You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit db622ae
Browse filesBrowse the repository at this point in the historyBrowse files
fix(supply-chain): attest the real published tags, and make the GPU image mirrorable
Review was right on both blocking points, and both needed code rather than
wording.
`imagetools create` always writes an index, even from a single manifest — so
`:<version>-amd64` is a single-entry index whose digest differs from the
`:<sha>-amd64` manifest it wraps. Verified against a local registry: pushing a
manifest at bd44eb13 and retagging it produced e857a74f. Attesting the manifest
therefore left the tag people actually pin unverifiable, and a static matrix
could not fix it: resolving the live tags for one image returns five distinct
digests, and which of them exist depends on whether the run is a release and
whether the latest guard passed.
A new attest-subjects job resolves the published tags to digests, de-duplicates,
and feeds attest-images as a dynamic matrix. Tags this run did not publish are
skipped rather than failing it.
The NVIDIA device plugin was hardcoded in the template, so the previous
guidance — mirror it to the same path, or patch the DaemonSet — was not durable:
copying to another registry does not redirect the pull, and a patch is reverted
by the next helm upgrade. It now takes its image from
ollama.gpu.devicePlugin.image and goes through the shared helper, so it honors
global.imageRegistry with useRegistryForAllImages like every other third-party
image. Default renders byte-identical; chart minor bumped for the new key.
Docs corrections from the same round, several of them regressions from my own
previous commit:
- The ADFS example set SSO_ISSUER to the IdP identifier, and SSO_SAML_AUDIENCE
defaults to SSO_ISSUER — so it silently broke audience validation. The example
now sets both.
- Compose does not pass MIGRATION_DATABASE_URL through from .env: its migrations
service declares an explicit environment list.
- CLI authentication requires Redis; it does not fall back, and redis.mdx
already said so.
- The rollback snippet assigned SIM_VERSION in a subshell that Compose never saw.
- Custom blocks hide their internals only when tracing is off.
- A new workspace is still governed by the organization's default group.
- doctor is not a Kubernetes tool, so it cannot be the first step for Helm users.
- ENTERPRISE_ENABLED needs its NEXT_PUBLIC twin.
- The 100 MB response cap does not cover MCP's standalone SSE stream.
- Generating CRON_SECRET in a shell configures nothing by itself.
Renaming two headings broke published anchors that an in-repo library article
links to; both now point at the new slugs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015BwsJTEQRzWJaY4BRCkPZt
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/enterprise/access-control.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -160,7 +160,7 @@ The **Chat Deployment** row also carries an **auth-mode allowlist** — *Auth mo
160
160
| Feature | What clearing it withholds |
161
161
|---------|---------------------------|
162
162
| Invitations | Prevents inviting anyone to a workspace or to the organization. |
163
-
| Workspace Creation | Prevents creating new workspaces. A new workspace falls outside every existing group's scope. |
163
+
| Workspace Creation | Prevents creating new workspaces. A new one is not covered by any workspace-scoped group until you add it, though the organization's default group still governs it. |
164
164
| Member Directory | Withholds the member directory. Members cannot see the names or email addresses of other members. |
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/enterprise/custom-blocks.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ A custom block always runs the **latest deployed version** of its source workflo
14
14
15
15
## Common uses
16
16
17
-
The block's author keeps the credentials and the workflow logic; consumers see only the inputs and outputs. Common patterns:
17
+
The block's author keeps the credentials and the workflow logic; by default consumers see only the inputs and outputs, unless the author enables **Trace runs in consumer logs**. Common patterns:
18
18
19
19
-**Internal API gateway.** Wrap an authenticated internal or partner endpoint — "Create Ticket", "Charge Account", "Provision User" — behind a block that takes only the business inputs. Teammates call it without the base URL, API key, or auth headers, and when the endpoint changes you update one workflow instead of every consumer's.
20
20
-**Blessed knowledge lookup.** Package a vetted retrieval pipeline — chunking, filters, reranking — as "Search Company Docs" with a single query input, so teams reuse the approved retrieval instead of each rebuilding it.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/enterprise/verified-domains.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -71,6 +71,6 @@ SSO_ENABLED=true
71
71
NEXT_PUBLIC_SSO_ENABLED=true
72
72
```
73
73
74
-
`ENTERPRISE_ENABLED` turns both on together. See the [self-hosted enterprise guide](/platform/enterprise/self-hosted).
74
+
`ENTERPRISE_ENABLED` turns both on together, but it needs its own browser twin — set `NEXT_PUBLIC_ENTERPRISE_ENABLED` alongside it, or the server enables SSO while the browser still hides it. See the [self-hosted enterprise guide](/platform/enterprise/self-hosted).
75
75
76
76
Once enabled, verify domains from **Settings → Organization → Single sign-on**, in the **Verified domains** section above the identity provider configuration. The older `/workspace/<workspaceId>/settings/domains` path still resolves to the same page.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/architecture.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -52,7 +52,7 @@ This holds essentially all durable state: workflows, runs, logs, users, organiza
52
52
53
53
### redis
54
54
55
-
Backs pub/sub, the Socket.IO adapter, the idempotency store, execution progress markers, distributed execution limits, and the CLI-auth approval store. The idempotency store, progress markers, and approval store fall back to Postgres or in-process state. Pub/sub falls back to a **process-local** emitter, which is fine on one replica and drops every cross-pod event on more than one. See [Redis](/platform/self-hosting/redis).
55
+
Backs pub/sub, the Socket.IO adapter, the idempotency store, execution progress markers, distributed execution limits, and the CLI-auth approval store. The idempotency storeand execution progress markers fall back to Postgres or in-process state. The CLI-auth approval store does not — CLI authentication requires Redis at any replica count. Pub/sub falls back to a **process-local** emitter, which is fine on one replica and drops every cross-pod event on more than one. See [Redis](/platform/self-hosting/redis).
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/security.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -220,7 +220,7 @@ The allowlist replaces four separate escape hatches, so a few deployments that w
220
220
221
221
Every guarded outbound response is bounded. A caller that does not set its own limit gets the default of **100 MB**; exceeding it rejects the request with a payload-size error and destroys the socket rather than buffering the rest.
222
222
223
-
This is an easily misread cause of "a large download from an integration fails" — the failure looks like a broken connection to the third-party service rather than a limit Sim imposed. It applies to the guarded provenances above, not to the presigned object-storage upload path.
223
+
This is an easily misread cause of "a large download from an integration fails" — the failure looks like a broken connection to the third-party service rather than a limit Sim imposed. It applies to the guarded provenances above, not to the presigned object-storage upload path, and not to MCP's standalone SSE stream, which is deliberately unbounded so a long-lived stream is not cut off.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/troubleshooting.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ description: Common issues and solutions
5
5
6
6
## Start here: `sim-setup doctor`
7
7
8
-
Before working through anything below, run the built-in checker. It catches most self-hosting failures without you having to guess which subsystem is broken.
8
+
On a Docker Compose or source install, run the built-in checker first. It catches most failures without you having to guess which subsystem is broken. It reads env files, so it is not a Kubernetes tool — on Helm, skip to the checks below.
0 commit comments