A registry tag names a reference that may point to different image content over time unless its repository enforces immutability. A scanner can inspect one digest while a later deployment pulls another digest through the same tag. Even an immutable tag rule can vary by repository or exception, so the release record should carry the exact image digest that passed checks.
Registry tag mutation: reject release decisions based on a moving pointer
Operational decision
A claims API pipeline scans a candidate tag and waits for approval. At build completion, record the digest returned by the registry. Run tests, provenance verification, and scan against that digest; at approval, compare the deployment manifest's digest to the approved one. The read-only commands inspect one repository's tag configuration and image identity. In a disposable registry, move a mutable candidate tag after scanning and verify the deployment gate refuses the changed digest. Use immutable release tags where the registry supports them, but still pin the production manifest to the digest. When copying across registries, verify the destination object's digest or an explicitly recorded mapping if a conversion changes bytes. Treat a missing destination artifact as a failed promotion rather than falling back to a tag with the same human-readable name.
aws ecr describe-repositories --repository-names claims-api --query 'repositories[].{name:repositoryName,mutability:imageTagMutability}'
aws ecr describe-images --repository-name claims-api --image-ids imageTag=release-47 --query 'imageDetails[].{digest:imageDigest,tags:imageTags}'Cost and verification
Digest pinning increases release-record precision and may require explicit manifest updates for each build. Mutable tags are convenient for development but create a time-of-check versus time-of-use race. Tag immutability reduces accidental moves, yet a deploy policy still needs to compare the approved digest with the actual image. Monitor unexpected tag changes, pull failures, and running digests by revision. A scan result bound only to a tag is ambiguous after that tag moves.
Common Mistakes
- Do not scan by tag and deploy by tag after an approval delay.
- Do not assume every registry or repository enforces the same mutability rule.
- Do not accept an identically named destination tag without checking its content identity.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Immutable artifacts and release provenance
- Software supply chain: SBOM and provenance at admission
- Multi-architecture images: verify every platform behind one tag
- Release evidence: tie one deployed digest to one approval decision
