You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Replaces the single docker-registry input with docker-registries, a newline-separated registry[|username[|password]] list. Lets a service dual-write during a Harbor → GAR migration and roll back without a rebuild: every build, merge and retag pushes to all configured registries, while GitOps manifests and release-retag lookups always use the first (primary) entry. A registry entry can also carry a path prefix after the host (e.g. GAR's europe-docker.pkg.dev/staffbase-artifacts/images-publish) for registries that address a project/repository as part of the push path.
Breaking change: docker-registry is removed. A single value still works unchanged via docker-registries (default registry.staffbase.com). gha-workflows/template_gitops.yml is already updated for this; direct callers of this action need to rename the input.
Verified end-to-end with a real dual-push to Harbor + GAR from backstage-app (run), pinned to this branch, then reverted.
Checklist
Write tests
Make sure all tests pass
Update documentation
Review the Contributing Guideline and sign CLA
Reference relevant issue(s) and close them after merging
Replaces the single docker-registry input with docker-registries, a
newline-separated "registry[|username[|password]]" list. This lets a
service dual-write during a Harbor -> GAR migration and roll back
without a rebuild: every build, merge and retag pushes to all
configured registries, while GitOps manifests and release-retag
lookups always use the first (primary) entry.
Breaking change: docker-registry is removed. A single value still
works unchanged via docker-registries (default registry.staffbase.com).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ath prefix
A registry entry can carry a project/repository path after the host
(e.g. GAR's europe-docker.pkg.dev/staffbase-artifacts/images-publish),
needed so the pushed image ref includes it. docker login only accepts
a bare host, so strip to it before logging in.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Buildx setup, login and build were gated solely on top-level
docker-username/docker-password. A registry entry supplying its
credentials entirely inline (as documented) left both unset, so login
and build silently skipped with no image pushed. Gate on a new
has_credentials output instead, computed from every resolved registry
entry.
Retagging's manifest GET/PUT also always authenticated with the raw
top-level credentials, ignoring the primary registry's own resolved
ones. A primary configured with only inline credentials either failed
validation or sent the wrong credentials. It now authenticates with
the primary entry's resolved username/password.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This comment claims action.yml synthesizes INPUT_DOCKER_REGISTRIES from the removed docker-registry input, but action.yml has no such input or fallback; the action only supplies the new input's default. That contradicts the documented breaking change and can mislead callers of these scripts into expecting legacy compatibility. Please update the comment to describe the actual docker-registries-only contract.
…I from primary
Generate Tags never received the top-level docker-username/
docker-password, so has_credentials was always false for the
documented single-registry-plus-top-level-creds configuration,
silently skipping login and build.
docker-registry-api was a separate static input decoupled from
docker-registries, so reordering the list to make a different
registry primary (the documented rollback path) still retagged the
old primary. It now defaults to the standard v2 API form derived from
the primary entry's host, overridable for non-standard endpoints.
Also: a docker-registries list with some entries credentialed and
others not now fails fast instead of letting buildx attempt an
unauthenticated push to the entries login-registries.sh skipped.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…d retag API
The derived docker-registry-api stripped everything after the host,
so a primary with a path prefix (e.g. GAR's
europe-docker.pkg.dev/staffbase-artifacts/images-publish) lost it: the
manifest API's literal /v2/ segment sits right after the bare host,
but the path prefix is part of the <name> the API addresses, appended
after /v2/, not before it. retag-image.sh only appends
INPUT_DOCKER_IMAGE to this URL, so dropping the prefix 404s against
any registry that addresses a project/repository this way.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Reject blank-line-only registry input with clear error
scripts/lib/registries.sh:33
A non-empty input containing only blank lines leaves REGISTRIES empty because blank lines are skipped, but callers immediately dereference REGISTRIES[0] under set -u. This makes a valid blank-line-only list fail with REGISTRIES[0]: unbound variable instead of a clear input error. Validate that at least one registry was parsed (and return non-zero) after the loop.
resolve_registries silently left REGISTRIES empty, so the first
dereference of REGISTRIES[0] downstream crashed on "unbound variable"
under set -u instead of a clear input error.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Document path preservation in derived default endpoint
action.yml:11
The input description says the default is derived from the primary entry's host as https://<host>/v2/, but path-prefixed entries are actually derived as https://<host>/v2/<path>/. Document the preserved path here as well, otherwise the action metadata contradicts the implemented GAR behavior.
…derived default
The description said the derived default is always https://<host>/v2/,
but a path-prefixed primary (e.g. GAR) preserves that path after /v2/.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Document preserved registry path prefixes in derived API URLs
README.md:224
This input-table description says the derived API defaults to the primary registry's host only, but the implementation deliberately preserves the primary entry's path prefix (generate-tags.sh:24-34) and the action metadata documents that behavior as well. The current text is misleading for path-scoped registries and should describe the actual https://<host>/v2/<path>/ form.
Rename test to reflect the default registry configuration it covers
tests/generate-tags.bats:361
This test is named as if it verifies behavior when INPUT_DOCKER_REGISTRIES is unset, but setup() always exports that variable and the old docker-registry input has been intentionally removed. It therefore provides no coverage for the condition it claims to test and can mislead future changes; rename it to describe the default value it actually exercises.
It was named as if it tested the removed docker-registry input's
fallback, but setup() always exports INPUT_DOCKER_REGISTRIES now — it
only covers the default value.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…licate-host credentials
Release-retag's manifest GET/PUT always sent HTTP Basic auth. Harbor
accepts that directly, but Google Artifact/Container Registry's raw
registry API requires a Bearer token for the "oauth2accesstoken"
convention docker login/gcloud auth configure-docker use — Basic auth
with that username fails against GAR. Detect it and send an
Authorization: Bearer header instead.
Also: Docker's credential store is keyed by host alone, so two
docker-registries entries sharing a host with different credentials
silently overwrote each other on login, breaking whichever entry
logged in first. login-registries.sh now fails fast on that
conflict and skips a harmless repeat login when credentials match.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket: https://mitarbeiterapp.atlassian.net/browse/DEVS-1547
Type of Change
Description
Replaces the single
docker-registryinput withdocker-registries, a newline-separatedregistry[|username[|password]]list. Lets a service dual-write during a Harbor → GAR migration and roll back without a rebuild: every build, merge and retag pushes to all configured registries, while GitOps manifests and release-retag lookups always use the first (primary) entry. A registry entry can also carry a path prefix after the host (e.g. GAR'seurope-docker.pkg.dev/staffbase-artifacts/images-publish) for registries that address a project/repository as part of the push path.Breaking change:
docker-registryis removed. A single value still works unchanged viadocker-registries(defaultregistry.staffbase.com).gha-workflows/template_gitops.ymlis already updated for this; direct callers of this action need to rename the input.Verified end-to-end with a real dual-push to Harbor + GAR from
backstage-app(run), pinned to this branch, then reverted.Checklist
🤖 Generated with Claude Code