Repository navigation
ci: add workflow to build the Noma litellm custom image - #18
Conversation
Automates the previously-manual `docker buildx --push` of the -custom image. Triggers on push to v*-custom branches + workflow_dispatch; builds docker/Dockerfile.non_root multi-arch and pushes to ECR tagged with the branch name (e.g. v1.102.0-custom) + a -<sha> variant. Build-only; deploy stays a values bump + canary (no ArgoCD sync). Prereqs for DevOps before first run: fork access to arc-runners-prod; OIDC trust on role/github-actions-region-deploy for repo Noma-Security/litellm; ecr:PutImage on the litellm repo for that role (or a dedicated build role). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
| run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v4 |
| uses: docker/setup-buildx-action@v4 | ||
|
|
||
| - name: Configure AWS credentials (OIDC) | ||
| uses: aws-actions/configure-aws-credentials@v6 |
| aws-region: ${{ env.AWS_REGION }} | ||
|
|
||
| - name: Login to Amazon ECR | ||
| uses: docker/login-action@v4 |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 90c1873. Configure here.
| run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v4 |
There was a problem hiding this comment.
Multi-arch build missing QEMU setup
High Severity
The job builds linux/amd64,linux/arm64 after only docker/setup-buildx-action, with no QEMU/binfmt registration. On typical amd64 arc-runners-prod hosts the arm64 stages in docker/Dockerfile.non_root cannot emulate, so docker buildx build --push fails and no image is published.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 90c1873. Configure here.
| - name: Resolve image tag (branch/tag name) | ||
| id: tag | ||
| shell: bash | ||
| run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT" |
There was a problem hiding this comment.
Untrusted ref interpolated into shell
Medium Severity
inputs.ref and github.ref_name are expanded directly inside run: scripts when resolving the image tag and writing the job summary. A crafted v*-custom branch name or workflow_dispatch ref can run arbitrary shell on the prod runner, including after AWS credentials exist.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 90c1873. Configure here.


What
Adds
.github/workflows/noma-build-custom-image.ymlto automate building the Noma litellm proxy image, replacing the current manualdocker buildx … --pushstep (no CI builds it today — verified: no ECR-push workflow in this fork, andgithub-actions/build-and-publishisn't wired to litellm).v*-custombranches (e.g.v1.102.0-custom) + manualworkflow_dispatch.docker/Dockerfile.non_root, multi-archlinux/amd64,linux/arm64, registry build cache.litellm:<branch>(e.g.v1.102.0-custom) +litellm:<branch>-<sha>for traceability.arc-runners-prod+ OIDC →role/github-actions-region-deploy(the381491951875ECR account) — same pattern asgithub-actions/.github/workflows/run-e2e-tenant-test.yml.Chose a dedicated ~90-line workflow over the shared
build-and-publishaction because that action hardcodes:latest+:<sha>tags and auto-syncs ArgoCD dev — wrong for a prod-line-customimage.Noma-Security/litellmto usearc-runners-prod.github-actions-region-deploytrust policy must permitrepo:Noma-Security/litellm:*(currently scoped to other repos).ecr:PutImage/ layer-upload on thelitellmrepo (it's a region-deploy role today). A dedicated build role is fine too — update therole-to-assumein the workflow if so.environment: prodapproval gate applies (expected).Until 1–3 are in place the workflow will fail at the AWS/ECR step. Happy to adjust the role ARN or runner label once DevOps confirms.
Tuning note
Builds both
amd64+arm64(litellm has no arch pin in values, so pods can land on either). If the litellm nodepools are amd64-only, droparm64to halve build time.🤖 Generated with Claude Code
Note
Low Risk
CI-only change that pushes container images to ECR; no application runtime or auth logic in the repo is modified, though org-level runner/OIDC/ECR setup must be correct before first use.
Overview
Adds a new GitHub Actions workflow Noma - Build custom image that automates building and pushing the Noma litellm proxy image to ECR, replacing manual
docker buildx … --push.It runs on pushes to
v*-custombranches and onworkflow_dispatch(optional ref), usesarc-runners-prodwithenvironment: prod, authenticates to AWS via OIDC (github-actions-region-deploy), and builds fromdocker/Dockerfile.non_rootfor linux/amd64 and linux/arm64 with registry cache. Images are tagged aslitellm:<branch>andlitellm:<branch>-<short-sha>with git/build metadata build-args. The workflow does not deploy or sync ArgoCD; the summary step reminds operators to bumpvalues-litellm.yamland canary separately.Reviewed by Cursor Bugbot for commit 90c1873. Bugbot is set up for automated code reviews on this repo. Configure here.