Skip to content

ci: mirror published multi-arch images to GHCR #224 - #230

Open
yupoet wants to merge 1 commit into
pgsty:mainfrom
yupoet:feat/ghcr-mirror-224
Open

yupoet wants to merge 1 commit into
pgsty:mainfrom
yupoet:feat/ghcr-mirror-224

Conversation

@yupoet

@yupoet yupoet commented Sep 26, 2026

Copy link
Copy Markdown

Summary

Implements #224 by adding a mirror stage at the end of the Docker release pipeline: after the multi-architecture manifests are promoted on Docker Hub and their digests verified, the four promoted tags (RELEASE.*, latest, RELEASE.*-distroless, distroless) are copied to ghcr.io/<repository> using docker buildx imagetools create.

Why a mirror stage instead of dual-registry pushes

  • Same digests by construction: registry-to-registry manifest copy preserves the exact manifests and blobs, so ghcr.io/pgsty/silo:RELEASE... resolves to the same digest as Docker Hub — the issue's same workflow / same tags / same digests ask, with zero changes to the six build lanes, SBOM generation, or the six existing attestations.
  • No new secrets: uses GITHUB_TOKEN with packages: write.
  • Divergence guard: every mirrored tag is digest-checked against the just-verified Docker Hub manifest; a mismatched mirror fails the release run.

Notes for reviewers

  • Architecture-suffixed staging tags (*-amd64/*-arm64) remain Docker-Hub-only; only the promoted multi-arch tags are mirrored. Happy to mirror those too if preferred.
  • Attestations keep their index.docker.io/pgsty/silo subject names; they remain verifiable against the shared digests by passing the Docker Hub subject registry explicitly. If GHCR-native attestation subjects are wanted later, that would be an additional actions/attest pair per mirrored subject — out of scope here.
  • Not runnable end-to-end without maintainer dispatch, so the workflow changes are validated for YAML correctness and staged conservatively after all existing gates.

After the Docker Hub manifests are promoted and digest-verified, copy the
four promoted tags to ghcr.io/<repo> with 'docker buildx imagetools create'.
Registry-to-registry manifest copy keeps GHCR tags on the exact same digests
as Docker Hub -- same workflow, same tags, same digests, as requested in the
issue -- with no rebuild lane and no new secrets (GITHUB_TOKEN + packages:
write). Each mirrored tag is digest-checked against the just-verified Docker
Hub manifest so a silently diverged mirror fails the release.

Architecture-suffixed staging tags stay Docker-Hub-only; attestations keep
their index.docker.io subject names and remain verifiable against the shared
digests.

Fixes pgsty#224
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant