Skip to content

fix(ecr): Inspector-visible latest tags, tag lifecycle, weekly production rebuilds - #155

Merged
gersmann merged 6 commits into
mainfrom
fix/ecr-latest-manifest
Sep 28, 2026
Merged

gersmann merged 6 commits into
mainfrom
fix/ecr-latest-manifest

Conversation

@gersmann

@gersmann gersmann commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Inspector-visible tags (Bake path). BuildKit's default provenance attestation turned each push into an OCI index; all tags sat on the index while Amazon Inspector scans the runtime manifest inside it, so findings carried no tags. Provenance is disabled per Bake target (as preview.build-image.yaml already does), so every tag points at the scanned manifest.

Tag scheme and lifecycle.

  • Staging version becomes staging-<sha7>.
  • Preview images are tagged preview-<PR> and preview-<PR>-<sha> (no bare SHA); closing the PR deletes all of them.
  • Lifecycle policy (identical in all workflows): last 50 v*, last 10 staging-*, last 10 rebuild-*, preview-* expire after 365 days, untagged after 7 days.

Weekly production rebuilds. Calling deployment.yaml with env: prod and rebuildProduction: true:

  • reads the version in .chart/prod/values.yaml (at the prod tag with pushToEnvTag, else main); it must be a release tag or commit SHA, since a branch would rebuild unreleased code;
  • deploys that ref with --pull --no-cache as rebuild-<run-id>.<attempt>-<release>;
  • refuses to write GitOps if production has moved to a different version in the meantime.

Trade-offs

  • Bake-built images no longer carry BuildKit provenance; nothing in this repo consumes it.
  • Rebuilds move latest and the SHA tag like any build.

Rollout

  • Preview appsets must deploy preview-<PR>-<sha> when this lands.
  • Publish in v9 before merging scheduled rebuild callers.
  • Existing ECR images are not retagged.

Validation

  • actionlint and prettier --check pass.
  • Tag check verified against the backend repo (v1.0.4144 accepted, main rejected); version stripping and the yq -e guard checked locally.
  • Not yet exercised end to end.

@gersmann
gersmann requested a review from a team as a code owner September 25, 2026 11:36
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T21:51:39.815842Z 9d105cc New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added docs Improvements or additions to documentation ci yaml labels Sep 25, 2026
Revert the latest retag loop and its mocked test. Disabling Bake provenance
makes each push a plain image manifest, so all tags land on the manifest
Amazon Inspector scans.
@gersmann gersmann changed the title fix(build-image): tag ECR runtime manifests as latest fix(build-image): disable Bake provenance so ECR tags hit the scanned manifest Sep 27, 2026
@github-actions github-actions Bot removed the docs Improvements or additions to documentation label Sep 27, 2026
…ge per PR

- staging version becomes staging-<sha7>; lifecycle keeps the last 10 staging images
- preview images are tagged preview-<PR> and preview-<PR>-<sha> (no bare SHA);
  each push deletes the PR's older preview images, closing the PR deletes all of them
- lifecycle policy: last 50 v*, last 10 staging-*, preview-* 365d backstop, untagged 7d
@gersmann gersmann changed the title fix(build-image): disable Bake provenance so ECR tags hit the scanned manifest feat(ecr): lifecycle-friendly image tags, per-PR preview cleanup, Bake provenance off Sep 27, 2026
@github-actions github-actions Bot added the docs Improvements or additions to documentation label Sep 27, 2026
@gersmann gersmann changed the title feat(ecr): lifecycle-friendly image tags, per-PR preview cleanup, Bake provenance off feat(ci): refresh production images weekly and manage ECR lifecycle Sep 27, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 82d9343c0d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/preview.build-image.yaml Outdated
Comment thread .github/workflows/deployment.yaml Outdated
- rebuild the release tag or commit production runs; no deployment API scan
- tag rebuilds rebuild-<run>-<release> with their own lifecycle rule, and
  give them latest/SHA tags like any build (drops the tag conditionals)
- guard: refuse if production moved to another release, or runs a branch
- drop per-push preview cleanup (PR close removes them) and the mocked test
@gersmann gersmann changed the title feat(ci): refresh production images weekly and manage ECR lifecycle fix(ecr): Inspector-visible latest tags, tag lifecycle, weekly production rebuilds Sep 27, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9d105cc373

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/deployment.yaml Outdated
A rerun keeps GITHUB_RUN_ID, so it rebuilt under the tag already deployed
and the GitOps commit failed with nothing to commit.
@gersmann
gersmann merged commit 0334ac5 into main Sep 28, 2026
9 checks passed
@gersmann
gersmann deleted the fix/ecr-latest-manifest branch September 28, 2026 08:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci docs Improvements or additions to documentation yaml

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants