diff --git a/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml b/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml index 2209e88..25b6d01 100644 --- a/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml +++ b/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml @@ -25,8 +25,19 @@ spec: type: RuntimeDefault containers: - name: dharma - image: registry.neuralplatform.ai/neuron-technologies/dharma:latest - imagePullPolicy: Always + # Pinned to a content-addressable SHA tag instead of :latest so the + # deployed image is deterministic and rollback is `git revert`. The + # tag is produced by the dharma-el ci-prod.yaml workflow on every + # push to main: registry.neuralplatform.ai/neuron-technologies/ + # dharma:. + # + # PINNED_BY_NEXT_BUILD is a deliberate placeholder. It will fail to + # pull (ImagePullBackOff) until a human replaces it with a real + # short SHA from a successful ci-prod run. That failure is the + # forcing function: the only way prod gets a new image is by + # opening a PR that names a real, built tag. + image: registry.neuralplatform.ai/neuron-technologies/dharma:PINNED_BY_NEXT_BUILD + imagePullPolicy: Always # redundant once on SHA tags; remove in a follow-up ports: - name: http containerPort: 8765