From 03f53393da830b6f0eb0a914e643d15da8d162e0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ju=CC=88rgen?= Date: Sun, 29 Mar 2026 13:24:09 +0200 Subject: [PATCH 1/2] Publish API container to GHCR --- .github/workflows/ci.yml | 8 ++-- .github/workflows/package.yml | 74 +++++++++++++++++++++++++++++++++++ .github/workflows/release.yml | 6 +-- CHANGELOG.md | 9 +++++ Dockerfile | 4 ++ README.md | 21 +++++++++- 6 files changed, 113 insertions(+), 9 deletions(-) create mode 100644 .github/workflows/package.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d6e85a4..5756850 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,8 +11,8 @@ jobs: name: Lint (ruff) runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v6 + - uses: actions/setup-python@v6 with: python-version: "3.12" - run: pip install ruff @@ -25,8 +25,8 @@ jobs: matrix: python-version: ["3.11", "3.12"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v6 + - uses: actions/setup-python@v6 with: python-version: ${{ matrix.python-version }} - run: pip install -r requirements.txt pytest pytest-asyncio httpx diff --git a/.github/workflows/package.yml b/.github/workflows/package.yml new file mode 100644 index 0000000..4c77b4f --- /dev/null +++ b/.github/workflows/package.yml @@ -0,0 +1,74 @@ +name: Package + +on: + push: + tags: + - "v*" + workflow_dispatch: + inputs: + tag_name: + description: "Existing release tag to package, e.g. v0.1.0-alpha.1" + required: true + type: string + +permissions: + contents: read + packages: write + +env: + IMAGE_NAME: ghcr.io/${{ github.repository_owner }}/beyond-ai-api + +jobs: + publish_api_image: + name: Publish API image + runs-on: ubuntu-latest + env: + IMAGE_VERSION: ${{ github.event_name == 'workflow_dispatch' && inputs.tag_name || github.ref_name }} + steps: + - uses: actions/checkout@v6 + with: + fetch-depth: 0 + ref: ${{ env.IMAGE_VERSION }} + + - name: Validate requested tag + run: git describe --tags --exact-match >/dev/null + + - uses: actions/setup-python@v6 + with: + python-version: "3.12" + + - name: Lint and test before publishing + run: | + pip install -r requirements.txt pytest pytest-asyncio httpx ruff + ruff check . + pytest sanctions/tests/ -q + + - uses: docker/setup-buildx-action@v3 + + - uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ github.token }} + + - id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.IMAGE_NAME }} + tags: | + type=raw,value=${{ env.IMAGE_VERSION }} + type=semver,pattern={{version}},value=${{ env.IMAGE_VERSION }} + type=raw,value=latest,enable=${{ !contains(env.IMAGE_VERSION, '-') }} + labels: | + org.opencontainers.image.title=Beyond AI API + org.opencontainers.image.description=Beyond AI Sanctions Screening API + + - uses: docker/build-push-action@v6 + with: + context: . + file: ./Dockerfile + push: true + build-args: | + BEYOND_AI_VERSION=${{ env.IMAGE_VERSION }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 137118b..ff892dd 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,8 +16,8 @@ jobs: matrix: python-version: ["3.11", "3.12"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v6 + - uses: actions/setup-python@v6 with: python-version: ${{ matrix.python-version }} - run: pip install -r requirements.txt pytest pytest-asyncio httpx ruff @@ -31,7 +31,7 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 with: fetch-depth: 0 - name: Create GitHub release from tag diff --git a/CHANGELOG.md b/CHANGELOG.md index 1cb273d..2eb77de 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,15 @@ Alle nennenswerten