From 152ea05f99efd5df64adaa59db8b88696ba775a8 Mon Sep 17 00:00:00 2001 From: Thecave3 Date: Wed, 23 Sep 2026 08:35:55 -0400 Subject: [PATCH] ci: rebuild the dependent container images on a merge A downstream repository builds images that bake this library's source, and a merge here left them stale: nothing asked for a rebuild. Dispatches that repository's publish workflow, pinned to this commit. The pin matters as much as the trigger -- those builds clone by branch when no pin is given, so the layer cache replays the old clone and republishes an unchanged image while reporting success. This repository is public, so the downstream repository is named by the DOWNSTREAM_IMAGE_REPO variable rather than inline, and the job fails with a clear message if it is unset. The owner comes from github.repository_owner for the same reason. Runs on a hosted runner: minutes are free for a public repository, and this one has never had access to a self-hosted runner. Authenticates with a GitHub App rather than a PAT, so the token is minted per run, expires, and is scoped to the one downstream repository. Assisted-by: Claude:claude-opus-5 --- .../workflows/refresh-dependent-images.yml | 64 +++++++++++++++++++ 1 file changed, 64 insertions(+) create mode 100644 .github/workflows/refresh-dependent-images.yml diff --git a/.github/workflows/refresh-dependent-images.yml b/.github/workflows/refresh-dependent-images.yml new file mode 100644 index 00000000..3077d060 --- /dev/null +++ b/.github/workflows/refresh-dependent-images.yml @@ -0,0 +1,64 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026 Northeastern University +# SPDX-License-Identifier: Apache-2.0 + +name: Refresh dependent images + +# A downstream repository builds container images that bake this library's +# source, so a merge here leaves those images stale until they are rebuilt +# against this commit. Passing the commit matters as much as the trigger: those +# builds clone by branch when no pin is given, and the layer cache would replay +# the old clone and republish an unchanged image while reporting success. +# +# The downstream repository is named by the DOWNSTREAM_IMAGE_REPO variable +# rather than inline, since this repository is public. +on: + push: + branches: [main] + paths-ignore: + - '**.md' + - 'docs/**' + - '.gitignore' + workflow_dispatch: + +# One refresh at a time, and never cancel one halfway: the build it starts +# writes shared moving tags. +concurrency: + group: refresh-dependent-images + cancel-in-progress: false + +jobs: + refresh: + # This repository is public, so hosted minutes are free here and it has + # never had access to a self-hosted runner. + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Check the downstream repository is configured + env: + DOWNSTREAM: ${{ vars.DOWNSTREAM_IMAGE_REPO }} + run: | + if [ -z "$DOWNSTREAM" ]; then + echo "::error::set the DOWNSTREAM_IMAGE_REPO variable to the repository that builds the dependent images" + exit 1 + fi + + - name: Mint a scoped token + id: apptoken + uses: actions/create-github-app-token@v1 + with: + app-id: ${{ secrets.CI_BOT_APP_ID }} + private-key: ${{ secrets.CI_BOT_APP_PRIVATE_KEY }} + owner: ${{ github.repository_owner }} + repositories: ${{ vars.DOWNSTREAM_IMAGE_REPO }} + + - name: Rebuild the images that bake this commit + env: + GH_TOKEN: ${{ steps.apptoken.outputs.token }} + DOWNSTREAM: ${{ vars.DOWNSTREAM_IMAGE_REPO }} + SHA: ${{ github.sha }} + run: | + gh workflow run publish-on-merge.yml \ + -R "${{ github.repository_owner }}/${DOWNSTREAM}" \ + -f image-tag=latest \ + -f libe3-commit="$SHA" + echo "requested a rebuild pinned to $SHA"