fix(deploy): close container final review
This commit is contained in:
@@ -36,3 +36,17 @@ The small input file pins the harness's PEP 517 build backend as well; it is not
|
||||
host environment. The image installs the resulting lock with pip's `--require-hashes`, then
|
||||
installs the local `tht` project with `--no-deps --no-build-isolation`. This prevents both project
|
||||
metadata and an isolated build environment from resolving unpinned packages.
|
||||
|
||||
## Base images
|
||||
|
||||
Every `FROM` uses an exact tag plus a multi-platform manifest-list digest. To update one:
|
||||
|
||||
1. Choose an exact patch tag that publishes both `linux/amd64` and `linux/arm64`.
|
||||
2. Inspect it with `docker buildx imagetools inspect <tag>`.
|
||||
3. Replace both the human-readable tag and `@sha256:...` digest.
|
||||
4. Run `./scripts/verify-container-images.sh` and the Compose smoke.
|
||||
5. Review the generated inventory under `.artifacts/container-images/`.
|
||||
|
||||
The digest freezes image layers, but `apt-get update` and `apk add` still consume mutable package
|
||||
repositories during a no-cache rebuild. Full OS-package immutability would require Debian/Alpine
|
||||
snapshot repositories and is not claimed by this deployment.
|
||||
|
||||
Reference in New Issue
Block a user