Commit Graph

4 Commits

Author SHA1 Message Date
Slavi Pantaleev
af557a7e45 Fix multi-arch manifest publish: use buildx imagetools
docker/build-push-action now wraps single-platform images in an OCI
image index (to carry provenance attestations), so the per-arch
`*-amd64`/`*-arm64` tags are manifest lists. `docker manifest create`
refuses manifest-list sources ("X is a manifest list"). Switch to
`docker buildx imagetools create`, which flattens index sources
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 09:22:50 +03:00
Slavi Pantaleev
ff1e128f0e Fix versioned image publish under workflow_run trigger
e978d3c switched the publish trigger from `push` to `workflow_run` and
correctly migrated the `type=raw,value=latest` rule to read the upstream
head_branch from `github.event.workflow_run.*` — but left the
`type=semver,pattern={{raw}}` rule unchanged. That rule still reads
`github.ref`, which under workflow_run dispatch is always
`refs/heads/main` (the default branch where the workflow file lives),
not the triggering tag ref. As a result, no semver tag was extracted,
metadata-action produced no tags, and `buildx` failed with
"tag is needed when pushing to registry". The `latest` tag kept
publishing because its rule was migrated; versioned tags (v1.19.0,
v1.19.1) silently stopped publishing.

Pass the upstream head_branch to the semver rule explicitly via `value`,
gated by `enable` so it only fires for v* tags. Mirrors the migration
the raw rule already received.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-09 17:28:54 +03:00
Slavi Pantaleev
e978d3cb2f Publish only after successful CI
Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags.

Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip.
2026-04-20 22:09:37 +03:00
Slavi Pantaleev
2b1bdbd3d2 Split CI and publish workflows
This supersedes 7d183b9 ("Run CI for pull requests"), which mixed validation and publishing in one workflow and regressed docker-manifest by dropping the package-write permission it needs to publish the manifest.

Split the workflows so CI handles pull requests, branch pushes, tags, and manual runs, while publishing stays focused on Docker delivery with the manifest permission fixed explicitly at the job level.
2026-04-20 22:08:07 +03:00