Repository navigation
ci(nightly): nightly GHCR releases for SMG + vllm/sglang/trtllm engine images - #1600
Conversation
Signed-off-by: key4ng <rukeyang@gmail.com>
Signed-off-by: key4ng <rukeyang@gmail.com>
Signed-off-by: key4ng <rukeyang@gmail.com>
Signed-off-by: key4ng <rukeyang@gmail.com>
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughReusable engine-image build workflow now accepts newline-separated ChangesNightly Docker Build Workflows
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/nightly-engine-docker.yml:
- Around line 15-17: Move the broad "packages: write" permission out of the
workflow-level permissions block and instead add it to the build job that pushes
to GHCR; keep "contents: read" at workflow level, remove "packages: write" from
the top-level, and add a short inline comment in the build job (e.g., "needed to
push images to GHCR") to explain why that job requires packages write access;
ensure the prep job has no packages permission as it only computes suffixes.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 377a8565-e12f-48f1-a2d2-3562e114969a
📒 Files selected for processing (3)
.github/workflows/_build-engine-image.yml.github/workflows/nightly-docker.yml.github/workflows/nightly-engine-docker.yml
Signed-off-by: key4ng <rukeyang@gmail.com>
Description
Problem
SMG's nightly Docker story has two gaps:
nightly-docker.ymlpushes onlyghcr.io/lightseekorg/smg:nightly, overwriting it in place each run. There's no immutable counterpart, so users can only pin a specific night's build by raw@sha256:digest — there's no readable, reproducible tag. ("Which nightly hit this bug?" is unanswerable from a tag.)mainis never exercised against the engines on a schedule.(Verified the existing main-image nightly does build and push successfully — the issue is tag hygiene and missing engine coverage, not a broken build.)
Solution
_build-engine-image.ymlreusable workflow, extending it with one optional, backward-compatibleextra_tagsinput so a single build can push multiple GHCR tags from the same loaded image (default''= current behavior, release path untouched).nightly-engine-docker.ymlthat builds all three engine images nightly with SMG pinned to the run'smainHEAD.nightly-<date>-<sha7>tag for reproducible pinning, both from a single build.Changes
.github/workflows/_build-engine-image.yml— add optionalextra_tagsinput (newline-separated, default''); push each extra tag from the same locally-loaded image after the primary push; extend cleanup to remove them. No-op for existing release callers..github/workflows/nightly-engine-docker.yml(new) — 07:00 UTC (staggered 1h after the 06:00 main nightly) +workflow_dispatch. Aprepjob computes a shared<date>-<sha7>suffix; afail-fast: falsematrix over vllm/sglang/trtllm (latest pinned bases) calls the reusable workflow withsmg_commit: ${{ github.sha }}, an immutabletag, and a floatingextra_tags..github/workflows/nightly-docker.yml— compute the same<date>-<sha7>suffix in a shell step (works identically onscheduleandworkflow_dispatch, unlikemetadata-action'stype=schedule) and push:nightly+:nightly-<date>-<sha7>.Resulting tags per night (example date
20260604, SMGmainHEAD97534f2)All in the single
ghcr.io/lightseekorg/smgpackage; thenightly-prefix keeps them disjoint from released<ver>-<engine>-<ver>tags. The immutable engine tag mirrors the released format withnightly-<date>-<sha>standing in for the version field.Test Plan
Static validation (CI is YAML-only; no source touched):
actionlinton all three workflows — only pre-existing warnings remain (customcpu-e5runner label; the pervasive unquoted>> \$GITHUB_STEP_SUMMARYshellcheck info/style idiom). Newnightly-engine-docker.ymlis fully clean; the new heredoc step innightly-docker.ymlproduces no shellcheck output.extra_tagspush loop confirms the empty default is a true no-op and non-empty values push exactly once.$GITHUB_OUTPUTheredoc confirms a valid newline-separatedtagslist.release-{vllm,sglang,trtllm}-docker.ymldon't referenceextra_tags→ unaffected.Post-merge manual verification (needs runners + GHCR):
workflow_dispatchrelease-vllm-docker.yml(or a PR touchingdocker/engine.Dockerfile) → still builds/pushes only its single release tag (nonightly-*tags).workflow_dispatchnightly-engine-docker.yml→ each engine pushes both its floating and immutable tag (docker buildx imagetools inspect ...).workflow_dispatchnightly-docker.yml→:nightlyand:nightly-<date>-<sha7>both resolve.Checklist
cargo +nightly fmtpasses (N/A — no Rust changed)cargo clippy --all-targets --all-features -- -D warningspasses (N/A — no Rust changed)Summary by CodeRabbit
New Features
Chores