ADR-0008 · Build once into the image, keep QA on the verified channel
Status: Accepted, 2026-10-10.
Context
The service image already moves through verified (automatic) and released
(manual) channels. The dashboard needs a deployable home and a place to check
the next release.
Decision
The dashboard is built once in CI and copied into the service image, so the
image is the single artifact; it is promoted, never rebuilt. QA at
qa-yqa.fio.sh tracks verified and stays up after production at
yqa.fio.sh promotes the same version. QA is a compose profile on the same
host, with its own environment file and session secret.
Why
Rebuilding to release would ship bytes nobody tested; a QA that disappears on promotion leaves nowhere to compare (renderer ADR-0015 and ADR-0020).
Consequences
Production-only hosts are unaffected: the QA image variable has an empty
default and the QA service only exists with --profile qa. One OAuth
application serves both hosts with two redirect URIs.
Evidence
QA environment: 498fe19, 0a4f2c1; ops/docker-compose.yml, test/hardening.test.js. Building the dashboard into the image is task T6.2 of the experiment plan and is not yet implemented.
Revisit when
QA needs several retained versions, or a retention policy changes rollback guarantees.