Skip to content

Validate a public release

Release validation checks the artifact customers install. It is separate from comparative benchmarks on benchmarks.siglake.dev, which measure engines and workloads under a declared performance protocol. The records below identify the exact artifacts and checks each run covers.

Current public images: October 8, 2026

The current published release is v0.2.1. After the Siglake rename, the rebuilt v0.1.0, v0.2.0 and v0.2.1 public images each passed a basic smoke test on October 8. The committed verification record contains the source revisions, immutable image digests, assertions, and dependency substitutions.

Each run checked engine and operator version identity, all four binary entrypoints, the renamed operator CRD, healthy Compose services, 100 exact committed events and grouped counts, query-server restart, and cleanup.

For v0.2.1, the rebuilt source is 08cbeaa6d508eba1a4a6810de4002e004b8686b9:

  • Engine digest: sha256:4ddeaf85826c18d6f225d433cac3488fa2b4ab118db51496340ef910764d6892
  • Operator digest: sha256:446f78f81b5ef52e6fccad477ff94ef13339c2acefb165b508b90f01f5eb2b1e

The v0.1.0 and v0.2.0 runs used pinned public MinIO fixture replacements for unavailable historical dependencies; they do not establish that the original dependency tags are available again. These basic checks establish renamed artifact behavior, not a full burn-in or Kubernetes upgrade qualification. The v0.2.1 run also recorded five side-aggregate guard refusals; it did not qualify side-aggregate acceleration. The historical records below retain their original scope and outcomes.

Clean install, 24-hour and 72-hour workflows

The customer-run runner is maintained in the Siglake source repository. It supports v0.1.0, v0.2.0 and v0.2.1, with the same assertions and evidence format for smoke, 24h and 72h. Use a Linux host with Docker Compose v2, Python 3.10+, git release tags, at least 16 GiB available memory and 20 GiB free storage.

git clone https://github.com/siglake/siglake
cd siglake
python3 scripts/release-validation/run.py --version v0.2.1 --profile smoke \
  --out "$HOME/siglake-validation/v0.2.1-smoke-$(date -u +%Y%m%dT%H%M%SZ)"

Each run anonymously resolves and pulls the immutable published image digest, uses configuration from that release tag, and creates new run-owned Docker volumes and a private network. API ports bind only to random loopback ports. It never builds the product locally. Each engine component has a 4 GiB, two-CPU limit; dependency limits are 1 GiB. This is a bounded single-host validation profile, not the stock Helm deployment or a performance claim.

The smoke profile runs at least two minutes of workload plus setup and final checks. Duration profiles require at least 86,400 or 259,200 seconds of workload; setup is excluded. A 72-hour run records its 24-hour checkpoint but does not replace an independent clean-install/cleanup cycle. Neither an unfinished run nor a process exit code alone is a pass.

Keep a long run alive and clean up

For a committed runner, use the detached launcher. It takes an immutable source snapshot and starts a bounded systemd user service that survives terminal and tmux loss. The user manager must have lingering enabled to survive logout.

python3 scripts/release-validation/start.py --version v0.2.1 --profile 72h \
  --results-root "$HOME/siglake-validation"

The launcher prints the service name and durable log/results paths. Read summary.json for state and events.jsonl for progress. To cancel, stop the printed unit with the following service command:

systemctl --user stop UNIT
Normal completion, failed checks and handled signals collect evidence before teardown. ExecStopPost repeats cleanup after an abnormal process exit. Cleanup removes only containers, networks and volumes bearing that run's identity, and verifies none remain. It preserves logs and shared image layers. Cleanup failure prevents a pass.

A host reboot interrupts qualification; elapsed time is not resumed or credited. After reboot or hard runner loss, explicitly recover the recorded run before starting again:

python3 scripts/release-validation/recover.py /absolute/path/to/run

Recovery verifies the recorded Compose hash and project identity before removal. Never use global Docker pruning to clean up a validation run. The manual GitHub workflow provides the same profiles and retains artifacts even on failure; 24/72-hour profiles require a dedicated runner labeled siglake-validation. Hosted jobs have a six-hour limit; self-hosted jobs allow up to five days. GitHub Actions limits.

Assertions and remaining coverage

The baseline ingests deterministic OTLP IDs with out-of-order event timestamps, then checks exact committed IDs, total counts, grouped counts and filtered counts under concurrent queries. Disabling the query WAL overlay ensures these are object-store commits. Result caching is off. Batch-query results must agree, missing bearer credentials must be refused, and component restarts must preserve answers. Resource samples verify enforced limits, container state, unexpected restarts and OOM events. Load is bounded, not a saturation or large-working-set stress test. A success does not prove absence of memory leaks.

