A pipeline can test source code and then rebuild an image for production, producing different bytes after dependency resolution, timestamps, or base-image changes. The source revision alone does not prove which binary reached users. A release record needs the tested artifact digest, the verification result bound to that digest, and the exact digest selected for deployment. A mutable tag is only a pointer.
Tested artifact identity: deploy the bytes that passed
Operational decision
A receipt image passes integration tests in CI. Push that image once to the registry, record its immutable digest, run the final tests against the pulled image by digest, and promote that same digest to staging and production. The policy fragment lists the acceptance record. Before a deployment, compare the requested digest with the tested subject and reject mismatches even when the tag or source revision matches. Simulate a tag update after testing and confirm the deployment still uses the original digest. If an image index serves multiple architectures, verify each referenced platform image and record the index digest as the release unit. Keep the old digest accessible through the rollback window. The attestation or evidence document must be produced by the trusted build path; an untrusted pull-request job should not be allowed to assert its own production approval.
Receipt promotion evidence
Checked revision: immutable commit identifier
Test subject: registry image digest
Supported platforms: each child image checked
Promotion target: same image or index digest
Admission result: digest and trusted builder match
Rollback: prior digest still pullableCost and verification
Digest-based promotion reduces surprise but requires registry retention and careful garbage collection. Pulling the image again for final tests adds network and storage cost; it proves the registry artifact, not only a local build output. Measure mismatch rejections, missing rollback digests, platform coverage, and time from test to deployment. A signed statement bound to the wrong digest remains the wrong evidence; identity comparison is the essential step.
Common Mistakes
- Do not rebuild after final tests and call the new image tested.
- Do not deploy by a mutable tag when the approved record names a digest.
- Do not let an untrusted job certify its own release artifact.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Immutable artifacts and release provenance
- Software supply chain: SBOM and provenance at admission
- Untrusted CI artifacts: separate a pull-request test from promotion
- Rollback image retention: keep every approved fallback pullable
Practice and check
Supply evidence follow-up
- SBOM binding: keep the inventory attached to the tested digest
- Admission verification: compare the running image with approved evidence
