forgejo-mcp/image/release-tools/.dockerignore
Christoph Görn 240a544ed3
feat(image): 🐳 add release-tools OCI image source tree (iteration 1)
Implements sections 1-2-5 of openspec/changes/release-tools-image/tasks.md.
Produces image/release-tools/ containing:

- Containerfile — multi-stage build on Project Hummingbird hi/go base
  (registry.access.redhat.com/hi/go:latest-builder; floats until
  Hummingbird publishes versioned tags). Bundles: Go toolchain, syft
  v1.44.0, goreleaser v2.16.0, cosign v3.0.6, Node 22, npm, jq, curl,
  ca-certificates, tar, gzip, xz, @anthropic-ai/mcpb v2.1.2.
- VERSIONS.md — single source of truth for pinned versions + Hummingbird
  base digest. Documents the TAG-FLOATING RISK for the base.
- npm/{package.json,package-lock.json} — pinned mcpb dep + integrity
  hashes. Containerfile installs via `npm ci --ignore-scripts` plus
  `npm install -g` so mcpb is on PATH AND offline npx works.
- .dockerignore — scoped to image/release-tools/ build context.
- renovate.json — Renovate config; Hummingbird base manual, tools auto.
- README.md — operator guide: pull, verify cosign, run locally, bump,
  lift-out 5-step procedure.
- build.sh — single-shot local podman build (tag localhost/release-tools:dev).
- verify.sh — runs the built image and asserts every bundled tool's
  --version. Covers spec.md scenarios "Image carries a shell" and
  "npx can resolve @anthropic-ai/mcpb without network".

End-to-end verifier `bash build.sh && bash verify.sh` exits 0 after 6
fix rounds (tar, gzip, build-context scope, npm offline, symlink-deref
in npm bin). All 10 tool checks green.

Out of scope (iteration 2): .tekton/release-tools/ pipelines for
PR-build + tag-publish.

Refs: forgejo-mcp-1b4
2026-05-25 17:40:36 +02:00

8 lines
248 B
Text

# Build context is image/release-tools/ (passed as SCRIPT_DIR in build.sh).
# All files in context are already scoped to this directory.
# Exclude only files not needed inside the image build.
build.sh
verify.sh
README.md
renovate.json
VERSIONS.md