Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/workflows/publish-images.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
name: publish-images

# Publishes every scope's worker image to ECR Public on each semver tag, then
# registers each as an oci_image platform artifact (visible-to organization=*).
# registers each as an oci_image platform artifact (visible-to organization=*)
# carrying both the digest and the release tag, so packages can resolve it by
# tag (`lookup = true` + meta.tag) instead of copying a digest around.
# Same mold as scopes-lambda (publish-image.yml), fanned out to the 3 images:
#
# scopes/containers <- k8s/ (base; FROM worker-bridge + tooling)
Expand Down Expand Up @@ -71,6 +73,7 @@ jobs:
--registry public.ecr.aws \
--repository nullplatform/scopes/containers \
--digest "${{ needs.containers.outputs.image_digest }}" \
--tag "${{ inputs.existing_tag || github.ref_name }}" \
--visible-to "organization=*"

# ── scheduled-task (standalone) ────────────────────────────────────────────
Expand Down Expand Up @@ -104,6 +107,7 @@ jobs:
--registry public.ecr.aws \
--repository nullplatform/scopes/scheduled-task \
--digest "${{ needs.scheduled-task.outputs.image_digest }}" \
--tag "${{ inputs.existing_tag || github.ref_name }}" \
--visible-to "organization=*"

# ── containers-datadog (overlay) ───────────────────────────────────────────
Expand Down Expand Up @@ -139,6 +143,7 @@ jobs:
--registry public.ecr.aws \
--repository nullplatform/scopes/containers-datadog \
--digest "${{ needs.containers-datadog.outputs.image_digest }}" \
--tag "${{ inputs.existing_tag || github.ref_name }}" \
--visible-to "organization=*"

# ── GitHub release with artifact metadata ──────────────────────────────────
Expand All @@ -153,6 +158,9 @@ jobs:
runs-on: ubuntu-24.04
env:
GH_TOKEN: ${{ github.token }}
# No checkout in this job: gh infers the repo from git otherwise and dies
# with "not a git repository" — GH_REPO pins it explicitly.
GH_REPO: ${{ github.repository }}
TAG: ${{ inputs.existing_tag || github.ref_name }}
REGISTRY: public.ecr.aws/nullplatform
DIGEST_CONTAINERS: ${{ needs.containers.outputs.image_digest }}
Expand Down
12 changes: 10 additions & 2 deletions docker/scheduled-task.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@
# its steps only reach for kubectl + gomplate (bash/jq/np ship in the base).
FROM public.ecr.aws/nullplatform/scopes/worker-bridge:1.0.0

RUN apk add --no-cache gomplate
# aws-cli: the k8s scope scripts this overlay runs on top of call `aws` (sts
# assume-role first of all, then IAM and ECR); without it every action fails at
# the assume_role step on AWS installs.
RUN apk add --no-cache aws-cli gomplate

ARG TARGETARCH
ARG KUBECTL_VERSION=1.30.4
Expand All @@ -13,6 +16,11 @@ RUN curl -fsSL -o /usr/local/bin/kubectl "https://dl.k8s.io/release/v${KUBECTL_V
&& kubectl version --client

COPY . /app/pkg
# The scheduled task is the k8s scope run with the scheduled_task overlay (see
# scheduled_task/specs/notification-channel.json.tpl: --service-path=k8s
# --overrides-path=scheduled_task), so the base stays k8s and the overlay goes
# in NP_OVERRIDES_PATH, like containers-datadog does.
ENV NP_PACKAGE_NAME=scheduled-task \
NP_SERVICE_PATH=/app/pkg/scheduled_task \
NP_SERVICE_PATH=/app/pkg/k8s \
NP_OVERRIDES_PATH=/app/pkg/scheduled_task \
NP_SCOPE_ENTRYPOINT=/app/pkg/entrypoint
Loading