diff --git a/modules/ecr/main.tf b/modules/ecr/main.tf index ed31545..d284f3a 100644 --- a/modules/ecr/main.tf +++ b/modules/ecr/main.tf @@ -33,17 +33,21 @@ resource "aws_ecr_repository" "this" { name = "${var.namespace}/${each.key}" - # MUTABLE, reluctantly, and for arena's sake. It applies to every repository - # here because tag mutability is a per-repository setting and splitting the - # module in two to vary it would cost more than it buys. See TODO.md. + # IMMUTABLE. It applies to every repository here because tag mutability is a + # per-repository setting and splitting the module in two to vary it would + # cost more than it buys. # - # The original reason no longer holds: arena's tag was - # `mm-sur`, derived from dependency versions alone, so a - # rebuild of the same versions reproduced the tag and IMMUTABLE would have - # rejected the second push. It now carries the branch and commit as well - # (`mm0.51.0-sur26.4.7-main-4e5403faaa6a`), and push.sh refuses a dirty tree, - # so the tag is unique per build. Flipping this to IMMUTABLE is unblocked and - # is its own change - see arena's TODO.md. + # This was MUTABLE while arena tagged images `mm-sur`, + # derived from dependency versions alone: a rebuild of the same versions + # reproduced the tag, and IMMUTABLE would have rejected the second push. The + # tag now carries the branch and commit as well + # (`mm0.51.0-sur26.4.7-main-4e5403faaa6a`) and push.sh refuses a dirty tree, + # so a tag identifies one build and overwriting one is a mistake by + # definition. + # + # Nothing pushes a moving tag: arena removed its `latest` push, and deploy.sh + # refuses to write one into the release file. This setting is the backstop + # under both of those, not the thing holding the line. image_tag_mutability = var.image_tag_mutability # Basic scanning is free. Enhanced scanning is Inspector and is charged per diff --git a/modules/ecr/variables.tf b/modules/ecr/variables.tf index afb489b..d65a717 100644 --- a/modules/ecr/variables.tf +++ b/modules/ecr/variables.tf @@ -20,9 +20,9 @@ variable "namespace" { } variable "image_tag_mutability" { - description = "MUTABLE or IMMUTABLE, for every repository here. Immutable is correct and is blocked on arena producing a unique tag per build; see the comment in main.tf." + description = "MUTABLE or IMMUTABLE, for every repository here. IMMUTABLE since arena started tagging per build; see the comment in main.tf. MUTABLE is an escape hatch, not a default to drift back to." type = string - default = "MUTABLE" + default = "IMMUTABLE" validation { condition = contains(["MUTABLE", "IMMUTABLE"], var.image_tag_mutability)