Some checks failed
CI/CD / lint (pull_request) Successful in 1m15s
CI/CD / test (pull_request) Successful in 1m23s
CI/CD / typecheck (pull_request) Successful in 2m59s
CI/CD / smoke (pull_request) Failing after 1m57s
CI/CD / build (pull_request) Successful in 4m58s
CI/CD / publish (pull_request) Has been skipped
Same hazard as the package build, with the cluster on the receiving end: a
branch behind main builds images missing whatever landed there, and deploy-k8s.sh
pins that sha in Pulumi — making the stale build the cluster's source of truth.
build-mcpd.sh gets its own call because it is run standalone as well as from
deploy-k8s.sh, so neither can rely on the other having checked.
`--dry-run` is exempt. It builds and cuts over nothing, and blocking a read-only
inspection is exactly what teaches people to export MCPCTL_ALLOW_BEHIND_MAIN=1
permanently — which would disable the gate for the real deploys too.
The failure text is now artifact-agnostic ("produce an artifact" / "shipping
it"), since one helper now speaks for packages, images and deploys.
Verified against a synthetic ref one commit ahead: build-mcpd.sh exits 1 before
any docker work, and deploy-k8s.sh exits 1 before the test gate, the pg_dump,
the image build and pulumi. Neither the working tree nor HEAD was moved to test
this — the ref was built with git commit-tree and deleted afterwards.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019wUmrfkVQR6CKcYKxENq7k
90 lines
2.6 KiB
Bash
Executable File
90 lines
2.6 KiB
Bash
Executable File
#!/bin/bash
|
|
# Build mcpd Docker image and push to Gitea container registry.
|
|
#
|
|
# Usage:
|
|
# ./build-mcpd.sh [tag] # Build for native arch
|
|
# ./build-mcpd.sh [tag] --platform linux/amd64 # Build for specific platform
|
|
# ./build-mcpd.sh [tag] --multi-arch # Build for both amd64 and arm64
|
|
set -e
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
PROJECT_ROOT="$(dirname "$SCRIPT_DIR")"
|
|
cd "$PROJECT_ROOT"
|
|
|
|
# Load .env for GITEA_TOKEN
|
|
if [ -f .env ]; then
|
|
set -a; source .env; set +a
|
|
fi
|
|
|
|
# This pushes an image to the registry, so the same staleness gate as the package
|
|
# builds applies. Run standalone as well as from deploy-k8s.sh, hence its own copy.
|
|
source "$SCRIPT_DIR/check-main-sync.sh"
|
|
check_main_sync
|
|
|
|
# Push directly to internal address (external proxy has body size limit)
|
|
REGISTRY="10.0.0.194:3012"
|
|
IMAGE="mcpd"
|
|
TAG="${1:-latest}"
|
|
|
|
# Parse optional flags
|
|
PLATFORM=""
|
|
MULTI_ARCH=false
|
|
shift 2>/dev/null || true
|
|
while [[ $# -gt 0 ]]; do
|
|
case "$1" in
|
|
--platform)
|
|
PLATFORM="$2"
|
|
shift 2
|
|
;;
|
|
--multi-arch)
|
|
MULTI_ARCH=true
|
|
shift
|
|
;;
|
|
*)
|
|
shift
|
|
;;
|
|
esac
|
|
done
|
|
|
|
if [ "$MULTI_ARCH" = true ]; then
|
|
echo "==> Building multi-arch mcpd image (linux/amd64 + linux/arm64)..."
|
|
podman build --platform linux/amd64,linux/arm64 \
|
|
--manifest "$IMAGE:$TAG" -f deploy/Dockerfile.mcpd .
|
|
|
|
echo "==> Tagging manifest as $REGISTRY/michal/$IMAGE:$TAG..."
|
|
podman tag "$IMAGE:$TAG" "$REGISTRY/michal/$IMAGE:$TAG"
|
|
|
|
echo "==> Logging in to $REGISTRY..."
|
|
podman login --tls-verify=false -u michal -p "$GITEA_TOKEN" "$REGISTRY"
|
|
|
|
echo "==> Pushing manifest to $REGISTRY/michal/$IMAGE:$TAG..."
|
|
podman manifest push --tls-verify=false --all \
|
|
"$REGISTRY/michal/$IMAGE:$TAG" "docker://$REGISTRY/michal/$IMAGE:$TAG"
|
|
else
|
|
PLATFORM_FLAG=""
|
|
if [ -n "$PLATFORM" ]; then
|
|
PLATFORM_FLAG="--platform $PLATFORM"
|
|
echo "==> Building mcpd image for $PLATFORM..."
|
|
else
|
|
echo "==> Building mcpd image (native arch)..."
|
|
fi
|
|
|
|
podman build $PLATFORM_FLAG -t "$IMAGE:$TAG" -f deploy/Dockerfile.mcpd .
|
|
|
|
echo "==> Tagging as $REGISTRY/michal/$IMAGE:$TAG..."
|
|
podman tag "$IMAGE:$TAG" "$REGISTRY/michal/$IMAGE:$TAG"
|
|
|
|
echo "==> Logging in to $REGISTRY..."
|
|
podman login --tls-verify=false -u michal -p "$GITEA_TOKEN" "$REGISTRY"
|
|
|
|
echo "==> Pushing to $REGISTRY/michal/$IMAGE:$TAG..."
|
|
podman push --tls-verify=false "$REGISTRY/michal/$IMAGE:$TAG"
|
|
fi
|
|
|
|
# Ensure package is linked to the repository
|
|
source "$SCRIPT_DIR/link-package.sh"
|
|
link_package "container" "$IMAGE"
|
|
|
|
echo "==> Done!"
|
|
echo " Image: $REGISTRY/michal/$IMAGE:$TAG"
|