Skip to content

ci: publish Docker image to GHCR; installer pulls it - #3

Merged
pipozzz merged 1 commit into
mainfrom
ci/ghcr-docker-publish
Sep 1, 2026
Merged

pipozzz merged 1 commit into
mainfrom
ci/ghcr-docker-publish

Conversation

@pipozzz

@pipozzz pipozzz commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Sets up automated Docker image build/publish so install.sh can pull a real image.

  • GHCR publish workflow (nomploy.yml) — builds the app image and pushes to ghcr.io/<owner>/nomploy using the built-in GITHUB_TOKEN (no external registry secrets). Triggers on push to main, version tags, and manual dispatch. Replaces the old Docker Hub workflow that needed secrets + Dokploy MCP/CLI/SDK sync jobs.
  • install.sh now defaults to ghcr.io/nomploy/nomploy:latest.

After merge, the push to main builds + publishes the image. One manual step: set the nomploy package to Public in its GHCR package settings so a fresh server can docker pull without auth (or docker login ghcr.io on the server).

🤖 Generated with Claude Code

- Replace the Docker Hub build workflow (needed external secrets + Dokploy
  MCP/CLI/SDK sync jobs) with a clean GHCR publish using the built-in
  GITHUB_TOKEN. Builds on push to main, tags, and manual dispatch.
- install.sh now defaults to ghcr.io/nomploy/nomploy:latest.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@pipozzz
pipozzz merged commit 58d6405 into main Sep 1, 2026
4 checks passed
@pipozzz
pipozzz deleted the ci/ghcr-docker-publish branch September 1, 2026 11:53
pipozzz added a commit that referenced this pull request Sep 29, 2026
…d; add release preflight

#1 Pack deploys re-cloned the whole registry every time via `nomad-pack
registry add`. Now that deploys are pinned to an immutable ref, skip the add
when that ref's pack cache dir already exists
($HOME/.cache/nomad/packs/<registry>/<ref>) — much faster deploys for a
large registry, safe because the ref can't change. Unpinned (fallback) still
re-adds to pull latest.

#3 scripts/check.sh runs the CI-equivalent prod build (switch:prod + cold
tsc -p tsconfig.server.json) — the only reliable way to catch CI-only type
failures (bit us on v0.30.133/.135; dev `tsc --noEmit` + its .tsbuildinfo
cache hide them). release.sh now runs it as a pre-flight gate (SKIP_CHECK=1
to override). App tsc is informational only — Next has ignoreBuildErrors.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant