Skip to content

[DOCS] partner guide: apply a later release while write access is granted - #14

Merged
haimbj1 merged 1 commit into
mainfrom
docs/later-release-with-write-access
Oct 5, 2026
Merged

haimbj1 merged 1 commit into
mainfrom
docs/later-release-with-write-access

Conversation

@haimbj1

@haimbj1 haimbj1 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Why

v1.0.3 will move all three images while every partner's write window is open (step 8 done, step 11 not yet).

"Apply a later release" has no grant_write_access flag. A partner who follows it during an open window closes the window. Then the keygen cannot write their share. Step 8 also says no one will ever ask for write access a second time, so reopening it later would look illegitimate.

Changes

  • New section "Apply a later release while write access is granted". The full command block keeps -var grant_write_access=true on plan and apply, and includes init and verify/. It also has:
    • the project-ID note (not the project number)
    • the expected plan for three changed images: 4 to add, 3 to change, 4 to destroy with the flag, and 2 / 3 / 4 without it, so "2 to add" means stop
    • the verify expectation: write_access_granted = true
    • "do not run step 11 now"
  • "Apply a later release": a note that sends partners with an open window to the new section.
  • Step 8 warning: reusing the flag during an open window is not a second grant.

Plan numbers, checked against the module

Both binding kinds put the image digest into the IAM member string, so a new digest replaces the binding. The gates update in place.

  • keygen gate: 1 change
  • attested_add × 2: 2 destroy + 2 add (keygen digest, main.tf:48)
  • reader gates × 2: 2 change
  • attested_read × 2: 2 destroy + 2 add (reader digests, main.tf:201)

Order

Merge this before dispatching v1.0.3, so the tag carries the corrected guide.

@haimbj1
haimbj1 merged commit 9804e2c into main Oct 5, 2026
2 checks passed
@haimbj1
haimbj1 deleted the docs/later-release-with-write-access branch October 5, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants