rogue has its own Publish scale image GitHub workflow (builds+pushes rogue's OCI image on a v* tag) AND the deployed gitwatcher now watches rogue's v* tags and drives the Linux pipeline to build+deploy it. So a single v* tag fires TWO build/deploy paths that can race on the scale-registry push and the deploy. Decide the single owner: either drop rogue's own deploy-image.yml now that the pipeline owns rogue, or stop watching rogue in the gitwatcher config. General rule for onboarding: a repo is owned by exactly one build path. Related: #508.