Skip to content

Add a container image and publish it on release - #131

Open
fatih-adjust wants to merge 1 commit into
adjust:masterfrom
fatih-adjust:schaufel-dockerization
Open

fatih-adjust wants to merge 1 commit into
adjust:masterfrom
fatih-adjust:schaufel-dockerization

Conversation

@fatih-adjust

@fatih-adjust fatih-adjust commented Aug 12, 2026 •

Copy link
Copy Markdown

schaufel is built in a multi-stage image based on Ubuntu 24.04. The builder installs the dependencies listed in the README and runs the Makefile based build; the runtime stage only carries the libraries from debian/control's Depends, so no headers, static libraries or pg_config end up in the published image. It runs as a non-root schaufel user with a fixed uid/gid so mounted volumes have predictable ownership, and expects the config to be mounted over CONFIG_FILE. doc/*.conf ships as a reference; the logger type should be set to stdout so output reaches the container log.

The image is built from the same release event as the deb packages and pushed to ghcr.io, tagged with SCHAUFEL_VERSION from the Makefile so image and package versions cannot diverge - the job fails if the release tag disagrees with it. Pushing is limited to releases of adjust/schaufel, so workflow_dispatch runs and forks build the image without publishing anything. The GHCR package is created private and needs to be made public once after the first push.

Only amd64 is built for now. The platform is selected by the build rather than pinned with FROM --platform=: a constant pin only selects the base image and leaves the resulting manifest advertising the platform the image was built on, which container runtimes then refuse to pull. Attestations are disabled so a single platform image is pushed as a plain manifest. Adding arm64 is a small change if that's wanted.

Tested locally: the binary reports 0.12.2, all libraries resolve, it runs as uid 999, and the file to file test from test-pr.yml round-trips with a matching diff. The image has also been run on Kubernetes from ECR, shovelling to Kafka.

🤖 Generated with Claude Code

Build schaufel in a multi-stage image based on Ubuntu 24.04. The builder
installs the dependencies listed in the README and runs the Makefile
based build; the runtime stage only carries the libraries named in
debian/control's Depends, so no headers, static libraries or pg_config
end up in the published image.

The image runs as a non-root schaufel user, creates the config and
working directories and ships doc/*.conf as a reference for the config
that has to be mounted over CONFIG_FILE. The uid/gid are fixed so that
mounted volumes have predictable ownership; the deb intentionally uses a
dynamic uid, but a container needs a known one.

The image is built from the same release event as the deb packages and
pushed to ghcr.io. It is tagged with SCHAUFEL_VERSION from the Makefile,
which is where the deb packages take their version from too, and the job
fails if the release tag disagrees with it. Pushing is limited to
releases of adjust/schaufel: workflow_dispatch runs and forks build the
image without publishing anything.

Only amd64 is built for now. The platform is selected by the build rather
than pinned with FROM --platform=, because a constant pin only selects
the base image and leaves the resulting manifest advertising the platform
the image was built on, which container runtimes then refuse to pull.
Attestations are disabled so that a single platform image is pushed as a
plain manifest.

.dockerignore keeps host build artefacts, the git history and local
configs out of the build context, .gitignore keeps the latter out of the
repository.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@fatih-adjust
fatih-adjust force-pushed the schaufel-dockerization branch from f6572b7 to e2c652c Compare August 12, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant