Skip to content

Releases & versioning

OpenDome Platform versions are CalVer YY.MM.MICRO — YY.MM is the release month, MICRO a counter within it. The latest release is 26.08.9 (August 2026).

A release is a git tag pointing at a pinned commit: the automated release:calver job computes the next CalVer, builds and scans the cell images, cosign-signs them, writes each image’s tag and immutable sha256 digest into the chart values, commits that pin back to main, and tags the pinned commit with a GitLab Release.

So deploying a release is just:

Terminal window
git clone https://gitlab.com/opendome.eu/platform.git
cd platform
git checkout <YY.MM.MICRO> # e.g. 26.08.9
# charts/*/values.yaml now reference repo:<tag>@sha256:<digest>

…and every chart pulls exactly the scanned, signed images — verify them with cosign before deploying.

  • Tags are immutable — a bad release is superseded, not deleted: the fix ships as the next CalVer and the affected range is noted in the changelog.
  • Security fixes land on the latest line only (no backports) — track the most recent release.
  • The spec versions independently: apiVersion: osl.opendome.eu/v1 is a promise not to break your YAML across the whole v1 line — see OSL specification.
  • Releases before 26.08.9 predate per-release changelog sections; their git tags and GitLab Releases are the record.