Files
Reactive-Resume/docs/agents/container-publishing.md
T

5.6 KiB

Container publishing

The repository is reactive-resume/reactive-resume. Docker Hub remains docker.io/amruthpillai/reactive-resume; GHCR follows the repository as ghcr.io/reactive-resume/reactive-resume. Do not derive Docker Hub's image name from github.repository.

Builds and release safety

.github/workflows/docker-build.yml builds AMD64 and ARM64 on matching native Blacksmith 32-vCPU runners. Blacksmith's persistent Docker builder caches layers and cache mounts; the architecture-specific cache keys keep the two builders separate.

Trigger Published aliases Production deployment
Push to main sha-*, nightly, timestamped nightly No
Manual dispatch, default release=false sha-*, canary-<run-id>-<attempt> No
Push of a v* tag or explicit release=true sha-*, latest, version/major/minor Yes: SSH redeploy and Cloudflare purge

Manual canaries first run a cache-only build on each architecture, then publish, merge, and sign both registry images. Run one with:

gh workflow run docker-build.yml --repo reactive-resume/reactive-resume --ref main -f release=false

Both registries retain SBOMs, maximum provenance, and Cosign signatures. Publishing uses DOCKER_USERNAME / DOCKER_PASSWORD for Docker Hub and the destination repository's GITHUB_TOKEN with packages: write for GHCR. New GHCR packages need public visibility, repository linkage, and Actions access before consumers can pull anonymously.

Verification and historical images

Check the manifest for linux/amd64 and linux/arm64, then pull both using an empty Docker configuration with explicit empty registry credentials to prove anonymous access (a completely empty directory can still discover a system credential helper):

docker buildx imagetools inspect ghcr.io/reactive-resume/reactive-resume:v5.3.0
registry_config=$(mktemp -d)
printf '%s\n' '{"auths":{"ghcr.io":{}}}' > "$registry_config/config.json"
docker --config "$registry_config" pull --platform linux/amd64 ghcr.io/reactive-resume/reactive-resume:v5.3.0
docker --config "$registry_config" pull --platform linux/arm64 ghcr.io/reactive-resume/reactive-resume:v5.3.0
rm -r "$registry_config"

On September 11, 2026, latest, v5, v5.3, and v5.3.0 were copied to the then-current public GHCR package, ghcr.io/reactive-resume/app. Both architectures were pulled anonymously; the original Cosign signature, SBOMs, provenance, and image digest were verified. The signed Blacksmith canary canary-34582818410-1 also passed on both registries without deploying production.

The original v5.3.0 at the previous GHCR address has digest sha256:c487ec5edcfe054bcb312fcd498f868e56f274756d0046b01c83f210855017ab. Copy complete image indexes rather than rebuilding historical releases or using a single-platform pull/tag/push. Preserve embedded attestation manifests and copy attached signatures separately. Verify the resulting digest before moving aliases. Retain the old GHCR packages for historical pulls; future updates publish under the new namespace. The repository rename does not rename registry packages. Rebuilt images use the new repository source label and signing identity; historical digests and signatures do not change. Release aliases are mutable: pin the original digest above if you need the pre-rename artifact.

New signatures identify https://github.com/reactive-resume/reactive-resume/.github/workflows/docker-build.yml@<ref>. Historical signatures and image source labels retain the old repository identity. Verify historical v5.3.0 with its original workflow identity, even at its new registry address:

cosign verify \
  --certificate-identity https://github.com/amruthpillai/reactive-resume/.github/workflows/docker-build.yml@refs/heads/main \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  ghcr.io/reactive-resume/app@sha256:c487ec5edcfe054bcb312fcd498f868e56f274756d0046b01c83f210855017ab

After the rename, GitHub reports use_immutable_subject: true and subject prefix repo:reactive-resume@245328954/reactive-resume@249995750. Inspect actual claims when updating external OIDC trust policies; the repository URL alone does not describe the subject.

Independent migration items

  • GitHub Sponsors stays AmruthPillai; Open Collective stays reactive-resume.
  • server.json keeps MCP registry identifier io.github.amruthpillai/reactive-resume. Changing that identifier creates a separate registry identity and requires its own migration.
  • The old GitHub repository redirects to the new repository. Never recreate the old repository.
  • The old Pages address https://amruthpillai.github.io/reactive-resume/ returned 404 on September 11, 2026. GitHub now reports https://reactive-resume.github.io/reactive-resume/; repository redirects do not redirect Pages traffic. No active repository references use the old Pages URL.
  • Confirm documentation hosting, Crowdin, Docker Hub source metadata, sponsorship access rewards, and any external OIDC policies in their owning accounts. Repository transfer alone does not verify those integrations.

Track availability and supported copied tags in migration issue #3503. No database reset, volume deletion, or resume-data migration is required.

References: Blacksmith Docker caching, GitHub package permissions, Cosign verification.