Skip to content

Pull urunit and the guest kernel from ghcr.io/nofireai, pinned - #1

Open
panosmaurikos wants to merge 1 commit into
nofirefrom
ci/mirror-guest-images
Open

panosmaurikos wants to merge 1 commit into
nofirefrom
ci/mirror-guest-images

Conversation

@panosmaurikos

@panosmaurikos panosmaurikos commented Sep 27, 2026 •

Copy link
Copy Markdown

Every Containerfile build injects urunit and the Cloud Hypervisor kernel, and bunny resolved both as harbor.nbfc.io/...:latest (hops/parse_file.go; libarchive the same way in hops/llb.go). So each build:

  • fetched unpinned artifacts: the guest kernel could change between two builds of the same commit without anyone noticing;
  • depended on a registry we do not run: on 2026-08-26 harbor.nbfc.io served a certificate for the wrong name and brain-go's urunc-e2e build failed on it (run 33002508492).

This PR:

  • adds .github/workflows/mirror-nofire.yml, which copies the three images into ghcr.io/nofireai with skopeo copy --all --preserve-digests, and fails unless each copy is byte-identical to its source;
  • pins the defaults to those copies by digest:
Default Now
urunit ghcr.io/nofireai/urunit@sha256:ae7553fc…
Cloud Hypervisor kernel ghcr.io/nofireai/bunny/linux-kernel-cloud-hypervisor@sha256:a9638a1d…
libarchive (initrd path) ghcr.io/nofireai/bunny/libarchive@sha256:5244491f…

The digests are today's upstream latest, so the output of a build does not change. The qemu and firecracker kernels still come from harbor; we do not use them.
Refs NOFireAI/brain-go#106

Every Containerfile build injects urunit and the Cloud Hypervisor kernel,
and bunny resolved both as harbor.nbfc.io/...:latest. So each build fetched
unpinned artifacts from a registry we do not run: the guest kernel could
change between two builds of the same commit, and a harbor outage failed the
build outright (a wrong-name certificate on 2026-08-26 broke brain-go's
urunc-e2e run 33002508492).

Mirror urunit, the Cloud Hypervisor kernel and libarchive into
ghcr.io/nofireai with digests preserved, and pin the defaults to those
digests. The new workflow copies them with skopeo and fails unless each copy
is byte-identical to its source.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant