DL-369
The three guest assets (kernel, rootfs erofs, initrd) publish as a digest-pinned NON-RUNNABLE OCI artifact at ghcr.io/rigelbuild/compass-guest-image — OCI 1.1 empty config + artifactType: application/vnd.compass.guest-image.v1 + per-asset layer media types, pushed by a TypeScript lane reusing the runner-image publish posture (immutability guard, digest assert, pre-push scan) — so an agent bump republishes one artifact instead of the multi-GB Runner image. ADDITIVE: the Runner keeps its three-file-path contract (--microvm-kernel/-rootfs/-initrd + optional sha256sum manifest; no registry client in the Go runtime), the Runner image keeps baking the assets (air-gapped support is a hard requirement), and materialisation is per-deployment — compass-stack up fetches-and-verifies by digest into a content-addressed state dir, --guest-dir bypasses all fetching
Status: Active (Matt, 2026-09-13)