image-retag¶
Publishes a release by retagging the image the default-branch pipeline already
built for that commit. Runs as the child pipeline
image-release triggers when it finds the commit's sha-
tag in the registry.
What it deliberately does not do¶
There is no build, no scan and no reproducibility check here. Each omission has a reason:
| omitted | because |
|---|---|
| build | the bytes already exist — a rebuild of a commit is byte-identical, verified by digest equality in the registry |
| scan | colophon's release MR scanned the exact commit being tagged; under fast-forward its head is the tagged commit |
| reproducibility check | the same release MR ran it on that commit |
What this does not cover is a newly-disclosed advisory against an image released weeks ago. That is the nightly rescan's job.
It verifies the retag landed¶
The job re-reads the released tag and compares it with the source digest. A retag that did not land fails the job rather than reporting success — a check that cannot fail is not a check.
It also re-reads the source digest rather than trusting the probe's: between the probe and this job the source tag could in principle have moved.
Inputs¶
| Input | Type | Default | Description |
|---|---|---|---|
stage |
string | publish |
Stage to assign the job to. You must declare it. |
image |
string | $CI_REGISTRY_IMAGE |
Registry repository holding the image, without a tag. |
sha_tag |
string | sha-$CI_COMMIT_SHORT_SHA |
Tag to retag from. |
tag_minor |
boolean | true |
Also move the vX.Y tag to this release. |
tag_latest |
boolean | true |
Also move latest to this release. |
crane_image |
string | digest-pinned crane:debug |
crane:debug publishes no version tag. |
registry_user |
string | $CI_REGISTRY_USER |
Registry username. |
registry_password |
string | $CI_REGISTRY_PASSWORD |
Registry password. |
Jobs produced¶
| Job | Runs when |
|---|---|
retag:semver |
the tag matches ^v\d+\.\d+\.\d+$ |
Usage¶
In .gitlab-ci-retag.yml:
include:
- component: gitlab.com/phpboyscout/cicd/[email protected]
inputs:
stage: publish
See also¶
image-release— decides which child pipeline runs- Spec 0094