Skip to content

Commit f460f75

Browse files
authored
Merge pull request #2259 from larsewi/build-base-images-debian-13
Add debian-13 to build-base-images workflow matrix
2 parents a5e06ca + 3405f11 commit f460f75

2 files changed

Lines changed: 47 additions & 13 deletions

File tree

‎.github/workflows/build-base-images.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,7 @@ jobs:
1919
- ubuntu-24
2020
- debian-11
2121
- debian-12
22+
- debian-13
2223
steps:
2324
- name: Checkout repository
2425
uses: actions/checkout@v6

‎build-in-container.md‎

Lines changed: 46 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -42,18 +42,19 @@ None of the above arguments are required for `--update`.
4242

4343
### Optional arguments
4444

45-
| Option | Default | Description |
46-
| ------------------ | -------------------------------- | ------------------------------------------------------------------- |
47-
| `--output-dir` | `./output` | Where to write output packages |
48-
| `--cache-dir` | `~/.cache/cfengine/buildscripts` | Dependency cache directory |
49-
| `--build-number` | `1` | Build number for package versioning |
50-
| `--version` | auto | Override version string |
51-
| `--rebuild-image` | | Force rebuild of Docker image (bypasses Docker layer cache) |
52-
| `--push-image` | | Build image and push to registry, then exit |
53-
| `--update` | | Fetch latest image versions from registry and update platforms.json |
54-
| `--shell` | | Drop into a bash shell inside the container for debugging |
55-
| `--list-platforms` | | List available platforms and exit |
56-
| `--source-dir` | parent of `buildscripts/` | Root directory containing repos |
45+
| Option | Default | Description |
46+
| ------------------ | -------------------------------- | ---------------------------------------------------------------------------------- |
47+
| `--output-dir` | `./output` | Where to write output packages |
48+
| `--cache-dir` | `~/.cache/cfengine/buildscripts` | Dependency cache directory |
49+
| `--build-number` | `1` | Build number for package versioning |
50+
| `--version` | auto | Override version string |
51+
| `--rebuild-image` | | Force rebuild of Docker image (bypasses Docker layer cache) |
52+
| `--push-image` | | Build image and push to registry, then exit |
53+
| `--update` | | Fetch latest image versions from registry and update platforms.json |
54+
| `--update-sha` | | Fetch latest base image manifest digests from Docker Hub and update platforms.json |
55+
| `--shell` | | Drop into a bash shell inside the container for debugging |
56+
| `--list-platforms` | | List available platforms and exit |
57+
| `--source-dir` | parent of `buildscripts/` | Root directory containing repos |
5758

5859
## Supported platforms
5960

@@ -64,8 +65,26 @@ None of the above arguments are required for `--update`.
6465
| `ubuntu-24` | `ubuntu:24.04` |
6566
| `debian-11` | `debian:11` |
6667
| `debian-12` | `debian:12` |
68+
| `debian-13` | `debian:13` |
69+
70+
Adding a new Debian/Ubuntu platform requires a new entry in `platforms.json`
71+
and adding the platform name to the matrix in
72+
`.github/workflows/build-base-images.yml` so the weekly job builds and
73+
pushes its image to `ghcr.io`. Without the matrix entry, no image is ever
74+
pushed and the `update-base-images.yml` workflow will fail with a 403 from
75+
`ghcr.io` when it queries tags for the missing repository.
76+
77+
The new entry in `platforms.json` needs:
78+
79+
- `image_version`: set to `"latest"` as a placeholder. The
80+
`update-base-images.yml` workflow (or `./build-in-container.py --update`
81+
run locally) will replace it with the real ghcr.io tag after the first
82+
image is pushed.
83+
- `base_image_sha`: the Docker Hub manifest digest for the `base_image`.
84+
Don't copy this by hand — run `./build-in-container.py --update-sha
85+
--platform <new-platform>` and it will fetch the current digest from
86+
Docker Hub and write it into `platforms.json`.
6787

68-
Adding a new Debian/Ubuntu platform requires only a new entry in `platforms.json`.
6988
Adding a non-debian based platform (e.g.,
7089
RHEL/CentOS) requires a new `container/Dockerfile.rhel` plus platform entries.
7190

@@ -151,6 +170,20 @@ The `update-base-images.yml` workflow automates this step. It runs weekly
151170
`platforms.json` changes. This workflow requires `contents: write` and
152171
`pull-requests: write` permissions.
153172

173+
The `base_image_sha` digests in `platforms.json` pin each platform to a
174+
specific Docker Hub manifest. To refresh them to the current digests:
175+
176+
```bash
177+
# Update all platforms
178+
./build-in-container.py --update-sha
179+
180+
# Update a single platform
181+
./build-in-container.py --update-sha --platform ubuntu-22
182+
```
183+
184+
The `update-base-image-shas.yml` workflow automates this. It runs weekly
185+
(Monday at 01:00 UTC) and opens a pull request with any digest changes.
186+
154187
The workflow authenticates to `ghcr.io` using the automatic `GITHUB_TOKEN`
155188
provided by GitHub Actions. For this to work:
156189

0 commit comments

Comments
 (0)