Skip to content

Publish Registryctl through reviewed package-manager channels #515

Description

@jeremi

User impact and evidence

The supported beginner installation uses a versioned GitHub Release installer and exact release assets. Package-manager distribution could improve upgrades and platform familiarity, but it would add independent metadata, signing, ownership, and lag risks.

Why this is non-blocking now

The versioned installer supports Linux amd64, Linux arm64, and macOS arm64 and binds the installed binary and image lock to release checksums. Extra packaging does not unblock the selected first-country journey.

Owner

Registry Stack release and Registryctl maintainers.

Prerequisites

  • Successful release-form evidence for the versioned installer.
  • A channel ownership, signing, provenance, update, rollback, and compromise-response decision.
  • A policy for version and image-lock atomicity.

Reconsideration trigger

Promote a specific channel when adopter evidence shows the installer is a material barrier, or an institution requires an approved package repository.

Expected verification

  • The package installs the exact released Registryctl and matching image lock atomically.
  • Package metadata binds the immutable source tag and published checksums/provenance.
  • Unsupported platforms fail without a source-build fallback.
  • Upgrade, downgrade, interrupted-install, stale-metadata, and compromised-channel negatives are covered.
  • Beginner documentation names only channels that actually contain the current release.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions