deploy: staging pins for a8b90181 (images.yml GH013) - #245
Conversation
Greptile SummarySummary
Merge safetySafe to merge. The rollback path now restores a consistent prior release. Confidence Score: 5/5Safe to merge. No new actionable findings remain. The previously reported rollback-snapshot issue is fully fixed: the current staging pin retains all five services from the prior Reviews (8): Last reviewed commit: "deploy: staging pins for a8b9018134a3e7b..." | Re-trigger Greptile |
|
@greptileai review P1 rollback snapshot is addressed in 24ef9ce: |
24ef9ce to
c4de49f
Compare
|
@greptileai review Retargeted to |
c4de49f to
7288312
Compare
|
@greptileai review Retargeted to |
7288312 to
a72840a
Compare
|
@greptileai review Retargeted to |
a72840a to
52becba
Compare
|
@greptileai review Retargeted to |
52becba to
2eed898
Compare
|
@greptileai review Retargeted to |
images.yml built GHCR digests on main then could not push the pin commit (GH013: PRs required + Greptile). Land the same promote via PR. Co-authored-by: Mathis <echobt@users.noreply.github.com>
2eed898 to
a3ff63e
Compare
|
@greptileai review Retargeted to |
Why
images.ymlonmainkeeps building GHCR digests then failing update · commit staging pins with GH013. Latest miss:a8b90181(#253, run 34373475123).Staging on
mainis still1dd07f74(2026-09-05). Prod pins were not touched.Separately,
deploy staging master/validatoron that SHA failed opening the DigitalOceanbase-hostsfirewall: HTTP 422must have no more than 50 rules. That is leftover ephemeral/32SSH rules, not a pin-file bug. This PR does not touch DO firewalls.What changed
deploy/digests/a8b9018134a3e7b5446514ab48a937882b0f0a63.jsondeploy/pins/staging.jsoncommit_sha→a8b90181…previousis the complete1dd07f74current setimages.ymlsnapshots that release once before the promote loop and writes it back aftera8b90181)1dd07f74)sha256:650bfe48…sha256:1b95fe82…sha256:17ded01b…sha256:fa8b73b7…sha256:e42a763e…sha256:4f0cf422…sha256:cdc9696f…sha256:624c1d1e…sha256:b7a33f89…sha256:2541d0af…This does not bump
config/proof-pin.toml/ proof-evalsha256:057a42ef….Greptile
a3ff63ea)@greptileai reviewTest plan
staging.jsoncommit_sha==a8b90181…previousis the full1dd07f74service setprod.jsonunchangeda3ff63eadeploy-stagingcan match staging pins to this SHA (also needs the DO firewall rule cap cleared)Risk
Staging pin ladder only. No emission, no
BASE_*rename, no invented sha256.Naming
I did not rename
BASE_*environment variables, deployed host paths, GHCR package names, orbase-*-v1cryptographic domain tags.