Skip to content

ci: publish the agent image on ghcr.io (MK8S-446) - #30

Open
ezekiel-alexrod wants to merge 3 commits into
mainfrom
ci/MK8S-446-publish-agent-image
Open

ezekiel-alexrod wants to merge 3 commits into
mainfrom
ci/MK8S-446-publish-agent-image

Conversation

@ezekiel-alexrod

Copy link
Copy Markdown
Collaborator

Component

ci, docs

Problem

Nothing publishes the agent image. agent-ci.yaml builds it and stops there, and promote.yaml only attaches the RPMs to the release, so anyone deploying the agent has to build and push it first.

Fix

A reusable workflow, agent-image.yaml, builds agent/ for linux/amd64 with buildx and pushes ghcr.io/scality/image-cache-agent. I'd mostly like eyes on the tag logic in that file.

  • A merge to main that touches agent/ publishes <last tag>-<n>-g<sha> (from git describe) and latest-dev (new post-merge.yaml).
  • A release tag publishes that tag, and latest or latest-dev for a pre-release. The build job runs before create-release in promote.yaml, so a broken image blocks the release.
  • A tag push names the image after GITHUB_REF_NAME, not git describe: two tags can sit on the same commit.
  • One publish at a time (concurrency), since two workflows move latest-dev.
  • Nothing is pushed from pull requests: a fork has no packages: write. agent-ci.yaml still builds the image there.

The agent README lists the tags, README and CONTRIBUTING point to it.

Test

Check Result
actionlint on the workflows OK
tag script replayed on main v0.1.0-alpha.1-45-g...
docker buildx build --platform linux/amd64 agent/ OK, 79 MB, UID 65532
push to ghcr.io, gha cache not verified, only runs on GitHub

Out of scope


  • The docs describing this behaviour are updated in the same pull request: README.md, agent/README.md, DESIGN.md, agent/DESIGN.md, CONTRIBUTING.md, whichever owns it.
  • A change to the cache directory layout (subdirectory scheme, archive names, sentinel, permissions) lands in both halves and in agent/DESIGN.md. Not applicable to most pull requests.

Relates-to: MK8S-446

A new reusable workflow builds the agent image for linux/amd64 and
pushes it to ghcr.io/<owner>/image-cache-agent. The version tag comes
from git describe.

Post Merge runs it on each push to main that touches agent/, and moves
latest-dev. Promote runs it before the release is created, so a broken
image blocks the release. A stable tag moves latest, a pre-release tag
moves latest-dev.

The caller jobs grant packages: write. No secret is passed: the login
uses GITHUB_TOKEN.

Relates-to: MK8S-446
The READMEs no longer ask the reader to build the image first. The
agent README lists the tags, and the other files link to it.

Relates-to: MK8S-446
@ezekiel-alexrod
ezekiel-alexrod requested a review from a team as a code owner October 7, 2026 15:04
Comment thread .github/workflows/agent-image.yaml
@ezekiel-alexrod
ezekiel-alexrod requested review from anthony-treuillier-scality and eg-ayoub and removed request for a team October 7, 2026 16:29
@ezekiel-alexrod ezekiel-alexrod self-assigned this Oct 7, 2026
@ezekiel-alexrod ezekiel-alexrod added the P2 Medium priority label Oct 7, 2026
GitHub keeps one pending run per concurrency group and cancels it when
a newer run arrives. With a single shared group, a merge to main could
cancel a pending release build, and the release was then never created.

Merges to main still publish in order. A pre-release can now race with
a merge to main on latest-dev; the workflow comment says so.

Relates-to: MK8S-446
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Medium priority

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants