source
At 2026-09-18T12:25:51.232588+00:00, it returned exit zero:
The installed CLI then deployed the published source B:
aegis forge deploy --repo mithran-hq/forge-smoke-fixture --sha 9f4f90938199215cbff64e57b153ea8e9f36ba12
aegis forge status deployment://sandbox/preview/1a6ac000a7d6e006 --json
aegis forge versions forge-smoke-fixture --json
Deployment, status, and versions returned exit zero. All 12 of 12 readiness assertions passed for source B. The deployment succeeded with runtime and route readiness. Its source snapshot matched source B, and its artifact differed from A.
Source B deployment reference:
deployment://sandbox/preview/1a6ac000a7d6e006
Source B artifact digest:
sha256:f2d98d7325a6a6f191becdc3b5fe1478f17f9090238b3567fd8c198ba3ea7190
The same HTTPS probe returned exit zero at
2026-09-18T12:28:28.651372+00:00:
The coordinator inspected current versions before targeting source B:
aegis forge rollback deployment://sandbox/preview/1a6ac000a7d6e006 --json
aegis forge status deployment://sandbox/preview/1a6ac000a7d6e006 --json
aegis forge status deployment://sandbox/preview/15dcef6f3ddd3a30 --json
aegis forge versions forge-smoke-fixture --json
The rollback command returned exit zero at
2026-09-18T12:28:57.574233+00:00.
All nine rollback assertions passed.
The response reported alias_reissue_error: null and
rollback_rebuild_performed: false.
The current alias restored A's original reference and digest.
The previous alias named B. B's status was RolledBack, with rollback
recorded as its last action.
Post-rollback status and versions returned exit zero.
All 12 of 12 readiness assertions passed for restored A.
The same HTTPS probe returned exit zero at
2026-09-18T12:29:37.074837+00:00:
| Serving step | Exact source SHA | Deployment reference | Artifact digest |
|---|---|---|---|
| A deployed | 276d85a3e75f753841bf2df5b05db73d608f11bb |
deployment://sandbox/preview/15dcef6f3ddd3a30 |
sha256:ef1dc662662bdd58bcf244167f38271d5c2bf4cd3dfe87c100df0edc76f5aca8 |
| B deployed | 9f4f90938199215cbff64e57b153ea8e9f36ba12 |
deployment://sandbox/preview/1a6ac000a7d6e006 |
sha256:f2d98d7325a6a6f191becdc3b5fe1478f17f9090238b3567fd8c198ba3ea7190 |
| A restored | 276d85a3e75f753841bf2df5b05db73d608f11bb |
deployment://sandbox/preview/15dcef6f3ddd3a30 |
sha256:ef1dc662662bdd58bcf244167f38271d5c2bf4cd3dfe87c100df0edc76f5aca8 |
A's original evidence output remained byte-identical after rollback.
Its SHA-256 was:
b08598402f23514eea00fef05f32391d796a5b590f4f52d78bbb681f6f5d63dc
Authorization refusal evidence¶
An authenticated request with a conflicting tenant returned exit one at
2026-09-18T12:30:01.483706+00:00.
The response reported forge_forbidden and HTTP 403.
Private request identifiers remain in the coordinator's evidence.
This negative request is not a customer configuration step.
Cross-environment refusal has deterministic control-plane proof:
cargo test --bin control-plane-service deploy_request_conflicting_body_environment_ref_refuses -- --nocapture
cargo test --bin control-plane-service matching_environment_is_admitted -- --nocapture
Each baseline test passed one test and returned zero. Removing the environment refusal caused its test to fail with exit 101. Restoring the refusal returned the test to exit zero. This proves the deterministic refusal boundary. The walkthrough observed no live cross-environment request.
Qualification limits¶
Current-account hosted renewal was not observed; renewal behavior is supported by deterministic CLI/local-issuer proof.
Protected-agent source control, autonomous PR merge, session continuation, ACP, and meta-harness qualification are deferred.
These capabilities are explicit non-goals of the adopted release scope: https://github.com/mithran-hq/aegis/issues/3636
This record covers the current sandbox journey only. It establishes no staging, production, recovery, availability, or scale property.
Long atomic commands, identifiers, URLs, table cells, and the adopted verbatim limitations are intentional prose-layout exceptions.
Published transcript identity¶
The original release transcript has SHA-256:
cd671094ccde6e7783679d903652e7f76c368ff7c78560b17f66614f4b5ea91c
This digest identifies the immutable release asset, not this portal page.