Skip to content

feat(CORE-5013): support fresh image rebuilds - #171

Draft
michikrug wants to merge 2 commits into
mainfrom
CORE-5013-fresh-image-builds
Draft

michikrug wants to merge 2 commits into
mainfrom
CORE-5013-fresh-image-builds

Conversation

@michikrug

@michikrug michikrug commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

CORE-5013

Type of Change

  • Enhancement / new feature

Description

Goal: let scheduled image rebuilds refresh packages and virus signatures without disabling caching for ordinary application builds.

Builds always check referenced base images for updates. The optional docker-build-no-cache input reruns Dockerfile steps and skips external cache transfers; it defaults to false. Digest-pinned bases remain pinned.

Dependencies: first of three PRs: this action → gha-workflows #520 → custom-images #537. The template exposes this input; the migration enables it to prevent cached ClamAV signatures.

Merge and release this first, then update the template’s temporary commit pin to the released SHA.

Review: check default cache behavior, opt-out handling, and the global pull: true change. ShellCheck and all 144 Bats tests passed; live build verification remains pending.

Checklist

  • Tests added and passing
  • Documentation updated
  • Ticket linked
  • Contributing guidelines / CLA confirmed

Co-authored-by: opencode <opencode@noreply.opencode.ai>
Co-authored-by: GitHub Copilot <copilot@noreply.github.com>

intent(image-freshness): scheduled package and virus-signature refreshes must execute again even when Dockerfile inputs are unchanged.
decision(base-images): always pull referenced bases so floating hardened tags receive updates; preserve digest pins.
rejected(cache-default): disabling cache globally would repeat expensive application builds; callers opt out instead.
rejected(compression): retain BuildKit defaults until compatibility testing demonstrates a need for forced gzip.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 17:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The looped no-cache test reuses accumulated outputs, allowing three intended scenarios to pass without being verified.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds optional fresh Docker image rebuilds while preserving normal caching behavior.

Changes:

  • Adds docker-build-no-cache input and cache controls.
  • Always checks base images for updates.
  • Documents and tests fresh-build behavior.
File Description
action.yml Wires fresh-build settings into Buildx.
scripts/​resolve-build-config.sh Resolves external cache configuration.
tests/​resolve-build-config.bats Tests cache behavior and validation.
README.md Documents the new input and behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/resolve-build-config.bats
Co-authored-by: opencode <opencode@noreply.opencode.ai>
Co-authored-by: GitHub Copilot <copilot@noreply.github.com>

learned(cache-tests): assertions read the first output entry, so accumulated outputs masked failures in later mode and architecture combinations.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants