Step 9
Step 9 — Bind a verified commit to a release and image
0 views
Step 9 — Bind a verified commit to a release and image
A green test is not evidence if the running bytes came from another source revision. Treat a clean worktree, Git SHA, image tag, and verification output as one release record.
- OS wrappers call one Node SSOT with explicit service scope.
frontend-civerifies only named services;prod-deploybuilds Git-SHA images and runs readiness, smoke, and rollback.- Fly static output and Docker SSR are different build targets. A failed export must never become an empty snapshot.
- This repository does not use remote GitHub Actions as its CI SSOT, so its local and operations runners are the source of delivery evidence.
If an image builds but readiness or a real DB smoke returns 500, replace only the target service with its previous rollback tag. Preserve tags, logs, URLs, and the restore result.