Kelos #820 live checkpoint — 2026-09-13 UTC

Kelos #820 live checkpoint — 2026-09-13 UTC

Later findings: Qwen and native session import checkpoint and authenticated native continuation. The admission-only snapshot below is retained as the initial checkpoint.

Qualification remains INCOMPLETE. A disposable single-node kind cluster ran Kelos v0.54.0 against the source baseline recorded in the fixture. Two admission runs passed on this same cluster; these are not two complete qualification runs.

CheckResult
Infrastructure preflightPASS in both admission reports
Eleven valid manifests, server-side dry-runPASS twice
Invalid deadline rejected by validationPASS twice
Fixture Python tests22 PASS locally and on the remote test host
Real coding, cancellation, retryNOT_RUN
Session persistence/replacement/suspend/resume, controller recoveryNOT_RUN
Owned-resource cleanup and residueNOT_RUN

First admission report and second admission report record timestamps, input hashes, commands and exit codes. They created no workload resources. Exported commands replace the host-specific fixture directory with `${KELOS_FIXTURE_ROOT}`. Infrastructure preflight deliberately omits model Secret lookup; workload preflight still requires it. No model credential was provisioned.

Runtime inventory records the observed infrastructure Pod UIDs, image IDs and readiness, node runtime, and storage provisioner. Kubernetes is v1.34.0; the node reports containerd 2.1.3. All observed infrastructure containers were ready with zero restarts. The controller image ID matches the pinned digest. This inventory is an observation, not a complete immutable workload profile. Upstream Git/Node helper references still need digest enforcement before workload qualification. Some infrastructure image IDs are runtime configuration digests, not registry manifest digests.

Verified downloaded chart packages:

PackageSHA256 of local archive
kelos-0.54.0.tgz`275ecc13634fd34ed82133d87aafcd13936919381bde86951ab83de98707d2bc`
cert-manager-v1.19.1.tgz`f72a727b1749df3521e7a65af5f18505f93b572d758841890270b150344b2b41`

OCI chart digests were respectively `sha256:b2dd2e01aca38940f8c4b065e258ca30430f782f66b0ef203e96410cea7f7f9b` and `sha256:9578566b26b2258bcb9a0be27feeaa7c0adaed635cc0f85b6293e42a80c58cc9`. Archive hashes and OCI digests identify different objects.

Installation exposed a namespace collision: the Kelos chart renders its own namespace, so Helm `--create-namespace` caused revision 1 to fail despite creating healthy controller resources. A server-side dry-run and upgrade using the same chart/profile without that flag produced deployed revision 2. The fixture README now documents the corrected command. Cert-manager is deployed revision 1.

The cluster remains available for subsequent scenarios. Real-agent execution requires a selected test model and scoped account reference. Issue #820 remains open; no production, persistence, retry or cleanup conclusion follows from these admission checks.