Checklist: What must pass before a container can auto-deploy

Index Cloud Partners
Last Updated: September 25, 2026•

Before you begin: Complete Using the Index testing tool. Run through this checklist last, immediately before your first push.

Your container image is not eligible for auto-deployment until all three of the following are satisfied.

1. It must follow the artifact naming conventions

The image tag and the S3 folder name must be compliant with the Artifact naming conventions and deployment regions: a CalVer version, plus an optional annotation, plus an optional single deployment region suffix (_AMS, _EMEA, or _APAC).

Note: This is not a pass/fail check like #2 and #3. Depending on which part of the name is wrong, a badly named artifact is either silently ignored or flagged with a warning. If you upload an image and "nothing happens," this is almost always why. See What happens to a non-conforming artifact.

Includes deployment region: omitting the region suffix deploys everywhere, and a global (no-suffix) upload will overwrite an existing region-specific deployment. See Artifact naming conventions and deployment regions for the full format, region definitions, and examples.

2. It must pass a vulnerability scan

Index scans every image automatically once it's pushed, and blocks deployment if any component in it scores 9 or higher on CVSS. Catch this yourself first, so a failed scan doesn't hold up your deployment.

  1. Run a vulnerability scanner against your image. For example: trivy image yourrepo/yourimage:2026.07.10.2.

  2. Confirm nothing comes back scored 9 or higher on CVSS.

If your image fails the Index scan during deployment, a Grafana log entry is made naming the specific component(s) that need to be updated.

3. It must expose the required endpoints

The container must expose the endpoints described in Building a Docker container:

Verification happens in two steps, in order:

  1. Locally, first, using the ARTF reference tools with no Index involvement required. See the Familiarize yourself with ARTF section in Validating a container.

  2. Final validation with Using the Index testing tool, which sends sample requests to your container against a live-like environment. This will not send any test traffic at all until the health check and metrics endpoint above both pass.

See also