Skip to content

fix(lock): pin SDK image URI to locked manifest digest - #751

Open
jmt-lab wants to merge 1 commit into
bottlerocket-os:developfrom
jmt-lab:push-pmnqmknkxkyz
Open

jmt-lab wants to merge 1 commit into
bottlerocket-os:developfrom
jmt-lab:push-pmnqmknkxkyz

Conversation

@jmt-lab

@jmt-lab jmt-lab commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Description of changes:
Export TLPRIVATE_SDK_IMAGE as registry/repo@sha256: so docker, krane, and buildkit verify the manifest digest recorded in Twoliter.lock. A new build_pinned_uri() helper in project/lock/image.rs is the single source of truth for the pinned URI format.

Testing done:

  • Built a Kernel kit fully resolving the sdk through lockfile then validated that fetch and buildsys run using the new uri format successfully.

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

@jmt-lab
jmt-lab marked this pull request as draft September 21, 2026 20:37
Export TLPRIVATE_SDK_IMAGE as registry/repo@sha256:<hex> so docker, krane,
and buildkit verify the manifest digest recorded in Twoliter.lock. A new
build_pinned_uri() helper in project/lock/image.rs is the single source of
truth for the pinned URI format.

Signed-off-by: Jarrett Tierney <jmt@amazon.com>
@jmt-lab
jmt-lab marked this pull request as ready for review September 22, 2026 22:40

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants