Repository navigation
ci(release): restore regular Docker image publishing - #6701
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe release workflow now publishes the regular ChangesRelease Docker publishing
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant GitHubRelease
participant docker-image
participant docker.yml
participant DockerRegistry
GitHubRelease->>docker-image: host creates release successfully
docker-image->>docker.yml: invoke release build with trigger_dind=false
docker.yml->>DockerRegistry: publish version, latest, and SHA tags
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
✅ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| ✅ Approved | 0 | 0 | 0 | 4a6c30226e11 |
Head: 4a6c30226e11beb9cfce2db545f1d252a9932b93
Next: No reviewer action needed.
Run details
Status: Current
Needs human: no
Needs validation: no
Summary
Approved: the small CI-only change correctly invokes the Docker reusable workflow after GitHub Release creation, passes only the Docker Hub secret, and disables the DIND dispatch for tag releases.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 85.53% — 307467 / 359484 lines Per-crate breakdown (60 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
|
🚅 Deployed to the ironclaw-pr-6701 environment in ironclaw-ci-preview
|
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/README.md (1)
215-222: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winClarify reusable workflow secret forwarding.
.github/workflows/docker.ymldeclares DIND app credentials optional, but the README says anysecrets.*reference must be passed. Narrow the rule: callers must passrequired: trueworkflow secrets and optional secrets used by reached steps; optional unused secrets may remain unset.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/README.md around lines 215 - 222, Update the reusable-workflow guidance in the README to distinguish required secrets from optional ones: callers must forward every workflow secret declared with required: true and any optional secret used by an executed step, while optional secrets that are not used may remain unset. Preserve the existing explicit mapping versus secrets: inherit guidance without claiming that every secrets.* declaration must be passed.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/README.md:
- Around line 215-222: Update the reusable-workflow guidance in the README to
distinguish required secrets from optional ones: callers must forward every
workflow secret declared with required: true and any optional secret used by an
executed step, while optional secrets that are not used may remain unset.
Preserve the existing explicit mapping versus secrets: inherit guidance without
claiming that every secrets.* declaration must be passed.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 30cd8dc9-448a-4ef2-b923-185ac6e7bd6a
📒 Files selected for processing (3)
.github/workflows/README.md.github/workflows/docker.yml.github/workflows/ironclaw-release.yml
Co-authored-by: Robert Yan <46699230+think-in-universe@users.noreply.github.com>
Summary
nearaidev/ironclawDocker publish job after cargo-dist successfully creates the GitHub Release.latest, and source-SHA tags while explicitly excludingironclaw-workerand the separateironclaw-dindrelease path.Change Type
Linked Issue
Closes #6635
Validation
cargo fmt --all -- --checkcargo clippy --all --benches --tests --examples --all-features -- -D warnings— used the narrower owning-crate all-targets/all-features command belowcargo build— covered by the targeted smoke test buildrelease_ci_smoke contract (2 passed)cargo test --features integrationif database-backed or integration behavior changed — not applicable; no database or runtime behavior changedreview-prorpr-shepherd --fixwas run before requesting reviewTest Strategy
User behavior: Pushing a matching Reborn release tag creates the cargo-dist GitHub Release first, then publishes the regular IronClaw Docker image with version/latest/SHA tags. The release caller does not dispatch DIND.
Risk areas:
Tests added or updated:
release_ci_publishes_reborn_and_regular_docker_without_legacy_or_dind_pathsin the CLI smoke suite.What the tests prove: The Docker caller depends on successful release hosting, requests only the required permissions, passes only the Docker Hub token, sets
release: trueandtrigger_dind: false, retains version/latest/SHA tagging and source-SHA summaries, and does not restore worker artifacts. Both DIND steps consume the explicit gate.Commands run:
cargo +1.96.0 fmt --all -- --check cargo +1.96.0 test -p ironclaw --test smoke release_ci_ -- --nocapture cargo +1.96.0 clippy -p ironclaw --all-targets --all-features -- -D warnings go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 \ .github/workflows/ironclaw-release.yml \ .github/workflows/docker.yml RUSTUP_TOOLCHAIN=1.96.0 scripts/pre-commit-safety.shSecurity Impact
The release Docker job can publish to Docker Hub. It receives
contents: read,packages: read, andactions: writefor checkout/cache behavior plus an explicitly mappedDOCKER_REGISTRY_TOKEN. It no longer usessecrets: inherit, so the DIND GitHub App credentials are not exposed to the release caller.trigger_dind: falseprevents the tag release path from dispatching the separate DIND repository workflow.Reborn Trust-Boundary Checklist
N/A — this is CI credential and release-DAG wiring only. It does not change Reborn policy/evidence types, prompt content, hashing, runtime/error variants, serialization, queues, driver errors, or sandbox/native/host naming.
Database Impact
None.
Blast Radius
Touches matching tag releases and the reusable Docker workflow interface. Direct manual and hourly scheduled Docker runs preserve their existing DIND behavior. Docker now runs only after GitHub Release hosting succeeds; if Docker publishing fails, the already-created GitHub Release remains available while the overall workflow reports failure.
Rollback Plan
Revert this commit to return Docker publishing to independent manual/hourly runs. Existing GitHub Releases and already-published Docker tags remain intact. A failed regular image publish can also be retried through the Docker workflow without rebuilding the GitHub Release.
Review Follow-Through
No known code follow-up. The first credentialed release run should confirm the repository's Docker Hub variable/secret configuration and provides the final external publish proof.
Review track: C (security/runtime/DB/CI)