Full release acceptance also needs Kubernetes/Helm and operator install, OIDC tenant isolation, distributed-query replicas, version upgrades, retention/deletion, schema evolution, catalog/object-store outages, and in-flight cancellation under sustained representative load. These are explicitly unqualified until their own evidence is available. The cancellation soak moved to the source runner; its preflight refuses queries that finish before the client disconnects. Passing the baseline is not a complete release gate.

Historical evidence: v0.2.1 before the rename

The October 1, 2026 patch release used the pre-rename source revision b9f77f86fe03102784e8ff2575cb21ae4bd4eb1a. Its exact-source strict checks, public-tree checks, paired mirror-reclamation runs and a fresh-volume source-candidate installation passed before tagging. The Garage safety check passed by refusing a store that ignores conditional-write preconditions; this is not a claim of Garage write support.

The anonymous published-image smoke passed on October 1 on Linux/AMD64. Both engine and operator reported 0.2.1 (b9f77f8). The run used an empty Docker client authentication configuration, public dependency pulls and fresh volumes. It checked 400 exact committed records over 145.24 seconds of workload, grouped and filtered queries, batch results, authentication refusal, component restarts and resource limits. Cleanup left no run-owned containers, networks or volumes. All eight retained artifact checksums verified against the unmodified tagged runner.

  • Engine digest: sha256:ce00353961641ec44c7cc476c5a31b22f38514ab16798361b127a1137d42476a
  • Operator digest: sha256:b27eae77124a127e60e667e8e08cfe77d508439e9e42562d7683455fe1045192

The historical review referred to validation-summary.json, its checksum, and log-review.json for those pre-rename artifacts. The current renamed release is documented by the October 8 verification record above. The October 1 run was a bounded baseline, not a 24/72-hour qualification or a Kubernetes operator installation test.

The log review found 23 refusals to publish query_audit side aggregates after the data commit. Stale aggregates are rejected in favor of per-file reads; the baseline query assertions passed. Audit aggregate acceleration is not qualified by this run. The conditional-probe cause and repeated logging remain under investigation; the safety guard stays enabled.

Dependency-performance, cache-depth and text-index-policy field measurements remain open work for 0.3.0. Moving their delivery milestone does not turn their previous failures or missing evidence into passes. New features and telemetry also remain deferred; see the 0.2.1 changelog.

Historical ledger: v0.1.0 and v0.2.0, September 24 snapshot

The first public-install attempts on September 24, 2026 both failed before starting a stack. Siglake's GHCR manifests were anonymously readable, but the release-pinned dependency quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z returned HTTP 401 to anonymous pulls. The same Docker Hub repository/tag also refused anonymous authorization. No run-owned containers or volumes were created; cleanup was not_needed.

Version Anonymous clean install Baseline smoke with cached dependencies 24h 72h Full release gate
v0.1.0 Failed: MinIO pull refused Passed: 400 exact committed events; cleanup passed Running, cached dependencies Running, cached dependencies Not qualified
v0.2.0 Failed: MinIO pull refused Passed: 400 exact committed events; cleanup passed Running, cached dependencies Running, cached dependencies Not qualified

The engine manifests tested were:

  • v0.1.0: sha256:c5fe5a6d414378c83b8977b3a8836db24c37a281383277cba9baf9e896136984
  • v0.2.0: sha256:9db3f04bbc9ee7d646a39955638b627dacf0126f4bec5e05ff80d7931e568d0a

Reviewed summaries are committed in release-validation results. The summary records the source/runner revision, image digests, effective configuration checksum, duration, assertions, omissions, outcome and teardown. Raw metrics, service logs and query/resource events remain in durable run artifacts, with a final SHA256 manifest; workflow artifacts retain them for 90 days. Hashes detect changes but are not signatures. Preserve failures and retries as separate records; review logs before publication.

An explicitly labeled cached-diagnostic dependency policy permits testing the published Siglake binary with already available MinIO/Postgres image digests. It still pulls Siglake anonymously and provisions fresh volumes. Such a run can supply runtime evidence, but cannot qualify an anonymous clean install or erase the release's dependency failure. The default public policy refuses the failed pull without substitution.

Separate 24-hour and 72-hour diagnostics for each release started on September 24 at about 19:47 UTC from committed runner df7a83f. The earliest nominal completion dates are September 25 and September 27 respectively, followed by final checks and teardown. These four runs use the explicit cached-dependency policy; none is an anonymous-install pass. Final summaries are pending.