fix(ecr): Inspector-visible latest tags, tag lifecycle, weekly production rebuilds - #155
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Revert the latest retag loop and its mocked test. Disabling Bake provenance makes each push a plain image manifest, so all tags land on the manifest Amazon Inspector scans.
…ge per PR - staging version becomes staging-<sha7>; lifecycle keeps the last 10 staging images - preview images are tagged preview-<PR> and preview-<PR>-<sha> (no bare SHA); each push deletes the PR's older preview images, closing the PR deletes all of them - lifecycle policy: last 50 v*, last 10 staging-*, preview-* 365d backstop, untagged 7d
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 82d9343c0d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- rebuild the release tag or commit production runs; no deployment API scan - tag rebuilds rebuild-<run>-<release> with their own lifecycle rule, and give them latest/SHA tags like any build (drops the tag conditionals) - guard: refuse if production moved to another release, or runs a branch - drop per-push preview cleanup (PR close removes them) and the mocked test
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d105cc373
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A rerun keeps GITHUB_RUN_ID, so it rebuilt under the tag already deployed and the GitOps commit failed with nothing to commit.
Summary
Inspector-visible tags (Bake path). BuildKit's default provenance attestation turned each push into an OCI index; all tags sat on the index while Amazon Inspector scans the runtime manifest inside it, so findings carried no tags. Provenance is disabled per Bake target (as
preview.build-image.yamlalready does), so every tag points at the scanned manifest.Tag scheme and lifecycle.
staging-<sha7>.preview-<PR>andpreview-<PR>-<sha>(no bare SHA); closing the PR deletes all of them.v*, last 10staging-*, last 10rebuild-*,preview-*expire after 365 days, untagged after 7 days.Weekly production rebuilds. Calling
deployment.yamlwithenv: prodandrebuildProduction: true:.chart/prod/values.yaml(at theprodtag withpushToEnvTag, elsemain); it must be a release tag or commit SHA, since a branch would rebuild unreleased code;--pull --no-cacheasrebuild-<run-id>.<attempt>-<release>;Trade-offs
latestand the SHA tag like any build.Rollout
preview-<PR>-<sha>when this lands.v9before merging scheduled rebuild callers.Validation
actionlintandprettier --checkpass.v1.0.4144accepted,mainrejected); version stripping and theyq -eguard checked locally.