Skip to content

Docs: optional TOA verify for runtime health / promote - #6470

Open
dulrajnr wants to merge 3 commits into
stacklok:mainfrom
dulrajnr:toa-optional-verify
Open

Docs: optional TOA verify for runtime health / promote#6470
dulrajnr wants to merge 3 commits into
stacklok:mainfrom
dulrajnr:toa-optional-verify

Conversation

@dulrajnr

Copy link
Copy Markdown

Summary

Docs-only. Optional offline toa-verify before promoting or enabling an MCP workload in ToolHive.

  • docs/toa-optional-runtime-gate.md
  • examples/toa-after-runtime.yml
  • Pointers in docs/registry/heuristics.md, docs/README.md, and root README.md

Does not change runtime code. TOA (toa/0.1) is adjacent delivery evidence, distinct from Sigstore provenance. No AgentStatus account is required to verify.

Commit includes DCO Signed-off-by: AgentStatus <dev@agentstatus.dev>.

Test plan

  • Docs / example YAML are clearly optional and gated on toa.json
  • Copy does not claim TOA replaces Sigstore, Cedar authz, or health probes

Made with Cursor

Adjacent delivery-evidence gate only. Not on the tools/call hot path.

Signed-off-by: AgentStatus <dev@agentstatus.dev>
@dulrajnr
dulrajnr requested a review from JAORMX as a code owner August 31, 2026 02:49
AgentStatus added 2 commits August 30, 2026 20:25
Match toa-verify --require-emitter / --max-age 7d after Carmel-Labs-Inc/toa#1.

Signed-off-by: AgentStatus <dev@agentstatus.dev>
Carmel-Labs-Inc/toa@99e2690 ships keys/agentstatus-v1.json inside the python package (toa#2).

Signed-off-by: AgentStatus <dev@agentstatus.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant