fix(ci): publish registry blobs in bounded chunks
This commit is contained in:
1 parent
047cd9f3dd
commit
2af244b634
5 files changed
+74
-8
No files matched your search
@@ -41,6 +41,29 @@ fi
|
||||
docker build --network=host --target migrations -t "$image-migrations" "$context"
|
||||
node scripts/verify-portable-image.mjs "$image" "$sha"
|
||||
# Publish only after the same application image passed both runtime configurations.
|
||||
docker push "$image-migrations"
|
||||
docker push "$image"
|
||||
# Bound each blob request below reverse-proxy upload limits. Pin the uploader
|
||||
# and verify its checksum before giving it access to the temporary Docker login.
|
||||
case "$(uname -m)" in
|
||||
x86_64) arch=amd64; checksum=8e0e62a497fcdb8048d18aa927a139613176ba0531f412bc541044e28f9856bd ;;
|
||||
aarch64|arm64) arch=arm64; checksum=a9b71a3ee79b2d1dbbd7d51fd5e8fa214722c192864235d3d8764463c751a1ff ;;
|
||||
*) echo "Unsupported registry uploader architecture" >&2; exit 1 ;;
|
||||
esac
|
||||
curl --fail --silent --show-error --location --retry 3 --connect-timeout 15 --max-time 120 \
|
||||
"https://github.com/regclient/regclient/releases/download/v0.11.6/regctl-linux-$arch" -o "$context/regctl"
|
||||
printf '%s %s\n' "$checksum" "$context/regctl" | sha256sum --check --status
|
||||
chmod 700 "$context/regctl"
|
||||
export REGCTL_CONFIG="$DOCKER_CONFIG/regctl.json"
|
||||
regctl() { "$context/regctl" "$@"; }
|
||||
regctl registry set "$registry" --blob-chunk 8388608 --blob-max 8388608
|
||||
for target in "$image-migrations" "$image"; do
|
||||
echo "Publishing $target with blob requests up to 8 MiB"
|
||||
docker image save --output "$context/image.tar" "$target"
|
||||
regctl image import "$target" "$context/image.tar"
|
||||
# Import may change compression/manifest representation, but the immutable
|
||||
# image config digest must still match the exact local image we verified.
|
||||
expected_config="$(docker image inspect --format '{{.Id}}' "$target")"
|
||||
remote_config="$(regctl manifest get "$target" --format '{{.GetConfig.Digest}}')"
|
||||
[[ "$remote_config" = "$expected_config" ]] || { echo "Published image config does not match verified local image" >&2; exit 1; }
|
||||
rm -f -- "$context/image.tar"
|
||||
done
|
||||
echo "Published application and migrations: $image"
|
||||
Reference in new issue
Block a user