Publish release images to GHCR and a CLI that defaults to them - #71
Draft
Tomer Glottmann (tomergee) wants to merge 1 commit into
Draft
Tomer Glottmann (tomergee) wants to merge 1 commit into
Tomer Glottmann (tomergee) wants to merge 1 commit into
Conversation
Nothing published images for this repo: the Makefile pushed to a personal registry, releases carried no assets, and the manifest command's error message pointed at "images published by the latest release" that did not exist. Every user, including the quickstart, had to build and push ate-env-api and ate-env-guest first. A release workflow now runs on every v* tag (and by hand for an existing tag): ko builds both images for linux/amd64 and linux/arm64, pushes them to ghcr.io/<org>/<repo>/ate-env-api and ate-env-guest tagged with the release and latest, signs them with cosign keyless signing bound to the workflow's identity, then builds the ate-env CLI for linux and darwin on amd64 and arm64 with the two digests and the version baked in, uploads the binaries, an images_<tag>.txt and checksums as release assets, and writes an Images section with the digests and the verify command into the release notes. The CLI gains build-time defaults: a release binary's `manifest --api-image` and `manifest template --guest-image` default to the images published with it, `ate-env --version` prints the tag, and a source build keeps the flags required with messages that say why. The worker image stays a required flag, since ateom-gvisor comes from the Substrate repo and must match the Substrate version on the cluster; the message says so. `make build-cli` reproduces a release-style binary locally. A ci workflow runs the Go build, vet and tests, the license-header check, and the Python client tests on pull requests and main; the repo had no checks before. The guest's bash base image is pinned by digest in .ko.yaml so a published guest is reproducible. docs/release.md describes the artifacts, pinning, verification, cutting and republishing a release, and the one-time organization setup for GitHub Container Registry; the README quickstart no longer needs image flags with a release binary.
Tomer Glottmann (tomergee)
marked this pull request as draft
October 1, 2026 16:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Make the images of this repo something a customer downloads rather than builds.
.github/workflows/release.yaml: on everyv*tag, or by hand for an existing tag, buildsate-env-apiandate-env-guestwith ko for linux/amd64 and linux/arm64, pushes them toghcr.io/agent-substrate/env/<image>tagged with the release andlatest, signs them with cosign keyless signing (bound to this repo's Actions identity), builds theate-envCLI for linux and darwin on amd64 and arm64 with the two digests baked in, and uploads binaries,images_<tag>.txtand checksums as release assets. The release notes get an## Imagessection with the digests and the verify command; a republish replaces it instead of duplicating it.ate-env manifest --api-imageandate-env manifest template --guest-imagedefault to the release's images, so the quickstart needs no image flags for this repo.ate-env --versionprints the tag. A source build keeps the flags required, with messages that explain the two cases.make build-clireproduces a release-style binary locally.--worker-imagestays required.ateom-gvisoris a Substrate image and must match the Substrate version on the cluster; Substrate publishes nothing yet, so the message points at building it there. That is the remaining piece for a zero-build customer experience and belongs to the Substrate repo..github/workflows/ci.yaml: Go build, vet, tests, license headers, and the Python client tests on PRs andmain. The repo had no checks before..ko.yaml: the guest'sbashbase pinned by digest, so a published guest image is reproducible.docs/release.md: artifacts, pinning by digest, signature verification, cutting and republishing a release, the one-time organization setup for GHCR. README: Installation and a new Images section; quickstart commands updated.Why this shape
latestmoves.ate-env manifest" work without reading release notes, and keeps the CLI and the images of one release consistent by construction.First-time setup (maintainers, once)
git tag -a v0.0.11 -m v0.0.11 && git push origin v0.0.11), watch thereleaseworkflow.Testing
go test ./...passes; new test covers the source-build and release-build flag defaults and the worker-image message.make build-cli ATE_ENV_API_IMAGE=... ATE_ENV_GUEST_IMAGE=... VERSION=v9.9.9produces a binary whose--versionand flag defaults carry the values, which is exactly what the workflow does.run:block passesbash -n; every referenced action tag exists. The Python CI steps were run locally as written.mainand a tag is pushed; the first tag is the real test, andworkflow_dispatchexists to rerun it without a new tag.Relation to other PRs
Independent of #69 and #70. Once this lands and a release is cut, the docs in #70 can name the published guest image instead of a placeholder.