fix(ci): smoke-containers pulls base images mirror-first with fallback + retry (#137) #138

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/137-smoke-mirror-pull in i main 2026-07-19 09:31:39 +00:00
Ägare

Closes #137 (phase 1). Makes CI resilient to external-registry outages like the codeberg.org 504 that flaked PR #136's smoke job, and stops fetching base images from outside the instance on every run (principle 1).

Changes

  • registry-mirror role — mirror the smoke base images into the Forgejo registry alongside the existing Renovate entry: forgejo/postgres/caddy via the group_vars *_image/*_image_tag refs (so a Renovate tag bump flows through automatically, no duplicated pin), and kanidm as a literal (its var isn't global; comment notes to keep it in lockstep with roles/kanidm/defaults).
  • scripts/smoke-containers.py — load_mirror_map() builds upstream→mirror refs from the role config; pull_image() tries the mirror first (one shot), then the upstream with retries + backoff. The fallback makes it non-breaking while the mirror is populated; the retry alone already survives the transient-5xx class that flaked #136.

Validation

  • python3 -m py_compile clean; ansible-lint roles/registry-mirror passes (production profile).
  • Unit-tested the actual functions against the real role config + a stubbed podman: load_mirror_map resolves all 5 entries; pull_image covers mirror-hit, mirror-miss→upstream, upstream-504-retry-then-success (the #136 flake), unmapped→upstream, and total-failure reporting.

Remaining (tracked in #137, needs prod)

  1. Apply site.yml → the mirror timer populates the 4 new packages.
  2. Make those org packages CI-pullable — public visibility (base images are public upstream) or a scoped podman login in the CI workflow. Until then, mirror-first falls back to upstream (still fixed by the retry). smoke currently skips git.gitborg.se/… as "not pullable in CI", which is exactly this gap.
Closes #137 (phase 1). Makes CI resilient to external-registry outages like the codeberg.org 504 that flaked PR #136's smoke job, and stops fetching base images from outside the instance on every run (principle 1). ### Changes - **`registry-mirror` role** — mirror the smoke base images into the Forgejo registry alongside the existing Renovate entry: forgejo/postgres/caddy via the group_vars `*_image`/`*_image_tag` refs (so a Renovate tag bump flows through automatically, no duplicated pin), and kanidm as a literal (its var isn't global; comment notes to keep it in lockstep with `roles/kanidm/defaults`). - **`scripts/smoke-containers.py`** — `load_mirror_map()` builds upstream→mirror refs from the role config; `pull_image()` tries the **mirror first (one shot)**, then the **upstream with retries + backoff**. The fallback makes it non-breaking while the mirror is populated; the retry alone already survives the transient-5xx class that flaked #136. ### Validation - `python3 -m py_compile` clean; `ansible-lint roles/registry-mirror` passes (production profile). - Unit-tested the actual functions against the real role config + a stubbed podman: `load_mirror_map` resolves all 5 entries; `pull_image` covers mirror-hit, mirror-miss→upstream, upstream-504-retry-then-success (the #136 flake), unmapped→upstream, and total-failure reporting. ### Remaining (tracked in #137, needs prod) 1. Apply `site.yml` → the mirror timer populates the 4 new packages. 2. Make those org packages **CI-pullable** — public visibility (base images are public upstream) or a scoped `podman login` in the CI workflow. Until then, mirror-first falls back to upstream (still fixed by the retry). smoke currently skips `git.gitborg.se/…` as "not pullable in CI", which is exactly this gap.
supernaut lade till 1 incheckning 2026-07-19 09:27:20 +00:00
fix(ci): smoke-containers pulls base images mirror-first with fallback + retry (#137)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 3m29s
230ff9fb20
The smoke test pulled base images live from external registries every run, so a
transient upstream 5xx failed CI (PR #136 hit a codeberg.org 504) and every run
reached outside the instance (sovereignty wrinkle).

- registry-mirror: mirror forgejo/postgres/caddy (group_vars refs, Renovate-tracked)
  + kanidm into the Forgejo registry, alongside the existing renovate entry.
- smoke-containers.py: for each public image, try the in-instance mirror ref first
  (one shot), then the upstream ref with retries + backoff. Fallback keeps it
  non-breaking until the mirror is populated + CI-pullable; the retry already rides
  out the transient-5xx flake. Unit-tested the map + pull-candidate logic.

Remaining (issue #137): make the mirrored packages CI-pullable (public packages or
a scoped podman login) so mirror-first actually hits instead of falling back.
supernaut sammanfogade incheckning a99e066e55 till main 2026-07-19 09:31:39 +00:00
supernaut tog bort grenen feat/137-smoke-mirror-pull 2026-07-19 09:31:39 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!138
Ingen beskrivning angiven.