AutoUpdate=registry on moving 'latest' tag auto-deploys to prod with no human gate #128

Öppen
öppnade 2026-07-19 06:58:03 +00:00 av supernaut · 0 kommentarer
Ägare

Severity: MEDIUM (supply-chain / availability) — pre-onboarding infra audit (2026-07-19).

ansible/roles/web/templates/bitborg-web.container.j2 uses AutoUpdate=registry on the moving latest tag (web_image_tag: "latest", group_vars/all/vars.yml:73) with the podman auto-update timer. Any digest pushed to registry latest (compromised CI, bad build) auto-deploys to prod on the next timer tick with no human gate. By ADR 0019 design, but a real risk once users depend on the portal.

Ask

Consider pinning to immutable tags with a deliberate promote step (ties into ADR 0030 environments/promotion), or add a post-update health gate that rolls back on failure. Effort M.

**Severity: MEDIUM** (supply-chain / availability) — pre-onboarding infra audit (2026-07-19). `ansible/roles/web/templates/bitborg-web.container.j2` uses `AutoUpdate=registry` on the moving `latest` tag (`web_image_tag: "latest"`, `group_vars/all/vars.yml:73`) with the podman auto-update timer. Any digest pushed to registry `latest` (compromised CI, bad build) **auto-deploys to prod** on the next timer tick with no human gate. By ADR 0019 design, but a real risk once users depend on the portal. ### Ask Consider pinning to immutable tags with a deliberate promote step (ties into ADR 0030 environments/promotion), or add a post-update health gate that rolls back on failure. Effort M.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#128
Ingen beskrivning angiven.