Choose the result that proves a release crossed each trust boundary safely. A configured control or a familiar file name is not evidence of the exact deployed bytes.
Review these lessons
- Untrusted CI artifacts: separate a pull-request test from promotion
- CI OIDC claims: bind cloud access to the exact deployment job
- Build secrets: keep credentials out of layers and exported caches
- Registry tag mutation: reject release decisions based on a moving pointer
- Signature trust rollover: rotate verification roots without disabling admission
- Registry replicas: prove the recovery region has the exact release image
- Rollback image retention: keep every approved fallback pullable
- Private package names: prevent a public registry winning resolution
Other checks
Common Mistakes
- Do not execute an untrusted artifact in a deployment job.
- Do not equate a registry tag with a verified digest.
