Prebuild and pin qualified Forgejo CI images #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feature/ci-images-v1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Moves repeated CI toolchain construction into project-owned, independently
qualified Forgejo container images.
Routine CI now consumes immutable image digests instead of rebuilding PHP and
installing Docker tooling on every run.
No Maintenance Tracker product behavior or persistent application data changes
are included in this PR.
Qualified CI images
Published to the Forgejo container registry:
PHP 8.2
forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:fbbd1d9067f302fc769e342fe292836131cde3c8b809522f90d7165bbfb2fdc6PHP 8.5
forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-php@sha256:a1c8b402f8cc6a61609cf4b0459b2a795b1b0671b95867995a1dd0b257c2a7dcNextcloud integration harness
forgejo.argentwolf.org/alan/maintenance_tracker_for_nextcloud/ci-nextcloud@sha256:3eea2dd55afb6004f7d8721a5c9e497cccc1e53ce476e997706aa9222d885d2cThe images were locally built and qualified before publication.
Changes
Nextcloud integration harness;
ci/images/qualified-images.json;setup-phpenvironment construction;composer.lockandpackage-lock.json;mutable image tags or unqualified images.
Image qualification
The PHP images verify their expected:
dom;libxml;mbstring;xml;xmlwriter.The Nextcloud harness verifies:
All three images completed local qualification successfully before publication.
Supply-chain model
Image construction and routine application CI are deliberately separate.
The reviewed image definition creates and qualifies a versioned environment.
Routine CI then consumes its immutable registry digest.
composer installandnpm cicontinue to install application dependenciesfrom repository lockfiles rather than baking those dependencies into the CI
images.
Expected benefit
The previous PHP matrix spent roughly three minutes per job constructing its
PHP environment. The Nextcloud jobs also repeatedly installed Docker tooling.
This PR should substantially reduce that repeated runner setup while keeping the
toolchain deterministic.
Acceptance gate
This PR's Forgejo CI is the first independent proof that the workstation runners
can:
Timing should be compared with the pre-image CI runs after this workflow is
green.