feat(images): move the self-hosted image paths to the bitborg namespace #408

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/rename-3-container-images in i main 2026-08-10 11:09:49 +00:00
Ägare

ADR 0039 §3, the registry half. Applied and verified on prod 2026-08-10.

bitborg/gitborg-web → bitborg/bitborg-web, bitborg/gitborg-auth-reconciler → bitborg/bitborg-auth-reconciler, bitborg/gitborg-reconcile-trigger → bitborg/bitborg-reconcile-trigger.

Retagged first, digests preserved

Six release tags were copied with skopeo copy --all before anything was repointed, reusing the credential and pattern registry-mirror already has (token from its EnvironmentFile, passed on stdin, never in argv). Registry credentials are per host and the host was unchanged, so no re-login.

skopeo copy preserves the digest, so no release tag was re-cut — the prohibition in the plan is satisfied. Verified by comparing raw manifests old vs new: byte-identical on all three live tags.

Copied: reconciler v1.0.0/v1.1.0/v1.2.1/v1.3.0, shim v0.1.0, portal latest, plus the four newest portal sha-* tags.

Full change surface

Three image variables, both # renovate: depName= annotations (plain comments that nothing templates — exactly how the reconciler and shim went untracked for a day, #395), and registry_retention_packages (gitborg-web, gitborg-web/cache). That last one matters more than it looks: retention keyed on a package name that no longer receives pushes would silently stop pruning the one that does.

Also corrected three stale markers found along the way, none of which were §3 work:

  • renovate_image was marked # LEGACY-PIN org+repo but its path is already bitborg/renovate — the org moved with an earlier tranche and the marker was never cleared.
  • registry_mirror_registry was marked # LEGACY-PIN. moves in §3 — it is derived from bitborg_registry_host, which moved in §4b.
  • A comment in roles/web/tasks/main.yml still named git.gitborg.se/bitborg/gitborg-web — both segments stale.

Verification

Baseline before: changed=0 on both hosts. Apply: changed=10, failed=0 — three pulls, three Quadlet units, deploy-verify script, retention script, and two container restarts that --check could not show (both are on the check-mode-blind list).

Per the plan's completion criterion, checked on the running containers rather than the declarations:

bitborg-web                git.bitborg.se/bitborg/bitborg-web:latest
bitborg-reconcile-trigger  git.bitborg.se/bitborg/bitborg-reconcile-trigger:v0.1.0

The reconciler is a oneshot timer so it is absent from podman ps; its Quadlet references bitborg-auth-reconciler:v1.3.0 and it completed a real run with gitborg_reconciler_last_run_status=0 after the repoint, which is the stronger proof.

All 8 probes 1, only Watchdog firing, gitborg_deploy_verify_last_run_status=0. scripts/check-renovate-annotations.py confirms both renamed annotations still resolve — the guard added earlier today catching exactly the class of drift §3 was warned about.

Deliberately out of scope

The locally-built images (localhost/gitborg-caddy, localhost/gitborg-runner-controller, and the v1.3.0-gitborg1 kanidm-provision tag) are a separate window. Each triggers a local rebuild with its own blast radius — Caddy fronts every public hostname, and the runner-controller is what deletes ephemeral CI VMs — so mixing them with a registry repoint would make attribution hard.

Companion CI changes: bitborg-web #211, bitborg-auth-reconciler #39, bitborg-reconcile-trigger #25, bitborg-payment #32.

ADR 0039 §3, the registry half. Applied and verified on prod 2026-08-10. `bitborg/gitborg-web` → `bitborg/bitborg-web`, `bitborg/gitborg-auth-reconciler` → `bitborg/bitborg-auth-reconciler`, `bitborg/gitborg-reconcile-trigger` → `bitborg/bitborg-reconcile-trigger`. ## Retagged first, digests preserved Six release tags were copied with `skopeo copy --all` before anything was repointed, reusing the credential and pattern `registry-mirror` already has (token from its EnvironmentFile, passed on stdin, never in argv). Registry credentials are per **host** and the host was unchanged, so no re-login. `skopeo copy` preserves the digest, so **no release tag was re-cut** — the prohibition in the plan is satisfied. Verified by comparing raw manifests old vs new: byte-identical on all three live tags. Copied: reconciler `v1.0.0`/`v1.1.0`/`v1.2.1`/`v1.3.0`, shim `v0.1.0`, portal `latest`, plus the four newest portal `sha-*` tags. ## Full change surface Three image variables, **both `# renovate: depName=` annotations** (plain comments that nothing templates — exactly how the reconciler and shim went untracked for a day, #395), and **`registry_retention_packages`** (`gitborg-web`, `gitborg-web/cache`). That last one matters more than it looks: retention keyed on a package name that no longer receives pushes would silently stop pruning the one that does. Also corrected three stale markers found along the way, none of which were §3 work: - `renovate_image` was marked `# LEGACY-PIN org+repo` but its path is already `bitborg/renovate` — the org moved with an earlier tranche and the marker was never cleared. - `registry_mirror_registry` was marked `# LEGACY-PIN. moves in §3` — it is derived from `bitborg_registry_host`, which moved in §4b. - A comment in `roles/web/tasks/main.yml` still named `git.gitborg.se/bitborg/gitborg-web` — both segments stale. ## Verification Baseline before: `changed=0` on both hosts. Apply: `changed=10`, `failed=0` — three pulls, three Quadlet units, deploy-verify script, retention script, and two container restarts that `--check` could not show (both are on the check-mode-blind list). Per the plan's completion criterion, checked on the **running containers** rather than the declarations: ``` bitborg-web git.bitborg.se/bitborg/bitborg-web:latest bitborg-reconcile-trigger git.bitborg.se/bitborg/bitborg-reconcile-trigger:v0.1.0 ``` The reconciler is a oneshot timer so it is absent from `podman ps`; its Quadlet references `bitborg-auth-reconciler:v1.3.0` and it completed a real run with `gitborg_reconciler_last_run_status=0` **after** the repoint, which is the stronger proof. All 8 probes `1`, only `Watchdog` firing, `gitborg_deploy_verify_last_run_status=0`. `scripts/check-renovate-annotations.py` confirms both renamed annotations still resolve — the guard added earlier today catching exactly the class of drift §3 was warned about. ## Deliberately out of scope The locally-built images (`localhost/gitborg-caddy`, `localhost/gitborg-runner-controller`, and the `v1.3.0-gitborg1` kanidm-provision tag) are a separate window. Each triggers a local rebuild with its own blast radius — Caddy fronts every public hostname, and the runner-controller is what deletes ephemeral CI VMs — so mixing them with a registry repoint would make attribution hard. Companion CI changes: bitborg-web #211, bitborg-auth-reconciler #39, bitborg-reconcile-trigger #25, bitborg-payment #32.
supernaut lade till 1 incheckning 2026-08-10 10:06:51 +00:00
feat(images): move the self-hosted image paths to the bitborg namespace
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m40s
64a1d97254
supernaut lade till 1 incheckning 2026-08-10 10:59:34 +00:00
feat(images): rename the locally-built caddy and runner-controller images
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m41s
8d0f189810
supernaut sammanfogade incheckning 081880ccb3 till main 2026-08-10 11:09:49 +00:00
supernaut tog bort grenen feat/rename-3-container-images 2026-08-10 11:09:50 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!408
Ingen beskrivning angiven.