Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Immutable artifacts and release provenance

Last updated: 7 Oct 20266 min read
tutorial
BeginnerBy AITrove Editorial

An artifact is an output of a build, such as a container image. A tag is a human-friendly pointer that can be moved; a digest identifies specific image content. Promotion means taking the tested digest to the next environment rather than rebuilding from the same source. Provenance connects that output to its source revision and trusted build process.

Operational decision

The payments worker is built once, scanned, and deployed to staging. When checks pass, production receives the same digest. Record the commit, build run, digest, scan result, and approval in one release record. A signature or attestation only helps if a deployment policy verifies the signer and its allowed source; storing an unsigned statement next to an image does not enforce anything. The manifest sketch uses a shortened digest for readability; substitute a real full SHA-256 digest before deployment. Rollback should also name an earlier approved digest, not an ambiguous latest tag. Keep the release record available during incident response so operators can answer which code and dependencies are running.

yaml
service: payments-worker
sourceCommit: b73e49a
buildRun: 4721
image: registry.internal/payments-worker@sha256:9a09c4f113a2
verifiedIn: staging
promotionTarget: production

Cost and verification

Retaining images and attestations costs registry space, so define a retention period that preserves rollback candidates. Rebuilding per environment can save some storage yet creates verification gaps and often wastes compute. A digest alone does not prove the builder was trustworthy; identity, permissions, dependency pinning, and verification policy matter. Treat the sample digest as illustrative. A working image reference needs the full digest from the registry and an accessible registry endpoint.

Common Mistakes

  • Do not deploy a mutable latest tag as the only release identity.
  • Do not infer trust from a digest without verifying its build origin.
  • Do not delete every earlier image needed for rollback.

Connected lessons

Operational follow-up

Advanced follow-up

Advanced follow-up

Advanced follow-up

Advanced follow-up

Related Prompt Engineering lesson: Prompt release artifacts: version the whole decision path.

devops
operations
Storage details