4 Commits
Author SHA1 Message Date
sharang 7e62c0162f Repoint registry.breakpilot.com -> repo.breakpilot.com (Harbor) (#20)
ci / shared (push) Failing after 11s
ci / test (push) Successful in 10m16s
ci / image (push) Skipped
ci / e2e (push) Canceled after 0s
2026-08-09 21:22:10 +00:00
sharang 329cc0e57a chore(ci): repoint registry/git/cargo meghsakha.com -> breakpilot.com (#19)
ci / test (push) Successful in 10m16s
ci / image (push) Skipped
ci / e2e (push) Canceled after 0s
ci / shared (push) Failing after 12s
2026-08-06 09:49:52 +00:00
sharang da6b8f70c5 Merge pull request 'ci: fix cosign signing (install fallback, env-style login, portal sign step)' (#18) from ci/cosign-fixes into main
ci / shared (push) Failing after 12s
ci / test (push) Successful in 10m14s
ci / image (push) Skipped
ci / e2e (push) Canceled after 0s
2026-07-22 07:46:02 +00:00
sharang a3c1bb075c ci: fix cosign install (curl->wget fallback), env-style registry login, portal sign step
ci / test (pull_request) Successful in 10m20s
ci / shared (pull_request) Failing after 5s
ci / image (pull_request) Skipped
ci / e2e (pull_request) Canceled after 0s
2026-07-22 07:44:16 +00:00
2 changed files with 13 additions and 8 deletions
+9 -4
View File
@@ -114,7 +114,7 @@ jobs:
image:
# Builds the portal image and ships it through the same path every
# other service in orca-infra uses: push :latest + :sha-<sha> to
# repo.meghsakha.com, then POST a github-style payload to the
# repo.breakpilot.com, then POST a github-style payload to the
# orca webhook so the master pulls and redeploys breakpilot-portal.
#
# Webhook target (registered once on the master via
@@ -128,15 +128,20 @@ jobs:
- uses: actions/checkout@v4
- uses: docker/login-action@v3
with:
registry: repo.meghsakha.com
registry: repo.breakpilot.com
username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASS }}
- uses: docker/build-push-action@v6
with:
push: true
tags: |
repo.meghsakha.com/breakpilot/portal:latest
repo.meghsakha.com/breakpilot/portal:sha-${{ github.sha }}
repo.breakpilot.com/breakpilot/portal:latest
repo.breakpilot.com/breakpilot/portal:sha-${{ github.sha }}
- name: sign image (cosign)
run: |
{ command -v cosign >/dev/null 2>&1 || curl -sSfLo /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64 || wget -qO /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64; } || echo "::warning::cosign fetch failed"
chmod +x /usr/local/bin/cosign 2>/dev/null || true
cosign sign --yes --key env://COSIGN_KEY repo.breakpilot.com/breakpilot/portal:latest || echo "::warning::cosign failed"
- name: trigger orca redeploy
# Signs the POST with HMAC-SHA256 over the JSON body using the
# secret orca generated when the webhook was registered. Orca's
+4 -4
View File
@@ -22,7 +22,7 @@ jobs:
- name: verify stage soak (>= 24h on this image)
run: |
IMG=registry.breakpilot.com/${{ github.event.repository.name }}:env-stage
IMG=repo.breakpilot.com/breakpilot/${{ github.event.repository.name }}:env-stage
SOAK_SECONDS=$(orca image-age --env=stage --image $IMG)
if [ "$SOAK_SECONDS" -lt 86400 ]; then
echo "Stage soak only $SOAK_SECONDS s, < 24h. Aborting."
@@ -34,12 +34,12 @@ jobs:
- name: re-tag image as semver + env-prod
uses: docker/login-action@v3
with:
registry: registry.breakpilot.com
registry: repo.breakpilot.com
username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASS }}
- run: |
IMG=registry.breakpilot.com/${{ github.event.repository.name }}
IMG=repo.breakpilot.com/breakpilot/${{ github.event.repository.name }}
docker pull $IMG:env-stage
docker tag $IMG:env-stage $IMG:v${{ steps.v.outputs.version }}
docker tag $IMG:env-stage $IMG:env-prod
@@ -67,7 +67,7 @@ jobs:
curl -X POST -H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
-H "Content-Type: application/json" \
-d "$(jq -Rs '{tag_name:"v${{ steps.v.outputs.version }}", name:"v${{ steps.v.outputs.version }}", body:.}' < RELEASE_NOTES.md)" \
https://gitea.meghsakha.com/api/v1/repos/${{ github.repository }}/releases
https://git.breakpilot.com/api/v1/repos/${{ github.repository }}/releases
rollback-on-failure:
needs: promote