Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
96 changes: 96 additions & 0 deletions .github/workflows/noma-build-custom-image.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
name: Noma - Build custom image

# Builds the Noma litellm proxy image and pushes it to ECR tagged with the
# branch name (e.g. v1.102.0-custom). Replaces the previous manual
# `docker buildx ... --push` step. Deploy is still a separate values bump +
# canary — this workflow only builds/pushes, it does NOT sync ArgoCD.

on:
push:
branches:
- "v*-custom" # v1.102.0-custom, v1.99.x-custom, ...
workflow_dispatch:
inputs:
ref:
description: "Branch/tag to build (defaults to the branch this is run from)"
required: false
type: string

concurrency:
group: noma-build-custom-${{ inputs.ref || github.ref_name }}
cancel-in-progress: false

permissions:
contents: read
id-token: write # OIDC -> AWS role

jobs:
build:
runs-on: arc-runners-prod
environment: prod
env:
AWS_REGION: us-east-1
AWS_ACCOUNT_ID: "381491951875"
IMAGE_NAME: litellm
steps:
- name: Checkout
uses: actions/checkout@v5

Check failure on line 37 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

unpinned-uses

noma-build-custom-image.yml:37: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
ref: ${{ inputs.ref || github.ref_name }}
fetch-depth: 0
persist-credentials: false

- name: Resolve image tag (branch/tag name)
id: tag
shell: bash
run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT"

Check failure on line 46 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

template-injection

noma-build-custom-image.yml:46: code injection via template expansion: may expand into attacker-controllable code

Check failure on line 46 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

template-injection

noma-build-custom-image.yml:46: code injection via template expansion: may expand into attacker-controllable code

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Untrusted ref interpolated into shell

Medium Severity

inputs.ref and github.ref_name are expanded directly inside run: scripts when resolving the image tag and writing the job summary. A crafted v*-custom branch name or workflow_dispatch ref can run arbitrary shell on the prod runner, including after AWS credentials exist.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 90c1873. Configure here.


- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4

Check failure on line 49 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

unpinned-uses

noma-build-custom-image.yml:49: unpinned action reference: action is not pinned to a hash (required by blanket policy)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Multi-arch build missing QEMU setup

High Severity

The job builds linux/amd64,linux/arm64 after only docker/setup-buildx-action, with no QEMU/binfmt registration. On typical amd64 arc-runners-prod hosts the arm64 stages in docker/Dockerfile.non_root cannot emulate, so docker buildx build --push fails and no image is published.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 90c1873. Configure here.


- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v6

Check failure on line 52 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

unpinned-uses

noma-build-custom-image.yml:52: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
role-to-assume: arn:aws:iam::381491951875:role/github-actions-region-deploy
aws-region: ${{ env.AWS_REGION }}

- name: Login to Amazon ECR
uses: docker/login-action@v4

Check failure on line 58 in .github/workflows/noma-build-custom-image.yml

View workflow job for this annotation

GitHub Actions / zizmor

unpinned-uses

noma-build-custom-image.yml:58: unpinned action reference: action is not pinned to a hash (required by blanket policy)
with:
registry: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com
username: AWS

- name: Build args
id: vars
shell: bash
run: |
echo "sha_short=$(git rev-parse --short HEAD)" >> "$GITHUB_OUTPUT"
echo "build_time=$(date '+%Y-%m-%dT%H:%M:%S')" >> "$GITHUB_OUTPUT"

- name: Build and push (multi-arch)
env:
REGISTRY: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com
TAG: ${{ steps.tag.outputs.value }}
SHA_SHORT: ${{ steps.vars.outputs.sha_short }}
BUILD_TIME: ${{ steps.vars.outputs.build_time }}
shell: bash
run: |
docker buildx build \
--push \
--platform linux/amd64,linux/arm64 \
--file docker/Dockerfile.non_root \
--tag "$REGISTRY/$IMAGE_NAME:$TAG" \
--tag "$REGISTRY/$IMAGE_NAME:$TAG-$SHA_SHORT" \
--build-arg GIT_VERSION_TAG="$TAG" \
--build-arg GIT_VERSION_HASH="$SHA_SHORT" \
--build-arg BUILD_TIME="$BUILD_TIME" \
--cache-from type=registry,ref="$REGISTRY/$IMAGE_NAME:cache-custom" \
--cache-to type=registry,mode=max,image-manifest=true,oci-mediatypes=true,ref="$REGISTRY/$IMAGE_NAME:cache-custom" \
.

- name: Summary
shell: bash
run: |
echo "### Pushed \`$IMAGE_NAME:${{ steps.tag.outputs.value }}\`" >> "$GITHUB_STEP_SUMMARY"
echo "Registry: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com" >> "$GITHUB_STEP_SUMMARY"
echo "Next: bump the tag in argo-cd/charts values-litellm.yaml and canary." >> "$GITHUB_STEP_SUMMARY"
Loading