Skip to content

ci(images): publish validated master-fpm channel - #76

Merged
vitormattos merged 4 commits into
mainfrom
ci/publish-master-fpm
Oct 8, 2026
Merged

vitormattos merged 4 commits into
mainfrom
ci/publish-master-fpm

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Closes #75.
Part of #47.
Supersedes #62.

This PR turns the existing Nextcloud Server master validation workflow into the publication path defined by the image contract.

Publication behavior:

  • PRs build amd64/arm64, run Trivy, and run runtime acceptance, but never publish;
  • pushes to main, the daily schedule, and manual dispatch may publish;
  • each architecture is pushed only after its own scan and runtime acceptance pass;
  • the :master-fpm multi-platform manifest is created only after both architecture jobs succeed;
  • no :35, :stable35, :main, or :latest development aliases are published.

Traceability:

  • resolves nextcloud:stable-fpm to an OCI digest before building;
  • records the exact SHA-512 of latest-master.tar.bz2;
  • records source repository, repository revision, build timestamp, channel, upstream source, resolved base digest, and runtime variant as image labels.

The upstream daily artifact does not expose a reliable Nextcloud Git commit SHA, so this PR records the exact verified artifact digest instead of inventing one.

Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
@vitormattos
vitormattos merged commit aef936d into main Oct 8, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish the validated Nextcloud master app image as master-fpm

1 participant