Skip to content

image-retag

Publishes a release by retagging the image the default-branch pipeline already built for that commit. Runs as the child pipeline image-release triggers when it finds the commit's sha- tag in the registry.

What it deliberately does not do

There is no build, no scan and no reproducibility check here. Each omission has a reason:

omitted because
build the bytes already exist — a rebuild of a commit is byte-identical, verified by digest equality in the registry
scan colophon's release MR scanned the exact commit being tagged; under fast-forward its head is the tagged commit
reproducibility check the same release MR ran it on that commit

What this does not cover is a newly-disclosed advisory against an image released weeks ago. That is the nightly rescan's job.

It verifies the retag landed

The job re-reads the released tag and compares it with the source digest. A retag that did not land fails the job rather than reporting success — a check that cannot fail is not a check.

It also re-reads the source digest rather than trusting the probe's: between the probe and this job the source tag could in principle have moved.

Inputs

Input Type Default Description
stage string publish Stage to assign the job to. You must declare it.
image string $CI_REGISTRY_IMAGE Registry repository holding the image, without a tag.
sha_tag string sha-$CI_COMMIT_SHORT_SHA Tag to retag from.
tag_minor boolean true Also move the vX.Y tag to this release.
tag_latest boolean true Also move latest to this release.
crane_image string digest-pinned crane:debug crane:debug publishes no version tag.
registry_user string $CI_REGISTRY_USER Registry username.
registry_password string $CI_REGISTRY_PASSWORD Registry password.

Jobs produced

Job Runs when
retag:semver the tag matches ^v\d+\.\d+\.\d+$

Usage

In .gitlab-ci-retag.yml:

include:
  - component: gitlab.com/phpboyscout/cicd/[email protected]
    inputs:
      stage: publish

See also