Skip to content

Publish ironclaw-worker image from Dockerfile.worker - #1979

Merged
Evrard-Nil merged 4 commits into
stagingfrom
feat/publish-worker-image
Apr 3, 2026
Merged

Evrard-Nil merged 4 commits into
stagingfrom
feat/publish-worker-image

Conversation

@Evrard-Nil

Copy link
Copy Markdown
Contributor

Summary

  • Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the same Docker workflow
  • Both images share the same tag scheme: :version, :latest, :sha-xxx, and manual override tags
  • Separate GHA cache scope (worker) to avoid cache collisions with the main image

This lets ironclaw-dind pull nearaidev/ironclaw-worker:latest for sandbox baking instead of cloning the repo and building from source each time.

Test plan

  • Run workflow_dispatch with a tag override — both images should be pushed
  • Verify nearaidev/ironclaw-worker tags appear on Docker Hub
  • Verify ironclaw-dind bake step can pull the worker image

Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the
same workflow. Both images share the same version/sha/tag scheme.

This lets ironclaw-dind pull the pre-built worker image for sandbox
baking instead of cloning the repo and building from source.

[skip-regression-check]
Copilot AI review requested due to automatic review settings April 3, 2026 18:13
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@github-actions github-actions Bot added scope: ci CI/CD workflows size: S 10-49 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: regular 2-5 merged PRs labels Apr 3, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Docker publishing workflow to also build and push a separate nearaidev/ironclaw-worker image from Dockerfile.worker, enabling consumers to pull a prebuilt worker image instead of building from source.

Changes:

  • Add a second image name and generate parallel tag sets for the worker image.
  • Build and push ironclaw-worker from Dockerfile.worker with an isolated GHA cache scope.
  • Expand the workflow summary to list tags for both images.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/docker.yml
Comment thread .github/workflows/docker.yml
@Evrard-Nil
Evrard-Nil requested a review from henrypark133 April 3, 2026 18:21
henrypark133
henrypark133 previously approved these changes Apr 3, 2026
Copilot AI review requested due to automatic review settings April 3, 2026 18:23
@github-actions github-actions Bot added scope: sandbox Docker sandbox size: M 50-199 changed lines and removed size: S 10-49 changed lines labels Apr 3, 2026
@github-actions github-actions Bot added size: S 10-49 changed lines and removed size: M 50-199 changed lines labels Apr 3, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 37 to 41
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'schedule' && 'staging' || '' }}

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actions/checkout is given an empty ref for non-scheduled runs (... || ''). checkout expects a valid ref/SHA and an empty string can cause the step to fail. Use a non-empty fallback like github.ref/github.sha, or split into two checkout steps with if: github.event_name == 'schedule' and no ref override otherwise.

Suggested change
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'schedule' && 'staging' || '' }}
- name: Checkout (scheduled staging build)
if: github.event_name == 'schedule'
uses: actions/checkout@v4
with:
ref: staging
- name: Checkout
if: github.event_name != 'schedule'
uses: actions/checkout@v4

Copilot uses AI. Check for mistakes.
@@ -45,22 +51,35 @@ jobs:
run: |
VERSION="${{ steps.version.outputs.version }}"
SHA="sha-${GITHUB_SHA::7}"

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On schedule runs you checkout the staging branch, but SHA="sha-${GITHUB_SHA::7}" will still be the scheduled event SHA (default branch), not the checked-out staging commit. This will push misleading sha-... tags and also break any downstream logic that assumes the sha tag matches the built contents. Derive the SHA from the checked-out workspace (e.g., git rev-parse --short HEAD) for tagging (and for sha_tag).

Suggested change
SHA="sha-${GITHUB_SHA::7}"
SHORT_SHA="$(git rev-parse --short HEAD)"
SHA="sha-${SHORT_SHA}"

Copilot uses AI. Check for mistakes.
This was referenced Apr 5, 2026
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
* feat(docker): publish ironclaw-worker image alongside ironclaw

Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the
same workflow. Both images share the same version/sha/tag scheme.

This lets ironclaw-dind pull the pre-built worker image for sandbox
baking instead of cloning the repo and building from source.

[skip-regression-check]

* feat(docker): daily scheduled build of :staging from staging branch

* perf(docker): worker image copies binary from ironclaw image instead of rebuilding

* revert Dockerfile.worker changes, keep it building from source
@ironclaw-ci ironclaw-ci Bot mentioned this pull request Apr 10, 2026
@ironclaw-ci ironclaw-ci Bot mentioned this pull request Apr 18, 2026
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
* feat(docker): publish ironclaw-worker image alongside ironclaw

Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the
same workflow. Both images share the same version/sha/tag scheme.

This lets ironclaw-dind pull the pre-built worker image for sandbox
baking instead of cloning the repo and building from source.

[skip-regression-check]

* feat(docker): daily scheduled build of :staging from staging branch

* perf(docker): worker image copies binary from ironclaw image instead of rebuilding

* revert Dockerfile.worker changes, keep it building from source
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: regular 2-5 merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: sandbox Docker sandbox size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants