Skip to content

fix(release): pin the release image ref to the manifest digest (RIG-4454) - #1653

Closed
rigel-mintaka wants to merge 2 commits into
mainfrom
compass-repo/rig-4454-release-image-manifest-ref
Closed

rigel-mintaka wants to merge 2 commits into
mainfrom
compass-repo/rig-4454-release-image-manifest-ref

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The release body printed the agent image as ghcr.io/rigelbuild/compass-agent@<config digest>. A config blob is not a manifest, so the ref could not be pulled: v0.3.0's @sha256:63210555… returns MANIFEST_UNKNOWN, while :v0.3.0 is manifest sha256:6f60bf04….

  • release-image now also outputs the :vX.Y.Z manifest digest (skopeo inspect --format '{{.Digest}}'), next to the config digest it already verifies.
  • tools/release-notes builds ref from the manifest digest and prints the config digest as config digest:. The flags are --image-manifest-digest and --image-config-digest, given together or not at all.
  • When neither flag is passed, the probe path hashes the raw manifest bytes, which is how registries address a manifest.

Verification

  • bun test tools/release-notes: 26 pass. Tests updated for the new contract; a half identity throws.
  • Smoke test against the real :v0.3.0: the probe path and the flag path both give @sha256:6f60bf04…, and skopeo inspect on that ref exits 0.
  • actionlint on release.yml: the same 8 findings as main, none new.
  • biome: clean.

v0.3.0 is immutable, so its body stays wrong. The fix applies from v0.3.1.

Ledger-impact: none

Refs RIG-4454, RIG-1746

…454)

The release body printed ghcr.io/...@<config digest>. A config blob is
not a manifest, so the ref was unpullable (MANIFEST_UNKNOWN on v0.3.0).
release-image now outputs the :vX.Y.Z manifest digest beside the config
digest, and release-notes builds the ref from the manifest digest. The
probe path hashes the raw manifest for the same value.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@trunk-io

trunk-io Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

❌ This pull request could not start testing because there was a merge conflict. See more details here.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

@linear-code

linear-code Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RIG-4454

RIG-1746

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-repo-rig-4454-releas.compass-eng-docs.pages.dev

Deployed from compass-repo/rig-4454-release-image-manifest-ref at 8102e6c.

Changed pages:

…-4454)

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@rigel-mintaka

Copy link
Copy Markdown
Contributor Author

Superseded by #1775 (agent image published as an amd64+arm64 index). On main, classifyImageResult and the release-image retag step both name the image by the sha256 of the raw manifest/index bytes, which GHCR can pull, not by the config digest. Tests "an image manifest yields the digest of its raw bytes, not its config digest" and "a multi-arch index yields the list digest of its raw bytes" cover it. RIG-4454's ask is met on main, so this PR's diff is now redundant.

@rigel-mintaka
rigel-mintaka deleted the compass-repo/rig-4454-release-image-manifest-ref branch October 7, 2026 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants