ci: pin ci-base to immutable lock-9cb7ffcd8828 (Closes #1328) (#1329)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/publish Pipeline was successful
Co-authored-by: ops-ci-01 <[email protected]>
This commit was merged in pull request #1329.
This commit is contained in:
+15
-1
@@ -2,8 +2,22 @@
|
|||||||
# node:24-alpine + python3/make/g++/postgresql-client + pnpm + a warm pnpm
|
# node:24-alpine + python3/make/g++/postgresql-client + pnpm + a warm pnpm
|
||||||
# store. The install step resolves from the baked store (--prefer-offline)
|
# store. The install step resolves from the baked store (--prefer-offline)
|
||||||
# instead of paying a ~731s cold fetch + native compile every run.
|
# instead of paying a ~731s cold fetch + native compile every run.
|
||||||
|
#
|
||||||
|
# PINNED to an immutable lock-tag (#1328, brain D27): ci-image.yml pushes
|
||||||
|
# lock-<sha256(pnpm-lock.yaml)[:12]> atomically with :latest, so the two are
|
||||||
|
# byte-identical at push time. A mutable :latest resolves per-pod at pull time
|
||||||
|
# on the k8s backend, which made CI verdicts non-reproducible (same tree, same
|
||||||
|
# config, different images across runs; see #1324 comment 23382/23386). The pin
|
||||||
|
# changes ONLY through reviewed commits; a wrong tag fails loudly at image pull.
|
||||||
|
#
|
||||||
|
# Bump procedure: when a recipe change (pnpm-lock.yaml / Dockerfile.ci) lands on
|
||||||
|
# main, ci-image.yml pushes lock-<new>; a follow-up PR updates this anchor.
|
||||||
|
# Until then pipelines keep the old pin: reproducible, with the documented
|
||||||
|
# network-fallback lag (frozen-lockfile resolves missing packages from network).
|
||||||
|
# Known limitation: lock- addresses the lockfile only, so a Dockerfile-only
|
||||||
|
# change re-pushes the same tag with new content (#1328 follow-up: recipe-hash).
|
||||||
variables:
|
variables:
|
||||||
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:latest'
|
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:lock-9cb7ffcd8828'
|
||||||
- &enable_pnpm 'corepack enable'
|
- &enable_pnpm 'corepack enable'
|
||||||
|
|
||||||
when:
|
when:
|
||||||
|
|||||||
@@ -18,7 +18,12 @@
|
|||||||
variables:
|
variables:
|
||||||
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
||||||
# toolchain + warm pnpm store. Kills the second cold install publish pays.
|
# toolchain + warm pnpm store. Kills the second cold install publish pays.
|
||||||
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:latest'
|
# PINNED to the immutable lock-tag, not :latest (#1328, brain D27): a mutable
|
||||||
|
# tag resolves per-pod at pull time on the k8s backend and made CI verdicts
|
||||||
|
# non-reproducible (#1324). Byte-identical to :latest at pin time (pushed
|
||||||
|
# atomically by the same kaniko run, main 712c770, 2026-07-26). Bump only via
|
||||||
|
# reviewed PR, per the procedure in .woodpecker/ci.yml's header comment.
|
||||||
|
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:lock-9cb7ffcd8828'
|
||||||
- &enable_pnpm 'corepack enable'
|
- &enable_pnpm 'corepack enable'
|
||||||
# Heavy kaniko image builds (~25 min) — gate them so a merge that only touches
|
# Heavy kaniko image builds (~25 min) — gate them so a merge that only touches
|
||||||
# the npm-only CLI (@mosaicstack/mosaic) or docs does NOT rebuild the platform
|
# the npm-only CLI (@mosaicstack/mosaic) or docs does NOT rebuild the platform
|
||||||
|
|||||||
Reference in New Issue
Block a user