Repository navigation
ci: add workflow to build the Noma litellm custom image #18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,96 @@ | ||
| name: Noma - Build custom image | ||
|
|
||
| # Builds the Noma litellm proxy image and pushes it to ECR tagged with the | ||
| # branch name (e.g. v1.102.0-custom). Replaces the previous manual | ||
| # `docker buildx ... --push` step. Deploy is still a separate values bump + | ||
| # canary — this workflow only builds/pushes, it does NOT sync ArgoCD. | ||
|
|
||
| on: | ||
| push: | ||
| branches: | ||
| - "v*-custom" # v1.102.0-custom, v1.99.x-custom, ... | ||
| workflow_dispatch: | ||
| inputs: | ||
| ref: | ||
| description: "Branch/tag to build (defaults to the branch this is run from)" | ||
| required: false | ||
| type: string | ||
|
|
||
| concurrency: | ||
| group: noma-build-custom-${{ inputs.ref || github.ref_name }} | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
| id-token: write # OIDC -> AWS role | ||
|
|
||
| jobs: | ||
| build: | ||
| runs-on: arc-runners-prod | ||
| environment: prod | ||
| env: | ||
| AWS_REGION: us-east-1 | ||
| AWS_ACCOUNT_ID: "381491951875" | ||
| IMAGE_NAME: litellm | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v5 | ||
| with: | ||
| ref: ${{ inputs.ref || github.ref_name }} | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
|
|
||
| - name: Resolve image tag (branch/tag name) | ||
| id: tag | ||
| shell: bash | ||
| run: echo "value=${{ inputs.ref || github.ref_name }}" >> "$GITHUB_OUTPUT" | ||
|
Check failure on line 46 in .github/workflows/noma-build-custom-image.yml
|
||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v4 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Multi-arch build missing QEMU setupHigh Severity The job builds Additional Locations (1)Reviewed by Cursor Bugbot for commit 90c1873. Configure here. |
||
|
|
||
| - name: Configure AWS credentials (OIDC) | ||
| uses: aws-actions/configure-aws-credentials@v6 | ||
|
|
||
| with: | ||
| role-to-assume: arn:aws:iam::381491951875:role/github-actions-region-deploy | ||
| aws-region: ${{ env.AWS_REGION }} | ||
|
|
||
| - name: Login to Amazon ECR | ||
| uses: docker/login-action@v4 | ||
|
|
||
| with: | ||
| registry: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com | ||
| username: AWS | ||
|
|
||
| - name: Build args | ||
| id: vars | ||
| shell: bash | ||
| run: | | ||
| echo "sha_short=$(git rev-parse --short HEAD)" >> "$GITHUB_OUTPUT" | ||
| echo "build_time=$(date '+%Y-%m-%dT%H:%M:%S')" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Build and push (multi-arch) | ||
| env: | ||
| REGISTRY: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com | ||
| TAG: ${{ steps.tag.outputs.value }} | ||
| SHA_SHORT: ${{ steps.vars.outputs.sha_short }} | ||
| BUILD_TIME: ${{ steps.vars.outputs.build_time }} | ||
| shell: bash | ||
| run: | | ||
| docker buildx build \ | ||
| --push \ | ||
| --platform linux/amd64,linux/arm64 \ | ||
| --file docker/Dockerfile.non_root \ | ||
| --tag "$REGISTRY/$IMAGE_NAME:$TAG" \ | ||
| --tag "$REGISTRY/$IMAGE_NAME:$TAG-$SHA_SHORT" \ | ||
| --build-arg GIT_VERSION_TAG="$TAG" \ | ||
| --build-arg GIT_VERSION_HASH="$SHA_SHORT" \ | ||
| --build-arg BUILD_TIME="$BUILD_TIME" \ | ||
| --cache-from type=registry,ref="$REGISTRY/$IMAGE_NAME:cache-custom" \ | ||
| --cache-to type=registry,mode=max,image-manifest=true,oci-mediatypes=true,ref="$REGISTRY/$IMAGE_NAME:cache-custom" \ | ||
| . | ||
|
|
||
| - name: Summary | ||
| shell: bash | ||
| run: | | ||
| echo "### Pushed \`$IMAGE_NAME:${{ steps.tag.outputs.value }}\`" >> "$GITHUB_STEP_SUMMARY" | ||
| echo "Registry: ${{ env.AWS_ACCOUNT_ID }}.dkr.ecr.${{ env.AWS_REGION }}.amazonaws.com" >> "$GITHUB_STEP_SUMMARY" | ||
| echo "Next: bump the tag in argo-cd/charts values-litellm.yaml and canary." >> "$GITHUB_STEP_SUMMARY" | ||


There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Untrusted ref interpolated into shell
Medium Severity
inputs.refandgithub.ref_nameare expanded directly insiderun:scripts when resolving the image tag and writing the job summary. A craftedv*-custombranch name orworkflow_dispatchrefcan run arbitrary shell on the prod runner, including after AWS credentials exist.Additional Locations (1)
.github/workflows/noma-build-custom-image.yml#L93-L94Reviewed by Cursor Bugbot for commit 90c1873. Configure here.