Skip to content

ci(docker): publish a sortable main-<commit UTC>-<sha7> relay tag - #8240

Draft
TheSentinel454 wants to merge 2 commits into
mainfrom
elrond/relay-sortable-main-tag
Draft

TheSentinel454 wants to merge 2 commits into
mainfrom
elrond/relay-sortable-main-tag

Conversation

@TheSentinel454

Copy link
Copy Markdown
Contributor

Summary

Each push to main adds one more tag to the relay image manifest that docker.yml already publishes:

  • :main-<YYYYMMDDHHmmss>-<sha7> (UTC commit time)
  • :debug-main-<YYYYMMDDHHmmss>-<sha7> on the debug manifest

:main, :sha-<7>, and the release tags don't change.

Why: :sha-<7> has no ordering, so a deploy tool that wants "the newest main build" has to fetch metadata for every tag before it can sort. Our staging promotion warehouse (Kargo, NewestBuild) does that on every discovery cycle, against about 1,700 sha-* tags (4,800 total) in ghcr.io/block/buzz. That's slow, it hits registry rate limits, and one failed fetch aborts the whole cycle. The timestamp prefix makes the tag sort lexically in build order. A Lexical selector with ^main-\d{14}-[0-9a-f]{7}$ can then pick the newest build from the tag list alone and fetch only the tags it keeps.

Details, checked against the pinned docker/metadata-action v6.1.0 (80c7e94d):

  • {{sha}} is the 7-char short sha (defaultShortShaLength = 7), the same value as :sha-<7>.
  • {{commit_date}} formats in UTC by default. On a push it uses the event's commits[].timestamp, so rerunning a commit produces the same tag.
  • type=raw inherits the flavor prefix, so the merge job's debug leg emits debug-main-…. That's the same mechanism that produces debug-main today.
  • enable= limits the tag to push on refs/heads/main. Release tags, rescue dispatches, and PRs never get it.

On main's last 40 commits, author time and committer time are the same instant, and both increase monotonically. A commit pushed with a backdated timestamp would sort below newer builds and just wouldn't be auto-picked; the next push supersedes it.

What got simpler: this adds one tag line in each of the two places that already mirror the tag matrix, plus header docs. In return, downstream tooling no longer needs per-tag metadata fetches to find the newest build.

Related issue

N/A (staging rollout tooling). The downstream warehouse and tag-guard changes land separately and don't switch over until this tag has been published.

Testing

  • scripts/test-relay-image-eligibility-workflow.sh and scripts/test-release-ref-contract.sh pass at 9ba1d8b7f.
  • PR runs don't push images (push: false), so the first real tag appears on the first main push after merge. I'll check the registry for main-<14 digits>-<sha7> and debug-main-… on that manifest.

Elrond added 2 commits October 9, 2026 23:41
Every main push already publishes :sha-<7> and :main. :sha-<7> carries no
order, so a consumer picking "newest main build" has to fetch metadata for
every tag. Kargo's NewestBuild strategy does that against ~1,700 sha-* tags
(4,800 total) on every warehouse discovery cycle.

Add :main-<YYYYMMDDHHmmss>-<7> (and the debug- variant via the merge job's
flavor prefix) to the same manifest on push to main. The UTC commit time
prefix makes the tag sort by build order, so a Lexical selector can pick the
newest from the tag list alone. It uses the commit date, not the run date,
so rerunning a commit re-pushes the same tag. Existing tags are unchanged.

Signed-off-by: Elrond <28d6302a099e5225b02c4155ac4236e4912603df2ab08dbfc2f4fef08ce598c8@buzz.block.builderlab.xyz>
Kargo's buzz-image warehouse selects Lexical over the main-<UTC>-<sha7>
tag; a drifted format would stop Freight discovery silently. Also note
the tag form in the chart README's Datadog version section.

Signed-off-by: Elrond <28d6302a099e5225b02c4155ac4236e4912603df2ab08dbfc2f4fef08ce598c8@buzz.block.builderlab.xyz>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant