## Summary
`k8s/deploy.yaml` takes the image from build-tools: `image: ${IMAGE}` instead of the hard-coded `oci.unbound.se/dancefinder/geo-service:${COMMIT}`.
`deploy` substitutes `${IMAGE}` with `<registry>/<owner>/<name>:<tag>`, where the registry comes from the build-tools config and the tag is the value `${COMMIT}` gets today. The rendered reference is unchanged. Moving off `oci.unbound.se` later becomes one change in infra.
Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
- unboundsoftware/infra#1808: registry in `BUILDTOOLS_FROSTMOLN_STAGING`
- shiny/acctest#952: acctest pins build-tools to the Gitea registry
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reviewed-on: https://gitea.unbound.se/dancefinder/geo-service/pulls/408