Browse documentation
Docs/Integrate

Publish Grid artifacts after the repository split

Prepare, submit, recover, and verify Libraries, Templates, Solutions, and Models with the 0.65.0 CLI and Registry ownership boundaries.

Publish Grid artifacts after the repository split

gridctl publish provides one remote Registry workflow for four signed artifact kinds. Each kind keeps its own manifest and verification contract.

Artifact Required manifest Specific command
Library or extension package grid-extension.json gridctl package publish
Template grid-template.json gridctl template publish
Solution or Domain Pack grid-domain-pack.json gridctl domain-pack publish
Pretrained Model grid-model.json gridctl model publish

A workbook file alone is not a complete signed publication directory. Changing signed catalog metadata changes the release.

The 0.65.0 source split changes where these tools are built: Grid Core owns shared protocol, trust, client, and verification libraries; grid-cli owns gridctl; and grid-registry owns Registry provider and recovery binaries. Record the exact revision of every repository selected by a source build. The wire formats, stored Registry data, and command meanings remain compatible.

Prepare authority and inspect the exact graph

Use an authorized Ed25519 private key outside the artifact directory. Keep private keys and publication credentials in the deployment's secret manager.

For a Registry that supports namespace enrollment:

gridctl publisher enroll --namespace acme \
  --private-key ./publisher-private.pem \
  --registry https://registry.example.com \
  --credential-out ./grid-publish.token \
  --request-out ./grid-publisher-enrollment.json

Inspect the exact descriptor and object graph before remote submission:

gridctl publish ./templates/engineering \
  --private-key ./publisher-private.pem --dry-run --pretty

Dry-run prepares and signs locally. It reports the coordinate, release digest, request digest, object count, and byte total; it does not read a publication credential or contact the Registry.

Submit and retain distinct identities

gridctl publish ./templates/engineering \
  --private-key ./publisher-private.pem \
  --registry https://registry.example.com \
  --credential-env GRID_REGISTRY_PUBLISH_TOKEN --pretty

Inspect the returned state, even when the process exits successfully. awaiting_upload, awaiting_finalize, verifying, awaiting_review, and publishing are intermediate states. Only published establishes the final publication result.

Retain the artifact kind, coordinate, Registry origin, submission ID, request digest, release digest, and publication receipt digest. They identify retry state, signed content, and publication authority; one cannot stand in for another.

Resume without changing bytes

An interrupted submission is resumed with the same signed descriptor and object bytes. The deterministic request identity lets the client request only missing objects. Do not alter a version's bytes to avoid a conflict.

Read authenticated submission status with the exact request digest and follow its retry disposition. Expired upload grants may require new grants for the same submission. Immutable identity conflicts require a deliberate correction rather than blind retry.

Publication recovery is separate from upload retry. Operators need the append-only publication and revocation receipts plus the complete retained descriptor and object inventory. A receipt without all referenced objects is not a recoverable publication, and a revoked coordinate must not reappear through an older catalog.

Keep publication and installation separate

Publication does not install or activate an artifact. Installation must resolve the exact signed coordinate, authenticate its publisher and Registry authority, check compatibility, and follow that artifact kind's activation boundary. Model installation also selects a compatible signed variant for the node; catalog presence alone does not supply a loader, accelerator, memory, or target qualification.

This page describes the candidate contract. It does not establish that a particular Registry service is deployed, that a namespace is yours, or that 0.65.0 product artifacts are available.