Skip to main content

AEROSIM-TS-47

Project task

Build versioned Nebula and Singularity container images

Nebula and Singularity each produce reproducible runtime images labeled and tagged with the immutable application source revision.

AEROSIM-TS-47Canonical ID TASK-0047
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application and API Service — container images
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Build separate multi-stage Nebula and Singularity images from a frozen lockfile, copy only runtime artifacts, run as numeric non-root users, add OCI source/revision/version labels from SOURCE_REVISION, and smoke-test Web HTTP plus API liveness. Primary files: applications/web/Dockerfile, applications/api/Dockerfile, .dockerignore, tests/container/image-contract.test.mjs.

Implementation contract

Implementation artifacts

  • applications/web/Dockerfile
  • applications/api/Dockerfile
  • .dockerignore
  • tests/container/image-contract.test.mjs

Inputs

  • Immutable application source at SOURCE_REVISION and pnpm-lock.yaml
  • Build arguments SOURCE_URL, SOURCE_REVISION, and VERSION

Outputs

  • Local aerosim-nebula:<full-sha> and aerosim-singularity:<full-sha> OCI images
  • Image labels org.opencontainers.image.source, revision, and version matching build arguments

Failure boundaries

  • Fail build if SOURCE_REVISION is absent/not 40 hex, frozen install changes the lockfile, or production build fails.
  • Fail contract test if runtime user is root, source files/dev dependencies are copied unnecessarily, labels mismatch, or health endpoint does not respond.

Excluded scope

  • Harbor push, chart rendering, vulnerability exception policy, and Kubernetes deployment are handled by later delivery tasks.

Verification steps

  • docker build --build-arg SOURCE_REVISION=$(git rev-parse HEAD) -f applications/web/Dockerfile -t aerosim-nebula:$(git rev-parse HEAD) . && docker build --build-arg SOURCE_REVISION=$(git rev-parse HEAD) -f applications/api/Dockerfile -t aerosim-singularity:$(git rev-parse HEAD) .
  • node --test tests/container/image-contract.test.mjs; inspect labels/users and smoke-test both containers.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #80 reviewed head 909f3749f76c8c0b6c28674ccb132496fc7a02ab, merged as 1585d83fa52684f66c5d16ff3421aece01c6ffe2; publication transport-repair PR #82 reviewed head c3cecd341419f2cd1f06e7731b74b12a833cd652, merged as fa7fa9a28e402076779a100084450d0ef9366b40; final whole-wave application head 7f26eca79eadef3171564fc60035e9866c2c848e: publication run 3914 succeeded and integration run 3915 succeeded. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.