Skip to content

phase2(s19.b): GHCR cache for router + controller; fix Dockerfile.base check - #111

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-ci-image-cache-router-controller
Apr 29, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-ci-image-cache-router-controller

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Phase 2 follow-up to S19 — three fixes:

1. Extend GHCR image cache to inference-router + controller

Renamed `sandbox-base-publish.yml` → `image-cache-publish.yml`. Now publishes a matrix of 3 images on dev/main pushes:

  • `-sandbox-base` (gated on `sandbox-images/openclaw/Dockerfile.base` + `vendor/sandbox-wheels/`)
  • `-inference-router` (gated on `inference-router/` + `Cargo.{toml,lock}`)
  • `-controller` (gated on `controller/` + `Cargo.{toml,lock}`)

Each matrix branch only runs when its own paths changed. `workflow_dispatch` always runs.

2. `container-scan` pulls inference router from GHCR

Same pattern as the sandbox base image: pull from `ghcr.io/azure/azureclaw-inference-router:latest` if `inference-router/` + `Cargo.{toml,lock}` are unchanged in the PR. Falls back to local build. Cuts the longest single step in container-scan when not touching router code.

Single GHCR login at the top of the job.

3. Fix the channel-dep sanity check in Dockerfile.base from S19

The S19 check asserted that `grammy`, `@discordjs/opus`, `@slack/bolt`, `@larksuiteoapi/node-sdk` exist under `/usr/local/lib/node_modules/openclaw/node_modules/`. Wrong location — channel deps in OpenClaw 2026.4.26 actually live under `dist/extensions//node_modules/` and are surfaced via the `link_pkg` symlink block earlier in the same Dockerfile.

Replaced with: trust `openclaw doctor --fix` exit code + add `set -o pipefail` so the `tail -40` pipe surfaces doctor failures. Drop `|| true` mask so real failures still fail the build.

Manual follow-up after merge

After image-cache-publish.yml runs successfully on dev for the first time, mark these GHCR packages private (Settings → Packages → each → Change visibility):

  • `azureclaw-sandbox-base`
  • `azureclaw-inference-router`
  • `azureclaw-controller`

CI in this repo can pull private GHCR images via `GITHUB_TOKEN` (`packages: read`).

Verification

This is the verification PR — container-scan must go green.

…ckerfile.base check

- Generalise sandbox-base-publish.yml → image-cache-publish.yml as a
  3-image matrix (sandbox-base, inference-router, controller). Each branch
  is gated on its own path filter.
- container-scan in ci.yml: pull inference router from GHCR (with local
  rebuild fallback), matching the pattern already in place for sandbox base.
  Single GHCR login at job top.
- sandbox-images/openclaw/Dockerfile.base: remove the false-negative
  channel-dep sanity check from S19. Channel deps in OpenClaw 2026.4.26
  don't live in /usr/local/lib/node_modules/openclaw/node_modules/ — they
  live under dist/extensions/<channel>/node_modules/ and are surfaced via
  the link_pkg symlink block. Replace with "trust openclaw doctor exit
  code" + set -o pipefail (real failures surface; success path doesn't
  fail on missing staging).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 5dec9b0 into dev Apr 29, 2026
14 of 15 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-ci-image-cache-router-controller branch April 29, 2026 21:58
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…ckerfile.base check (#111)

- Generalise sandbox-base-publish.yml → image-cache-publish.yml as a
  3-image matrix (sandbox-base, inference-router, controller). Each branch
  is gated on its own path filter.
- container-scan in ci.yml: pull inference router from GHCR (with local
  rebuild fallback), matching the pattern already in place for sandbox base.
  Single GHCR login at job top.
- sandbox-images/openclaw/Dockerfile.base: remove the false-negative
  channel-dep sanity check from S19. Channel deps in OpenClaw 2026.4.26
  don't live in /usr/local/lib/node_modules/openclaw/node_modules/ — they
  live under dist/extensions/<channel>/node_modules/ and are surfaced via
  the link_pkg symlink block. Replace with "trust openclaw doctor exit
  code" + set -o pipefail (real failures surface; success path doesn't
  fail on missing staging).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant