Wire the existing release-tools image tasks into the app release pipeline
so that pushing a vX.Y.Z tag also builds, signs, and publishes the
forgejo-mcp container image — closing forgejo-mcp-dn0.
- Build the root Containerfile, push by digest to
codeberg.org/goern/forgejo-mcp, then promote vX.Y.Z + latest only after
cosign sign + SBOM attach succeed (TOCTOU-safe).
- Reuse release-tools-{build-image,push-image-by-digest,
cosign-sign-image-by-digest,cosign-attach-sbom,promote-image-tag};
image build runs in parallel with goreleaser.
- Add an optional BUILD_ARGS param to release-tools-build-image (default
empty, no-op for the release-tools run) and pass VERSION=<tag> so the
in-image binary reports the real release instead of "dev".
- Export IMAGE_URL/IMAGE_DIGEST + enable Tekton Chains for SLSA provenance.
- Exclude .buildah/ in .containerignore so CONTEXT=. does not tar buildah's
own store into the build context.
- Document the published image (registry, tags, cosign verify, SBOM) in
README, install Option D.
Operator precondition: codeberg-pusher PAT needs write:package on
goern/forgejo-mcp (separate from its operate-first grant).
37 lines
649 B
Text
37 lines
649 B
Text
# Dependencies
|
|
node_modules/
|
|
npm-debug.log
|
|
yarn-debug.log
|
|
yarn-error.log
|
|
|
|
# Build output
|
|
build/
|
|
dist/
|
|
|
|
# buildah store created in-workspace by the Tekton release-tools-build-image
|
|
# task (CONTEXT=. shares the workspace root). Excluding it stops the build
|
|
# context from tarring up buildah's own image store mid-build. Harmless for
|
|
# local `make container`, where no .buildah/ exists.
|
|
.buildah/
|
|
|
|
# Environment variables
|
|
.env
|
|
.env.local
|
|
.env.development.local
|
|
.env.test.local
|
|
.env.production.local
|
|
|
|
# IDE and editor files
|
|
.idea/
|
|
.vscode/
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
|
|
# OS files
|
|
.DS_Store
|
|
Thumbs.db
|
|
project/
|
|
.social-media/
|
|
images/Screenshot*
|
|
images/forgejo-mcp.xcf
|