Skip to content

ci(docker): build and publish multi-architecture images for amd64 and arm64 (#1245) - #1286

Closed
luciusverus-cyber wants to merge 1 commit into
ceejaylaboratory:mainfrom
luciusverus-cyber:infra/issue-1245-multi-arch-docker
Closed

luciusverus-cyber wants to merge 1 commit into
ceejaylaboratory:mainfrom
luciusverus-cyber:infra/issue-1245-multi-arch-docker

Conversation

@luciusverus-cyber

Copy link
Copy Markdown

Problem

The repository has no image build workflow at all — every deployment had to run docker build on the target host (see docker-compose.prod.yml, which builds rather than pulls). That makes images amd64-only by default: a Graviton instance or an ARM Kubernetes node pulls an emulated image or fails outright, and nothing in the pipeline proves it.

Changes

New .github/workflows/docker.yml using QEMU + buildx:

  • pull requests build backend and dashboard for linux/amd64 and linux/arm64 separately with load: true, so the build actually executes instead of being deferred to the registry, and push nothing — a fork PR cannot publish to the package registry
  • main / v* tags / manual dispatch publish one manifest list per service, tagged with the commit SHA and :latest, authenticated with GITHUB_TOKEN only
  • gha layer cache is shared per service; the runner disk is freed first, because emulated arm64 plus npm ci regularly exhausts the 14 GB image before the build finishes
  • after publishing, imagetools inspect asserts both platforms are present in the manifest, so a silently amd64-only manifest cannot report green
  • path filters include the root and dashboard manifests, because the dashboard image builds from the repo root and copies them

Verification

python3 -c "import yaml; yaml.safe_load(...)" on the workflow to confirm it parses, and a structural pass over every uses:/if:/permissions: block. The two Dockerfiles are the ones already in main (both multi-stage, node:20-alpine / nginx:1.27-alpine); the dashboard builds from the repo root, which is why its context is . with file: dashboard/Dockerfile — same as docker-compose.yml.

helm/docker are not available in this environment, so the build itself was not executed here; the first run on a real runner is the actual test of the QEMU path.

Note

This issue is currently closed (batch backlog cleanup on 2026-09-23). The multi-arch gap it describes is still real, so this is offered as a concrete implementation rather than a reopened issue.

Refs #1245

…eejaylaboratory#1245)

The repo had no image build workflow at all, so every deployment had to run
docker build on the target host. That made images amd64-only by default:
a Graviton or ARM Kubernetes node either pulled an emulated image or failed
outright, and nothing in the pipeline proved it.

Add .github/workflows/docker.yml using QEMU + buildx:

- pull requests build backend and dashboard for linux/amd64 and linux/arm64
  separately with load:true so the build actually executes, and push nothing,
  so a fork PR cannot publish to the package registry
- main, v* tags and workflow_dispatch publish one manifest list per service
  tagged with the commit SHA and :latest, using only GITHUB_TOKEN
- gha layer cache is shared per service; the runner disk is freed first
  because emulated arm64 plus npm ci regularly exhausts the 14 GB image
- after publishing, imagetools inspect asserts both platforms are in the
  manifest, so a silently amd64-only manifest cannot go green
- path filters include the root and dashboard manifests the dashboard image
  copies at build time
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

Hey @luciusverus-cyber! 👋 It looks like this PR isn't linked to any issue.

If this PR is for one of the issues assigned to you as part of a Wave, please link it to ensure your contribution is tracked properly. You can do this by adding a keyword to the PR description (e.g., Closes #123), or by clicking a button below:

Issue Title
#1256 [DevOps/Security] Add Secret Scanning & Pre-Commit Git Hooks Configuration Link to this issue
#1246 [DevOps/Docker] Optimize Dockerfile with Multi-Stage Builds & Minimal Base Image Link to this issue
#1247 [DevOps/Kubernetes] Add Helm Charts for Deployment to Production Kubernetes Clusters Link to this issue
#1245 [DevOps/CI] Implement Multi-Architecture Docker Builds (amd64, arm64) Link to this issue

ℹ️ Learn more about linking PRs to issues

@luciusverus-cyber

Copy link
Copy Markdown
Author

Superseded by a single consolidated PR covering #1245, #1246, #1247 and #1256.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant