Hewbers / Status and news

Current development snapshot.

Main at 1bb1bcfa combines continuous self-hosted backlog operation with calibrated workflow simulation, qualified minikube remote placement and restricted prompt and context artifacts. The service uses Hew 0.6.0-rc7 and remains under maintainer supervision.

Updated 2026-10-03Revision 1bb1bcfaHew 0.6.0-rc7

01 / Current state

What is operating today.

Operation

Continuous supervised service

The service self-deployed the current revision, resumed scheduled backlog work and advanced to stage-scoped short-lived credential resolution.

Release

Source-built development snapshot

The current operating profile is Linux from a developer checkout. A packaged public release has not been cut.

Execution

Local workflows plus remote image-stage path

Local authored workflows are established. Kubernetes placement now includes real minikube dispatch, accepted-result restart and exact pod-loss recovery.

Providers

GitHub, Gitea and multiple coding harnesses

Repository operations support GitHub and Gitea. Coding adapters support Copilot CLI, Claude Code, Codex and OpenClaw-compatible commands.

02 / Recent work

Delivered changes.

Recent merged work through the current main revision.

  1. Prompt and context artifacts now use restricted private files

    Authoring, review, remediation and verifier capture preserve private artifact permissions and avoid exposing sensitive payloads through arguments, diagnostics or broadly readable state.

  2. Remote placement and pod-loss recovery qualified on minikube

    Non-self image dispatch, accepted-result restart and exact-UID pod replacement ran through the repository's disposable Kubernetes profile with owner-validated completion and scoped cleanup.

  3. Workflow simulation now learns from recorded journal history

    Path simulation can use recorded task, gate and retry observations to calibrate hypothetical outcomes without rewriting or confusing them with actual run history.

  4. Remote authored stages can surrender results to the run owner

    A checked non-self image stage can now publish the exact configured result to its fenced owner. Missing, stale, duplicate or cross-run callbacks remain rejected.

  5. Pod-loss recovery and Azure workload identity landed

    The remote path records exact-pod deletion intent, observes a bounded successor and avoids repeating a completed recovery action. Azure model credentials can be exchanged through a configured federated identity.

  6. Interrupted implementation and exact-head verification recovered

    Hewbers can resume an interrupted implementation stage, preserve its fenced worktree and pass the selected Hew toolchain into deterministic verification.

  7. Continuous self-hosted operation established

    The service moved beyond a bounded canary: it polls its backlog, completes distinct changes over time and updates itself only after a successful rebuild.

03 / Development direction

What the project is building next.

This reflects active pull requests and the current open backlog; it is direction, not a release-date promise.

Finish remote execution as an operating profile

Exercise the complete non-self Kubernetes and Azure paths with disposable infrastructure, authenticated images, failure recovery and independently checked completion.

Strengthen review and provider reconciliation

Finish moving-base exact-head verification, persist uncertain provider mutations and route fresh human pull-request comments into bounded remediation.

Protect stage-scoped credentials

Resolve short-lived credentials from each run's immutable capability pin, keep values out of durable state and stage envelopes, and scrub them before any diagnostic or provider effect is recorded.

Add event and agent communication foundations

Integrate Nisshi as the durable event-log sink, then add NATS transport with explicit delivery, ordering, authentication and agent-isolation semantics.

Ship a supported install

Package the service, configuration and upgrade/restore workflow so evaluation and operation no longer depend on a developer checkout.

Release channel

Source-built development snapshots.

Hewbers is operating and useful, but there is not yet a packaged public release. The next release milestone is an installable service with configuration, upgrade, restore and rollback paths that preserve the current recovery model.

Read setup and operating concepts →