DL-445
The guest-image agent pin records the compass-agent OCI index, not one image: guest-image/agent-oci.lock keeps repo, tag and digest (now the index digest, which stays the artifact’s agent-image provenance annotation and Renovate’s tracked digest) and adds a platforms map keyed exactly linux/amd64 and linux/arm64, each member holding its manifest digest and ordered layer descriptors. Both the pin tool and the nix eval reject a v1 lock or a lock without exactly those two platforms. The pin tool fails closed on every registry member: a missing, extra or duplicate platform, a nested index, a non-OCI-index top level, and a member whose bytes or config platform disagree with its descriptor. The nix eval fetches no config; it fails closed on the index platform set and on the selected member’s digest and layers. guest-image/default.nix fetches index → member → layers for the member matching the pkgs that builds the boot layer (x86_64-linux → amd64, aarch64-linux → arm64), throws at eval on any other system, and is proven for aarch64 by an eval-only smoke. Registry reads stay anonymous (--no-creds). The derivation-time userland contract check is enforced for linux/amd64 only until an arm64 build leg exists; booting an aarch64 guest is a separate follow-up. Refines DL-368 §(a)’s lock schema, and scopes DL-366’s “no consumer changes” to bare-tag engine pullers: the digest-pinned guest image needs this lock change. DL-368 and DL-366 stay Active.
Status: Active (Matt, 2026-10-10)
Record: ../../infra/runtime/compass-guest-agent-pin-multiarch/design.md#approach