## 0.69.0 - **Anchorpoint installs from one line.** `curl -fsSL https://get.anchorpoint.fikia.app/install.sh | sh` stands up a throwaway evaluation instance; the same line with `-s -- --install` performs a real install. The script itself installs nothing: it checks for docker, python3 and an `ssh-keygen` that knows the `-Y` verbs, downloads the release key and the bundle, prints the key's fingerprint, refuses to continue until an operator confirms it against a value obtained elsewhere, and then hands the whole job to `install.py` inside the bundle, which is covered by a signature the script did not produce and cannot forge. The prompt has no default, fetches no expected value, and refuses a bare newline: a script that supplied the value it checks against would be checking nothing. `deploy/install.sh` reads its base URL from one variable, so moving the endpoint is a redirect rather than a change to anything downstream. - **An evaluation instance, with a corpus that was generated and not captured.** `deploy/try/compose.yml` pulls the public image by digest and stands up postgres, a migration, a seed one-shot, a gateway and a console on ports and a volume of its own, so it cannot collide with an install on the same host. It runs no worker, which is what would send a heartbeat, so an evaluator's laptop never appears in the fleet. It holds no provider credential and calls no provider: every span in it comes from the delivery kit's replay fixtures. The console renders a banner on every screen saying so and printing the one command that removes it. - **The trial corpus lives in the package rather than in `scripts/`.** `scripts/` is deliberately absent from the image and try mode has no checkout to mount, so `anchorpoint/trial/` carries the seeder and the engagement it runs. That engagement is its own, on its own tenant, rather than a copy of the delivery kit's demo configuration: copying it put a client directory's engagement name inside `anchorpoint/`, which CI check 2 refuses, and correctly, because the platform names no client's engagement and that rule has no exception for a fixture. The list of strings that would mean our own captured corpus had leaked into a public image lives in `tests/test_trial_corpus.py` for the same reason, and the suite scans every shipped file and every generated row against it, with no exemptions. - **The installer is published to PyPI as `anchorpoint-install`, and deliberately does not contain the platform.** A Python wheel carries readable source, so shipping the platform that way would publish the source tree as a side effect of a packaging choice. The distribution holds one file, a byte-equal copy of `deploy/install.py`, with no dependencies at all. The shorter name `anchorpoint` is held on PyPI by an unrelated project and was never available. `install.py` no longer hardcodes `install.py` as its program name, so somebody who installed it from PyPI and typed `anchorpoint-install --help` is shown usage for the command they ran. - **The release image is published to `ghcr.io/sagacian/anchorpoint` by digest.** A second carrier for the same image, not a second build of it. GitHub Container Registry rather than Docker Hub because a package there can be public while its repository stays private. The bundle remains the artifact: an air-gapped boundary cannot pull. - **The licence, and it travels.** Business Source License 1.1, converting to Apache-2.0 three years after each release, with a non-production Additional Use Grant. `LICENSE`, `NOTICE` and `TRADEMARKS.md` reach the bundle, the image, the wheel and both npm packages, each by its own mechanism and each held by its own test. The npm connector stays MIT and `NOTICE` says why: it is a library a customer embeds in their own application, and a production restriction is the one thing such a library must not carry. - **CI builds the bundle; a person signs it.** A tag now runs a `release` job that builds an UNSIGNED bundle, pushes the image and uploads the bundle as a workflow artifact the public endpoint does not serve. `scripts/promote-release.py` refuses a bundle with no `MANIFEST.sig`, writes `latest.txt` last so a failed promotion leaves the previous release current, and is the act that makes an artifact public. The signing key never enters CI. - **`docs/INSTALL.md` is written for the person installing**, ships inside every bundle, and publishes both the release fingerprint and the install script's SHA-256; CI fails if that number and the file disagree. `docs/DEPLOY.md` is retitled "Deploying the staging line" and now says in its first paragraph that it is our runbook and not an install guide. - **What this release does not claim.** Nobody outside the team has installed Anchorpoint. Three of the distribution proofs need a real docker daemon and a real signed bundle and are hand run from `scripts/rehearse-distribution.sh` rather than in CI. `docs/DEFERRED.md` carries a row for each, and for the two places the trial corpus is thinner than the spec's sentence.