Skip to content

ci(release): publish the agent image as an amd64+arm64 index - #1775

Merged
trunk-io[bot] merged 3 commits into
mainfrom
compass-native/rig-3751-agent-image-index
Oct 7, 2026
Merged

trunk-io[bot] merged 3 commits into
mainfrom
compass-native/rig-3751-agent-image-index

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 2 PRs:

  1. main
  2. "ci(release): publish the agent image as an amd64+arm64 index" (this PR)
  3. refactor(release): move the agent-image index publish logic into a tested tool #1804

Summary

  • Split publish-image into publish-image-amd64 (ubuntu-latest) and publish-image-arm64 (ubuntu-24.04-arm). Each job pushes only its immutable git-<sha12>-<arch> tag.
  • New publish-image-manifest job:
    • builds the index by digest, amd64 first, then arm64;
    • asserts two members;
    • guards :git-<sha12>: an equal list digest skips, a different one fails, only manifest-unknown pushes, and any other error aborts.
  • :latest moves only when this sha is on main and no newer main commit has a published :git index. Runs can reach this job out of commit order, so an older run cannot move :latest backward. :latest must then match the newest published index, or the job fails.
  • The job then verifies the platform set, the member digests, each member's config platform, and that :latest matches when it moved.
  • release-image copies the full index to :vX.Y.Z with --multi-arch all --preserve-digests, then verifies and exports the list digest.
  • tools/release-notes records the manifest digest (sha256 of the raw bytes), so an index is reported as itself.
  • publish.sh requires --arch-suffix or explicit tags; a bare call now errors. It also truncates the sha to exactly 12 characters, matching the index job.
  • The temporary arm64 spike job is removed.

Verification

  • The arm64 build was proven on a throwaway ref: release.yml run 37413566470.
  • Local registry:2 harness with real busybox amd64 and arm64 members:
    • index push: a fresh push succeeded, a rerun skipped, a tampered tag failed, and registry-down failed;
    • the release-image copy kept the index list digest and both platforms (a plain copy produced one image manifest);
    • the :latest guard behaved correctly in five cases: no newer index, newer index published, tip run, sha not on main (aborts), registry down (aborts).
  • bun test in tools/release-notes: 26 pass. The two new digest tests fail against the old code.
  • biome check tools/release-notes and shellcheck agent-image/publish.sh are clean.
  • actionlint findings match main's baseline exactly.
  • Deferred: permanent tests for the publish guards need the inline shell moved into a TS tool; tracked in RIG-4735.
  • Not run: the publish and release jobs, because they are guarded to run only on main.

Risks

The first main run is the real test of the index job. A failure leaves :latest on the previous amd64 image. Rollback is a revert. GitHub runners ship podman 4.9.3; the flags used are present there.

Compatibility

:latest, :git-<sha12> and :vX.Y.Z become multi-arch indexes. amd64 pulls resolve to the same kind of image as before. The release body's image digest is now the index digest instead of a config digest. Calling publish.sh with no arguments now fails.

Documentation

None: CI-only change. The behaviour follows the existing design record.

Refs RIG-3751

publish-image splits into publish-image-amd64 and publish-image-arm64,
each pushing only its immutable git-<sha12>-<arch> tag. A new
publish-image-manifest job composes the index by digest in a fixed
member order, guards :git-<sha12> (equal list digest skips, different
fails, only manifest-unknown pushes), pushes :latest, and verifies the
platform set, the member digest set, each member's config platform, and
the :latest coherence. publish.sh loses its bare default tag set, and
the temporary arm64 spike job is removed.

Refs RIG-3751

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@trunk-io

trunk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

😎 This pull request was merged.

@linear-code

linear-code Bot commented Oct 6, 2026

Copy link
Copy Markdown

RIG-3751

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-native-rig-3751-agen.compass-eng-docs.pages.dev

Deployed from compass-native/rig-3751-agent-image-index at 053a33b.

rigel-mintaka and others added 2 commits October 6, 2026 14:40
…er :latest

- release-image copies :git-<sha12> to :vX.Y.Z with --multi-arch all
  and --preserve-digests, and verifies and exports the list digest.
- release-notes records the manifest digest (sha256 of the raw bytes),
  so an index is reported as itself.
- publish-image-manifest leaves :latest unmoved when a newer main commit
  already has its :git index, so out-of-order runs cannot move it back.
- publish.sh truncates the sha to 12 chars, matching the index job.

Refs RIG-3751

Co-authored-by: Matt Wilkinson <matt@rigel.build>
- A run whose sha is no longer on main never moves :latest.
- When a newer :git index exists, :latest must match it; a newer run
  that failed before :latest now reds the older run instead of passing.

Refs RIG-3751

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@trunk-io

trunk-io Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request is queued for merge as part of 1804, which will merge 1775, 1804.

@trunk-io
trunk-io Bot merged commit bff6d1b into main Oct 7, 2026
17 checks passed
@trunk-io
trunk-io Bot deleted the compass-native/rig-3751-agent-image-index branch October 7, 2026 05:34
@trunk-io

trunk-io Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1804.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants