Skip to content

ci: add workflow to build the Noma litellm custom image - #18

Merged
omerbd21-noma merged 1 commit into
mainfrom
ci/noma-build-custom-image
Sep 24, 2026
Merged

omerbd21-noma merged 1 commit into
mainfrom
ci/noma-build-custom-image

Conversation

@omerbd21-noma

@omerbd21-noma omerbd21-noma commented Sep 24, 2026 •

Copy link
Copy Markdown

What

Adds .github/workflows/noma-build-custom-image.yml to automate building the Noma litellm proxy image, replacing the current manual docker buildx … --push step (no CI builds it today — verified: no ECR-push workflow in this fork, and github-actions/build-and-publish isn't wired to litellm).

  • Trigger: push to v*-custom branches (e.g. v1.102.0-custom) + manual workflow_dispatch.
  • Build: docker/Dockerfile.non_root, multi-arch linux/amd64,linux/arm64, registry build cache.
  • Tags: litellm:<branch> (e.g. v1.102.0-custom) + litellm:<branch>-<sha> for traceability.
  • Auth: arc-runners-prod + OIDC → role/github-actions-region-deploy (the 381491951875 ECR account) — same pattern as github-actions/.github/workflows/run-e2e-tenant-test.yml.
  • Scope: build + push only. No ArgoCD sync — deploy stays a values bump in argo-cd/charts + canary.

Chose a dedicated ~90-line workflow over the shared build-and-publish action because that action hardcodes :latest+:<sha> tags and auto-syncs ArgoCD dev — wrong for a prod-line -custom image.

⚠️ Prereqs for DevOps before the first run (org settings, can't be set from this repo)

  1. Runner access — allow Noma-Security/litellm to use arc-runners-prod.
  2. OIDC trust — github-actions-region-deploy trust policy must permit repo:Noma-Security/litellm:* (currently scoped to other repos).
  3. ECR push perms — that role needs ecr:PutImage / layer-upload on the litellm repo (it's a region-deploy role today). A dedicated build role is fine too — update the role-to-assume in the workflow if so.
  4. environment: prod approval gate applies (expected).

Until 1–3 are in place the workflow will fail at the AWS/ECR step. Happy to adjust the role ARN or runner label once DevOps confirms.

Tuning note

Builds both amd64 + arm64 (litellm has no arch pin in values, so pods can land on either). If the litellm nodepools are amd64-only, drop arm64 to halve build time.

🤖 Generated with Claude Code


Note

Low Risk
CI-only change that pushes container images to ECR; no application runtime or auth logic in the repo is modified, though org-level runner/OIDC/ECR setup must be correct before first use.

Overview
Adds a new GitHub Actions workflow Noma - Build custom image that automates building and pushing the Noma litellm proxy image to ECR, replacing manual docker buildx … --push.

It runs on pushes to v*-custom branches and on workflow_dispatch (optional ref), uses arc-runners-prod with environment: prod, authenticates to AWS via OIDC (github-actions-region-deploy), and builds from docker/Dockerfile.non_root for linux/amd64 and linux/arm64 with registry cache. Images are tagged as litellm:<branch> and litellm:<branch>-<short-sha> with git/build metadata build-args. The workflow does not deploy or sync ArgoCD; the summary step reminds operators to bump values-litellm.yaml and canary separately.

Reviewed by Cursor Bugbot for commit 90c1873. Bugbot is set up for automated code reviews on this repo. Configure here.

Automates the previously-manual `docker buildx --push` of the -custom image.
Triggers on push to v*-custom branches + workflow_dispatch; builds
docker/Dockerfile.non_root multi-arch and pushes to ECR tagged with the
branch name (e.g. v1.102.0-custom) + a -<sha> variant. Build-only; deploy
stays a values bump + canary (no ArgoCD sync).

Prereqs for DevOps before first run: fork access to arc-runners-prod;
OIDC trust on role/github-actions-region-deploy for repo Noma-Security/litellm;
ecr:PutImage on the litellm repo for that role (or a dedicated build role).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@omerbd21-noma
omerbd21-noma merged commit ad59de5 into main Sep 24, 2026
44 of 58 checks passed
run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
uses: docker/setup-buildx-action@v4

- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v6
aws-region: ${{ env.AWS_REGION }}

- name: Login to Amazon ECR
uses: docker/login-action@v4

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 90c1873. Configure here.

run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Multi-arch build missing QEMU setup

High Severity

The job builds linux/amd64,linux/arm64 after only docker/setup-buildx-action, with no QEMU/binfmt registration. On typical amd64 arc-runners-prod hosts the arm64 stages in docker/Dockerfile.non_root cannot emulate, so docker buildx build --push fails and no image is published.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 90c1873. Configure here.

- name: Resolve image tag (branch/tag name)
id: tag
shell: bash
run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Untrusted ref interpolated into shell

Medium Severity

inputs.ref and github.ref_name are expanded directly inside run: scripts when resolving the image tag and writing the job summary. A crafted v*-custom branch name or workflow_dispatch ref can run arbitrary shell on the prod runner, including after AWS credentials exist.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 90c1873. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants