noCV
DREL-101 · Make the delivery contract visible

Bind release identity to an artifact digest

Practice briefTaskFoundational

The deployment record stores image:latest and commit branch, so two releases display the same identity after the tag moves.

Focused work estimate
1h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
Artifact identity · Release metadata

Estimated field mix

  • DevOps70%
  • Platform engineering30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional scheduling API is rebuilt separately for test, staging, and production-like local environments. The resulting images differ, release notes list the branch instead of the artifact, and rollback rebuilds old source with new dependencies. Use a local registry simulator and synthetic deployments; no cluster or customer traffic is supplied.

Setup prerequisites

  • Artifact digests
  • Release states
  • Health checks

Preceding work

No earlier ticket is required. Complete the project setup above.

Acceptance criteria

  • Release stores immutable artifact digest, source revision, and build manifest hash
  • Mutable tags resolve to a digest before approval
  • Display distinguishes requested tag from deployed digest

Implementation constraints

  • Use the local registry simulator and never pull public images.

Verification to include

  • Resolve and deploy one fixture tag while retaining its digest.
  • Move the tag and confirm the approved release identity does not change.

Deliverables

  • Immutable release record and moved-tag test

Rollout and recovery

Require digest resolution before any environment accepts a new release.

Value of the work

For the engineer: Practice immutable promotion, release authority, compatibility gates, canaries, and rollback.

For the team: Review a delivery flow that can identify exactly what is running and restore a known artifact without rebuilding it.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.