Aenderungen an diesem Projekt werden in dieser Datei festgeha ## [Unreleased] +### Added + +- GHCR-Publish-Workflow fuer das API-Container-Image bei Release-Tags und manuellen Tag-Backfills. +- Build-Argument fuer `BEYOND_AI_VERSION`, damit Container und Health-Endpoint dieselbe Release-Version tragen. + +### Changed + +- GitHub-Actions-Workflows auf Node-24-faehige Major-Versionen von `actions/checkout` und `actions/setup-python` angehoben. + ## [0.1.0-alpha.1] - 2026-03-29 ### Added diff --git a/Dockerfile b/Dockerfile index 5e596b3..acad3ac 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,11 @@ FROM python:3.12-slim +ARG BEYOND_AI_VERSION=dev + WORKDIR /app +ENV BEYOND_AI_VERSION=${BEYOND_AI_VERSION} + COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt diff --git a/README.md b/README.md index 58cd63a..9ba08a1 100644 --- a/README.md +++ b/README.md @@ -72,14 +72,31 @@ curl -X POST http://localhost:8000/api/screen \ ## Releases -Beyond AI veroeffentlicht aktuell bewusst **GitHub Releases fuer Source + Docker**, noch keine installierbaren Packages. +Beyond AI veroeffentlicht aktuell bewusst **GitHub Releases fuer Source + Docker**. Paketiert wird vorerst nur die API als GHCR-Container, noch nicht als installierbares Python-Package. - Tags im Format `vX.Y.Z-alpha.N`, `vX.Y.Z-beta.N` oder `vX.Y.Z-rc.N` werden als Pre-Releases veroeffentlicht. - Tags im Format `vX.Y.Z` werden als stabile Releases veroeffentlicht. - Jeder Push eines passenden Tags startet den Release-Workflow und erstellt automatisch den GitHub Release. - Der aktuelle Release-Verlauf steht in [CHANGELOG.md](CHANGELOG.md). -Das erste oeffentliche Release ist als `v0.1.0-alpha.1` vorgesehen: fruehes Nutzerfeedback, reproduzierbarer Quellstand, aber noch kein Packaging fuer PyPI oder GitHub Packages. +Das erste oeffentliche Release `v0.1.0-alpha.1` dient bewusst dem fruehen Nutzerfeedback: reproduzierbarer Quellstand, veroeffentlichter Docker-Stack und optionales GHCR-Container-Package, aber noch kein Packaging fuer PyPI. + +## Packages + +Das API-Image wird ueber GitHub Container Registry als `ghcr.io/endvater/beyond-ai-api` veroeffentlicht. + +- Release-Tags publizieren ein Image mit exakt demselben Tag, z. B. `v0.1.0-alpha.1`. +- Zusaetzlich wird ein SemVer-Tag ohne fuehrendes `v` publiziert, z. B. `0.1.0-alpha.1`. +- Nur stabile Releases ohne Suffix publizieren ausserdem `latest`. +- Bereits existierende Release-Tags lassen sich ueber den `Package`-Workflow per `workflow_dispatch` nachziehen. + +```bash +docker pull ghcr.io/endvater/beyond-ai-api:v0.1.0-alpha.1 + +docker run --rm -p 8000:8000 \ + -e YENTE_URL=http://host.docker.internal:8100 \ + ghcr.io/endvater/beyond-ai-api:v0.1.0-alpha.1 +``` ## Voraussetzungen From 59bf337d84f1c9527ed89351fa20ffcda578141b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ju=CC=88rgen?= Date: Sun, 29 Mar 2026 13:38:07 +0200 Subject: [PATCH 2/2] Grant provenance permissions to package workflow --- .github/workflows/package.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/package.yml b/.github/workflows/package.yml index 4c77b4f..66ec85f 100644 --- a/.github/workflows/package.yml +++ b/.github/workflows/package.yml @@ -14,6 +14,8 @@ on: permissions: contents: read packages: write + attestations: write + id-token: write env: IMAGE_NAME: ghcr.io/${{ github.repository_owner }}/beyond-ai-api @@ -68,6 +70,7 @@ jobs: context: . file: ./Dockerfile push: true + provenance: true build-args: | BEYOND_AI_VERSION=${{ env.IMAGE_VERSION }} tags: ${{ steps.meta.outputs.tags }}