You have a pipeline that builds a Docker image and pushes it to Azure Container Registry. You need to ensure that only the latest successful build image is tagged as 'latest'. Which tagging strategy should you use?
This approach guarantees that the 'latest' tag is only moved after a fully successful build, using a condition such as `condition: succeeded()` to run a docker tag/push step. It ensures the image referenced by 'latest' is always a known-good artifact, avoiding the risk of tagging broken builds.
Why this answer
It ensures the 'latest' tag is applied only after a successful build, preventing broken or incomplete images from being tagged as 'latest'. In Azure Pipelines, you can use a condition like `condition: succeeded()` on a script or Docker task that runs `docker tag` and `docker push` to update the 'latest' tag only when the preceding build steps succeed. This maintains a reliable 'latest' pointer to the most recent stable image.
Exam trap
The trap here is that candidates may assume any tagging strategy that includes 'latest' is sufficient, overlooking the critical requirement that the tag must only be applied to successful builds, which is enforced by a conditional step.
How to eliminate wrong answers
Option B is wrong because manually updating the 'latest' tag introduces human error and operational overhead, and it does not automate the process to ensure only successful builds are tagged. Option C is wrong because using the Git commit hash as the tag is a valid strategy for traceability, but pushing 'latest' separately without a conditional check on build success could result in tagging a failed build as 'latest'. Option D is wrong because always tagging the image as 'latest' regardless of build status would overwrite the 'latest' tag with a broken or incomplete image, breaking downstream consumers that rely on 'latest' being a stable reference.