Skip to content
This repository was archived by the owner on Sep 14, 2026. It is now read-only.

fix(ci): derive control base tags from control/Dockerfile - #64

Merged
haasonsaas merged 1 commit into
mainfrom
ci/derive-control-base-tags-from-dockerfile
Sep 2, 2026
Merged

haasonsaas merged 1 commit into
mainfrom
ci/derive-control-base-tags-from-dockerfile

Conversation

@haasonsaas

Copy link
Copy Markdown
Contributor

What broke

scripts/update-control-base-images.sh hardcoded golang:1.26.6-alpine in two places: as the candidate image to resolve, and as a literal regex that control/Dockerfile had to match. Any Go tag bump made the script exit 1 with unexpected Go build base reference.

That script runs inside scripts/test-image-safety.sh, which the CI jobs License and prose hygiene and Build, boot, persist, and scan candidate both execute. So #62 (golang 1.26.6-alpine -> 1.27.0-alpine) has been red since 2026-08-24 for a reason unrelated to the bump itself. Failing line from run 32691589249:

unexpected Go build base reference: golang:1.27.0-alpine@sha256:4c9fe60190a2a3350ddc51de80d0224b8a6698d12bdfc999fee45ea9d6c46dbc

scripts/check-image-drift.sh defaulted to the same literal tag. After a bump it would compare the 1.26.6 digest against a 1.27.0 pin and report drift forever.

The change

The updater now reads the pinned tags out of control/Dockerfile and re-resolves their digests. The gate keeps the same strength:

  • Go base must match ^golang:[0-9]+\.[0-9]+(\.[0-9]+)?-alpine@sha256:[0-9a-f]{64}$
  • Alpine base must match ^alpine:[0-9]+\.[0-9]+(\.[0-9]+)?@sha256:[0-9a-f]{64}$

Unpinned tags and off-family images still exit 1. check-image-drift.sh takes its defaults from the same file; the GHOSTLIGHT_GO_BASE_CANDIDATE / GHOSTLIGHT_ALPINE_BASE_CANDIDATE overrides are untouched.

How I verified

On this branch:

Check Result
bash scripts/test-image-safety.sh pass
bash scripts/test-browser-update-workflow.sh pass
bash scripts/check-repo-hygiene.sh pass
shellcheck scripts/update-control-base-images.sh scripts/check-image-drift.sh clean

With #62 merged into this branch locally, scripts/check-image-safety.sh and scripts/test-image-safety.sh both pass and the updater resolves golang:1.27.0-alpine@sha256:4c9fe60....

Negative cases still fail as before: unpinned golang:1.27.0-alpine exits 1, and off-family golang:1.27.0-bookworm@sha256:... exits 1.

Unblocks

#62.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XpuXXVrWCZk3Tq5NRXejNP

scripts/update-control-base-images.sh hardcoded `golang:1.26.6-alpine`
both as the candidate to resolve and as a literal regex that
control/Dockerfile had to match. Any reviewed tag bump therefore aborted
the script with `unexpected Go build base reference`, which failed the
"License and prose hygiene" and "Build, boot, persist, and scan
candidate" jobs on every Docker dependency PR. #62 (golang 1.26.6-alpine
-> 1.27.0-alpine) has been blocked on this since 2026-08-24.

The script now reads the pinned tags out of control/Dockerfile and
re-resolves their digests. The gate is unchanged in strength: the Go base
must still be `golang:<version>-alpine` pinned by a canonical sha256
digest, and the runtime base must still be `alpine:<version>` pinned the
same way. Unpinned or off-family references still exit 1.

scripts/check-image-drift.sh defaulted to the same literal tag, so after
a bump it would have reported permanent phantom drift against a tag the
repository no longer builds from. Its defaults now come from
control/Dockerfile too; the GHOSTLIGHT_*_BASE_CANDIDATE overrides are
unchanged.

Verified locally on this branch:
- `bash scripts/test-image-safety.sh` passes.
- `bash scripts/test-browser-update-workflow.sh` passes.
- `bash scripts/check-repo-hygiene.sh` passes.
- `shellcheck scripts/update-control-base-images.sh scripts/check-image-drift.sh` is clean.
- With #62 merged into this branch, `bash scripts/check-image-safety.sh`
  and `bash scripts/test-image-safety.sh` both pass and the updater
  resolves `golang:1.27.0-alpine@sha256:4c9fe60...`.
- Negative cases still fail: an unpinned `golang:1.27.0-alpine` and an
  off-family `golang:1.27.0-bookworm@sha256:...` both exit 1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpuXXVrWCZk3Tq5NRXejNP
@haasonsaas
haasonsaas merged commit 7dc1e1e into main Sep 2, 2026
10 of 12 checks passed
@haasonsaas
haasonsaas deleted the ci/derive-control-base-tags-from-dockerfile branch September 2, 2026 01:43
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant