Publish ironclaw-worker image from Dockerfile.worker - #1979
Conversation
Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the same workflow. Both images share the same version/sha/tag scheme. This lets ironclaw-dind pull the pre-built worker image for sandbox baking instead of cloning the repo and building from source. [skip-regression-check]
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
There was a problem hiding this comment.
Pull request overview
Updates the Docker publishing workflow to also build and push a separate nearaidev/ironclaw-worker image from Dockerfile.worker, enabling consumers to pull a prebuilt worker image instead of building from source.
Changes:
- Add a second image name and generate parallel tag sets for the worker image.
- Build and push
ironclaw-workerfromDockerfile.workerwith an isolated GHA cache scope. - Expand the workflow summary to list tags for both images.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event_name == 'schedule' && 'staging' || '' }} | ||
|
|
There was a problem hiding this comment.
actions/checkout is given an empty ref for non-scheduled runs (... || ''). checkout expects a valid ref/SHA and an empty string can cause the step to fail. Use a non-empty fallback like github.ref/github.sha, or split into two checkout steps with if: github.event_name == 'schedule' and no ref override otherwise.
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ github.event_name == 'schedule' && 'staging' || '' }} | |
| - name: Checkout (scheduled staging build) | |
| if: github.event_name == 'schedule' | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: staging | |
| - name: Checkout | |
| if: github.event_name != 'schedule' | |
| uses: actions/checkout@v4 |
| @@ -45,22 +51,35 @@ jobs: | |||
| run: | | |||
| VERSION="${{ steps.version.outputs.version }}" | |||
| SHA="sha-${GITHUB_SHA::7}" | |||
There was a problem hiding this comment.
On schedule runs you checkout the staging branch, but SHA="sha-${GITHUB_SHA::7}" will still be the scheduled event SHA (default branch), not the checked-out staging commit. This will push misleading sha-... tags and also break any downstream logic that assumes the sha tag matches the built contents. Derive the SHA from the checked-out workspace (e.g., git rev-parse --short HEAD) for tagging (and for sha_tag).
| SHA="sha-${GITHUB_SHA::7}" | |
| SHORT_SHA="$(git rev-parse --short HEAD)" | |
| SHA="sha-${SHORT_SHA}" |
* feat(docker): publish ironclaw-worker image alongside ironclaw Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the same workflow. Both images share the same version/sha/tag scheme. This lets ironclaw-dind pull the pre-built worker image for sandbox baking instead of cloning the repo and building from source. [skip-regression-check] * feat(docker): daily scheduled build of :staging from staging branch * perf(docker): worker image copies binary from ironclaw image instead of rebuilding * revert Dockerfile.worker changes, keep it building from source
* feat(docker): publish ironclaw-worker image alongside ironclaw Build and push nearaidev/ironclaw-worker from Dockerfile.worker in the same workflow. Both images share the same version/sha/tag scheme. This lets ironclaw-dind pull the pre-built worker image for sandbox baking instead of cloning the repo and building from source. [skip-regression-check] * feat(docker): daily scheduled build of :staging from staging branch * perf(docker): worker image copies binary from ironclaw image instead of rebuilding * revert Dockerfile.worker changes, keep it building from source
Summary
nearaidev/ironclaw-workerfromDockerfile.workerin the same Docker workflow:version,:latest,:sha-xxx, and manual override tagsworker) to avoid cache collisions with the main imageThis lets
ironclaw-dindpullnearaidev/ironclaw-worker:latestfor sandbox baking instead of cloning the repo and building from source each time.Test plan
nearaidev/ironclaw-workertags appear on Docker Hubironclaw-dindbake step can pull the worker image