Skip to content

fix(azure): preserve exact worker image on replay - #352

Merged
ruby-dlee merged 1 commit into
mainfrom
codex/azure-claim-recovery
Aug 26, 2026
Merged

fix(azure): preserve exact worker image on replay#352
ruby-dlee merged 1 commit into
mainfrom
codex/azure-claim-recovery

Conversation

@ruby-dlee

@ruby-dlee ruby-dlee commented Aug 26, 2026

Copy link
Copy Markdown
Owner

Summary:

  • allow the owner-private no-mistakes worker config to carry the exact immutable Azure Compute Gallery image-version ID and a single canonical IPv4 operator data-plane route
  • forward both values to lifecycle without shell interpretation so replay cannot fall back to a marketplace image or close the storage route
  • preserve fail-closed validation: CIDRs, IPv6, whitespace, noncanonical IPv4, and broad 0.0.0.0/0 access are rejected
  • keep CI fixtures aligned with shared reviewer-host admission and bounded timeout exit semantics

Verification:

  • focused credential-expiry, watcher-triage, behavior-shard, and no-mistakes-worker regressions
  • shellcheck --norc -x on all touched shell tests
  • bin/fm-behavior-shards.sh --check 8
  • git diff --check
  • cold adversarial review: CLEAR

@ruby-dlee
ruby-dlee force-pushed the codex/azure-claim-recovery branch 2 times, most recently from 55a4664 to 4209a30 Compare August 26, 2026 18:11
@ruby-dlee
ruby-dlee force-pushed the codex/azure-claim-recovery branch from 4209a30 to 7a2055f Compare August 26, 2026 18:45
@ruby-dlee
ruby-dlee merged commit 556e029 into main Aug 26, 2026
13 checks passed
@ruby-dlee
ruby-dlee deleted the codex/azure-claim-recovery branch August 26, 2026 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant