Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 3 additions & 14 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,20 +59,9 @@ jobs:
run: |
image="$(printf '%s\n' "$IMAGE_TAGS" | head -n 1)"
test -n "$image"
# The package is private by org policy, so this pull relies on the
# ghcr.io login established earlier in the job. Do not add an
# anonymous-pull check here: it cannot succeed.
docker pull "$image"
docker run --rm "$image" --version
docker run --rm "$image" python tools/import_smoke.py --stage 2

# GHCR can briefly return 401 for anonymous requests immediately after
# a public image is pushed. Verify public access separately with retries.
docker logout ghcr.io
for attempt in 1 2 3 4 5 6; do
if docker pull "$image"; then
exit 0
fi
if [ "$attempt" -eq 6 ]; then
echo "::error::Published image is not anonymously pullable: $image"
exit 1
fi
sleep $((attempt * 5))
done
11 changes: 7 additions & 4 deletions apodex/tests/test_deployment_config.py
Original file line number Diff line number Diff line change
Expand Up @@ -295,13 +295,16 @@ def test_publish_workflow_uses_canonical_image_and_runtime_smoke() -> None:

assert f"images: {IMAGE}" in workflow
assert "type=sha,format=long" in workflow
assert "docker logout ghcr.io" in workflow
assert workflow.index('docker pull "$image"') < workflow.index("docker logout ghcr.io")
assert "for attempt in 1 2 3 4 5 6" in workflow
assert "Published image is not anonymously pullable" in workflow
assert 'docker pull "$image"' in workflow
assert 'docker run --rm "$image" --version' in workflow
assert "python tools/import_smoke.py --stage 2" in workflow

# The published package is private by org policy, so the smoke test can only
# pull while the job still holds its ghcr.io login. An anonymous-pull check
# can never pass here; keep it from being reintroduced.
assert "docker logout ghcr.io" not in workflow
assert "anonymously pullable" not in workflow


def test_user_docs_use_the_published_registry_name() -> None:
# The container recipes live in docs/install/docker.md; the README links to it
Expand Down
Loading