diff --git a/deploy/README.md b/deploy/README.md index 2915557..81b9e75 100644 --- a/deploy/README.md +++ b/deploy/README.md @@ -8,7 +8,7 @@ the server port or export a copy before applying. Apply order is documented in `docs/operator-runbook.md`. Do not apply the Deployment until: -1. The image digest is pinned (currently `sha256:7febc28e…` from commit `5fd04e2`). +1. The image digest is pinned (currently `sha256:c2fe39a0…` from commit `abd22fa`). 2. Secrets `audit-core-database`, `audit-core-database-migrate`, and `audit-core-senders` exist. ConfigMap `audit-core-senders-scope` is applied (`deploy/senders-scope.yaml`) before the Deployment mounts it. diff --git a/deploy/audit-core.yaml b/deploy/audit-core.yaml index f71709f..1d00e28 100644 --- a/deploy/audit-core.yaml +++ b/deploy/audit-core.yaml @@ -80,7 +80,7 @@ spec: - name: audit-core # REPLACE at release time with the built digest. A mutable tag is not # an immutable image, and `:latest` must never be the only reference. - image: forgejo.coulomb.social/coulomb/audit-core@sha256:7febc28e8a828dbc245144a38e5728e0fbf496b594dd7591170b450a1265fb10 + image: forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6 imagePullPolicy: IfNotPresent ports: - name: http diff --git a/deploy/migrate-job.yaml b/deploy/migrate-job.yaml index a52e263..ace4ea8 100644 --- a/deploy/migrate-job.yaml +++ b/deploy/migrate-job.yaml @@ -33,7 +33,7 @@ spec: type: RuntimeDefault containers: - name: migrate - image: forgejo.coulomb.social/coulomb/audit-core@sha256:7febc28e8a828dbc245144a38e5728e0fbf496b594dd7591170b450a1265fb10 + image: forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6 imagePullPolicy: IfNotPresent command: ["python", "-m", "audit_core", "migrate"] env: