DL-386
The compass gateway image is built and published by compass, not by the fork (RIG-4209 option B). A tools/gateway-image/ lane fetches the oh-my-pi fork commit pinned in fork-pin.json, which must be an ancestor of fork main. It builds that commit with two rootless BuildKit solves (pi-runtime, then Dockerfile.gateway with the base as a named OCI-layout context), smoke-boots the image with a broker before any push (/healthz 200, /v1/models 401 without the token and 200 with it, exit 143), and pushes those same bytes by skopeo copy to :git-<sha12> with a registry digest assert. It reuses no runner-image code
Status: Active (Matt, 2026-10-03)
Record: ../../infra/release/compass-gateway-image/design.md#approach