Build fails after automatic ubuntu-latest image update in Azure DevOps pipeline
0 reputation · 18 Jun 2022, 15:34 UTC
Goal: ensure that a pipeline that passes on a developer's machine continues to pass in production without unexpected failures due to agent image updates.
Constraint: the `vmImage: 'ubuntu-latest'` alias resolves to the newest Microsoft-hosted image at queue time, which may introduce newer runtimes or removed tools, while pinning to an explicit version such as `ubuntu-22.04` guarantees reproducibility but adds the burden of tracking security patches and scheduling updates.
Uncertainty: teams must weigh the convenience of automatic updates against the risk of breakage and decide on an image‑management strategy that balances reliability with operational overhead.
Should teams adopt a strict pinning policy with regular, scheduled updates? What update frequency provides a good trade‑off between security and stability? How can teams automatically detect when a newer `ubuntu-latest` image would introduce breaking changes before it is used in a production pipeline?