k8s/deploy.yaml takes the image from build-tools: image: ${IMAGE} instead of the hard-coded oci.unbound.se/unboundsoftware/unbound-site:${COMMIT}.
deploy substitutes ${IMAGE} with <registry>/<owner>/<name>:<tag>, where the registry comes from the build-tools config and the tag is the value ${COMMIT} gets today. The rendered reference is unchanged. Moving off oci.unbound.se later becomes one change in infra.
Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
## Summary
`k8s/deploy.yaml` takes the image from build-tools: `image: ${IMAGE}` instead of the hard-coded `oci.unbound.se/unboundsoftware/unbound-site:${COMMIT}`.
`deploy` substitutes `${IMAGE}` with `<registry>/<owner>/<name>:<tag>`, where the registry comes from the build-tools config and the tag is the value `${COMMIT}` gets today. The rendered reference is unchanged. Moving off `oci.unbound.se` later becomes one change in infra.
Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
- unboundsoftware/infra#1808: registry in `BUILDTOOLS_FROSTMOLN_STAGING`
- shiny/acctest#952: acctest pins build-tools to the Gitea registry
🤖 Generated with [Claude Code](https://claude.com/claude-code)
deploy substitutes ${IMAGE} with <registry>/<owner>/<name>:<tag> from the build-tools config, so the registry is set in one place (infra) instead of in every manifest. Renders the same reference as before. Same change as shiny/time-service#864.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
argoyle
merged commit b8c7b0c6f7 into main2026-10-02 22:39:58 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
k8s/deploy.yamltakes the image from build-tools:image: ${IMAGE}instead of the hard-codedoci.unbound.se/unboundsoftware/unbound-site:${COMMIT}.deploysubstitutes${IMAGE}with<registry>/<owner>/<name>:<tag>, where the registry comes from the build-tools config and the tag is the value${COMMIT}gets today. The rendered reference is unchanged. Moving offoci.unbound.selater becomes one change in infra.Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
BUILDTOOLS_FROSTMOLN_STAGING🤖 Generated with Claude Code
deploy substitutes ${IMAGE} with <registry>/<owner>/<name>:<tag> from the build-tools config, so the registry is set in one place (infra) instead of in every manifest. Renders the same reference as before. Same change as shiny/time-service#864. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>