@@ -42,18 +42,19 @@ None of the above arguments are required for `--update`.
4242
4343### Optional arguments
4444
45- | Option | Default | Description |
46- | ------------------ | -------------------------------- | ------------------------------------------------------------------- |
47- | ` --output-dir ` | ` ./output ` | Where to write output packages |
48- | ` --cache-dir ` | ` ~/.cache/cfengine/buildscripts ` | Dependency cache directory |
49- | ` --build-number ` | ` 1 ` | Build number for package versioning |
50- | ` --version ` | auto | Override version string |
51- | ` --rebuild-image ` | | Force rebuild of Docker image (bypasses Docker layer cache) |
52- | ` --push-image ` | | Build image and push to registry, then exit |
53- | ` --update ` | | Fetch latest image versions from registry and update platforms.json |
54- | ` --shell ` | | Drop into a bash shell inside the container for debugging |
55- | ` --list-platforms ` | | List available platforms and exit |
56- | ` --source-dir ` | parent of ` buildscripts/ ` | Root directory containing repos |
45+ | Option | Default | Description |
46+ | ------------------ | -------------------------------- | ---------------------------------------------------------------------------------- |
47+ | ` --output-dir ` | ` ./output ` | Where to write output packages |
48+ | ` --cache-dir ` | ` ~/.cache/cfengine/buildscripts ` | Dependency cache directory |
49+ | ` --build-number ` | ` 1 ` | Build number for package versioning |
50+ | ` --version ` | auto | Override version string |
51+ | ` --rebuild-image ` | | Force rebuild of Docker image (bypasses Docker layer cache) |
52+ | ` --push-image ` | | Build image and push to registry, then exit |
53+ | ` --update ` | | Fetch latest image versions from registry and update platforms.json |
54+ | ` --update-sha ` | | Fetch latest base image manifest digests from Docker Hub and update platforms.json |
55+ | ` --shell ` | | Drop into a bash shell inside the container for debugging |
56+ | ` --list-platforms ` | | List available platforms and exit |
57+ | ` --source-dir ` | parent of ` buildscripts/ ` | Root directory containing repos |
5758
5859## Supported platforms
5960
@@ -64,8 +65,26 @@ None of the above arguments are required for `--update`.
6465| ` ubuntu-24 ` | ` ubuntu:24.04 ` |
6566| ` debian-11 ` | ` debian:11 ` |
6667| ` debian-12 ` | ` debian:12 ` |
68+ | ` debian-13 ` | ` debian:13 ` |
69+
70+ Adding a new Debian/Ubuntu platform requires a new entry in ` platforms.json `
71+ and adding the platform name to the matrix in
72+ ` .github/workflows/build-base-images.yml ` so the weekly job builds and
73+ pushes its image to ` ghcr.io ` . Without the matrix entry, no image is ever
74+ pushed and the ` update-base-images.yml ` workflow will fail with a 403 from
75+ ` ghcr.io ` when it queries tags for the missing repository.
76+
77+ The new entry in ` platforms.json ` needs:
78+
79+ - ` image_version ` : set to ` "latest" ` as a placeholder. The
80+ ` update-base-images.yml ` workflow (or ` ./build-in-container.py --update `
81+ run locally) will replace it with the real ghcr.io tag after the first
82+ image is pushed.
83+ - ` base_image_sha ` : the Docker Hub manifest digest for the ` base_image ` .
84+ Don't copy this by hand — run `./build-in-container.py --update-sha
85+ --platform <new-platform >` and it will fetch the current digest from
86+ Docker Hub and write it into ` platforms.json ` .
6787
68- Adding a new Debian/Ubuntu platform requires only a new entry in ` platforms.json ` .
6988Adding a non-debian based platform (e.g.,
7089RHEL/CentOS) requires a new ` container/Dockerfile.rhel ` plus platform entries.
7190
@@ -151,6 +170,20 @@ The `update-base-images.yml` workflow automates this step. It runs weekly
151170` platforms.json ` changes. This workflow requires ` contents: write ` and
152171` pull-requests: write ` permissions.
153172
173+ The ` base_image_sha ` digests in ` platforms.json ` pin each platform to a
174+ specific Docker Hub manifest. To refresh them to the current digests:
175+
176+ ``` bash
177+ # Update all platforms
178+ ./build-in-container.py --update-sha
179+
180+ # Update a single platform
181+ ./build-in-container.py --update-sha --platform ubuntu-22
182+ ```
183+
184+ The ` update-base-image-shas.yml ` workflow automates this. It runs weekly
185+ (Monday at 01:00 UTC) and opens a pull request with any digest changes.
186+
154187The workflow authenticates to ` ghcr.io ` using the automatic ` GITHUB_TOKEN `
155188provided by GitHub Actions. For this to work:
156189
0 commit comments