Publish the Image on push to main #7
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
#9 README: using the Image in a coding project
vicoli-oss/docker-forgejo-mcp
#6 CI builds and smoke-tests the Image on every PR
vicoli-oss/docker-forgejo-mcp
#5 Set up vicoli-oss, move the repo, and store the package token
vicoli-oss/docker-forgejo-mcp
#16 Pin records which Upstream Version the Rebuild counts against
vicoli-oss/docker-forgejo-mcp
Reference
vicoli-oss/docker-forgejo-mcp#7
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What to build
Extend CI so a push to
main(and manual dispatch) builds, smoke-tests and publishes the multi-arch Image tocode.vicoli.de/vicoli-oss/forgejo-mcp(ADR 0004). Log in withusername: dockhandandpassword: ${{ secrets.PACKAGE_TOKEN }}, notgithub.actor.Tags follow ADR 0003, given Upstream Version
vX.Y.Zand RebuildNfrom the Pin. Take the tag from the Makefile (#16) rather than working outNagain in the workflow:X.Y.Z-rN: immutable. If it already exists in the registry, skip publishing without failing. That's the normal case for pushes that don't change the Pin.X.Y.Z,X.Y,X: moving, always pointing to the newest Rebuild.latest: only if this Upstream Version is the highest one published so far.Attach buildx SBOM and provenance attestations. Set OCI labels:
org.opencontainers.image.source(this repo),org.opencontainers.image.licenses=GPL-3.0(the Image redistributes Upstream's GPL-3.0 binary), andorg.opencontainers.image.version. A Rebuild is triggered by raising the Rebuild number in the Pin and merging, or by manual dispatch after doing so.Acceptance criteria
3.2.0-r1,3.2.0,3.2,3andlatestas a multi-arch manifest (amd64 + arm64)docker pull code.vicoli.de/vicoli-oss/forgejo-mcp:3.2.0works without login on an arm64 Mac and on an amd64 hostmainthat doesn't change the Pin publishes nothing and the run is greenX.Y.Z-rNtag that already exists fails instead of skipping. That catches a Rebuild whereREBUILDwas raised butREBUILD_OFwasn't updated.-rNtag never overwrites itBlocked by
Context: see
GLOSSARY.md(Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) anddocs/adr/(0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public orgvicoli-oss).Once #26 lands (fixes #25), the publish workflow should run
make verify-pinbefore it builds. It checks on Upstream that the tag of the Upstream Version still points at the Pin's commit, and doesn't depend on the build cache.Published by #28, in the push run for its merge (run #51):
3.2.0-r1was pushed after both smoke tests passed, and3.2.0,3.2,3andlatestwere moved to it.Acceptance criteria:
sha256:319936feba60…: linux/amd64 + linux/arm64 + 2 attestation manifests.docker pull …:3.2.0without login. With an emptyDOCKER_CONFIG, on an arm64 Mac: arm64 natively and amd64 with--platform, and both ranforgejo-mcp 3.2.0. On the x86_64 runner: an anonymous check that both platforms are there runs on every publish, and a real anonymous pull was tested before the merge (run #33).-rNtag already exists → the run fails. Runs #34 and #39.-rNtag. Dispatch #38 and push #39. The digests of all tags were identical before and after.source=https://code.vicoli.de/vicoli-oss/docker-forgejo-mcp,licenses=GPL-3.0,version=3.2.0-r1, andrevisionset to this repo's commit.Runs #31–#48 ran on throwaway branches against a test package. Both are deleted.
Also added: publish runs queue in a workflow-level
concurrencygroup. Forgejo ignoresconcurrencyset on a job (runs #43–48).Known edge case, not fixed: if a dispatch runs before the push for the same Pin change, the push run goes red with "already exists", even though the Image is correct.
Follow-up #33 fixes the edge case above. When X.Y.Z-rN already exists, publish.sh now compares this run's Pin with the Pin the existing Image was built from (read through its revision label). The same Pin skips and stays green, a different one fails, whichever run goes first. Verified on main: run #62 says "3.2.0-r1 already exists, built from the same Pin (commit
7f2e214): nothing to publish" and is green.