noCV
AIMAGE-105 · Promote exact artifacts

Promote the tested digest instead of rebuilding for each environment

Practice briefStoryAdvanced

The staging build passes, but production rebuilds the same commit with different transitive dependencies.

Focused work estimate
3h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Artifact promotion · Identity checks

Estimated field mix

  • Platform engineering100%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional reporting API is rebuilt separately for staging and production. Different dependency resolutions and mutable tags make incident rollback unreliable.

Setup prerequisites

  • Create a tiny local HTTP service and nonprivileged image build.
  • Use synthetic registries or provider fixtures; no production deployment.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Promotion selects the exact tested digest.
  • Separate runtime configuration from artifact construction.
  • Reject a tag that resolves to a different digest at promotion.

Implementation constraints

  • Model registries through a testable provider interface.

Verification to include

  • Promote a tested synthetic digest through two environments.
  • Move a mutable tag and verify promotion rejects the changed artifact.

Deliverables

  • Digest promotion command and tag-race regression

Rollout and recovery

Canary promotion metadata; restore the previously selected digest if validation fails.

Value of the work

For the engineer: Practice artifact identity, least privilege and reproducible delivery.

For the team: Review whether deployed bytes can be traced and rolled back reliably.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.