mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Motivation: Release images should be built, checked, published, and consumed through the same Nostr-native OCI path operators will use, without relying on an unreviewed local release procedure. Approach: Add a checked-in container manifest, a Docker-to-OCI layout helper, automatic tag publication and pull verification, a safe exact-tag backfill workflow, and deployment CI that imports and runs the exact generated layout. Correctness: Release tags come only from reviewed OCI index annotations; ordinary publication preserves prior tags; historical backfills cannot move latest or prerelease channels; generated images and temporary resources use bounded, validated names and cleanup. Excluded scope: This change does not alter ngit-grasp runtime behavior, change package versions, create v3.0.2, publish a container, move a release tag, or run the heavyweight container build in the coding VM. Validation: git diff --check; shellcheck on all container scripts; actionlint on all affected workflows; ngit parsing of .ngit/containers.yaml; canonical source and v3.0.1 tag resolution. The PR pipeline performs the full OCI build, import, and deployment test. Assisted-by: Codex (GPT-5)
53 lines
1.2 KiB
Bash
Executable File
53 lines
1.2 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
if [ "$#" -ne 1 ]; then
|
|
echo "usage: $0 <version>" >&2
|
|
exit 2
|
|
fi
|
|
|
|
version=$1
|
|
case "${version}" in
|
|
[A-Za-z0-9_]*) ;;
|
|
*)
|
|
echo "version is not a valid OCI tag: ${version}" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
case "${version}" in
|
|
*[!A-Za-z0-9._-]*)
|
|
echo "version is not a valid OCI tag: ${version}" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
|
|
if ! command -v docker >/dev/null 2>&1; then
|
|
echo "missing required command: docker" >&2
|
|
exit 2
|
|
fi
|
|
|
|
image="ncontainer.io/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp:${version}"
|
|
cleanup() {
|
|
docker image rm --force "${image}" >/dev/null 2>&1 || true
|
|
}
|
|
trap cleanup EXIT HUP INT TERM
|
|
|
|
deadline=$(($(date +%s) + 300))
|
|
until docker pull "${image}"; do
|
|
if [ "$(date +%s)" -ge "${deadline}" ]; then
|
|
echo "published image did not become pullable within five minutes" >&2
|
|
exit 1
|
|
fi
|
|
sleep 5
|
|
done
|
|
|
|
actual=$(docker run --rm --entrypoint /usr/local/bin/ngit-grasp \
|
|
"${image}" --version)
|
|
expected="ngit-grasp ${version}"
|
|
if [ "${actual}" != "${expected}" ]; then
|
|
echo "expected '${expected}' from the published image, got '${actual}'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
printf 'published image verified: %s\n' "${image}"
|