You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5bf3f06
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docker-promote/README.md
+11-4Lines changed: 11 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,6 +13,7 @@ The calling workflow must trigger promotion from a release tag such as `vX.Y.Z`,
13
13
14
14
- Validates that the release tag matches the version release-please recorded for the component
15
15
- Waits for the CI workflow run for the tagged commit to complete successfully
16
+
- Reuses the exact image tag CI recorded for the commit from the `docker-image-tag` artifact, and fails if the CI run did not publish one
16
17
- Resolves the source image digest before promotion
17
18
- Optionally re-scans the tested digest with Trivy
18
19
- Copies the tested manifest to the release tag
@@ -26,7 +27,6 @@ The calling workflow must trigger promotion from a release tag such as `vX.Y.Z`,
26
27
|`image-name`| Fully qualified OCI image name, without a tag | Yes | - |
27
28
|`registry`| Registry hosting the image | No |`"docker.io"`|
28
29
|`security-scan`| Enable the Trivy security scan before promotion | No |`true`|
29
-
|`source-tag-prefix`| Prefix used by CI before the short commit SHA | No |`"dev-"`|
30
30
|`trivy-version`| Trivy security scanner version | No |`"v0.71.0"`|
31
31
32
32
## Secrets
@@ -38,6 +38,8 @@ The calling workflow must trigger promotion from a release tag such as `vX.Y.Z`,
38
38
39
39
## Example Usage
40
40
41
+
The source tag is not passed to this workflow: it is fetched from the `docker-image-tag` artifact that the CI run for the tagged commit uploaded (published by `docker-build` when `push: true`).
42
+
41
43
```yaml
42
44
name: Release Docker Image
43
45
@@ -54,13 +56,17 @@ jobs:
54
56
with:
55
57
image-name: docker-regis.iex.ec/my-service
56
58
registry: docker-regis.iex.ec
57
-
source-tag-prefix: dev-
58
59
security-scan: false
59
60
secrets:
60
61
username: ${{ secrets.NEXUS_USERNAME }}
61
62
password: ${{ secrets.NEXUS_PASSWORD }}
62
63
```
63
64
65
+
The flow:
66
+
67
+
1. **CI workflow** — builds the image, tags it (e.g. via a `prepare` job), pushes it, and uploads the applied tag as the `docker-image-tag` artifact.
68
+
2. **Release workflow** — this one. On `vX.Y.Z` (or `component-vX.Y.Z`) it waits for that CI run, downloads the artifact to learn the exact tag CI pushed, and promotes that digest to the release tag.
69
+
64
70
## Notes
65
71
66
72
- The release tag must point at a commit that is contained in `main`; the workflow refuses to release a tag created elsewhere.
@@ -69,7 +75,7 @@ jobs:
69
75
- A tag without a component is matched against the `.` package, or against the single entry of the manifest.
70
76
- A component is matched against a manifest key by full path or by its last segment, so `post-compute` resolves the key `post-compute` and a workspace path such as `crates/post-compute`.
71
77
- The project must be released by release-please in manifest mode; `.release-please-manifest.json` is committed in the same PR as the version bump, so at the tagged commit it holds the version being released.
72
-
- The source tag is formed as `<source-tag-prefix><short-commit-sha>`, for example `dev-1a2b3c4d`.
78
+
- The source tag is the tag `docker-build` recorded in the `docker-image-tag` artifact of the CI run for the commit, so any CI tag scheme (`dev-<sha>`, `feature-<sha>`, `cid.<sha>.main`, …) is supported. Promotion fails with a clear error if the CI run did not publish the artifact.
73
79
- Set `security-scan: false` to skip the promotion-time Trivy scan. The CI build should still perform its configured scan.
74
80
- Keep `trivy-version` in sync with the version used by `docker-build` so a promotion finding reflects a vulnerability database update rather than a scanner change.
75
81
- The registry credentials need read and write access because promotion creates the release tag.
@@ -81,6 +87,7 @@ jobs:
81
87
- **No version recorded for the component** — the tag prefix is not a package in `.release-please-manifest.json`; check the `component` names in `release-please-config.json`.
82
88
- **Tag version does not match the recorded version** — the tag is expected to be `v` or `<component>-v` followed by the version release-please released for that component.
83
89
- **Timed out waiting for the CI run** — confirm that `ci-workflow` names the workflow that builds the image and that it has started for the tagged commit.
84
-
- **Source image or digest cannot be resolved** — confirm that CI pushed `<image-name>:<source-tag-prefix><short-commit-sha>` to `registry`.
90
+
- **CI did not publish the docker-image-tag artifact** — the CI workflow named by `ci-workflow` must build the image with a `docker-build` version that records and uploads the `docker-image-tag` artifact (`push: true`); promotion cannot infer the tag otherwise.
91
+
- **Source image or digest cannot be resolved** — confirm that CI pushed `<image-name>:<source-tag>` to `registry`.
85
92
- **Release tag does not point at the tested image** — the registry or buildx version may not support manifest promotion; keep the buildx setup step up to date.
86
93
- **Trivy reports CRITICAL or HIGH vulnerabilities** — the promotion is stopped before the release tag is created; update the image and rerun the release.
0 commit comments