feat(P03): docker release — multi-stage Dockerfile + Gitea container registry publish
REQ-046: Docker image published to Gitea container registry per release. Dockerfile: multi-stage (golang:1.25 -> distroless/static-debian12:nonroot). CGO_ENABLED=0, ORCA_HOME=/var/lib/orca, ENTRYPOINT [/orca]. Image size: ~28MB. Runs as nonroot. .coreci.yml: new container-publish step in release pipeline (docker:24-cli, builds + tags + login + push + logout). scripts/release.sh: docker build + push after Gitea release. Graceful skip if docker absent or GITEA_TOKEN unset. Env-overridable registry. .dockerignore: excludes .git, bin/, .env, .ciagent/, testdata/, *.tar.gz. docs/docker.md: pull, run, state persistence (volume mount), local build, manual publish guide. Verified: docker build + run version/init with volume persistence. ---ci--- project: orca phase: 3 milestone: v0.5 status: verify ---/ci---
This commit is contained in:
@@ -136,3 +136,39 @@ tea releases create "$VERSION" \
|
||||
--asset "$TARBALL"
|
||||
|
||||
info "✓ release $VERSION published"
|
||||
|
||||
# --- publish container image to gitea registry (REQ-046) ------------------
|
||||
# Skipped gracefully if docker is not on PATH (e.g. local dev without docker).
|
||||
# The .coreci.yml release pipeline has a dedicated container-publish step
|
||||
# that runs in a docker:24-cli image with docker-in-docker.
|
||||
|
||||
CONTAINER_REGISTRY="${CONTAINER_REGISTRY:-git.cloudinit.dev}"
|
||||
CONTAINER_OWNER="${CONTAINER_OWNER:-coreci}"
|
||||
CONTAINER_IMAGE="${CONTAINER_IMAGE:-orca}"
|
||||
IMAGE="${CONTAINER_REGISTRY}/${CONTAINER_OWNER}/${CONTAINER_IMAGE}"
|
||||
|
||||
if ! command -v docker >/dev/null 2>&1; then
|
||||
info "docker not found on PATH — skipping container image publish (CI handles it)."
|
||||
else
|
||||
info "building container image ${IMAGE}:${VERSION}..."
|
||||
docker build \
|
||||
--build-arg VERSION="$VERSION" \
|
||||
--build-arg GIT_COMMIT="$GIT_COMMIT" \
|
||||
--build-arg BUILD_TIME="$BUILD_TIME" \
|
||||
-t "${IMAGE}:${VERSION}" \
|
||||
-t "${IMAGE}:latest" \
|
||||
"$REPO_ROOT"
|
||||
|
||||
if [ -z "${GITEA_TOKEN:-}" ]; then
|
||||
info "GITEA_TOKEN not set — skipping docker push (image built locally only)."
|
||||
else
|
||||
info "logging in to ${CONTAINER_REGISTRY}..."
|
||||
echo "$GITEA_TOKEN" | docker login "$CONTAINER_REGISTRY" -u cloudinit-bot --password-stdin
|
||||
info "pushing ${IMAGE}:${VERSION}..."
|
||||
docker push "${IMAGE}:${VERSION}"
|
||||
info "pushing ${IMAGE}:latest..."
|
||||
docker push "${IMAGE}:latest"
|
||||
docker logout "$CONTAINER_REGISTRY"
|
||||
info "✓ container image ${IMAGE}:${VERSION} published"
|
||||
fi
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user