Skip to content
This repository was archived by the owner on Sep 14, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions scripts/check-image-drift.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,11 @@ SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
ROOT_DIR="$(cd -- "$SCRIPT_DIR/.." && pwd)"
CONTROL_DIR="$ROOT_DIR/control"
neko_candidate="${GHOSTLIGHT_NEKO_CANDIDATE_IMAGE:-ghcr.io/m1k1o/neko/chromium:latest}"
go_candidate="${GHOSTLIGHT_GO_BASE_CANDIDATE:-golang:1.26.6-alpine}"
alpine_candidate="${GHOSTLIGHT_ALPINE_BASE_CANDIDATE:-alpine:3.24}"
# Default the drift candidates to the tags control/Dockerfile already pins, so a
# reviewed tag bump does not turn into permanent phantom drift against a tag the
# repository no longer builds from.
go_candidate="${GHOSTLIGHT_GO_BASE_CANDIDATE:-$(awk '$1 == "FROM" && $2 ~ /^golang:/ { image = $2; sub(/@.*$/, "", image); print image; exit }' "$CONTROL_DIR/Dockerfile")}"
alpine_candidate="${GHOSTLIGHT_ALPINE_BASE_CANDIDATE:-$(awk '$1 == "FROM" && $2 ~ /^alpine:/ { image = $2; sub(/@.*$/, "", image); print image; exit }' "$CONTROL_DIR/Dockerfile")}"
# The deployed NEKO_IMAGE pin tracks the hardened ghostlight-viewer rebuild, so
# upstream drift is measured against the base the hardened viewer builds from.
neko_pinned="$(awk '$1 == "FROM" && $2 ~ /^ghcr\.io\/m1k1o\/neko\/chromium@/ { image = $2; sub(/^[^@]*@/, "", image); print image; exit }' "$ROOT_DIR/viewer/Dockerfile")"
Expand Down
23 changes: 14 additions & 9 deletions scripts/update-control-base-images.sh
Original file line number Diff line number Diff line change
Expand Up @@ -62,24 +62,29 @@ resolve_digest() {
printf '%s\n' "$digest"
}

go_candidate=golang:1.26.6-alpine
alpine_candidate=alpine:3.24
go_digest=$(resolve_digest "$go_candidate" "${GHOSTLIGHT_GO_BASE_RESOLVED_DIGEST:-}")
alpine_digest=$(resolve_digest "$alpine_candidate" "${GHOSTLIGHT_ALPINE_BASE_RESOLVED_DIGEST:-}")
go_new="$go_candidate@$go_digest"
alpine_new="$alpine_candidate@$alpine_digest"

# control/Dockerfile is the source of truth for which base tags this repository
# builds from. Deriving the candidates from it lets a reviewed tag bump (for
# example a Dependabot Docker update) flow through without editing this script,
# while the shape checks below still require an immutable digest pin on the
# expected image families.
go_current=$(awk '$1 == "FROM" && $2 ~ /^golang:/ { print $2; exit }' "$dockerfile")
alpine_current=$(awk '$1 == "FROM" && $2 ~ /^alpine:/ { print $2; exit }' "$dockerfile")
[[ "$go_current" =~ ^golang:1\.26\.6-alpine@sha256:[0-9a-f]{64}$ ]] || {
[[ "$go_current" =~ ^golang:[0-9]+\.[0-9]+(\.[0-9]+)?-alpine@sha256:[0-9a-f]{64}$ ]] || {
printf 'unexpected Go build base reference: %s\n' "$go_current" >&2
exit 1
}
[[ "$alpine_current" =~ ^alpine:3\.24@sha256:[0-9a-f]{64}$ ]] || {
[[ "$alpine_current" =~ ^alpine:[0-9]+\.[0-9]+(\.[0-9]+)?@sha256:[0-9a-f]{64}$ ]] || {
printf 'unexpected Alpine runtime base reference: %s\n' "$alpine_current" >&2
exit 1
}

go_candidate=${go_current%@*}
alpine_candidate=${alpine_current%@*}
go_digest=$(resolve_digest "$go_candidate" "${GHOSTLIGHT_GO_BASE_RESOLVED_DIGEST:-}")
alpine_digest=$(resolve_digest "$alpine_candidate" "${GHOSTLIGHT_ALPINE_BASE_RESOLVED_DIGEST:-}")
go_new="$go_candidate@$go_digest"
alpine_new="$alpine_candidate@$alpine_digest"

if [[ "$go_current" != "$go_new" || "$alpine_current" != "$alpine_new" ]]; then
GO_CURRENT="$go_current" GO_NEW="$go_new" ALPINE_CURRENT="$alpine_current" ALPINE_NEW="$alpine_new" \
perl -0pi -e 's/\Q$ENV{GO_CURRENT}\E/$ENV{GO_NEW}/g; s/\Q$ENV{ALPINE_CURRENT}\E/$ENV{ALPINE_NEW}/g' "$dockerfile"
Expand Down
Loading