From 9ff320ecca0c2c324e3ff61a710cd447b3eff972 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 11 Sep 2026 01:06:14 +0200 Subject: [PATCH] Pin the operator's own images by digest, as every other image already is MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nine references across seven modules named ':latest'. ADR 0006 forbids it and the host refuses it by name — and the refusal had never fired, because the lab pushed every image into its own registry and rewrote each reference to the digest it had just assigned. Deleting that registry made these the only manifests the host would now reject (novox/hq 04-ISSUES/039). The digests are what each tag resolves to today, read from the registry that serves them. This is a stopgap and should be said as one: a digest written into a repository is wrong the moment anybody rebuilds, which is precisely why the design has the repository name artifacts and the mesh hold digests. Until something builds and publishes, a digest that is stale is still better than a tag that silently moves. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/amqp-email-forwarder/module.json | 2 +- modules/de-spiegel/module.json | 2 +- modules/invoicing/module.json | 4 ++-- modules/novox.be/module.json | 2 +- modules/photos-eef/module.json | 2 +- modules/photos-filip/module.json | 2 +- modules/photos/module.json | 4 ++-- 7 files changed, 9 insertions(+), 9 deletions(-) diff --git a/modules/amqp-email-forwarder/module.json b/modules/amqp-email-forwarder/module.json index 208e633..81163b4 100644 --- a/modules/amqp-email-forwarder/module.json +++ b/modules/amqp-email-forwarder/module.json @@ -42,7 +42,7 @@ "id": "app", "type": "container", "name": "amqp-email-forwarder", - "image": "registry-api.novox.be/novox/amqp-email-forwarder:latest", + "image": "registry-api.novox.be/novox/amqp-email-forwarder@sha256:f76d34646d9d3b2098c72688a63f6ae656f1888ffcb2f90a9c8dd2a44ad7f8af", "network": "amqp-email-forwarder", "env-file": [ "/var/lib/amqp-email-forwarder/app.env" diff --git a/modules/de-spiegel/module.json b/modules/de-spiegel/module.json index 5fb00cf..97804a3 100644 --- a/modules/de-spiegel/module.json +++ b/modules/de-spiegel/module.json @@ -52,7 +52,7 @@ "id": "server", "type": "container", "name": "de-spiegel", - "image": "registry-api.novox.be/novox/de-spiegel:latest", + "image": "registry-api.novox.be/novox/de-spiegel@sha256:e144b72ce9c145870470d765343549f2c60211728cd118b9ff0e4029f36342ba", "network": "de-spiegel", "env-file": [ "/var/lib/de-spiegel/server.env" diff --git a/modules/invoicing/module.json b/modules/invoicing/module.json index e07579e..0cbf319 100644 --- a/modules/invoicing/module.json +++ b/modules/invoicing/module.json @@ -74,7 +74,7 @@ "id": "app", "type": "container", "name": "invoicing-app", - "image": "registry-api.novox.be/novox/invoicing-app:latest", + "image": "registry-api.novox.be/novox/invoicing-app@sha256:1e6ed40822f07169b24867cbfe8fc1ab3ef6a15ad642f3b3a2882a8e15c3dbec", "network": "invoicing", "env": { "UID": "2201", @@ -88,7 +88,7 @@ "id": "api", "type": "container", "name": "invoicing-api", - "image": "registry-api.novox.be/novox/invoicing-api:latest", + "image": "registry-api.novox.be/novox/invoicing-api@sha256:efa6fba1fa9ba78849e94e958d33793a76654df0468e3012da9c02c54c265354", "network": "invoicing", "env": { "UID": "2201", diff --git a/modules/novox.be/module.json b/modules/novox.be/module.json index 64c31c7..89b0d8b 100644 --- a/modules/novox.be/module.json +++ b/modules/novox.be/module.json @@ -40,7 +40,7 @@ "id": "server", "type": "container", "name": "novox-be", - "image": "registry-api.novox.be/novox/www:latest", + "image": "registry-api.novox.be/novox/www@sha256:aa7ed20a293e1d7444c5c5d59b6d8bdb382bad159559a22e006810e379cae69c", "network": "novox-be", "ports": [ "4000:8080" diff --git a/modules/photos-eef/module.json b/modules/photos-eef/module.json index 6bd86e5..751c3e3 100644 --- a/modules/photos-eef/module.json +++ b/modules/photos-eef/module.json @@ -41,7 +41,7 @@ "id": "client", "type": "container", "name": "photos-eef", - "image": "registry-api.novox.be/novox/photos-client:latest", + "image": "registry-api.novox.be/novox/photos-client@sha256:f87d63ee7bfb44c9f9748b99be6ba6dc0daf955a1d463699e9e7e3009693c0ab", "network": "photos-eef", "ports": [ "4012:80" diff --git a/modules/photos-filip/module.json b/modules/photos-filip/module.json index 4e092f3..a3be7d4 100644 --- a/modules/photos-filip/module.json +++ b/modules/photos-filip/module.json @@ -41,7 +41,7 @@ "id": "client", "type": "container", "name": "photos-filip", - "image": "registry-api.novox.be/novox/photos-client:latest", + "image": "registry-api.novox.be/novox/photos-client@sha256:f87d63ee7bfb44c9f9748b99be6ba6dc0daf955a1d463699e9e7e3009693c0ab", "network": "photos-filip", "ports": [ "4013:80" diff --git a/modules/photos/module.json b/modules/photos/module.json index 999acdd..29c826a 100644 --- a/modules/photos/module.json +++ b/modules/photos/module.json @@ -67,7 +67,7 @@ "id": "server", "type": "container", "name": "photos-server", - "image": "registry-api.novox.be/novox/photos-server:latest", + "image": "registry-api.novox.be/novox/photos-server@sha256:3f165acbbd1fd731b12fe798c95879c081a44b00e2c569ef7f47165f6a527201", "network": "photos", "env-file": [ "/var/lib/photos/server.env" @@ -80,7 +80,7 @@ "id": "admin-client", "type": "container", "name": "photos-admin-client", - "image": "registry-api.novox.be/novox/photos-admin-client:latest", + "image": "registry-api.novox.be/novox/photos-admin-client@sha256:f437fa9ed28b29a012f715fb8d9b809a15cff4a672794c620d5d400f57695580", "network": "photos", "ports": [ "4001:80"