forgejo-mcp/.containerignore
Christoph Görn bdfd968f73
feat: ✨ build and publish signed OCI image on tag release
Wire the existing release-tools image tasks into the app release pipeline
so that pushing a vX.Y.Z tag also builds, signs, and publishes the
forgejo-mcp container image — closing forgejo-mcp-dn0.

- Build the root Containerfile, push by digest to
  codeberg.org/goern/forgejo-mcp, then promote vX.Y.Z + latest only after
  cosign sign + SBOM attach succeed (TOCTOU-safe).
- Reuse release-tools-{build-image,push-image-by-digest,
  cosign-sign-image-by-digest,cosign-attach-sbom,promote-image-tag};
  image build runs in parallel with goreleaser.
- Add an optional BUILD_ARGS param to release-tools-build-image (default
  empty, no-op for the release-tools run) and pass VERSION=<tag> so the
  in-image binary reports the real release instead of "dev".
- Export IMAGE_URL/IMAGE_DIGEST + enable Tekton Chains for SLSA provenance.
- Exclude .buildah/ in .containerignore so CONTEXT=. does not tar buildah's
  own store into the build context.
- Document the published image (registry, tags, cosign verify, SBOM) in
  README, install Option D.

Operator precondition: codeberg-pusher PAT needs write:package on
goern/forgejo-mcp (separate from its operate-first grant).
2026-06-01 08:49:09 +02:00

37 lines
649 B
Text

# Dependencies
node_modules/
npm-debug.log
yarn-debug.log
yarn-error.log
# Build output
build/
dist/
# buildah store created in-workspace by the Tekton release-tools-build-image
# task (CONTEXT=. shares the workspace root). Excluding it stops the build
# context from tarring up buildah's own image store mid-build. Harmless for
# local `make container`, where no .buildah/ exists.
.buildah/
# Environment variables
.env
.env.local
.env.development.local
.env.test.local
.env.production.local
# IDE and editor files
.idea/
.vscode/
*.swp
*.swo
*~
# OS files
.DS_Store
Thumbs.db
project/
.social-media/
images/Screenshot*
images/forgejo-mcp.xcf