A container base tag is a pointer, not a guarantee that the same digest will resolve next week. Security fixes may arrive through distribution rebuilds without a change to application dependencies. Conversely, rebuilding from a mutable tag without recording its resolved digest can produce different output that cannot be explained from source commit alone. Base refresh is a new release with its own tests, SBOM, provenance, and rollback plan.
Base-image refresh: rebuild and retest when inherited bytes change
Operational decision
A receipt API inherits a minimal runtime image. Record the base manifest digest used for each architecture at build time and compare it with the approved update candidate. Trigger a rebuild when a base package needs a fix or the base image's support window changes; do not wait for an application code commit. Regenerate the final-image SBOM and compare the component graph, file changes, image size, startup behavior, and runtime identity. Test the release against synthetic receipt traffic and one node restart in each target architecture before canary promotion. Keep the previous digest pullable during rollback, but do not let an old vulnerable rollback image remain an unreviewed default for months. If the new base changes libc, certificate roots, locale files, or user IDs, verify behavior under actual deployment restrictions rather than relying on unit tests. Record advisory disposition for old and new digests. Pin the new base by digest for the tested build; schedule a later review rather than relying on automatic tag motion. A successful scanner report with no critical finding does not prove the application starts or can reach its dependencies.
Receipt API base refresh
Old base digest: recorded per architecture
Candidate base digest: reviewed before build
New image: fresh SBOM, provenance, test result
Runtime checks: startup, TLS, filesystem, user ID
Canary: receipt success and tail latency
Rollback: old digest pullable for a bounded windowCost and verification
A rebuild costs CPU, network transfer, scan time, and canary capacity even when application code is unchanged. For A architectures and T runtime checks, the acceptance matrix grows with A × T, while SBOM comparison scales with component count. Measure age of deployed base digests, rebuild lead time after an advisory, canary failures caused by base changes, and rollback-window exposure. Treat inherited package fixes as delivery work, not just a registry housekeeping task.
Common Mistakes
- Do not assume an unchanged source commit means unchanged runtime risk.
- Do not rebuild from a moving tag without recording the resolved base digest.
- Do not delete the old image before the tested rollback window ends.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Container builds: small runtime, explicit privilege
- Dependency patch campaigns: update, test, and prove the running image
- Multi-architecture images: verify every platform behind one tag
- Rollback image retention: keep every approved fallback pullable
