The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 6: CI basics and artifact discipline · Lab

Prevent Different Artifacts Under One Version Name

45 min hands-on · Core

A container registry with immutable-tag rules (or a local registry) plus the repo from L16 under /tmp/dlab-m06-02.

Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.

Objectives

  • Reproduce the movable-tag incident with two different digests
  • Enforce append-only versions and promote by digest
  • Show two environments resolving identical bytes
  1. Step 1

    Stage the incident

    Build version 0.1.0, record its digest, rebuild from a changed commit under the same tag, and show the digest changing while the name stays still. Write the incident note: which bytes were certified versus which would ship.

  2. Step 2

    Freeze the names

    Enable tag immutability (or a push-guard hook), mint 0.1.1 for the new bytes, and promote by digest through two stages. Show the failed overwrite attempt in the record.

  3. Step 3

    Prove identical bytes

    Pull the digest in two separate environments and compare digests plus a smoke check. Record both pulls showing the same sha256.

How to confirm it worked

  • Two digests under one name demonstrated with the incident note written
  • Overwrite attempt blocked in the record; new version minted append-only
  • Both environments resolve the same digest with matching smoke checks
  • Promotion path uses digests, never movable names