Skip to content

ci(release): restore regular Docker image publishing - #6701

Merged
think-in-universe merged 2 commits into
mainfrom
codex/issue-6635-restore-release-docker
Aug 3, 2026
Merged

think-in-universe merged 2 commits into
mainfrom
codex/issue-6635-restore-release-docker

Conversation

@hanakannzashi

Copy link
Copy Markdown
Contributor

Summary

  • Restore the regular nearaidev/ironclaw Docker publish job after cargo-dist successfully creates the GitHub Release.
  • Publish the existing version, latest, and source-SHA tags while explicitly excluding ironclaw-worker and the separate ironclaw-dind release path.
  • Narrow the reusable workflow's release credentials to the Docker Hub token, document failure/rollback semantics, and update the release smoke contract.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Closes #6635

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings — used the narrower owning-crate all-targets/all-features command below
  • cargo build — covered by the targeted smoke test build
  • Relevant tests pass: release_ci_ smoke contract (2 passed)
  • cargo test --features integration if database-backed or integration behavior changed — not applicable; no database or runtime behavior changed
  • Manual testing: no real release tag was pushed from this branch because it would publish external artifacts
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Test Strategy

User behavior: Pushing a matching Reborn release tag creates the cargo-dist GitHub Release first, then publishes the regular IronClaw Docker image with version/latest/SHA tags. The release caller does not dispatch DIND.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: Updated release_ci_publishes_reborn_and_regular_docker_without_legacy_or_dind_paths in the CLI smoke suite.
  • Reborn integration: Not applicable: this is a GitHub Actions DAG and credential contract, not Reborn runtime behavior.
  • Recorded fixture: Not applicable: no model behavior changed.
  • Browser E2E: Not applicable: no UI behavior changed.
  • Backend or runtime: Not applicable: the existing Dockerfile/runtime image is unchanged.
  • Live canary: Not applicable: a live release would publish external GitHub and Docker Hub artifacts.

What the tests prove: The Docker caller depends on successful release hosting, requests only the required permissions, passes only the Docker Hub token, sets release: true and trigger_dind: false, retains version/latest/SHA tagging and source-SHA summaries, and does not restore worker artifacts. Both DIND steps consume the explicit gate.

Commands run:

cargo +1.96.0 fmt --all -- --check
cargo +1.96.0 test -p ironclaw --test smoke release_ci_ -- --nocapture
cargo +1.96.0 clippy -p ironclaw --all-targets --all-features -- -D warnings
go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 \
  .github/workflows/ironclaw-release.yml \
  .github/workflows/docker.yml
RUSTUP_TOOLCHAIN=1.96.0 scripts/pre-commit-safety.sh

Security Impact

The release Docker job can publish to Docker Hub. It receives contents: read, packages: read, and actions: write for checkout/cache behavior plus an explicitly mapped DOCKER_REGISTRY_TOKEN. It no longer uses secrets: inherit, so the DIND GitHub App credentials are not exposed to the release caller. trigger_dind: false prevents the tag release path from dispatching the separate DIND repository workflow.

Reborn Trust-Boundary Checklist

N/A — this is CI credential and release-DAG wiring only. It does not change Reborn policy/evidence types, prompt content, hashing, runtime/error variants, serialization, queues, driver errors, or sandbox/native/host naming.

Database Impact

None.

Blast Radius

Touches matching tag releases and the reusable Docker workflow interface. Direct manual and hourly scheduled Docker runs preserve their existing DIND behavior. Docker now runs only after GitHub Release hosting succeeds; if Docker publishing fails, the already-created GitHub Release remains available while the overall workflow reports failure.

Rollback Plan

Revert this commit to return Docker publishing to independent manual/hourly runs. Existing GitHub Releases and already-published Docker tags remain intact. A failed regular image publish can also be retried through the Docker workflow without rebuilding the GitHub Release.

Review Follow-Through

No known code follow-up. The first credentialed release run should confirm the repository's Docker Hub variable/secret configuration and provides the final external publish proof.


Review track: C (security/runtime/DB/CI)

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ironloopai

ironloopai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 4a6c30226e11beb9cfce2db545f1d252a9932b93
Result: 1/1 reviewers completed without blocking findings.
Next: Ready for normal human review and CI checks.
Updated: 2026-07-27T10:47:35.150Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Approved 0 blocking findings / 0 notes 2026-07-27T10:47:35.141Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Approved; 0 blocking findings; Approved: the small CI-only change correctly invokes the Docker reusable workflow after GitHub Release creation, passes only the Docker Hub secret, and disables the DIND dispatch …
Recent activity
Time Reviewer State Detail
2026-07-27T10:44:06.296Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head 4a6c302.
2026-07-27T10:44:06.296Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-27T10:44:06.539Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-27T10:44:10.205Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 7cb3aa9.
2026-07-27T10:47:35.141Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-27T10:47:35.141Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6701 July 27, 2026 10:44 Destroyed
@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: S 10-49 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 27, 2026
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Release workflows now publish the regular Docker image automatically after creating a GitHub Release.
    • Docker publishing can control whether the DIND image workflow is triggered.
    • Manual and scheduled staging workflows retain their existing DIND behavior.
  • Documentation

    • Updated release, CI, failure-mode, retry, and Docker publishing guidance.
    • Clarified release image targets and publishing timing.
  • Tests

    • Expanded CI checks to validate Docker publishing and workflow input behavior.

Walkthrough

The release workflow now publishes the regular nearaidev/ironclaw Docker image after GitHub Release creation, with trigger_dind: false. The reusable Docker workflow adds explicit DIND controls. Documentation and smoke tests validate the updated CI contract.

Changes

Release Docker publishing

Layer / File(s) Summary
DIND dispatch control
.github/workflows/docker.yml
Adds trigger_dind controls for reusable and manual workflow calls, gating DIND token creation and dispatch.
Release image integration
.github/workflows/ironclaw-release.yml, .github/workflows/README.md
Adds post-release regular Docker publishing with DIND disabled and documents the release DAG, secret handling, and failure behavior.
Workflow contract validation
crates/ironclaw_reborn_cli/tests/smoke.rs
Validates the docker-image job and Docker workflow inputs, tags, scheduling, skip conditions, and DIND gating.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubRelease
  participant docker-image
  participant docker.yml
  participant DockerRegistry
  GitHubRelease->>docker-image: host creates release successfully
  docker-image->>docker.yml: invoke release build with trigger_dind=false
  docker.yml->>DockerRegistry: publish version, latest, and SHA tags
Loading

Possibly related PRs

Suggested reviewers: ilblackdragon, serrrfirat

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and clearly describes restoring regular Docker image publishing.
Description check ✅ Passed The description includes all required sections, explains the CI and security changes, and records targeted validation and rollback details.
Linked Issues check ✅ Passed The changes satisfy issue #6635 by restoring release Docker publishing, preserving release tags, excluding DIND, and documenting credentials and failure behavior.
Out of Scope Changes check ✅ Passed The workflow interface, documentation, smoke tests, and explicit DIND gate support the linked issue and do not introduce unrelated changes.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 4a6c30226e11

Head: 4a6c30226e11beb9cfce2db545f1d252a9932b93
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Approved: the small CI-only change correctly invokes the Docker reusable workflow after GitHub Release creation, passes only the Docker Hub secret, and disables the DIND dispatch for tag releases.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.53% (307467 / 359484 lines)
  floor:    80.81% (tolerance 0.5pp -> effective floor 80.31%)
  denominator: 359484 lines now vs 377084 at floor capture (-17600 lines, -4.67%) — not a material change

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.53% — 307467 / 359484 lines

