@zephytiju/lattice-infrastructure
v0.1.3
Published
Lattice control-plane deployment composition for Juntai Platform
Readme
Juntai Lattice Infrastructure
Deployment composition for the Lattice Model Configuration and Runtime
Generation control-plane services. The approved distribution is public npm
@zephytiju/lattice-infrastructure.
The Platform IaC design, section 5.3.1 owns the package boundary. This repository owns exact released service inputs, deployment images and factories, service resources, routes, policies, opaque configuration and secret references, logical Meridian requirements, migration, health, telemetry and recovery.
Platform Infrastructure only selects and invokes an immutable package release. Platform Foundations owns common substrate and physical Meridian bindings. LatticeDeployment owns generated-application topology and packaging for Vangu. Generated application resources, KES, provider creation and physical storage selection are outside this package.
Implementation and delivery are tracked by Lattice control-plane Platform onboarding. The 0.1.0 and 0.1.1 artifacts remain immutable. Version 0.1.2 consumes the released Authoring 0.5.3 / Query Engine 2.0.1 result-contract correction through normal exact dependency locks and role-image builds.
The 0.1.3 candidate adds native self-agent and delegated-agent recipient composition to the normal startup path. See the native agent configuration and acceptance record for its exact limits and pending gates.
The runtime readiness report records the exact
selected releases and verification limits. Foundations 1.7.0 now provides the
peer runtime composition and bounded shared-storage compatibility path.
Authoring 0.5.3, Generation 0.3.3, Metadata 3.2.1 and Blueprint 3.3.1 are released.
Both role images use the standard python:3.12.11-slim-bookworm base by digest.
All 89 dependencies, including Meridian, are installed from exact released Python
packages with hashes and normal dependency resolution. CI does not pull or
project a Foundations runtime image. The checked-in consumer lock selects the
package and storage contracts; the installed Python package verifies those
selections.
Lattice-owned factories now compose released IAM verification, native policy reads, request-scoped original-token forwarding, file-based signing, approval evidence reads and fresh workload callers for recovery. The deployment renders separate HTTP/MCP services, explicit token projections and a bounded compiler namespace. Local integration verification remains active; final images, package publication, Core selection and full lifecycle acceptance are still pending.
Local acceptance now covers real Metadata/Blueprint handoffs, source/destination authorization, HTTP/MCP restart and revocation, TLS telemetry export and Calico compiler isolation. Generation recovery now passes real Kubernetes TokenReview, an isolated build, six native Metadata contributions, strict duplicate-admission conflict and restart. Both candidate images read the same operation and all seven artifact digests through a v3/v4/v3 restore, upgrade and rollback sequence. The readiness report distinguishes completed checks from pending release work.
Real Pulumi acceptance has created the four service profiles and passed their schema gates, authenticated Service calls, and Envoy HTTPRoute rewrites. Rollout found a schema Job naming issue (fixed here) and a transient recovery-scan issue in Generation (PR 7, released in 0.3.3). Both HTTP/MCP processes now recover readiness after a real 20-second API outage without restarting. Repeated package rollback/upgrade, Envoy calls, negative ingress and all seven artifact digests pass. See the readiness report for release limits. The publishing procedure preserves the tested image bytes and npm tarball through verified release delivery.
