forgejo-mcp/.tekton
Christoph Görn 97ee636e49
fix: 🐛 filename mismatch in sha256sum + privileged SCC for buildah
Two bugs surfaced during first real pipeline run:

1. Containerfile: goreleaser and syft downloaded to renamed files
   (goreleaser.tar.gz, syft.tar.gz) but sha256sum -c expected the
   original release filenames. Download now uses original names so
   sha256sum -c resolves them correctly.

2. build-image task: privileged: true required for buildah on this
   OpenShift cluster. The pipeline SA has been granted privileged SCC
   in op1st-pipelines namespace (scoped grant, standard CI pattern).
   Rootless alternatives (--isolation=chroot, --userns=host) both
   fail due to nested user namespace restrictions even with anyuid SCC.

Closes forgejo-mcp-aps
2026-05-26 01:24:49 +02:00
..
release-tools/tasks fix: 🐛 filename mismatch in sha256sum + privileged SCC for buildah 2026-05-26 01:24:49 +02:00
tasks refactor: ♻️ rewrite .tekton/tasks/ to use release-tools image 2026-05-25 23:23:47 +02:00
code-scans.yaml ci: 🚀 add gitleaks scanning (Tekton + pre-commit) 2026-05-12 13:08:14 +02:00
on-pull-request.yaml ci: 🚀 migrate CI from Forgejo Actions to op1st Tekton 2026-05-12 08:39:45 +02:00
on-push-to-main.yaml ci: 🚀 migrate CI from Forgejo Actions to op1st Tekton 2026-05-12 08:39:45 +02:00
on-tag-push-release.yaml feat(ci): 🚀 add release-tools image build + publish Tekton pipelines (iteration 2) 2026-05-25 18:53:49 +02:00
openspec-validate-pr.yaml ci: 🚀 drop redundant PaC annotations on openspec-validate 2026-05-12 13:14:19 +02:00
openspec-validate-push.yaml ci: 🚀 drop redundant PaC annotations on openspec-validate 2026-05-12 13:14:19 +02:00
release-tools-on-pull-request-build.yaml fix: ✏️ correct CEL macro files.any.exists → files.exists 2026-05-26 00:57:06 +02:00
release-tools-on-tag-publish.yaml fix: 🐛 move release-tools PipelineRuns to .tekton/ root 2026-05-26 00:53:58 +02:00
repository.yaml ci: 🚀 migrate CI from Forgejo Actions to op1st Tekton 2026-05-12 08:39:45 +02:00