CI and image delivery
Stage 5 · Payload Integration
When an engineer asks "Is commit abc1234 currently running in production?", the answer requires tracing an unbroken lineage from git history through container registries to running Pod specifications.
The delivery pipeline handoffs
Diagram DL-05 — four sequential handoffs: commit triggers CI, CI builds and pushes image, manifest references image, kubelet pulls and runs container.
- 1. Source revision: The recorded commit identifies the intended code snapshot. The pipeline must still prove that this was the revision it checked out and tested.
- 2. Artifact build: Container image compiled and pushed to registry.
- 3. Manifest reference: Deployment updated to reference the new image artifact.
- 4. Runtime execution: Kubelet pulls the image digest and launches the container.
Mutable tags vs. Immutable digests
- Image tags (e.g.
:v1.2.0or:latest):- Mutable pointers. Registries allow overwriting the same tag with a new binary.
- Nodes with cached images (
imagePullPolicy: IfNotPresent) might run stale code despite tag updates.
- Image digests (e.g.
@sha256:e3b0c44...):- Cryptographically immutable hash of image content.
- Guarantees every node runs the exact binary compiled by CI.
Evidence and limits
- 1. Identify image running in Pod:
kubectl get pod -l app=booking -n apollo-airlines-apps \-o jsonpath='{.items[0].spec.containers[0].image}'
- 2. Verify exact pulled digest:
kubectl get pod -l app=booking -n apollo-airlines-apps \-o jsonpath='{.items[0].status.containerStatuses[0].imageID}'
- 3. Audit Git commit provenance: Verify the container image short-SHA corresponds to an approved commit in git history.