feat(images): move the self-hosted image paths to the bitborg namespace #408
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!408
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/rename-3-container-images"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ADR 0039 §3, the registry half. Applied and verified on prod 2026-08-10.
bitborg/gitborg-web→bitborg/bitborg-web,bitborg/gitborg-auth-reconciler→bitborg/bitborg-auth-reconciler,bitborg/gitborg-reconcile-trigger→bitborg/bitborg-reconcile-trigger.Retagged first, digests preserved
Six release tags were copied with
skopeo copy --allbefore anything was repointed, reusing the credential and patternregistry-mirroralready has (token from its EnvironmentFile, passed on stdin, never in argv). Registry credentials are per host and the host was unchanged, so no re-login.skopeo copypreserves the digest, so no release tag was re-cut — the prohibition in the plan is satisfied. Verified by comparing raw manifests old vs new: byte-identical on all three live tags.Copied: reconciler
v1.0.0/v1.1.0/v1.2.1/v1.3.0, shimv0.1.0, portallatest, plus the four newest portalsha-*tags.Full change surface
Three image variables, both
# renovate: depName=annotations (plain comments that nothing templates — exactly how the reconciler and shim went untracked for a day, #395), andregistry_retention_packages(gitborg-web,gitborg-web/cache). That last one matters more than it looks: retention keyed on a package name that no longer receives pushes would silently stop pruning the one that does.Also corrected three stale markers found along the way, none of which were §3 work:
renovate_imagewas marked# LEGACY-PIN org+repobut its path is alreadybitborg/renovate— the org moved with an earlier tranche and the marker was never cleared.registry_mirror_registrywas marked# LEGACY-PIN. moves in §3— it is derived frombitborg_registry_host, which moved in §4b.roles/web/tasks/main.ymlstill namedgit.gitborg.se/bitborg/gitborg-web— both segments stale.Verification
Baseline before:
changed=0on both hosts. Apply:changed=10,failed=0— three pulls, three Quadlet units, deploy-verify script, retention script, and two container restarts that--checkcould not show (both are on the check-mode-blind list).Per the plan's completion criterion, checked on the running containers rather than the declarations:
The reconciler is a oneshot timer so it is absent from
podman ps; its Quadlet referencesbitborg-auth-reconciler:v1.3.0and it completed a real run withgitborg_reconciler_last_run_status=0after the repoint, which is the stronger proof.All 8 probes
1, onlyWatchdogfiring,gitborg_deploy_verify_last_run_status=0.scripts/check-renovate-annotations.pyconfirms both renamed annotations still resolve — the guard added earlier today catching exactly the class of drift §3 was warned about.Deliberately out of scope
The locally-built images (
localhost/gitborg-caddy,localhost/gitborg-runner-controller, and thev1.3.0-gitborg1kanidm-provision tag) are a separate window. Each triggers a local rebuild with its own blast radius — Caddy fronts every public hostname, and the runner-controller is what deletes ephemeral CI VMs — so mixing them with a registry repoint would make attribution hard.Companion CI changes: bitborg-web #211, bitborg-auth-reconciler #39, bitborg-reconcile-trigger #25, bitborg-payment #32.