Skip to content

ci(images): publish scanned Nextcloud development channels - #62

Closed
vitormattos wants to merge 4 commits into
mainfrom
perf/ncdd-development-images
Closed

vitormattos wants to merge 4 commits into
mainfrom
perf/ncdd-development-images

Conversation

@vitormattos

@vitormattos vitormattos commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Rebuilt on the current main after #61 merged.

This PR keeps only the development-image work that is still useful after the NCDD architecture was simplified.

Highlights:

  • one development image build path for the existing stable35 channel and the rolling Nextcloud master channel
  • stable35 publishes app:35 and app:stable35
  • master publishes app:main
  • both amd64 and arm64 are built and scanned with the repository Trivy policy before publication
  • the official Nextcloud base tag is resolved to an immutable digest before the build
  • the Nextcloud daily archive is verified against the upstream SHA-512 file
  • docker-php-extension-installer is pinned to release 2.12.0 and verified by SHA-256
  • GitHub Actions used by the modified workflow are pinned to immutable commit SHAs
  • daily schedule plus PR validation of the exact development image paths

Removed from the old scope because those assumptions no longer exist after #59-#61:

  • dev-worker image
  • second development Compose stack
  • NCDD image-resolution logic
  • frontend/node-worker/scenario infrastructure

The branch was rebuilt from main; the pre-rebase branch is preserved as backup/perf-ncdd-development-images-before-rebase.

@vitormattos
vitormattos marked this pull request as draft October 7, 2026 13:51
@vitormattos
vitormattos force-pushed the feat/ncdd-automation-consumers branch from a1d4b0f to cfbc8b1 Compare October 7, 2026 16:43
@vitormattos
vitormattos force-pushed the perf/ncdd-development-images branch from cca1cdc to cf91ffb Compare October 7, 2026 17:07
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
@vitormattos vitormattos changed the title perf(ncdd): publish cached versioned development images ci(images): publish scanned Nextcloud development channels Oct 7, 2026
@vitormattos
vitormattos changed the base branch from feat/ncdd-automation-consumers to main October 7, 2026 17:09
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
@vitormattos
vitormattos marked this pull request as ready for review October 7, 2026 17:23
@vitormattos
vitormattos marked this pull request as draft October 7, 2026 17:26

Copy link
Copy Markdown
Member Author

This PR remains draft and blocked by the image-foundation work.

Its current implementation still evolves .docker/app/Dockerfile.35 and publishes :35, :stable35, and :main from that temporary version-specific path. That is not the architecture we want to stabilize.

Do not merge or extend this branch as the image contract. The next steps are:

  1. land the documentation-only convention from Document the container image naming and tagging convention #53;
  2. replace the version-specific app image foundation with one generic build path;
  3. only then rebuild the development publication workflow on top of that generic foundation, using the agreed :master-fpm contract and scanning/smoke gates.

No publication/caching work from this PR should be treated as authoritative until that foundation exists.

Copy link
Copy Markdown
Member Author

The generic app-image foundation is now implemented in #67.

#67 removes .docker/app/Dockerfile.35, validates both release and Nextcloud Server master from the same Dockerfile, and gates both amd64/arm64 master builds with Trivy plus the runtime acceptance test from #49.

This PR should remain draft until #67 is merged. After that, it should be rebuilt from current main and reduced to the remaining publication concern only: publish the validated generic development image under the agreed :master-fpm contract, with no :35, :stable35, or :main compatibility path.

Copy link
Copy Markdown
Member Author

#67 is now merged and replaces the foundation this draft PR was built on.

This branch still depends on the removed .docker/app/Dockerfile.35 path and the rejected :35, :stable35, and :main development tags. Reworking it in place would preserve obsolete history and make review harder.

Closing this PR as superseded. The remaining publication work will be rebuilt from current main and limited to the validated generic :master-fpm channel.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant