Skip to content

CES-96: re-pin agent-workloads sha-64ede0f95c68#178

Open
cesaregarza wants to merge 1 commit into
mainfrom
bot/agent-workloads-release-64ede0f95c68
Open

CES-96: re-pin agent-workloads sha-64ede0f95c68#178
cesaregarza wants to merge 1 commit into
mainfrom
bot/agent-workloads-release-64ede0f95c68

Conversation

@cesaregarza

Copy link
Copy Markdown
Owner

Summary

  • Re-pin SplatTopConfig to an immutable agent-workloads release.
  • Apply generated registry overlay manifest/image pins and Helm values.
  • Surface mandateReleasePins so token rotation uses the same computed digests.

Provenance

  • Source repo: cesaregarza/agent-workloads
  • Source commit: 64ede0f95c687cdbfc65258a44664fafd04da3bb
  • Publish run id: 27491421992

Digest Pins

workload image digest manifest digest code digest
data.workspace_probe sha256:56d0120ad3cf41625b390f3f3d9d7ab21fb686cf9517e7e5c6e3431ee11ef6b4 sha256:d0eabf22dde73b832caaf90d72224167b65b6be4c9ccb0eb873639fc8e6635c3 sha256:59de77a73957a1c70f7861716dc8aebf99b2de0935cecb774366b357742b4907
opencode.apply_executor sha256:877a1315dd24f3d3701cb0772d650d0eb09bba3e6e81e23a94bd952ae375dc0c sha256:84deb27454831f26afdee93b91b94542c7dad70f0674d67c21b13b9db2ce5578 sha256:dbefa9777f5828832c6bc4f53d7a2103f46118a1f311f5cd912cd771f1e91db2
opencode.proposer sha256:a85427d0e9038a05871be74332d2edf69428245d67febdee8a510b960b50ac17 sha256:20d9ed27a80ea376005a1a39c00c4bbcf6227887a2897a98ab89c819c817e65e sha256:71eab11b413d3ad3f5469008e6eda0468260528d81c917c831fd58dd3e77dc1f

Safety

  • This PR does not mint workload identity tokens.
  • The SplatTopConfig drift gate must pass before merge: decrypted workload identity token code_digest claims must match mandateReleasePins and the embedded registry overlay manifests.
  • No mutable :latest image tag is introduced.

Refs CES-96.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant