Repository navigation
phase2(s19.b): GHCR cache for router + controller; fix Dockerfile.base check - #111
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 29, 2026
Conversation
…ckerfile.base check - Generalise sandbox-base-publish.yml → image-cache-publish.yml as a 3-image matrix (sandbox-base, inference-router, controller). Each branch is gated on its own path filter. - container-scan in ci.yml: pull inference router from GHCR (with local rebuild fallback), matching the pattern already in place for sandbox base. Single GHCR login at job top. - sandbox-images/openclaw/Dockerfile.base: remove the false-negative channel-dep sanity check from S19. Channel deps in OpenClaw 2026.4.26 don't live in /usr/local/lib/node_modules/openclaw/node_modules/ — they live under dist/extensions/<channel>/node_modules/ and are surfaced via the link_pkg symlink block. Replace with "trust openclaw doctor exit code" + set -o pipefail (real failures surface; success path doesn't fail on missing staging). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2-ci-image-cache-router-controller
branch
April 29, 2026 21:58
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…ckerfile.base check (#111) - Generalise sandbox-base-publish.yml → image-cache-publish.yml as a 3-image matrix (sandbox-base, inference-router, controller). Each branch is gated on its own path filter. - container-scan in ci.yml: pull inference router from GHCR (with local rebuild fallback), matching the pattern already in place for sandbox base. Single GHCR login at job top. - sandbox-images/openclaw/Dockerfile.base: remove the false-negative channel-dep sanity check from S19. Channel deps in OpenClaw 2026.4.26 don't live in /usr/local/lib/node_modules/openclaw/node_modules/ — they live under dist/extensions/<channel>/node_modules/ and are surfaced via the link_pkg symlink block. Replace with "trust openclaw doctor exit code" + set -o pipefail (real failures surface; success path doesn't fail on missing staging). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase 2 follow-up to S19 — three fixes:
1. Extend GHCR image cache to inference-router + controller
Renamed `sandbox-base-publish.yml` → `image-cache-publish.yml`. Now publishes a matrix of 3 images on dev/main pushes:
Each matrix branch only runs when its own paths changed. `workflow_dispatch` always runs.
2. `container-scan` pulls inference router from GHCR
Same pattern as the sandbox base image: pull from `ghcr.io/azure/azureclaw-inference-router:latest` if `inference-router/` + `Cargo.{toml,lock}` are unchanged in the PR. Falls back to local build. Cuts the longest single step in container-scan when not touching router code.
Single GHCR login at the top of the job.
3. Fix the channel-dep sanity check in Dockerfile.base from S19
The S19 check asserted that `grammy`, `@discordjs/opus`, `@slack/bolt`, `@larksuiteoapi/node-sdk` exist under `/usr/local/lib/node_modules/openclaw/node_modules/`. Wrong location — channel deps in OpenClaw 2026.4.26 actually live under `dist/extensions//node_modules/` and are surfaced via the `link_pkg` symlink block earlier in the same Dockerfile.
Replaced with: trust `openclaw doctor --fix` exit code + add `set -o pipefail` so the `tail -40` pipe surfaces doctor failures. Drop `|| true` mask so real failures still fail the build.
Manual follow-up after merge
After image-cache-publish.yml runs successfully on dev for the first time, mark these GHCR packages private (Settings → Packages → each → Change visibility):
CI in this repo can pull private GHCR images via `GITHUB_TOKEN` (`packages: read`).
Verification
This is the verification PR — container-scan must go green.