Open
Description
I don't think we've done this yet, we can gain a little more peace of mind if we know the promoter jobs don't have access to this, only the terraform automation (and ideally not even that, we should really only let a handful of infra leads and the CNCF have access to manipulate the GCP project hosting release images).
note: immutable tags are incompatible with cleanup policies, for this and other reasons we should only enable them for production registries and not staging
note: deleting untagged images is still permitted in this mode, so this mode is not a complete "append-only" option xref #8008
https://cloud.google.com/artifact-registry/docs/docker/names#versions
Metadata
Metadata
Assignees
Labels
Type
Projects
Status