Skip to content

ci: export private release images for deployment - #10

Merged
harley merged 1 commit into
mainfrom
ci/private-image-transfer
Sep 24, 2026
Merged

harley merged 1 commit into
mainfrom
ci/private-image-transfer

Conversation

@harley

@harley harley commented Sep 24, 2026

Copy link
Copy Markdown

What does this PR do?

Let an operator download already-built CoderPush release images through authenticated GitHub Actions artifacts. The new GHCR packages are private, and Singapore has no registry credential. This keeps personal and agent credentials off the host and leaves package visibility unchanged.

Type of Change

  • CI / infrastructure

Changes Made

A manual main-only workflow validates a full SHA and main ancestry, pulls both existing images with the workflow token's read-only package permission, and exports a three-day artifact with archive checksum, registry digests, and image identities. It does not build, deploy, or change images.

How to Test

Source review and whitespace check. Run against the successful image pair for 355006f; verify checksum and image identities after download/load.

Risks

Only dispatch for a release whose original image build passed; tags remain mutable, so compare exported digests with that build. Artifacts require repository access. No secrets are exported.

AI Disclosure

Codex prepared this transfer path as part of the authorized production upgrade.

@amazon-q-developer amazon-q-developer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR adds a GitHub Actions workflow to export private CoderPush release images as artifacts. The workflow implements proper authentication, validation, and artifact retention.

Critical Issue Found:

  • Missing error handling when docker images don't exist for the specified SHA - this will cause confusing failures

The workflow correctly validates SHA format and ancestry, uses read-only permissions, and includes verification artifacts (digests and identities).


You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.

Comment on lines +40 to +41
docker pull "$backend"
docker pull "$frontend"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Logic Error: The docker pull commands will fail silently if the images don't exist for the specified SHA. Add error handling to verify image existence or provide clear failure messages when images are not found in the registry.

Suggested change
docker pull "$backend"
docker pull "$frontend"
docker pull "$backend" || { echo "Error: Backend image not found for SHA $RELEASE_SHA"; exit 1; }
docker pull "$frontend" || { echo "Error: Frontend image not found for SHA $RELEASE_SHA"; exit 1; }

@harley
harley merged commit 0310c4c into main Sep 24, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant