AutoUpdate=registry on moving 'latest' tag auto-deploys to prod with no human gate #128
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#128
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Severity: MEDIUM (supply-chain / availability) — pre-onboarding infra audit (2026-07-19).
ansible/roles/web/templates/bitborg-web.container.j2usesAutoUpdate=registryon the movinglatesttag (web_image_tag: "latest",group_vars/all/vars.yml:73) with the podman auto-update timer. Any digest pushed to registrylatest(compromised CI, bad build) auto-deploys to prod on the next timer tick with no human gate. By ADR 0019 design, but a real risk once users depend on the portal.Ask
Consider pinning to immutable tags with a deliberate promote step (ties into ADR 0030 environments/promotion), or add a post-update health gate that rolls back on failure. Effort M.