Task · CAOT-0029

Container publish and GHCR cleanup

Description

The runtime image publishes through the shared container-publish reusable rather than a hand-rolled job. A caller pinned to an old release does not receive a fix landed after it, so the pin is part of the task.

Acceptance Criteria

Definition of Done

Implementation Plan

Wave 1 lane 11: root creates additive OpenBao/GitHub release plumbing from live sibling shape, wires shared workflows and repository settings, then proves the release broker mint step and release PR.

Final Summary

Pinned shared publish and cleanup workflows use serialized release concurrency; run 35718855219 built, scanned, published, signed and attested the edge image.

View the source file on GitHub