Skip to content

ci: publish a multi-arch container image to GHCR - #95

Open
jonasgrosch wants to merge 1 commit into
tobi:mainfrom
conxai-technologies:conxai/ghcr-image
Open

jonasgrosch wants to merge 1 commit into
tobi:mainfrom
conxai-technologies:conxai/ghcr-image

Conversation

@jonasgrosch

Copy link
Copy Markdown

walgit ships a Containerfile but no published image, so every deployment builds its own. This
adds .github/workflows/image.yml, which publishes ghcr.io/<owner>/<repo>:

  • Both architectures, natively. linux/amd64 on ubuntu-24.04 and linux/arm64 on
    ubuntu-24.04-arm, each pushed by digest, then merged into one multi-arch tag with
    docker buildx imagetools create. No QEMU — an emulated release build of this workspace is
    far slower than a native one.
  • What publishes. The default branch: latest, <branch>, sha-<short>. Tags v*:
    <version> and <major>.<minor>. Other branch pushes do nothing.
  • Pull requests that touch build inputs (Containerfile, Cargo.*, crates/**, web/**,
    the workflow) build both architectures without pushing, so a broken Containerfile is caught
    before merge.
  • Provenance. OCI labels from docker/metadata-action (image.source, image.revision),
    WALGIT_BUILD_SHA passed as the build arg the Containerfile already reads, BuildKit attestations.
  • Cache. type=gha per platform.

Only GitHub-owned and Docker's verified actions; permissions: contents: read at the top,
packages: write only on the two jobs that push. actionlint-clean.

Tested on a fork: run conxai-technologies/walgit#36764429797 — amd64 14m51s, arm64 13m29s,
merge 22s; ghcr.io/conxai-technologies/walgit:sha-3d1e502 pulls anonymously on both
architectures and walgit --version reports the commit.

One thing for you: a new GHCR package in a user or org account starts private; after the first
publish it needs "Change visibility → Public" once in the package settings.

Part of #94.

🤖 Generated with Claude Code

Builds the Containerfile for linux/amd64 and linux/arm64, each natively on a
runner of its own architecture (no emulation), and merges both into one tag
under ghcr.io/<owner>/<repo>.

The repository's default branch publishes latest, <branch> and sha-<short>;
version tags v* publish <version> and <major>.<minor>. Pull requests that
touch the build inputs build both architectures without pushing, so a broken
Containerfile shows before merge. Other branch pushes do nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants