Repository navigation
ci: publish the agent image on ghcr.io (MK8S-446) - #30
Open
ezekiel-alexrod wants to merge 3 commits into
Open
ezekiel-alexrod wants to merge 3 commits into
ezekiel-alexrod wants to merge 3 commits into
Conversation
A new reusable workflow builds the agent image for linux/amd64 and pushes it to ghcr.io/<owner>/image-cache-agent. The version tag comes from git describe. Post Merge runs it on each push to main that touches agent/, and moves latest-dev. Promote runs it before the release is created, so a broken image blocks the release. A stable tag moves latest, a pre-release tag moves latest-dev. The caller jobs grant packages: write. No secret is passed: the login uses GITHUB_TOKEN. Relates-to: MK8S-446
The READMEs no longer ask the reader to build the image first. The agent README lists the tags, and the other files link to it. Relates-to: MK8S-446
ezekiel-alexrod
requested review from
anthony-treuillier-scality and
eg-ayoub
and removed request for
a team
October 7, 2026 16:29
eg-ayoub
approved these changes
Oct 8, 2026
GitHub keeps one pending run per concurrency group and cancels it when a newer run arrives. With a single shared group, a merge to main could cancel a pending release build, and the release was then never created. Merges to main still publish in order. A pre-release can now race with a merge to main on latest-dev; the workflow comment says so. Relates-to: MK8S-446
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Component
ci, docs
Problem
Nothing publishes the agent image.
agent-ci.yamlbuilds it and stops there, andpromote.yamlonly attaches the RPMs to the release, so anyone deploying the agent has to build and push it first.Fix
A reusable workflow,
agent-image.yaml, buildsagent/forlinux/amd64with buildx and pushesghcr.io/scality/image-cache-agent. I'd mostly like eyes on the tag logic in that file.mainthat touchesagent/publishes<last tag>-<n>-g<sha>(fromgit describe) andlatest-dev(newpost-merge.yaml).latestorlatest-devfor a pre-release. Thebuildjob runs beforecreate-releaseinpromote.yaml, so a broken image blocks the release.GITHUB_REF_NAME, notgit describe: two tags can sit on the same commit.concurrency), since two workflows movelatest-dev.packages: write.agent-ci.yamlstill builds the image there.The agent README lists the tags, README and CONTRIBUTING point to it.
Test
actionlinton the workflowsmainv0.1.0-alpha.1-45-g...docker buildx build --platform linux/amd64 agent/Out of scope
cap_dac_override, and an image published before it would lack it.README.md,agent/README.md,DESIGN.md,agent/DESIGN.md,CONTRIBUTING.md, whichever owns it.agent/DESIGN.md. Not applicable to most pull requests.Relates-to: MK8S-446