Prepare scoped GitOps adoption and tested immutable image releases
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 7s
Build and Publish Container Image / build-and-push (push) Successful in 2m18s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 13:50:16 +02:00
parent 5d5ee84d70
commit c12a8fbcfb
12 changed files with 2585 additions and 731 deletions

View file

@ -16,6 +16,10 @@ on:
- "pyproject.toml"
- "uv.lock"
- "alembic.ini"
- "tests/**"
- "schemas/**"
- "k8s/**"
- ".dockerignore"
workflow_dispatch:
env:
@ -33,18 +37,22 @@ jobs:
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: |
set -eu
REF="${GITHUB_SHA:-main}"
SHORT="${REF:0:7}"
REF="${GITHUB_SHA:?commit required}"
test "${#REF}" -eq 40
mkdir -p buildctx "${HOME}/bin"
wget -qO /tmp/repo.tar.gz \
"https://forgejo.coulomb.social/${GITHUB_REPOSITORY}/archive/${SHORT}.tar.gz"
"https://forgejo.coulomb.social/${GITHUB_REPOSITORY}/archive/${REF}.tar.gz"
tar xzf /tmp/repo.tar.gz -C buildctx --strip-components=1
wget -qO- https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \
| tar xz --strip-components=1 -C "${HOME}/bin" docker/docker
export PATH="${HOME}/bin:${PATH}"
echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" -u "${REGISTRY_USER}" --password-stdin
IMAGE="${REGISTRY}/${IMAGE_NAME}"
docker build -t "${IMAGE}:latest" -t "${IMAGE}:main-${SHORT}" buildctx
docker push "${IMAGE}:latest"
docker push "${IMAGE}:main-${SHORT}"
echo "pushed ${IMAGE}:latest and ${IMAGE}:main-${SHORT}"
# Check the exact source archive before publishing. Never update latest.
docker build --target test buildctx
docker build --label "org.opencontainers.image.revision=${REF}" -t "${IMAGE}:git-${REF}" buildctx
docker push "${IMAGE}:git-${REF}"
docker inspect --format '{{index .RepoDigests 0}}' "${IMAGE}:git-${REF}" > image-digest.txt
grep -Eq '^forgejo.coulomb.social/coulomb/activity-core@sha256:[a-f0-9]{64}$' image-digest.txt
cat image-digest.txt
# Deployment promotion is separate and consumes the digest, never the tag.