chore(harness): pin fleet images to the v0.44.0-rc.2 release builds - #1570
Conversation
The fleet harnesses still pinned the v0.42.0 images (v0.43.0 was never repinned). Pin them to the images published by fullsend v0.44.0-rc.2, which passed the release gate (validate-agents), so the v0.44.0 agents tag ships with current sandbox images: - fullsend-sandbox (prioritize, retro, scribe, triage): sha256:61787695ada71876324447979ac26a16bc64dc7139b819151cda817937be1276 - fullsend-code (code, fix, review): sha256:d681249e95e6a26e31cf4f5192ee7ed7c9ed050d03bb4d80b40a3bf252238103 examples/link-check keeps the digest `agent new` emits. Assisted-by: Claude Signed-off-by: Wayne Sun <gsun@redhat.com>
PR Summary by QodoPin fleet harness images to v0.44.0-rc.2 release builds
AI Description
Diagram
High-Level Assessment
Files changed (7)
|
Code Review by Qodo
1. Fleet image changes require human approval
|
| # when the model: above moves to a generation with a different default. | ||
| effort: high | ||
| image: ghcr.io/fullsend-ai/fullsend-code@sha256:623fc74588876062f12f40690ee759c6134ba516fabdd36e6dcfc4eeb9cd1d0b | ||
| image: ghcr.io/fullsend-ai/fullsend-code@sha256:d681249e95e6a26e31cf4f5192ee7ed7c9ed050d03bb4d80b40a3bf252238103 |
There was a problem hiding this comment.
1. Fleet image changes require human approval 📜 Skill insight § Compliance
The PR modifies seven files under the protected harness/ infrastructure path by replacing pinned container digests. The release-image repin rationale is documented in the PR description, but this protected-path change still requires explicit human review rather than automated approval.
|
🤖 Finished Review · ✅ Success · Started 12:03 AM UTC · Completed 12:12 AM UTC Commit: Runtime: pi · Model: openai/gpt-6.1-sol → gpt-6.1-sol · Effort: high · Cost: $1.47 |
|
Review skipped — this PR is already merged. The Posted by fullsend post-review check |
…flow skills/cutting-releases documented a single tag push per release, but tag-agents tags agents main in that same run before anyone can repin fullsend-ai/agents/harness/*.yaml to the images that release just built. Released CLIs fetch agents@tags/vX.Y.Z, so every release shipped the previous release's fleet images (the one-release lag from fullsend-ai#6607). v0.44.0 was cut with an RC -> repin -> final flow that removed the lag end to end; this change makes that the documented default. SKILL.md: every release now starts as vX.Y.Z-rc.N at a commit X. After the RC gate is green, agents is repinned (new step 8, using fullsend-ai/agents#1570 as the template), and only then is vX.Y.Z tagged at X (or a later commit Y, gated on a git log check over images/sandbox, images/code, and sandbox-images.yml -- a non-empty result means cut rc.N+1 instead of reusing the RC). Added a hold window note against merging image-affecting PRs between the RC and the repin merge. Notes section documents two behaviors this flow depends on: tag-agents runs for prereleases too (unlike the v0 move), and sandbox-images.yml builds on every v* tag regardless of whether the publish gate passes, and is not reproducible. pre-flight.md: new step A3 compares the functional-tests.yml@sha pin in release.yml against agents main's copy of that file, since PR CI never exercises the pinned workflow and a stale pin only surfaces as a tag-time gate failure (as it did for v0.44.0-rc.1). post-flight.md: extended B2 to verify the agents tag lands on the repin PR's merge commit and that v0 moved on both repos, and added B3 to verify the harness pins equal the RC's digests rather than the final tag's own (different, since the build isn't reproducible) digests. The release.yml GoReleaser fix for same-commit RC/final tagging (GORELEASER_CURRENT_TAG) is out of scope here per the issue -- it is a workflow file change tracked separately. Automating the repin PR is also out of scope; this documents the manual flow. Note: pre-commit could not fetch its hook repos in this sandbox (TLS/network restriction). Ran the hooks relevant to the changed markdown files directly instead: no trailing whitespace, no CRLF, no merge-conflict markers, single trailing newline (matches end-of-file-fixer/trailing-whitespace/mixed-line-ending/ check-merge-conflict). make lint-md-links (lychee --offline) passed repo-wide. Closes fullsend-ai#6607 Closes fullsend-ai#7954
Summary
Pins the 7 fleet harness images to the release builds published by fullsend v0.44.0-rc.2, so that the
v0.44.0agents tag (cut from agentsmainby fullsend's release workflow) ships with current sandbox images. The harnesses still pinned the v0.42.0 images, because v0.43.0 was never repinned (fullsend#6607 tracks automating this).fullsend-sandboxsha256:259605fe…995asha256:61787695…1276fullsend-codesha256:623fc745…d0bsha256:d681249e…8103Both digests were verified against the registry's
0.44.0-rc.2tags. They come from the release run that passedvalidate-agents(all 5 functional-test suites) for v0.44.0-rc.2.examples/link-checkkeeps the digestfullsend agent newemits.What changes for the fleet with the newer images (pi 0.85 → 0.99.2, Claude Code 2.1.263 → 2.1.286, Codex 0.157 → 0.159.3):
pi-anthropic-vertexfalls back to non-strict after one refused request.Test plan
pre-commitandmake lintpassmake testpasses exceptpost-code-test.sh, a known macOS BSD-sed limitation (CI runs Linux)v0.44.0; agents gets tagged at amainthat includes this