Skip to content

CES-96: re-pin agent-workloads sha-303b601591b7#179

Open
cesaregarza wants to merge 1 commit into
mainfrom
bot/agent-workloads-release-303b601591b7
Open

CES-96: re-pin agent-workloads sha-303b601591b7#179
cesaregarza wants to merge 1 commit into
mainfrom
bot/agent-workloads-release-303b601591b7

Conversation

@cesaregarza

Copy link
Copy Markdown
Owner

Summary

  • Re-pin SplatTopConfig to an immutable agent-workloads release.
  • Apply generated registry overlay manifest/image pins and Helm values.
  • Surface mandateReleasePins so token rotation uses the same computed digests.

Provenance

  • Source repo: cesaregarza/agent-workloads
  • Source commit: 303b601591b7a67d37919d23b7c9bb69df9bb684
  • Publish run id: 27492126685

Digest Pins

workload image digest manifest digest code digest
data.workspace_probe sha256:b17e9a92e203aa7c84d17cf92205dc09aacf21b84514c64348d0d1e6833af786 sha256:9f819d658ac8b7a0107b828b03123fc9b20db3ec169a3a81a0101eb0c0ef4348 sha256:62b2313c4a73337e7d4474d4c7bba8ee264ee106ce492620f4472c32b143125c
opencode.apply_executor sha256:2738a0b7aab153c8e5cc7f3610d44242047ed1ce416f22644d01567a48104a0d sha256:e76fdc94c8cb67a57893efc77975b63bee70b96a7a5269f25e57c0e5421f6749 sha256:155c42acfe6d04218a6fb7679f88b11b1e5825247c51b34f694a27c27581391f
opencode.proposer sha256:3321a60efe69f033989ce4ded40a33f6eb20f5d8392a75a4ce1f6a63797adbc1 sha256:fcd8cc09a050e87ad679eb7b7f2f110f4724945683d32dac34668921b7edeacf sha256:9c822db05dc17c2d0023ca3781e848cd2945c7a5a525bbab297af2c93436dbc6

Safety

  • This PR does not mint workload identity tokens.
  • The SplatTopConfig drift gate must pass before merge: decrypted workload identity token code_digest claims must match mandateReleasePins and the embedded registry overlay manifests.
  • No mutable :latest image tag is introduced.

Refs CES-96.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant