The Flux release renderer now accepts an expected-consumer set per workload (chat may carry the HUX sidecar as a second consumer of the exact same WebUI image) and binds HUX_IMAGE_TAG/HUX_IMAGE_DIGEST env metadata to the released tag and digest when those fields are present. Rendering fails when the binding fields are incomplete, keeping the image identity single-sourced. Tests adapt to both topologies. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf