Skip to content

ci(nightly): nightly GHCR releases for SMG + vllm/sglang/trtllm engine images - #1600

Merged
key4ng merged 5 commits into
mainfrom
ci/nightly-ghcr-release
Jun 5, 2026
Merged

key4ng merged 5 commits into
mainfrom
ci/nightly-ghcr-release

Conversation

@key4ng

@key4ng key4ng commented Jun 4, 2026 •

Copy link
Copy Markdown
Member

Description

Problem

SMG's nightly Docker story has two gaps:

  1. The main-image nightly uses a single mutable tag. nightly-docker.yml pushes only ghcr.io/lightseekorg/smg:nightly, overwriting it in place each run. There's no immutable counterpart, so users can only pin a specific night's build by raw @sha256: digest — there's no readable, reproducible tag. ("Which nightly hit this bug?" is unanswerable from a tag.)
  2. The gRPC engine images (vllm/sglang/trtllm) have no nightly at all. They only build on version-bump push, PR (dry-run), or manual dispatch, so the latest SMG main is never exercised against the engines on a schedule.

(Verified the existing main-image nightly does build and push successfully — the issue is tag hygiene and missing engine coverage, not a broken build.)

Solution

  • Reuse the existing _build-engine-image.yml reusable workflow, extending it with one optional, backward-compatible extra_tags input so a single build can push multiple GHCR tags from the same loaded image (default '' = current behavior, release path untouched).
  • Add a new scheduled nightly-engine-docker.yml that builds all three engine images nightly with SMG pinned to the run's main HEAD.
  • Give every nightly artifact (main + engines) a floating tag for convenience and an immutable nightly-<date>-<sha7> tag for reproducible pinning, both from a single build.

Changes

  • .github/workflows/_build-engine-image.yml — add optional extra_tags input (newline-separated, default ''); push each extra tag from the same locally-loaded image after the primary push; extend cleanup to remove them. No-op for existing release callers.
  • .github/workflows/nightly-engine-docker.yml (new) — 07:00 UTC (staggered 1h after the 06:00 main nightly) + workflow_dispatch. A prep job computes a shared <date>-<sha7> suffix; a fail-fast: false matrix over vllm/sglang/trtllm (latest pinned bases) calls the reusable workflow with smg_commit: ${{ github.sha }}, an immutable tag, and a floating extra_tags.
  • .github/workflows/nightly-docker.yml — compute the same <date>-<sha7> suffix in a shell step (works identically on schedule and workflow_dispatch, unlike metadata-action's type=schedule) and push :nightly + :nightly-<date>-<sha7>.

Resulting tags per night (example date 20260604, SMG main HEAD 97534f2)

smg:nightly                                       (main, floating)
smg:nightly-20260604-97534f2                      (main, immutable)
smg:nightly-vllm                                  (vllm, floating)
smg:nightly-20260604-97534f2-vllm-v0.19.0         (vllm, immutable)
smg:nightly-sglang                                (sglang, floating)
smg:nightly-20260604-97534f2-sglang-v0.5.10       (sglang, immutable)
smg:nightly-trtllm                                (trtllm, floating)
smg:nightly-20260604-97534f2-trtllm-1.3.0rc10     (trtllm, immutable)

All in the single ghcr.io/lightseekorg/smg package; the nightly- prefix keeps them disjoint from released <ver>-<engine>-<ver> tags. The immutable engine tag mirrors the released format with nightly-<date>-<sha> standing in for the version field.

Test Plan

Static validation (CI is YAML-only; no source touched):

  • actionlint on all three workflows — only pre-existing warnings remain (custom cpu-e5 runner label; the pervasive unquoted >> \$GITHUB_STEP_SUMMARY shellcheck info/style idiom). New nightly-engine-docker.yml is fully clean; the new heredoc step in nightly-docker.yml produces no shellcheck output.
  • PyYAML parse of all three — OK.
  • Local bash simulation of the extra_tags push loop confirms the empty default is a true no-op and non-empty values push exactly once.
  • Local simulation of the $GITHUB_OUTPUT heredoc confirms a valid newline-separated tags list.
  • Confirmed release-{vllm,sglang,trtllm}-docker.yml don't reference extra_tags → unaffected.

Post-merge manual verification (needs runners + GHCR):

  • workflow_dispatch release-vllm-docker.yml (or a PR touching docker/engine.Dockerfile) → still builds/pushes only its single release tag (no nightly-* tags).
  • workflow_dispatch nightly-engine-docker.yml → each engine pushes both its floating and immutable tag (docker buildx imagetools inspect ...).
  • workflow_dispatch nightly-docker.yml → :nightly and :nightly-<date>-<sha7> both resolve.
  • Pin check: an immutable tag's digest is unchanged across nightly runs, while the floating tags move.

