From 24c2b056ab42c79349e2ad2b7bcd787d1aecf3e3 Mon Sep 17 00:00:00 2001 From: Will Anderson Date: Mon, 4 May 2026 15:26:36 -0500 Subject: [PATCH] dharma: pin deployment image to SHA tag (placeholder) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replaces `:latest` + `imagePullPolicy: Always` with a content- addressable SHA tag produced by the dharma-el ci-prod workflow. The deployed image is now deterministic and rollback is `git revert` of this file. `PINNED_BY_NEXT_BUILD` is a deliberate placeholder — Argo CD will fail to reconcile (ImagePullBackOff) until a human replaces it with a real short SHA. That failure is the forcing function: prod only gets a new image via a PR that names a real, built tag. This PR is opened as a draft. Do not merge until: 1. dharma-el#1 (feature/ci-prod-image-build) is merged 2. Dharma CI — prod runs on main and produces a SHA-tagged image 3. The placeholder here is replaced with that SHA `imagePullPolicy: Always` is left in place for now — redundant once we're on SHA tags but removing it in the same PR adds risk. Drop it in a follow-up. --- .../neuron-technologies/dharma/deployment.yaml | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml b/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml index 2209e88..25b6d01 100644 --- a/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml +++ b/servers/legion/k8s/neuron-technologies/dharma/deployment.yaml @@ -25,8 +25,19 @@ spec: type: RuntimeDefault containers: - name: dharma - image: registry.neuralplatform.ai/neuron-technologies/dharma:latest - imagePullPolicy: Always + # Pinned to a content-addressable SHA tag instead of :latest so the + # deployed image is deterministic and rollback is `git revert`. The + # tag is produced by the dharma-el ci-prod.yaml workflow on every + # push to main: registry.neuralplatform.ai/neuron-technologies/ + # dharma:. + # + # PINNED_BY_NEXT_BUILD is a deliberate placeholder. It will fail to + # pull (ImagePullBackOff) until a human replaces it with a real + # short SHA from a successful ci-prod run. That failure is the + # forcing function: the only way prod gets a new image is by + # opening a PR that names a real, built tag. + image: registry.neuralplatform.ai/neuron-technologies/dharma:PINNED_BY_NEXT_BUILD + imagePullPolicy: Always # redundant once on SHA tags; remove in a follow-up ports: - name: http containerPort: 8765