Skip to content

ci(il4): add a one-time workflow to mirror db fixtures into GHCR - #3093

Closed
terryozaki-wq wants to merge 1 commit into
devfrom
ci/il4-accp-mirror-db-fixtures-workflow
Closed

terryozaki-wq wants to merge 1 commit into
devfrom
ci/il4-accp-mirror-db-fixtures-workflow

Conversation

@terryozaki-wq

Copy link
Copy Markdown

Summary

  • Adds a new, workflow_dispatch-only workflow, .github/workflows/il4-accp-mirror-db-fixtures.yml. It runs nothing automatically.
  • When manually triggered, it pulls the pinned postgres/mariadb images used as disposable test fixtures by the IL4-dev-ACCP branch's comparison step, and republishes them to ghcr.io/semoss/semoss-il4-db-fixtures/{postgres,mariadb}, authenticating only with the run's own GITHUB_TOKEN.
  • This file needs to exist on the default branch for GitHub to allow dispatching it at all (a general GitHub Actions requirement) — the branch that actually consumes it (IL4-dev-ACCP) already has it as of eed46dbf8.

Why

The IL4-dev-ACCP build was hitting Docker Hub's anonymous pull rate limit when pulling postgres/mariadb for its concurrent baseline/candidate comparison step. Mirroring those two images into this repo's own GHCR namespace removes the need for any Docker Hub credential in that recurring CI path — once mirrored, the comparison step pulls from ghcr.io using the GHCR login it already has.

Test plan

  • python3 -c "import yaml; yaml.safe_load(...)" — parses cleanly
  • actionlint — clean
  • bash -n on every run: block — clean
  • Manually dispatch this workflow once merged, to produce the real GHCR digests and finish pinning docker/il4/database_fixtures.py on IL4-dev-ACCP to the mirror

🤖 Generated with Claude Code

workflow_dispatch-only; runs nothing automatically. Lets the IL4-dev-ACCP
branch's comparison-fixture mirror (postgres/mariadb -> GHCR) actually be
triggered, since GitHub only allows dispatching a workflow once it also
exists on the default branch. See IL4-dev-ACCP for the consuming change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@terryozaki-wq
terryozaki-wq requested a review from a team as a code owner October 6, 2026 00:26
@snyk-io

snyk-io Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@terryozaki-wq

Copy link
Copy Markdown
Author

Closing without merging — keeping this change scoped to IL4-dev-ACCP instead of the default branch. Reworking the mirror workflow to trigger via push instead of workflow_dispatch so it doesn't need default-branch registration.

@terryozaki-wq
terryozaki-wq deleted the ci/il4-accp-mirror-db-fixtures-workflow branch October 6, 2026 00:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant