fix(ci): verify registry upload against exported OCI config
This commit is contained in:
1 parent
e617ed176a
commit
8dc187483c
4 files changed
+19
-18
No files matched your search
@@ -58,12 +58,16 @@ regctl registry set "$registry" --blob-chunk 8388608 --blob-max 8388608
|
||||
for target in "$image-migrations" "$image"; do
|
||||
echo "Publishing $target with blob requests up to 8 MiB"
|
||||
docker image save --output "$context/image.tar" "$target"
|
||||
regctl image import "$target" "$context/image.tar"
|
||||
# Import may change compression/manifest representation, but the immutable
|
||||
# image config digest must still match the exact local image we verified.
|
||||
expected_config="$(docker image inspect --format '{{.Id}}' "$target")"
|
||||
# Normalize the saved archive locally before copying it unchanged to Gitea.
|
||||
# Docker engine IDs and OCI index IDs are not interchangeable with config IDs.
|
||||
local_ref="ocidir://$context/oci:verified"
|
||||
regctl image import "$local_ref" "$context/image.tar"
|
||||
expected_config="$(regctl manifest get "$local_ref" --platform "linux/$arch" --format '{{.GetConfig.Digest}}')"
|
||||
[[ "$expected_config" =~ ^sha256:[0-9a-f]{64}$ ]] || { echo "Invalid local image config digest" >&2; exit 1; }
|
||||
regctl image copy "$local_ref" "$target"
|
||||
remote_config="$(regctl manifest get "$target" --platform "linux/$arch" --format '{{.GetConfig.Digest}}')"
|
||||
[[ "$remote_config" = "$expected_config" ]] || { echo "Published image config does not match verified local image" >&2; exit 1; }
|
||||
rm -f -- "$context/image.tar"
|
||||
rm -rf -- "$context/oci"
|
||||
done
|
||||
echo "Published application and migrations: $image"
|
||||
Reference in new issue
Block a user