Skip to content

Publish the validated Nextcloud master app image as master-fpm #75

Description

@vitormattos

Goal

Complete the development-image lifecycle from #47 by publishing the already validated generic Nextcloud Server master image as:

ghcr.io/librecodecoop/nextcloud-docker-app:master-fpm

This replaces the obsolete publication approach from #62.

Foundation

#67 provides the required generic foundation:

  • one .docker/app/Dockerfile;
  • NEXTCLOUD_SOURCE=daily;
  • verified latest-master.tar.bz2;
  • amd64 and arm64 builds;
  • Trivy gate;
  • runtime acceptance gate.

Do not create another Dockerfile or Compose stack.

Publication contract

  • publish only :master-fpm for the development app channel;
  • do not publish :35, :stable35, :main, :latest, or a future-major development alias;
  • publish a multi-platform manifest for amd64 and arm64;
  • only publish after both architectures pass vulnerability scanning and runtime acceptance;
  • PRs validate but never publish;
  • main/scheduled/manual runs may publish;
  • architecture-specific staging tags may be used internally for assembling the manifest but are not part of the public channel contract.

Traceability

Published images must include the OCI/source metadata that can be known at build time, including:

  • source repository;
  • repository revision;
  • channel/version master-fpm;
  • runtime variant fpm;
  • upstream daily source URL/base runtime reference.

Do not invent a Nextcloud commit SHA if the upstream daily artifact does not expose one.

Any remaining exact-upstream-revision gap should be documented as follow-up work rather than fabricating traceability.

Acceptance criteria

  • PR validation still runs build + Trivy + runtime acceptance for amd64 and arm64;
  • failed scan or runtime acceptance prevents publication;
  • successful publication creates one multi-platform :master-fpm manifest;
  • workflow does not publish obsolete development tags;
  • publication runs on a defined rolling cadence and can be run manually;
  • GitHub Actions dependencies remain under the repository dependency-management policy;
  • docs reflect the implemented publication behavior.

Parent epic: #47.
Supersedes implementation in #62.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions