fix(ci): publish container under token account namespace
CI / check (push) Successful in 56s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Failing after 30s

This commit is contained in:
Simo committed 2026-09-09 19:53:16 +02:00
1 parent c389c3893d
commit 867113d5d4
5 files changed
+35 -6

No files matched your search

+14 -3
View File
@@ -17,7 +17,7 @@ const bash =
.find((path) => existsSync(path)) ?? "bash")
: "bash";
const sha = "a".repeat(40);
function simulate(scenario: string) {
function simulate(scenario: string, namespace = "") {
const dir = mkdtempSync(join(tmpdir(), "cms-publish-test-"));
try {
const result = spawnSync(
@@ -35,7 +35,8 @@ function simulate(scenario: string) {
SCENARIO: scenario,
REGISTRY_SERVER: "https://registry.invalid",
REGISTRY_REPOSITORY: "owner/cms",
REGISTRY_USER: "fixture",
REGISTRY_USER: "Simo",
REGISTRY_NAMESPACE: namespace,
REGISTRY_TOKEN: "fixture-only",
},
},
@@ -51,7 +52,7 @@ describe("verified application image reuse", () => {
it("reuses only the exact image digest that passed deployment checks", () => {
const calls = simulate("verified");
expect(calls).toContain(
`docker tag sha256:candidate registry.invalid/owner/cms:${sha}`,
`docker tag sha256:candidate registry.invalid/simo/cms:${sha}`,
);
expect(calls).not.toContain("docker build --network=host --build-arg");
expect(
@@ -67,3 +68,13 @@ describe("verified application image reuse", () => {
},
);
});
it("uses the token account namespace instead of the repository owner", () => {
const calls = simulate("verified");
expect(calls).toContain(`docker push registry.invalid/simo/cms:${sha}`);
expect(calls).not.toContain("registry.invalid/owner/cms");
});
it("supports an explicit organization namespace", () => {
const calls = simulate("verified", "My-Org");
expect(calls).toContain(`docker push registry.invalid/my-org/cms:${sha}`);
});