Repository navigation
ci(docker): publish a sortable main-<commit UTC>-<sha7> relay tag - #8240
Draft
TheSentinel454 wants to merge 2 commits into
Draft
TheSentinel454 wants to merge 2 commits into
TheSentinel454 wants to merge 2 commits into
Conversation
added 2 commits
October 9, 2026 23:41
Every main push already publishes :sha-<7> and :main. :sha-<7> carries no order, so a consumer picking "newest main build" has to fetch metadata for every tag. Kargo's NewestBuild strategy does that against ~1,700 sha-* tags (4,800 total) on every warehouse discovery cycle. Add :main-<YYYYMMDDHHmmss>-<7> (and the debug- variant via the merge job's flavor prefix) to the same manifest on push to main. The UTC commit time prefix makes the tag sort by build order, so a Lexical selector can pick the newest from the tag list alone. It uses the commit date, not the run date, so rerunning a commit re-pushes the same tag. Existing tags are unchanged. Signed-off-by: Elrond <28d6302a099e5225b02c4155ac4236e4912603df2ab08dbfc2f4fef08ce598c8@buzz.block.builderlab.xyz>
Kargo's buzz-image warehouse selects Lexical over the main-<UTC>-<sha7> tag; a drifted format would stop Freight discovery silently. Also note the tag form in the chart README's Datadog version section. Signed-off-by: Elrond <28d6302a099e5225b02c4155ac4236e4912603df2ab08dbfc2f4fef08ce598c8@buzz.block.builderlab.xyz>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Each push to main adds one more tag to the relay image manifest that
docker.ymlalready publishes::main-<YYYYMMDDHHmmss>-<sha7>(UTC commit time):debug-main-<YYYYMMDDHHmmss>-<sha7>on the debug manifest:main,:sha-<7>, and the release tags don't change.Why:
:sha-<7>has no ordering, so a deploy tool that wants "the newest main build" has to fetch metadata for every tag before it can sort. Our staging promotion warehouse (Kargo,NewestBuild) does that on every discovery cycle, against about 1,700sha-*tags (4,800 total) inghcr.io/block/buzz. That's slow, it hits registry rate limits, and one failed fetch aborts the whole cycle. The timestamp prefix makes the tag sort lexically in build order. ALexicalselector with^main-\d{14}-[0-9a-f]{7}$can then pick the newest build from the tag list alone and fetch only the tags it keeps.Details, checked against the pinned
docker/metadata-actionv6.1.0 (80c7e94d):{{sha}}is the 7-char short sha (defaultShortShaLength = 7), the same value as:sha-<7>.{{commit_date}}formats in UTC by default. On a push it uses the event'scommits[].timestamp, so rerunning a commit produces the same tag.type=rawinherits the flavor prefix, so the merge job's debug leg emitsdebug-main-…. That's the same mechanism that producesdebug-maintoday.enable=limits the tag topushonrefs/heads/main. Release tags, rescue dispatches, and PRs never get it.On main's last 40 commits, author time and committer time are the same instant, and both increase monotonically. A commit pushed with a backdated timestamp would sort below newer builds and just wouldn't be auto-picked; the next push supersedes it.
What got simpler: this adds one tag line in each of the two places that already mirror the tag matrix, plus header docs. In return, downstream tooling no longer needs per-tag metadata fetches to find the newest build.
Related issue
N/A (staging rollout tooling). The downstream warehouse and tag-guard changes land separately and don't switch over until this tag has been published.
Testing
scripts/test-relay-image-eligibility-workflow.shandscripts/test-release-ref-contract.shpass at9ba1d8b7f.push: false), so the first real tag appears on the first main push after merge. I'll check the registry formain-<14 digits>-<sha7>anddebug-main-…on that manifest.