Repository navigation
Add a container image and publish it on release - #131
Open
fatih-adjust wants to merge 1 commit into
Open
fatih-adjust wants to merge 1 commit into
fatih-adjust wants to merge 1 commit into
Conversation
Build schaufel in a multi-stage image based on Ubuntu 24.04. The builder installs the dependencies listed in the README and runs the Makefile based build; the runtime stage only carries the libraries named in debian/control's Depends, so no headers, static libraries or pg_config end up in the published image. The image runs as a non-root schaufel user, creates the config and working directories and ships doc/*.conf as a reference for the config that has to be mounted over CONFIG_FILE. The uid/gid are fixed so that mounted volumes have predictable ownership; the deb intentionally uses a dynamic uid, but a container needs a known one. The image is built from the same release event as the deb packages and pushed to ghcr.io. It is tagged with SCHAUFEL_VERSION from the Makefile, which is where the deb packages take their version from too, and the job fails if the release tag disagrees with it. Pushing is limited to releases of adjust/schaufel: workflow_dispatch runs and forks build the image without publishing anything. Only amd64 is built for now. The platform is selected by the build rather than pinned with FROM --platform=, because a constant pin only selects the base image and leaves the resulting manifest advertising the platform the image was built on, which container runtimes then refuse to pull. Attestations are disabled so that a single platform image is pushed as a plain manifest. .dockerignore keeps host build artefacts, the git history and local configs out of the build context, .gitignore keeps the latter out of the repository. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
fatih-adjust
force-pushed
the
schaufel-dockerization
branch
from
August 12, 2026 14:21
f6572b7 to
e2c652c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
schaufel is built in a multi-stage image based on Ubuntu 24.04. The builder installs the dependencies listed in the README and runs the Makefile based build; the runtime stage only carries the libraries from debian/control's Depends, so no headers, static libraries or pg_config end up in the published image. It runs as a non-root schaufel user with a fixed uid/gid so mounted volumes have predictable ownership, and expects the config to be mounted over CONFIG_FILE. doc/*.conf ships as a reference; the logger type should be set to stdout so output reaches the container log.
The image is built from the same release event as the deb packages and pushed to ghcr.io, tagged with SCHAUFEL_VERSION from the Makefile so image and package versions cannot diverge - the job fails if the release tag disagrees with it. Pushing is limited to releases of adjust/schaufel, so workflow_dispatch runs and forks build the image without publishing anything. The GHCR package is created private and needs to be made public once after the first push.
Only amd64 is built for now. The platform is selected by the build rather than pinned with
FROM --platform=: a constant pin only selects the base image and leaves the resulting manifest advertising the platform the image was built on, which container runtimes then refuse to pull. Attestations are disabled so a single platform image is pushed as a plain manifest. Adding arm64 is a small change if that's wanted.Tested locally: the binary reports 0.12.2, all libraries resolve, it runs as uid 999, and the file to file test from test-pr.yml round-trips with a matching diff. The image has also been run on Kubernetes from ECR, shovelling to Kafka.
🤖 Generated with Claude Code