Kelos #820 live checkpoint — 2026-09-13 UTC
Kelos #820 live checkpoint — 2026-09-13 UTC
Later findings: Qwen and native session import checkpoint and authenticated native continuation. The admission-only snapshot below is retained as the initial checkpoint.
Qualification remains INCOMPLETE. A disposable single-node kind cluster ran Kelos v0.54.0 against the source baseline recorded in the fixture. Two admission runs passed on this same cluster; these are not two complete qualification runs.
| Check | Result |
|---|---|
| Infrastructure preflight | PASS in both admission reports |
| Eleven valid manifests, server-side dry-run | PASS twice |
| Invalid deadline rejected by validation | PASS twice |
| Fixture Python tests | 22 PASS locally and on the remote test host |
| Real coding, cancellation, retry | NOT_RUN |
| Session persistence/replacement/suspend/resume, controller recovery | NOT_RUN |
| Owned-resource cleanup and residue | NOT_RUN |
First admission report and second admission report record timestamps, input hashes, commands and exit codes. They created no workload resources. Exported commands replace the host-specific fixture directory with `${KELOS_FIXTURE_ROOT}`. Infrastructure preflight deliberately omits model Secret lookup; workload preflight still requires it. No model credential was provisioned.
Runtime inventory records the observed infrastructure Pod UIDs, image IDs and readiness, node runtime, and storage provisioner. Kubernetes is v1.34.0; the node reports containerd 2.1.3. All observed infrastructure containers were ready with zero restarts. The controller image ID matches the pinned digest. This inventory is an observation, not a complete immutable workload profile. Upstream Git/Node helper references still need digest enforcement before workload qualification. Some infrastructure image IDs are runtime configuration digests, not registry manifest digests.
Verified downloaded chart packages:
| Package | SHA256 of local archive |
|---|---|
| kelos-0.54.0.tgz | `275ecc13634fd34ed82133d87aafcd13936919381bde86951ab83de98707d2bc` |
| cert-manager-v1.19.1.tgz | `f72a727b1749df3521e7a65af5f18505f93b572d758841890270b150344b2b41` |
OCI chart digests were respectively `sha256:b2dd2e01aca38940f8c4b065e258ca30430f782f66b0ef203e96410cea7f7f9b` and `sha256:9578566b26b2258bcb9a0be27feeaa7c0adaed635cc0f85b6293e42a80c58cc9`. Archive hashes and OCI digests identify different objects.
Installation exposed a namespace collision: the Kelos chart renders its own namespace, so Helm `--create-namespace` caused revision 1 to fail despite creating healthy controller resources. A server-side dry-run and upgrade using the same chart/profile without that flag produced deployed revision 2. The fixture README now documents the corrected command. Cert-manager is deployed revision 1.
The cluster remains available for subsequent scenarios. Real-agent execution requires a selected test model and scoped account reference. Issue #820 remains open; no production, persistence, retry or cleanup conclusion follows from these admission checks.