Skip to content

ci: publish fork release images to public ECR - #9

Merged
dmakarenko merged 1 commit into
goodnotesfrom
kratos-ecr-publish-workflow-20260930
Oct 1, 2026
Merged

dmakarenko merged 1 commit into
goodnotesfrom
kratos-ecr-publish-workflow-20260930

Conversation

@dmakarenko

@dmakarenko dmakarenko commented Sep 30, 2026 •

Copy link
Copy Markdown

Adds .github/workflows/publish-image.yml: on a v*-gn-v* tag push, build linux/amd64 and linux/arm64 natively from .docker/Dockerfile-build and push one multi-arch tag to public.ecr.aws/f2w7e5y1/goodnotes/kratos.

Why: images for v5–v9 were pushed by hand. Auth is GitHub OIDC with the role ARN in repo variable AWS_ECR_PUBLIC_ROLE_ARN (no long-lived keys). The role is arn:aws:iam::701646985046:role/github-kratos-image-publish from GoodNotes/shared-infra#2226.

Tested: actionlint passes. Actions runs on the fork and AWS_ECR_PUBLIC_ROLE_ARN is set, so the first real run needs only the role applied.

Depends on #11 (builder golang:1.26-trixie, runner distroless/static-debian13), because Dockerfile-build on golang:1.22-bullseye no longer builds.

https://claude.ai/code/session_0155gve5RBgPYnT29G5TRp9o

Builds linux/amd64 and linux/arm64 on native runners from .docker/Dockerfile-build
for v*-gn-v* tags and merges them into one tag in public.ecr.aws/f2w7e5y1/goodnotes/kratos.
Auth uses GitHub OIDC with the role ARN in repo variable AWS_ECR_PUBLIC_ROLE_ARN.

Claude-Session: https://claude.ai/code/session_0155gve5RBgPYnT29G5TRp9o
@dmakarenko
dmakarenko force-pushed the kratos-ecr-publish-workflow-20260930 branch from 5ee4427 to 1e65c38 Compare September 30, 2026 20:30
@dmakarenko
dmakarenko merged commit b310514 into goodnotes Oct 1, 2026
2 checks passed
@dmakarenko
dmakarenko deleted the kratos-ecr-publish-workflow-20260930 branch October 1, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant