Work Done
Merged virdx/mono#378 at 5761077cae561e194fac6a1ba2fa44378d8697be after approval and passing PR checks. bold-flint is clean, detached at merged origin/main. Submitted tekton-builds/build-vxdata-api-pmsx6 pinned to that SHA, image-name vxdata-api, tags latest and 4.2.0. Initial LVM workspace provisioning timed out on compute-001, then recovered. Clone SHA verified. Build task and automatic retry failed with connection refused to BuildKit; no image digest produced. BuildKit service had no ready endpoints: buildkitd-2 terminating, buildkitd-0 pending. No infrastructure restart, deployment, backfill, or DB mutation performed. Build heartbeat cancelled after terminal failure.
Opened virdx/infra_k8s#201, commit c8ebafdb1c42f5a6bdb260ed013e64b577df1337, changing exactly staging/prod API tags from 3.2.1 to 4.2.0. AlexLeakeQC review requested and verified. Native manifest/docs lint and YAML parsing passed. PR explicitly says build failed and must not merge until image publication succeeds. Task worktree: /Users/felix.knispel/work/worktrees/infra_k8s/vxdata-api-4.2.0. Shared cache not edited.
Pitfalls
The build helper omits image-name, but tekton-image-name admission injects the correct API image name. Pipeline defaults alone are insufficient to judge behavior; an initial claim that omission was a bug was corrected. Pin build revision to exact merge SHA rather than moving main. Knowledge release-automation page says mono#323 is open; live GitHub reports it closed. Service-account requestor label normalization still does not remove colons; verify before enabling automated Tekton submission.
Improvements
Suggested narrow automation: merge event -> exact-SHA Tekton build -> verify publication/digest -> GitHub App opens infra PR and requests Alex; keep deployment approval. Later promote identical digest from smoke-tested staging to production. Fix least-privilege build submission and admission identity handling first. Resume this release only after BuildKit recovers; retry exact source SHA, confirm tag/digest, and update PR201 build gate.
Final outcome: published, deployment still pending
After another failed user-requested retry (build-vxdata-api-qlqbt), user requested a new retry when maintenance progressed. build-vxdata-api-822c6 succeeded at 2026-09-11T11:42:29Z, including archive and signing. Clone SHA verified as 5761077cae561e194fac6a1ba2fa44378d8697be. Registry HEAD for vxdata-api:4.2.0 returned HTTP 200 and Docker-Content-Digest sha256:5dd5dffc4e257ead7152e1d3e13b9722ad08f33d15ce5e49c64387681694c3a2, matching Tekton result. Laptop could not connect directly to the registry; verification used existing buildkitd-0 with SSL_CERT_FILE=/etc/ssl/certs/ipa-ca.crt and wget –spider, no credential exposure or TLS bypass.
PR201 body now marks image publication verified, preserving the user’s opening sentence. AlexLeakeQC review remains requested. No infra merge, deployment, DB migration, backfill, or service restart performed by this task. Build heartbeat 44942867-5b27-44b8-8efe-a027231dfe5e cancelled.