CI builds and smoke-tests the Image on every PR #6

Closed
opened 2026-09-30 13:14:53 +00:00 by piscis · 1 comment
Owner

What to build

A PR workflow on the docker runner that builds the Image for linux/amd64 and linux/arm64 from the Pin and runs the smoke test against each architecture. It reuses the build and smoke-test commands from the local tracer bullet rather than duplicating their logic. It never pushes to the registry.

Use whatever the runner probe established as the working way to reach Docker and emulate arm64.

Acceptance criteria

  • Opening or updating a PR triggers the workflow, which builds both architectures and runs the smoke test on both
  • A PR with a broken Dockerfile turns red
  • A PR whose Pin commit doesn't match the Upstream tag turns red
  • Nothing is pushed to code.vicoli.de from a PR run
  • The workflow can also be dispatched manually

Blocked by

Context: see GLOSSARY.md (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and docs/adr/ (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags).

## What to build A PR workflow on the `docker` runner that builds the Image for linux/amd64 and linux/arm64 from the Pin and runs the smoke test against each architecture. It reuses the build and smoke-test commands from the local tracer bullet rather than duplicating their logic. It never pushes to the registry. Use whatever the runner probe established as the working way to reach Docker and emulate arm64. ## Acceptance criteria - [x] Opening or updating a PR triggers the workflow, which builds both architectures and runs the smoke test on both - [x] A PR with a broken Dockerfile turns red - [x] A PR whose Pin commit doesn't match the Upstream tag turns red - [x] Nothing is pushed to `code.vicoli.de` from a PR run - [x] The workflow can also be dispatched manually ## Blocked by - #3 - #4 Context: see `GLOSSARY.md` (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and `docs/adr/` (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags).
piscis self-assigned this 2026-09-30 14:26:15 +00:00
piscis 2026-09-30 14:34:20 +00:00
Author
Owner

Done. ci (.forgejo/workflows/ci.yml) builds and smoke-tests the Image for amd64 and arm64 on every PR and on manual dispatch. It landed in #20, with follow-ups #23 and #24.

Acceptance criterion Evidence
PR triggers build and smoke test of both architectures PR runs 4, 9, 21, 25: green, PASS: 156 tools listed on amd64 and arm64
Broken Dockerfile turns red run 5, throwaway commit, reverted
Pin commit ≠ Upstream tag turns red run 6: Upstream tag v3.2.0 resolves to commit e30bb7e…, but the Pin expects 0000…, throwaway commit, reverted
Nothing pushed to code.vicoli.de no docker login, no --push, no secrets, --load only; the checkout token is removed right after the fetch (#23); GET /api/v1/packages/vicoli-oss?type=container returns []
Manual dispatch e.g. run 28 on main after #24, green

Along the way:

  • Runner DNS (#22, closed): RUN steps on the runner's dind daemon couldn't resolve names, because the runner's firewall blocked outbound DNS (UDP port 53). #23 worked around it with --network host. The firewall is now fixed, and #24 removed the workaround.
  • Shared daemon: concurrent runs don't collide. Image tags are per run, and smoke-test container and network names are random per run. The PR run plus two concurrent dispatches on the same commit, with a cold cache, were all green (25, 26, 27).
  • tonistiigi/binfmt is pinned by digest (#23).

Left open, outside this issue's criteria: #25. A cached clone step can hide an Upstream tag that moves without a Pin change.

Done. `ci` (`.forgejo/workflows/ci.yml`) builds and smoke-tests the Image for amd64 and arm64 on every PR and on manual dispatch. It landed in #20, with follow-ups #23 and #24. | Acceptance criterion | Evidence | |---|---| | PR triggers build and smoke test of both architectures | PR runs [4](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/4), [9](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/9), [21](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/21), [25](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/25): green, `PASS: 156 tools listed` on amd64 and arm64 | | Broken Dockerfile turns red | [run 5](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/5), throwaway commit, reverted | | Pin commit ≠ Upstream tag turns red | [run 6](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/6): `Upstream tag v3.2.0 resolves to commit e30bb7e…, but the Pin expects 0000…`, throwaway commit, reverted | | Nothing pushed to `code.vicoli.de` | no `docker login`, no `--push`, no secrets, `--load` only; the checkout token is removed right after the fetch (#23); `GET /api/v1/packages/vicoli-oss?type=container` returns `[]` | | Manual dispatch | e.g. [run 28](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/28) on main after #24, green | Along the way: - **Runner DNS (#22, closed):** `RUN` steps on the runner's dind daemon couldn't resolve names, because the runner's firewall blocked outbound DNS (UDP port 53). #23 worked around it with `--network host`. The firewall is now fixed, and #24 removed the workaround. - **Shared daemon:** concurrent runs don't collide. Image tags are per run, and smoke-test container and network names are random per run. The PR run plus two concurrent dispatches on the same commit, with a cold cache, were all green ([25](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/25), [26](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/26), [27](https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp/actions/runs/27)). - **`tonistiigi/binfmt`** is pinned by digest (#23). Left open, outside this issue's criteria: #25. A cached clone step can hide an Upstream tag that moves without a Pin change.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
vicoli-oss/docker-forgejo-mcp#6
No description provided.