Build the Android CI image in CI, not on a laptop
The Android job ran in gitea.tourolle.paris/dtourolle/darkroom-android:latest, a tag that had never been pushed. The image existed only as a local darkroom-android:latest on one machine, so every Android job died at docker pull with "manifest unknown" before reaching a step. The registry API confirms it: that manifest is a 404 while the other builder images answer 200. android-image.yml now builds and pushes it, following KPN's docker.yaml — host runner rather than a container, so it has the Docker daemon and the host's cached registry credentials, and a plain-git checkout because that host has no Node for actions/checkout. Where it diverges from KPN: that workflow gates on dorny/paths-filter running inside the builder image, which here would need the very image that is missing. The tag is the git tree hash of docker/android instead, which changes when and only when a file there changes. An unrelated push reuses the image, a Dockerfile edit cannot keep serving a stale latest, and a missing tag rebuilds itself without a manual step. The presence probe is curl against the registry API, not `docker manifest inspect`. The latter exits 1 on this registry even for tags that are plainly there — jellytau-builder:latest answers HTTP 200 while docker reports "manifest unknown" for it — and trusting it would have rebuilt 7 GB on every push. The HEAD request also yields Docker-Content-Digest, so latest is repointed only when the digests actually disagree, without pulling any layers. A probe that cannot authenticate falls through to building. Rebuilding when it was unnecessary costs minutes; skipping a build that was needed is the failure this commit exists to remove. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -25,6 +25,21 @@ image, so a break appears in one place rather than two.
|
||||
Prefers `podman`, falls back to `docker`. First run builds the image, which takes several minutes;
|
||||
after that it is cached.
|
||||
|
||||
## In CI
|
||||
|
||||
`.gitea/workflows/android-image.yml` builds this image and pushes it to
|
||||
`gitea.tourolle.paris/dtourolle/darkroom-android`, which the Android job then runs inside. It is
|
||||
called on every push and finishes in seconds unless something here changed — the image is tagged
|
||||
with the git tree hash of `docker/android/`, so a rebuild happens when and only when a file in this
|
||||
directory does.
|
||||
|
||||
Nothing needs pushing by hand. Editing the Dockerfile is the trigger; `latest` follows
|
||||
automatically. To force a rebuild without a content change, run the workflow from the Gitea UI with
|
||||
`force` set to `true`.
|
||||
|
||||
The job runs on the host runner rather than in a container, because it needs the Docker daemon and
|
||||
the runner host's cached registry credentials.
|
||||
|
||||
## Pinned versions
|
||||
|
||||
| Component | Version | Why this one |
|
||||
|
||||
Reference in New Issue
Block a user