ci: export private release images for deployment - #10
Conversation
There was a problem hiding this comment.
This PR adds a GitHub Actions workflow to export private CoderPush release images as artifacts. The workflow implements proper authentication, validation, and artifact retention.
Critical Issue Found:
- Missing error handling when docker images don't exist for the specified SHA - this will cause confusing failures
The workflow correctly validates SHA format and ancestry, uses read-only permissions, and includes verification artifacts (digests and identities).
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
| docker pull "$backend" | ||
| docker pull "$frontend" |
There was a problem hiding this comment.
🛑 Logic Error: The docker pull commands will fail silently if the images don't exist for the specified SHA. Add error handling to verify image existence or provide clear failure messages when images are not found in the registry.
| docker pull "$backend" | |
| docker pull "$frontend" | |
| docker pull "$backend" || { echo "Error: Backend image not found for SHA $RELEASE_SHA"; exit 1; } | |
| docker pull "$frontend" || { echo "Error: Frontend image not found for SHA $RELEASE_SHA"; exit 1; } |
What does this PR do?
Let an operator download already-built CoderPush release images through authenticated GitHub Actions artifacts. The new GHCR packages are private, and Singapore has no registry credential. This keeps personal and agent credentials off the host and leaves package visibility unchanged.
Type of Change
Changes Made
A manual main-only workflow validates a full SHA and main ancestry, pulls both existing images with the workflow token's read-only package permission, and exports a three-day artifact with archive checksum, registry digests, and image identities. It does not build, deploy, or change images.
How to Test
Source review and whitespace check. Run against the successful image pair for 355006f; verify checksum and image identities after download/load.
Risks
Only dispatch for a release whose original image build passed; tags remain mutable, so compare exported digests with that build. Artifacts require repository access. No secrets are exported.
AI Disclosure
Codex prepared this transfer path as part of the authorized production upgrade.