An artifact is an output of a build, such as a container image. A tag is a human-friendly pointer that can be moved; a digest identifies specific image content. Promotion means taking the tested digest to the next environment rather than rebuilding from the same source. Provenance connects that output to its source revision and trusted build process.
Immutable artifacts and release provenance
Operational decision
The payments worker is built once, scanned, and deployed to staging. When checks pass, production receives the same digest. Record the commit, build run, digest, scan result, and approval in one release record. A signature or attestation only helps if a deployment policy verifies the signer and its allowed source; storing an unsigned statement next to an image does not enforce anything. The manifest sketch uses a shortened digest for readability; substitute a real full SHA-256 digest before deployment. Rollback should also name an earlier approved digest, not an ambiguous latest tag. Keep the release record available during incident response so operators can answer which code and dependencies are running.
service: payments-worker
sourceCommit: b73e49a
buildRun: 4721
image: registry.internal/payments-worker@sha256:9a09c4f113a2
verifiedIn: staging
promotionTarget: productionCost and verification
Retaining images and attestations costs registry space, so define a retention period that preserves rollback candidates. Rebuilding per environment can save some storage yet creates verification gaps and often wastes compute. A digest alone does not prove the builder was trustworthy; identity, permissions, dependency pinning, and verification policy matter. Treat the sample digest as illustrative. A working image reference needs the full digest from the registry and an accessible registry endpoint.
Common Mistakes
- Do not deploy a mutable latest tag as the only release identity.
- Do not infer trust from a digest without verifying its build origin.
- Do not delete every earlier image needed for rollback.
Connected lessons
- DevOps Tutorial
- Container builds: small runtime, explicit privilege
- GitHub Actions: narrow tokens and cloud trust
- Progressive delivery: canary checks and rollback
Operational follow-up
Advanced follow-up
Advanced follow-up
- Registry tag mutation: reject release decisions based on a moving pointer
- Rollback image retention: keep every approved fallback pullable
Advanced follow-up
Advanced follow-up
Related Prompt Engineering lesson: Prompt release artifacts: version the whole decision path.
