Conversation
After the Docker Hub manifests are promoted and digest-verified, copy the four promoted tags to ghcr.io/<repo> with 'docker buildx imagetools create'. Registry-to-registry manifest copy keeps GHCR tags on the exact same digests as Docker Hub -- same workflow, same tags, same digests, as requested in the issue -- with no rebuild lane and no new secrets (GITHUB_TOKEN + packages: write). Each mirrored tag is digest-checked against the just-verified Docker Hub manifest so a silently diverged mirror fails the release. Architecture-suffixed staging tags stay Docker-Hub-only; attestations keep their index.docker.io subject names and remain verifiable against the shared digests. Fixes pgsty#224
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements #224 by adding a mirror stage at the end of the Docker release pipeline: after the multi-architecture manifests are promoted on Docker Hub and their digests verified, the four promoted tags (
RELEASE.*,latest,RELEASE.*-distroless,distroless) are copied toghcr.io/<repository>usingdocker buildx imagetools create.Why a mirror stage instead of dual-registry pushes
ghcr.io/pgsty/silo:RELEASE...resolves to the same digest as Docker Hub — the issue'ssame workflow / same tags / same digestsask, with zero changes to the six build lanes, SBOM generation, or the six existing attestations.GITHUB_TOKENwithpackages: write.Notes for reviewers
*-amd64/*-arm64) remain Docker-Hub-only; only the promoted multi-arch tags are mirrored. Happy to mirror those too if preferred.index.docker.io/pgsty/silosubject names; they remain verifiable against the shared digests by passing the Docker Hub subject registry explicitly. If GHCR-native attestation subjects are wanted later, that would be an additionalactions/attestpair per mirrored subject — out of scope here.