Verify artifacts
Use these checks to prove a published release artifact came from the postvec release workflow, or that a cluster is healthy after setup.
Needs GitHub CLI 2.49 or newer for attestations. Checksums need SHA256SUMS from the same GitHub Release.
Packages
SIGNER=univec-ai/postvec/.github/workflows/postvec-release.yml
sha256sum --ignore-missing --check SHA256SUMS
gh attestation verify postgresql-18-postvec_0.5.0-2+deb12_amd64.deb \
--repo univec-ai/postvec --signer-workflow "$SIGNER"--ignore-missing supports a partial download; omit it for a complete release.
The signer is univec-ai/postvec/.github/workflows/postvec-release.yml.
Prerequisites script
gh --version # 2.49 or newer
gh attestation verify postvec-prerequisites.sh \
--repo univec-ai/postvec \
--signer-workflow univec-ai/postvec/.github/workflows/postvec-release.yml
less postvec-prerequisites.shInstalled files
postvec --version
test -f /usr/lib/postgresql/18/lib/postvec.so
test -f /usr/share/postgresql/18/extension/postvec.controlExpected
These checks succeed on the files alone. A local install also has libonnxruntime.so under /opt/postvec/libs and a model tree under /opt/postvec/models.
Container images
gh attestation verify oci://ghcr.io/univec-ai/postvec:0.5.0-2-pg18-local \
--repo univec-ai/postvec \
--signer-workflow univec-ai/postvec/.github/workflows/postvec-release.ymlThe node image:
gh attestation verify oci://ghcr.io/univec-ai/postvec-server:0.5.0-2 \
--repo univec-ai/postvec \
--signer-workflow univec-ai/postvec/.github/workflows/postvec-release.ymlContainer health
postvec-healthcheck asserts six properties in one query: the extension is installed; the library version equals the installed SQL version; the running mode equals POSTVEC_MODE; the build has embedded capability; the worker heartbeat is younger than postvec.heartbeat_interval_ms plus three postvec.poll_interval_ms ticks plus two seconds; and the first name in POSTVEC_EMBEDDED_MODELS is installed. POSTVEC_HEALTHCHECK_DATABASE selects the database and POSTVEC_HEALTHCHECK_BEAT_AGE overrides the heartbeat budget. The exit code is 0 only when all six hold.
Inference node
On a host that runs a postvec-server node:
postvec-server status
curl --silent --insecure https://127.0.0.1:22222/readystatus prints the binary version, the resident models, and every member of the cluster with its address, status and version; --fleet adds the model count per member. postvec-server --version matches the extension's release. /ready answers 200 once a model can serve, and 503 with a reason before the first model loads and during a drain; the node image uses it as its container healthcheck. Fleet covers drift between nodes.
Cluster
After setup:
sudo postvec doctor --database app --deepSHOW postvec.mode;
SHOW postvec.path;
SELECT postvec.version(), postvec.build_info();
SELECT extname, extversion FROM pg_extension
WHERE extname IN ('vector', 'postvec');
SELECT name, model_type, target_dim FROM postvec.models ORDER BY name;
SELECT * FROM postvec.status();Expected
doctor exit 0: library and SQL versions match, the heartbeat advances, on-disk / engine / SQL inventories agree. postvec.mode is embedded or grpc. At least one model is listed when inference is reachable.
--deep also hashes CLI-installed model receipts, --strict fails on warnings and --format json is for scripts.
On a container host, postvec doctor finds no pg_lsclusters cluster. Use postvec-healthcheck, or:
docker exec -u postgres postvec \
postvec doctor \
--database-url 'postgresql:///app?host=/var/run/postgresql' \
--database app