Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Registry evidence retention: keep referrers with the release digest

Last updated: 1 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

An OCI registry can expose artifacts that refer to an image digest, including SBOMs and attestations. The reference relationship lets clients discover evidence for a subject, but a registry copy or retention rule may omit or delete those attached objects. Deleting a tag can be different from deleting the underlying manifest; implementations also vary in supported deletion operations. The release owner must test evidence discovery and pullability in the registry used for deployment and rollback.

Operational decision

A billing service promotes an image from a build registry to a production registry. The source digest has a signed provenance statement and a final-image SBOM. Copy the image by digest, then enumerate evidence that refers to the destination subject. Copy each required statement, verify its own digest and signature, and reject promotion if the expected set is missing or points at the wrong subject. Repeat this on a registry that uses an alternate referrer-discovery mechanism, because a client returning no referrers is not necessarily proof none exist. Apply a dry-run retention rule that protects running, canary, rollback, and incident-held digests along with their required evidence. In a disposable repository, delete an unused tag and verify the protected digest and evidence remain pullable; then test manifest deletion behavior separately. Record which artifacts are held for legal or operational reasons and which can expire after the review window. During registry failover, verify a clean node can pull the image and a clean verifier can fetch its evidence from the replica. A cached success from the source registry is not acceptable proof of destination availability.

Output
Billing registry promotion contract
Subject: tested image digest
Evidence: SBOM digest and provenance digest
Destination: image and required referrers discoverable
Retention: running, canary, rollback, incident hold protected
Clean-node test: image pull and evidence verification
Deletion test: tag removal distinguished from manifest removal

Cost and verification

For R retained release digests and E attached evidence objects, inventory and retention review process O(R + E) records; copy cost includes bytes for both images and evidence. Keeping every historical artifact indefinitely raises storage charges, while deleting the only attestation can make a valid rollback inadmissible. Measure evidence discovery failures, orphaned statements, protected digest age, and successful clean-node failover pulls. A release is retained only when its bytes and required proof both remain available.

Common Mistakes

  • Do not assume image copy also copied its SBOM and attestation.
  • Do not treat deleting a tag as equivalent to deleting its digest everywhere.
  • Do not test registry failover only from a node with cached layers and trust data.

Connected lessons

Practice and check

devops
supply-chain
Storage details