Prebuild and pin qualified Forgejo CI images #3

Merged
alan merged 3 commits from feature/ci-images-v1 into main 2026-09-03 00:53:48 +00:00
Owner

Summary

Moves repeated CI toolchain construction into project-owned, independently
qualified Forgejo container images.

Routine CI now consumes immutable image digests instead of rebuilding PHP and
installing Docker tooling on every run.

No Maintenance Tracker product behavior or persistent application data changes
are included in this PR.

Qualified CI images

Published to the Forgejo container registry:

PHP 8.2

forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:fbbd1d9067f302fc769e342fe292836131cde3c8b809522f90d7165bbfb2fdc6

PHP 8.5

forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:a1c8b402f8cc6a61609cf4b0459b2a795b1b0671b95867995a1dd0b257c2a7dc

Nextcloud integration harness

forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-nextcloud@sha256:3eea2dd55afb6004f7d8721a5c9e497cccc1e53ce476e997706aa9222d885d2c

The images were locally built and qualified before publication.

Changes

  • adds project-owned Docker definitions for PHP 8.2, PHP 8.5, and the
    Nextcloud integration harness;
  • pins upstream image bases;
  • provides explicit local build, qualification, and publication tooling;
  • records the approved images in ci/images/qualified-images.json;
  • changes routine PHP CI to run directly in the qualified PHP images;
  • removes the repeated setup-php environment construction;
  • changes Nextcloud SQLite/PostgreSQL jobs to the qualified harness image;
  • removes repeated Docker CLI installation from those jobs;
  • keeps application dependencies controlled by composer.lock and
    package-lock.json;
  • adds validator coverage preventing routine CI from silently reverting to
    mutable image tags or unqualified images.

Image qualification

The PHP images verify their expected:

  • PHP version;
  • Composer;
  • Node;
  • Git;
  • dom;
  • libxml;
  • mbstring;
  • xml;
  • xmlwriter.

The Nextcloud harness verifies:

  • Node;
  • Docker CLI;
  • Git.

All three images completed local qualification successfully before publication.

Supply-chain model

Image construction and routine application CI are deliberately separate.

The reviewed image definition creates and qualifies a versioned environment.
Routine CI then consumes its immutable registry digest.

composer install and npm ci continue to install application dependencies
from repository lockfiles rather than baking those dependencies into the CI
images.

Expected benefit

The previous PHP matrix spent roughly three minutes per job constructing its
PHP environment. The Nextcloud jobs also repeatedly installed Docker tooling.

This PR should substantially reduce that repeated runner setup while keeping the
toolchain deterministic.

Acceptance gate

This PR's Forgejo CI is the first independent proof that the workstation runners
can:

  1. pull the private/project Forgejo registry images;
  2. launch jobs using the pinned digests;
  3. execute checkout and normal CI steps inside those images;
  4. complete the PHP 8.2 and 8.5 suites;
  5. complete the Nextcloud SQLite and PostgreSQL integration tests.

Timing should be compared with the pre-image CI runs after this workflow is
green.

## Summary Moves repeated CI toolchain construction into project-owned, independently qualified Forgejo container images. Routine CI now consumes immutable image digests instead of rebuilding PHP and installing Docker tooling on every run. No Maintenance Tracker product behavior or persistent application data changes are included in this PR. ## Qualified CI images Published to the Forgejo container registry: ### PHP 8.2 `forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:fbbd1d9067f302fc769e342fe292836131cde3c8b809522f90d7165bbfb2fdc6` ### PHP 8.5 `forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:a1c8b402f8cc6a61609cf4b0459b2a795b1b0671b95867995a1dd0b257c2a7dc` ### Nextcloud integration harness `forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-nextcloud@sha256:3eea2dd55afb6004f7d8721a5c9e497cccc1e53ce476e997706aa9222d885d2c` The images were locally built and qualified before publication. ## Changes - adds project-owned Docker definitions for PHP 8.2, PHP 8.5, and the Nextcloud integration harness; - pins upstream image bases; - provides explicit local build, qualification, and publication tooling; - records the approved images in `ci/images/qualified-images.json`; - changes routine PHP CI to run directly in the qualified PHP images; - removes the repeated `setup-php` environment construction; - changes Nextcloud SQLite/PostgreSQL jobs to the qualified harness image; - removes repeated Docker CLI installation from those jobs; - keeps application dependencies controlled by `composer.lock` and `package-lock.json`; - adds validator coverage preventing routine CI from silently reverting to mutable image tags or unqualified images. ## Image qualification The PHP images verify their expected: - PHP version; - Composer; - Node; - Git; - `dom`; - `libxml`; - `mbstring`; - `xml`; - `xmlwriter`. The Nextcloud harness verifies: - Node; - Docker CLI; - Git. All three images completed local qualification successfully before publication. ## Supply-chain model Image construction and routine application CI are deliberately separate. The reviewed image definition creates and qualifies a versioned environment. Routine CI then consumes its immutable registry digest. `composer install` and `npm ci` continue to install application dependencies from repository lockfiles rather than baking those dependencies into the CI images. ## Expected benefit The previous PHP matrix spent roughly three minutes per job constructing its PHP environment. The Nextcloud jobs also repeatedly installed Docker tooling. This PR should substantially reduce that repeated runner setup while keeping the toolchain deterministic. ## Acceptance gate This PR's Forgejo CI is the first independent proof that the workstation runners can: 1. pull the private/project Forgejo registry images; 2. launch jobs using the pinned digests; 3. execute checkout and normal CI steps inside those images; 4. complete the PHP 8.2 and 8.5 suites; 5. complete the Nextcloud SQLite and PostgreSQL integration tests. Timing should be compared with the pre-image CI runs after this workflow is green.
Pin routine CI to qualified Forgejo images
All checks were successful
CI / Frontend and generated assets (pull_request) Successful in 20s
CI / PHP 8.2 (pull_request) Successful in 23s
CI / PHP 8.5 (pull_request) Successful in 28s
CI / Nextcloud 34 / pgsql (pull_request) Successful in 32s
CI / Nextcloud 34 / sqlite (pull_request) Successful in 44s
CI / Unsigned install candidate (pull_request) Successful in 4s
3f78c97e23
alan merged commit 04025509a1 into main 2026-09-03 00:53:48 +00:00
alan deleted branch feature/ci-images-v1 2026-09-03 00:53:48 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
alan/maintenance_tracker_for_nextcloud!3
No description provided.