fix(deploy): close container final review

This commit is contained in:
2026-07-12 00:44:39 +02:00
parent 0ca6346f75
commit a3a266fd81
30 changed files with 526 additions and 37 deletions
+14
View File
@@ -36,3 +36,17 @@ The small input file pins the harness's PEP 517 build backend as well; it is not
host environment. The image installs the resulting lock with pip's `--require-hashes`, then
installs the local `tht` project with `--no-deps --no-build-isolation`. This prevents both project
metadata and an isolated build environment from resolving unpinned packages.
## Base images
Every `FROM` uses an exact tag plus a multi-platform manifest-list digest. To update one:
1. Choose an exact patch tag that publishes both `linux/amd64` and `linux/arm64`.
2. Inspect it with `docker buildx imagetools inspect <tag>`.
3. Replace both the human-readable tag and `@sha256:...` digest.
4. Run `./scripts/verify-container-images.sh` and the Compose smoke.
5. Review the generated inventory under `.artifacts/container-images/`.
The digest freezes image layers, but `apt-get update` and `apk add` still consume mutable package
repositories during a no-cache rebuild. Full OS-package immutability would require Debian/Alpine
snapshot repositories and is not claimed by this deployment.