-
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): standardize image tag step ID across integration workflows #646
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -133,7 +133,7 @@ jobs: | |
| # Determine the correct image tag based on trigger context | ||
| # For PRs: pr-{number}-{sha}, For branches: {sanitized-branch}-{sha} | ||
| - name: Determine image tag | ||
| id: image | ||
| id: determine-tag | ||
| env: | ||
| EVENT: ${{ github.event.workflow_run.event }} | ||
| REF: ${{ github.event.workflow_run.head_branch }} | ||
|
|
@@ -199,7 +199,7 @@ jobs: | |
| max_attempts: 3 | ||
| retry_wait_seconds: 10 | ||
| command: | | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.image.outputs.tag }}" | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.determine-tag.outputs.tag }}" | ||
| echo "Pulling image: $IMAGE_NAME" | ||
|
Comment on lines
+202
to
203
|
||
| docker pull "$IMAGE_NAME" | ||
| docker tag "$IMAGE_NAME" charon:local | ||
|
Comment on lines
201
to
205
|
||
|
|
@@ -211,12 +211,12 @@ jobs: | |
| if: steps.pull_image.outcome == 'failure' | ||
| env: | ||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| echo "⚠️ Registry pull failed, falling back to artifact..." | ||
|
|
||
| # Determine artifact name based on source type | ||
| if [[ "${{ steps.image.outputs.source_type }}" == "pr" ]]; then | ||
| if [[ "${{ steps.determine-tag.outputs.source_type }}" == "pr" ]]; then | ||
| PR_NUM=$(echo '${{ toJson(github.event.workflow_run.pull_requests) }}' | jq -r '.[0].number') | ||
| ARTIFACT_NAME="pr-image-${PR_NUM}" | ||
| else | ||
|
|
@@ -240,7 +240,7 @@ jobs: | |
| # Validate image freshness by checking SHA label | ||
| - name: Validate image SHA | ||
| env: | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| LABEL_SHA=$(docker inspect charon:local --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' | cut -c1-7) | ||
| echo "Expected SHA: $SHA" | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -111,7 +111,7 @@ jobs: | |
| # Determine the correct image tag based on trigger context | ||
| # For PRs: pr-{number}-{sha}, For branches: {sanitized-branch}-{sha} | ||
| - name: Determine image tag | ||
| id: image | ||
| id: determine-tag | ||
|
||
| env: | ||
| EVENT: ${{ github.event.workflow_run.event }} | ||
| REF: ${{ github.event.workflow_run.head_branch }} | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -96,7 +96,7 @@ jobs: | |
| # Determine the correct image tag based on trigger context | ||
| # For PRs: pr-{number}-{sha}, For branches: {sanitized-branch}-{sha} | ||
| - name: Determine image tag | ||
| id: image | ||
| id: determine-tag | ||
| env: | ||
| EVENT: ${{ github.event.workflow_run.event }} | ||
| REF: ${{ github.event.workflow_run.head_branch }} | ||
|
|
@@ -162,7 +162,7 @@ jobs: | |
| max_attempts: 3 | ||
| retry_wait_seconds: 10 | ||
| command: | | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.image.outputs.tag }}" | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.determine-tag.outputs.tag }}" | ||
| echo "Pulling image: $IMAGE_NAME" | ||
|
Comment on lines
+165
to
166
|
||
| docker pull "$IMAGE_NAME" | ||
| docker tag "$IMAGE_NAME" charon:local | ||
|
|
@@ -174,12 +174,12 @@ jobs: | |
| if: steps.pull_image.outcome == 'failure' | ||
| env: | ||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| echo "⚠️ Registry pull failed, falling back to artifact..." | ||
|
|
||
| # Determine artifact name based on source type | ||
| if [[ "${{ steps.image.outputs.source_type }}" == "pr" ]]; then | ||
| if [[ "${{ steps.determine-tag.outputs.source_type }}" == "pr" ]]; then | ||
| PR_NUM=$(echo '${{ toJson(github.event.workflow_run.pull_requests) }}' | jq -r '.[0].number') | ||
| ARTIFACT_NAME="pr-image-${PR_NUM}" | ||
| else | ||
|
|
@@ -203,7 +203,7 @@ jobs: | |
| # Validate image freshness by checking SHA label | ||
| - name: Validate image SHA | ||
| env: | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| LABEL_SHA=$(docker inspect charon:local --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' | cut -c1-7) | ||
| echo "Expected SHA: $SHA" | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -96,7 +96,7 @@ jobs: | |
| # Determine the correct image tag based on trigger context | ||
| # For PRs: pr-{number}-{sha}, For branches: {sanitized-branch}-{sha} | ||
| - name: Determine image tag | ||
| id: image | ||
| id: determine-tag | ||
| env: | ||
| EVENT: ${{ github.event.workflow_run.event }} | ||
| REF: ${{ github.event.workflow_run.head_branch }} | ||
|
|
@@ -162,7 +162,7 @@ jobs: | |
| max_attempts: 3 | ||
| retry_wait_seconds: 10 | ||
| command: | | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.image.outputs.tag }}" | ||
| IMAGE_NAME="ghcr.io/${{ github.repository_owner }}/charon:${{ steps.determine-tag.outputs.tag }}" | ||
| echo "Pulling image: $IMAGE_NAME" | ||
|
Comment on lines
+165
to
166
|
||
| docker pull "$IMAGE_NAME" | ||
| docker tag "$IMAGE_NAME" charon:local | ||
|
|
@@ -174,12 +174,12 @@ jobs: | |
| if: steps.pull_image.outcome == 'failure' | ||
| env: | ||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| echo "⚠️ Registry pull failed, falling back to artifact..." | ||
|
|
||
| # Determine artifact name based on source type | ||
| if [[ "${{ steps.image.outputs.source_type }}" == "pr" ]]; then | ||
| if [[ "${{ steps.determine-tag.outputs.source_type }}" == "pr" ]]; then | ||
| PR_NUM=$(echo '${{ toJson(github.event.workflow_run.pull_requests) }}' | jq -r '.[0].number') | ||
| ARTIFACT_NAME="pr-image-${PR_NUM}" | ||
| else | ||
|
|
@@ -203,7 +203,7 @@ jobs: | |
| # Validate image freshness by checking SHA label | ||
| - name: Validate image SHA | ||
| env: | ||
| SHA: ${{ steps.image.outputs.sha }} | ||
| SHA: ${{ steps.determine-tag.outputs.sha }} | ||
| run: | | ||
| LABEL_SHA=$(docker inspect charon:local --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' | cut -c1-7) | ||
| echo "Expected SHA: $SHA" | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The step id
determine-tagcontains a hyphen but is referenced using dot notation (steps.determine-tag...). In GitHub Actions expressions,-is parsed as an operator, so this will not resolve the step outputs and can break the workflow. Rename the step id to use underscores (e.g.,determine_tag) and update references, or use bracket notation when accessing the step outputs.