Auton 1.0 readiness review¶
Updated 2026-09-30 for the 1.0.0 release candidate, based on master 9435e943.
The candidate updates package metadata and release/migration documentation.
Publication is gated by the release PR checks; a version change alone is not approval.
Implemented and verified before this review¶
Local visibility, ownership and endpoint ACLs; compatible run/status API.
CLI/TUI, named targets/groups, scenarios/groups and explicit multi-target work. URI chains remain failover; ambiguous submissions are never automatically replayed.
Separate optional SQLite authentication and job-history stores using HTTPdis and Sonicprobe. Interrupted jobs become explicit outcomes rather than being replayed.
Required authentication, Argon2 accounts, scoped expiring/revocable tokens and private token-file input; legacy Basic migration remains explicit.
Optional daemon web console with same-origin browser sessions, CSRF enforcement, maintenance permissions and confirmed execution through the existing services.
Master PR #25 passed 166 unittest cases, supported Python versions, packaging, Docker build and Chromium acceptance. Real TUI and browser screenshots are local repository assets. These checks are evidence for that revision, not a 1.0 approval.
Release gates and evidence¶
Gate |
Finding / required result |
|---|---|
Multi-daemon credentials |
Implemented after the initial review: explicit origin-bound token profiles, flat credential imports, CLI/TUI/scenario integration and complete selection checks before I/O. Tested with two independent daemon stores and maintenance failover. Single-token and legacy Basic modes remain explicit alternatives. |
Authentication audit |
Implemented after the initial review: optional private rotating JSONL audit, bounded writes/suppression summaries, HTTP 401/403, authentication 503 and HTTPdis login throttling. Real HTTP tests cover denied requests, throttling, backend failure and exclusion of request secrets. No per-user attribution or administrative history is claimed. |
Fresh installation |
Previous Compose used required auth without provisioning and listened on container loopback. This change supplies a dedicated config, interactive provisioning, separate persistent files and real Compose acceptance in CI. |
Documentation |
Release guide documents 0.3.2 upgrade/rollback, explicit auth migration, default memory vs optional SQLite and lifecycle limits. README examples target 1.0.0. Sphinx and screenshot links are CI gates. |
Release artifacts |
Candidate 1.0.0: matching client/daemon wheels, sdists and non-root image. CI checks source/wheel parity, installed entry points/web assets and actual 0.3.2 client/server compatibility outside the checkout before publication. Python 3.13+ remains unsupported. |
Website |
auton.run is deployed via GitHub Pages from the separate private auton-site repository, with HTTPS, verified version provenance, local captures/video and browsable docs. Pin it to the release commit after packages publish. |
Contact |
Recipient is auton@doowan.net. A working mailto contact is available. A contact form is non-blocking; delivery and spam protection remain to be supplied; never present a form that silently drops messages. |
Website content contract¶
The first site should introduce the product, then give a working install/quickstart, architecture, CLI/TUI/web-console examples, targets/scenarios, failover vs explicit multi-target execution, security, CI/CD, releases and GitHub/PyPI links. Keep captures local with an accessible gallery/lightbox and visible version provenance. No public execution daemon or credentials are needed for the demonstration.
Deliberately deferred¶
Redis adapters and mixed stores, SSO/OIDC, mTLS, Python 3.13+, cancellation and additional TUI operation UX are separate work. Centrex, global RBAC and centralized multi-node persistent history remain outside this roadmap. A durable local history does not supervise or recover an orphaned child after an abrupt daemon death.