Per-crate breakdown (60 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_process_sandbox 33.91% 118 / 348
ironclaw_host_ingress 42.5% 17 / 40
ironclaw_event_projections 43.71% 684 / 1565
ironclaw_observability 61.54% 16 / 26
ironclaw_telegram_v2_adapter 62.35% 631 / 1012
ironclaw_authorization 62.98% 609 / 967
ironclaw_memory 70.15% 919 / 1310
ironclaw_trust 73.21% 664 / 907
ironclaw_filesystem 73.65% 4584 / 6224
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 75.45% 2879 / 3816
ironclaw_mcp 76.2% 775 / 1017
ironclaw_projects 76.48% 400 / 523
ironclaw_reborn_cli 78.19% 10670 / 13647
ironclaw_telegram_extension 78.59% 962 / 1224
ironclaw_llm 79.2% 21307 / 26902
ironclaw_wasm 79.72% 735 / 922
ironclaw_memory_native 80.97% 3114 / 3846
ironclaw_auth 81.88% 6679 / 8157
ironclaw_first_party_extensions 82.38% 6682 / 8111
ironclaw_events 82.47% 1604 / 1945
ironclaw_host_api 82.65% 9120 / 11035
ironclaw_processes 83.3% 933 / 1120
ironclaw_reborn_identity 83.8% 450 / 537
ironclaw_operator 84.37% 5558 / 6588
ironclaw_secrets 84.56% 2798 / 3309
ironclaw_reborn_config 85.24% 2102 / 2466
ironclaw_skills 85.29% 4494 / 5269
ironclaw_extension_host 85.39% 18814 / 22032
ironclaw_reborn_composition 85.67% 24387 / 28465
ironclaw_run_state 85.77% 458 / 534
ironclaw_webui 85.87% 10914 / 12710
ironclaw_triggers 85.92% 2783 / 3239
ironclaw_network 85.97% 913 / 1062
ironclaw_reborn_event_store 86.51% 1251 / 1446
ironclaw_hooks 86.63% 9931 / 11464
ironclaw_extensions 86.98% 3669 / 4218
ironclaw_common 86.99% 1772 / 2037
ironclaw_approvals 87.18% 1543 / 1770
ironclaw_threads 87.2% 4851 / 5563
ironclaw_product 87.52% 19698 / 22507
ironclaw_reborn_traces 88.13% 11986 / 13600
ironclaw_turns 88.33% 14317 / 16208
ironclaw_slack_extension 88.47% 1934 / 2186
ironclaw_host_runtime 88.49% 18983 / 21451
ironclaw_reborn_openai_compat 89.32% 3780 / 4232
ironclaw_conversations 90.01% 3164 / 3515
ironclaw_resources 90.84% 4474 / 4925
ironclaw_runner 90.87% 17192 / 18920
ironclaw_event_streams 91.24% 1063 / 1165
ironclaw_loop_host 91.9% 16503 / 17958
ironclaw_attachments 93.06% 630 / 677
ironclaw_outbound 93.91% 4101 / 4367
ironclaw_agent_loop 94.94% 9924 / 10453
ironclaw_safety 95.28% 3858 / 4049
ironclaw_first_party_extension_ports 95.62% 3672 / 3840
ironclaw_runtime_policy 96.56% 813 / 842

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@railway-app

railway-app Bot commented Jul 27, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6701 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 27, 2026 at 10:55 am

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/README.md (1)

215-222: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Clarify reusable workflow secret forwarding.

.github/workflows/docker.yml declares DIND app credentials optional, but the README says any secrets.* reference must be passed. Narrow the rule: callers must pass required: true workflow secrets and optional secrets used by reached steps; optional unused secrets may remain unset.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/README.md around lines 215 - 222, Update the
reusable-workflow guidance in the README to distinguish required secrets from
optional ones: callers must forward every workflow secret declared with
required: true and any optional secret used by an executed step, while optional
secrets that are not used may remain unset. Preserve the existing explicit
mapping versus secrets: inherit guidance without claiming that every secrets.*
declaration must be passed.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/README.md:
- Around line 215-222: Update the reusable-workflow guidance in the README to
distinguish required secrets from optional ones: callers must forward every
workflow secret declared with required: true and any optional secret used by an
executed step, while optional secrets that are not used may remain unset.
Preserve the existing explicit mapping versus secrets: inherit guidance without
claiming that every secrets.* declaration must be passed.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 30cd8dc9-448a-4ef2-b923-185ac6e7bd6a

📥 Commits

Reviewing files that changed from the base of the PR and between 4a6c302 and 3ba2bff.

📒 Files selected for processing (3)
  • .github/workflows/README.md
  • .github/workflows/docker.yml
  • .github/workflows/ironclaw-release.yml

@think-in-universe
think-in-universe added this pull request to the merge queue Aug 3, 2026
Merged via the queue into main with commit 4b71aaa Aug 3, 2026
46 checks passed
@think-in-universe
think-in-universe deleted the codex/issue-6635-restore-release-docker branch August 3, 2026 10:18
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
Co-authored-by: Robert Yan <46699230+think-in-universe@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Restore Docker image build in the CI pipeline

2 participants