Operational follow-up (not in this PR): confirm the ghcr.io/lightseekorg/smg package visibility is public if external users are expected to pull nightlies.

Checklist
  • cargo +nightly fmt passes (N/A — no Rust changed)
  • cargo clippy --all-targets --all-features -- -D warnings passes (N/A — no Rust changed)
  • (Optional) Documentation updated
  • (Optional) Please join us on Slack #sig-smg to discuss, review, and merge PRs

Summary by CodeRabbit

  • New Features

    • Nightly Docker images now include date-stamped and short-commit tags alongside static nightly tags for clearer versioning.
    • Added scheduled nightly builds across multiple engine targets with per-engine floating and detailed nightly tags.
  • Chores

    • Enhanced image build/push process to support pushing multiple additional registry tags and clean them up locally.
    • Build workflow now outputs computed tag lists for use by downstream steps.

@github-actions github-actions Bot added the ci CI/CD configuration changes label Jun 4, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Jun 4, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: c954657a-de78-49d9-91a4-11df5ec64479

📥 Commits

Reviewing files that changed from the base of the PR and between 8536ff9 and 224a107.

📒 Files selected for processing (1)
  • .github/workflows/nightly-engine-docker.yml

📝 Walkthrough

Walkthrough

Reusable engine-image build workflow now accepts newline-separated extra_tags and pushes them to GHCR. The nightly Docker workflow computes multiple tags (static nightly and date+SHA variants). A new nightly-engine workflow builds multiple engine images (matrix) and calls the reusable workflow with per-engine nightly and floating extra tags.

Changes

Nightly Docker Build Workflows

Layer / File(s) Summary
Reusable engine image build workflow with extra tags support
.github/workflows/_build-engine-image.yml
Added optional extra_tags input (newline-separated), updated GHCR push to iterate over inputs.extra_tags and push additional ghcr.io/<owner>/smg:<extra> images, and extended cleanup to remove those extra-tagged images locally.
Dynamic tag computation in nightly Docker workflow
.github/workflows/nightly-docker.yml
Replaced hardcoded nightly tag with a step that computes UTC date + short SHA suffixed tags, emits them as a multiline tags output, and wires that output into the docker/build-push-action tags input.
Nightly engine build orchestrator workflow
.github/workflows/nightly-engine-docker.yml
New workflow (cron + manual) that computes YYYYMMDD-<7charSHA> suffix, runs a matrix across engine targets (vLLM, SGLang, TRT-LLM), computes per-engine nightly tags and a floating per-engine nightly tag, and calls the reusable _build-engine-image.yml workflow with those tags (build job uses packages: write).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • lightseekorg/smg#658: Modifications to the reusable workflow _build-engine-image.yml related to tag generation and pushing.
  • lightseekorg/smg#507: Prior changes to .github/workflows/nightly-docker.yml that introduced nightly tagging behavior.

Suggested labels

docker

Suggested reviewers

  • CatherineSue
  • slin1237
  • XinyueZhang369

Poem

🐰 I hop at midnight through the repo glade,
Tags in my paws, a nightly trade.
Engines three, a dated stride,
Extra flags hop at my side.
CI hums softly — the warren's made.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main changes: introducing nightly GHCR releases for the SMG image and three engine images (vllm, sglang, trtllm), which directly aligns with the primary objectives of the PR.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/nightly-ghcr-release

Comment @coderabbitai help to get the list of available commands and usage tips.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean CI-only PR. The extra_tags input is backward-compatible (empty default = no-op for existing callers), shell quoting is correct throughout, and the nightly engine workflow is well-structured. No issues found.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/nightly-engine-docker.yml:
- Around line 15-17: Move the broad "packages: write" permission out of the
workflow-level permissions block and instead add it to the build job that pushes
to GHCR; keep "contents: read" at workflow level, remove "packages: write" from
the top-level, and add a short inline comment in the build job (e.g., "needed to
push images to GHCR") to explain why that job requires packages write access;
ensure the prep job has no packages permission as it only computes suffixes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 377a8565-e12f-48f1-a2d2-3562e114969a

📥 Commits

Reviewing files that changed from the base of the PR and between f21917b and 8536ff9.

📒 Files selected for processing (3)
  • .github/workflows/_build-engine-image.yml
  • .github/workflows/nightly-docker.yml
  • .github/workflows/nightly-engine-docker.yml

Comment thread .github/workflows/nightly-engine-docker.yml Outdated
Signed-off-by: key4ng <rukeyang@gmail.com>
@key4ng
key4ng merged commit 82e4901 into main Jun 5, 2026
35 checks passed
@key4ng
key4ng deleted the ci/nightly-ghcr-release branch June 5, 2026 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant