Skip to content

Retire blobheart sources (47ded742 21bc3aad 0569d74a 1364536b) - #38

Open
shariqahmed-cohere wants to merge 1 commit into
shariq/update-prune-flowfrom
prune/retire-47ded742-21bc3aad-0569d74a-1364536b
Open

Retire blobheart sources (47ded742 21bc3aad 0569d74a 1364536b)#38
shariqahmed-cohere wants to merge 1 commit into
shariq/update-prune-flowfrom
prune/retire-47ded742-21bc3aad-0569d74a-1364536b

Conversation

@shariqahmed-cohere

@shariqahmed-cohere shariqahmed-cohere commented Aug 25, 2026

Copy link
Copy Markdown
Collaborator

Note: Confirmed that our clusters dont have a live deployment from these sources.

Summary

Retired blobheart sources: 47ded742780246155c119caa1b3f90fd8b598c58 21bc3aad241a5299aa8586e6bc9dad690104e790 0569d74a9c500308f02625d9c903fe8129be5a16 1364536b6ee56ad6b8441840b4acfb5dd6cf9e1e

  • 15 targets removed (sources list became empty)
  • 0 targets trimmed (still active via other sources)
  • 7 targets remaining

Please review the removed targets and merge when ready.


Note

Medium Risk
Touches TEE attestation inputs; risk is mainly deleting the wrong blob if anything still attested against these hashes—verify nothing references the removed filenames before merge.

Overview
Removes two orphaned attestation initdata blobs under attestation-policy/initdata/ (SHA-384–named .toml files). Each file bundled aa.toml, embedded Kata/CoCo policy.rego (GPU CDI + image pinning extensions), and policy_data for a specific GPU peer-pod layout—one aligned with qw3-4b-l-cc sandbox naming and one with cat2508rws-l-cc.

This is cleanup after retiring blobheart deployment sources from the attestation pipeline: those hashes are no longer produced or wired through policy-manifest.yaml, which already points models like qw3-4b-l and cat2508rws-l at different initdata files. No Rego source changes—only deletion of unused, superseded attestation artifacts.

Reviewed by Cursor Bugbot for commit 485d434. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant