Files
DanConwayDev 5fed50e5e3 ci(release): publish OCI container images
Motivation: Release images should be built, checked, published, and consumed through the same Nostr-native OCI path operators will use, without relying on an unreviewed local release procedure.

Approach: Add a checked-in container manifest, a Docker-to-OCI layout helper, automatic tag publication and pull verification, a safe exact-tag backfill workflow, and deployment CI that imports and runs the exact generated layout.

Correctness: Release tags come only from reviewed OCI index annotations; ordinary publication preserves prior tags; historical backfills cannot move latest or prerelease channels; generated images and temporary resources use bounded, validated names and cleanup.

Excluded scope: This change does not alter ngit-grasp runtime behavior, change package versions, create v3.0.2, publish a container, move a release tag, or run the heavyweight container build in the coding VM.

Validation: git diff --check; shellcheck on all container scripts; actionlint on all affected workflows; ngit parsing of .ngit/containers.yaml; canonical source and v3.0.1 tag resolution. The PR pipeline performs the full OCI build, import, and deployment test.

Assisted-by: Codex (GPT-5)
2026-09-10 15:30:13 +00:00

46 lines
1.4 KiB
YAML

# ngit-ci currently evaluates push path filters but not pull-request path
# filters, so PRs run this workflow unconditionally.
on:
push:
paths:
- ".dockerignore"
- "Cargo.lock"
- "Cargo.toml"
- "Dockerfile"
- "build.rs"
- "compose*.yaml"
- "deploy/**"
- "scripts/build-container-layout.sh"
- "scripts/test-container-deployment.sh"
- "scripts/test-container-release.sh"
- "src/**"
pull_request:
name: Container deployment e2e
jobs:
container-deployment:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Require the disposable guest container daemon
run: |
if [[ ! -S /var/run/docker.sock ]]; then
echo "container daemon socket is not available" >&2
echo "this workflow requires an ngit-ci operator opt-in" >&2
exit 1
fi
- name: Build, import, replace, and verify the OCI release layout
shell: bash
run: |
set -euo pipefail
version="$(nix eval --raw .#static.version)"
revision="$(git rev-parse 'HEAD^{commit}')"
nix shell nixpkgs#docker-client nixpkgs#curl nixpkgs#jq nixpkgs#skopeo \
--command scripts/test-container-release.sh "$version" "$revision"