Step 01 of 06
Learn the concept
Rebuilding for staging and production sounds tidy until one compiler cache, base image or network mirror changes. Promotion moves an immutable digest through environments so approval changes where the artifact may run, not what the artifact is.
The ideas this is made of
A digest is the artifact fingerprint
An OCI digest is a hash of the image manifest. If one byte changes, the digest changes. Tags are pointers that can move. Promotion records the digest because scanners, signatures and deployments can all agree on it.
Environment config changes around the artifact
Development may use one replica and production five. Those differences belong in overlays, secrets and environment variables. They do not require rebuilding Beacon. A binary that needs recompilation to know where it runs is smuggling deployment policy into the artifact.
Approval gates are about permission
GitHub environments can require reviewers before a job targets production. That gate should authorize a known digest. If the job rebuilds after approval, the reviewer approved yesterday's evidence for today's unknown artifact.
crate digest: sha256:91b4...
label: v1.5.0
route: warehouse -> store -> customer
rule: never repack between stopsThe label helps humans, but the seal proves identity. Repacking at each stop would make the first inspection irrelevant.
Tags and digests serve different jobs
| Identifier | Can move | Good for |
|---|---|---|
| Yes | Local convenience |
Version tag | Should not | Human release name |
Git SHA tag | Can be overwritten | Trace to source |
Digest | No | Promotion and signing |
What these are called on the job
Digest — Immutable OCI identifier for an image manifest, usually beginning with
sha256:.Tag — A human-friendly registry pointer that can be moved unless policy prevents it.
Promotion — Authorizing one already-built artifact to run in a later environment.
