Build Stage Discussion?? Need better title
Background
There have been recent questions about the CHT pipeline's build stage and how we handle rebuilds and the storage policy these images in Harbor.
- One issue raised is that our policy to not retain untagged images, causes SHAs to be deleted in the production
ironbank
project to be deleted when an automated rebuild pushes a new tag. - Others have taken issue with rebuilding images with updated dependencies (e.g. a resource noted in the hardening_manifest's resource section that Renovate provides updates for), without updating the tag of the image.
DoD
-
Make better title -
Review via a team discussion if these issues should be addressed -
If so, document what is decided, and create required issues
-
Edited by morgan.vlasse