fix(release): link the image and chart to the repo on GHCR (ADR-0020) #38
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/link-packages-to-repo"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Neither published package is connected to a repository on GHCR, for two different reasons. Both are one line of metadata — plus the record explaining why the value is what it is.
GHCR links a package to a repository by matching
org.opencontainers.image.sourceagainst a github.com URL.https://forgejo.webgrip.dev/webgrip/ploegChart.yamlsources[0], and there was nosourcesfieldThe decision, not just the fix — ADR-0020
The value change looks like an inconsistency until explained, which is precisely what ADR-0004 said about the module path. So this is 0004's asymmetry applied to a second artifact class:
Forgejo is not demoted — it moves to
image.url, "URL to find more information on the image", which is where a canonical home belongs. The governance claim lives in the ledger, not in a label.The record captures the constraint that removed most of the option space — the image is built once and digest-copied, so one label serves all three registries; per-registry values would mean per-registry builds and the loss of identical-digest mirroring — and weighs the three rejected alternatives (keep Forgejo + link by hand, add a bespoke
canonical-sourcelabel, stop publishing to GHCR).Two facts that settled it, both checked rather than argued:
revision 0225131… → HTTP 200), and all 38 tags are present, so the annotation's claim is true for every holder of the artifactforgejo.webgrip.devdoes not resolve off the VPN, so the old value was a dead hostname for the entire audience GHCR exists to servedocker-mirror.yml, no consumer)Confirmation is a gate, not a promise
Verify image metadata labelsnow assertsimage.sourceagainstEXPECTED_SOURCEfor every platform, so a regression to the Forgejo value fails the Harbor job instead of silently orphaning the packages again. Exercised against a correct image (passes) and one carrying the old value (fails, naming the offending platform).Helm's
Chart.yaml→ OCI annotation mapping was verified by pushing the packaged chart to a throwaway local registry and reading the manifest back:Gates
go build/vet/test ./...green — includinginternal/ledger, the ADR consistency validator —gofmtclean,helm lintand all three chart renderings.Two caveats
fix(release): link the image and chart to the repo on GHCRto fix(release): link the image and chart to the repo on GHCR (ADR-0020)