feat(sms-bridge): select safe telemetry image - #206
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Selects the published PII-safe SMS bridge telemetry image
fe2c1cb435ca5f2f2c657f7b73a5d15c1ba95070in the existingopencode-sms-bridgeApplication.Fixes #
None — owner-approved deployment of the published telemetry image.
Type of change
Validation
testrun 33942414686 passed repository pre-commit validation.No local Kubernetes, Kustomize, SOPS, OpenTofu, or image operation was run or claimed. CI is the validation authority.
Impact and rollout
Producer:
imagesPR #32 is merged atfe2c1cb4, and its successfulmain buildah run 33942142243published the exact immutable image selected here.Consumer:
workloads/apps/opencode-sms-bridge-app.yamlchanges the Helm image tag only. The current bridge chart0.1.2,opencodenamespace, Service, PVC, TunnelBinding, encrypted Secrets, sender allowlist, fixed agent mapping, and Twilio webhook configuration are unchanged.Authorized delivery path: after merge,
maintest must pass; then the repository sync workflow requests reconciliation ofgitops-workloadsat the tested Git revision. The workload root must update this child Application, and the child automated policy must reconcile the selected image. Verify root/child revisions, sync, health, resource tree, Deployment rollout, and both container statuses before repeating the authorized SMS test. This PR itself does not prove any of those stages.Rollback: select the previous known-good immutable image tag
8fbb926ea958fff53edff11238891ac84c4da305through a reviewed GitOps change; never retag published images or patch the live Deployment.Safety and secrets
GitHub Advanced Security secret scanning is unavailable for this repository; the one-line diff was manually reviewed. AI-assisted change: an OpenCode agent materially produced this change; reviewers should verify the exact immutable image tag and retained ownership boundaries before merging.