Skip to content

feat(docker): Dockerfile.operator + node publish CI — distroless multi-arch (ADR-0815) - #184

Merged
lusoris merged 1 commit into
masterfrom
worktree-agent-ad6e3b565a001d2e6
Jun 3, 2026
Merged

lusoris merged 1 commit into
masterfrom
worktree-agent-ad6e3b565a001d2e6

Conversation

@lusoris

@lusoris lusoris commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds docker/Dockerfile.operator: pure-Go cmd/vmafx-operator binary into gcr.io/distroless/static-debian12, runs as nonroot (uid 65532), multi-arch amd64+arm64 via BuildKit native cross-compilation (no QEMU needed — CGO_ENABLED=0).
  • Adds .github/workflows/docker-publish-operator-node.yml: fires on v* tags + workflow_dispatch; builds and pushes ghcr.io/vmafx/vmafx-operator and ghcr.io/vmafx/vmafx-node (CPU, amd64+arm64); cosign keyless sign + syft CycloneDX SBOM attest for both; smoke-test + aggregator gate. Mirrors the docker-publish-production.yml pattern (ADR-0698).
  • docker/Dockerfile.node (existing, ADR-0717) is unchanged — the workflow now wires it to release CI for the first time.
  • ADR-0815, docs/backends/operator.md runbook, changelog fragment.

Deliverables checklist (ADR-0108)

  • Research digest: no digest needed: straightforward Dockerfile + workflow addition mirroring ADR-0698 pattern
  • Decision matrix: ADR-0815 ## Alternatives considered (static vs cc distroless; separate vs inline Dockerfile)
  • AGENTS.md invariant note: no rebase-sensitive invariants — all files are fork-local docker/CI, no C/Python surface touched
  • Reproducer/smoke-test: docker build -f docker/Dockerfile.operator --target operator -t ghcr.io/vmafx/vmafx-operator:dev .
  • changelog.d/added/0815-operator-node-distroless-dockerfiles.md
  • docs/rebase-notes.md entry: no rebase impact — all fork-local files

Reproducer

# Build and smoke-test the operator image locally
docker build -f docker/Dockerfile.operator --target operator \
  -t ghcr.io/vmafx/vmafx-operator:dev .
docker run --rm ghcr.io/vmafx/vmafx-operator:dev --help

# Build and smoke-test the node CPU image locally
docker build -f docker/Dockerfile.node --target node-cpu \
  -t ghcr.io/vmafx/vmafx-node:dev .
docker run --rm ghcr.io/vmafx/vmafx-node:dev --help

PR checklist

  • make lint passes (no C/Python files touched)
  • pre-commit hooks all green (YAML, secrets, ADR collision, Conventional Commits)
  • No Netflix golden assertions modified
  • No git push --force to master
  • docs/state.md update: not applicable (no bug opened/closed)
  • ffmpeg-patches/ update: not applicable (no C-API surface changed)
  • Human-readable docs: docs/backends/operator.md added

🤖 Generated with Claude Code

@lusoris
lusoris enabled auto-merge (squash) May 29, 2026 10:26
@lusoris
lusoris disabled auto-merge May 29, 2026 11:43
@lusoris
lusoris marked this pull request as draft May 29, 2026 11:43
@lusoris
lusoris force-pushed the worktree-agent-ad6e3b565a001d2e6 branch from 7409de9 to e477368 Compare May 29, 2026 12:12
@lusoris

lusoris commented May 29, 2026

Copy link
Copy Markdown
Contributor Author

Contaminated (60 files) — needs reconstruction, skipping rebase per session policy

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:37
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by master after merge marathon 2026-05-31.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the worktree-agent-ad6e3b565a001d2e6 branch May 31, 2026 13:43
@lusoris
lusoris restored the worktree-agent-ad6e3b565a001d2e6 branch May 31, 2026 18:43
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:50
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
#184/#439 (#535)

Four ADR numbers referenced in open DRAFT PR bodies had no backing .md
files on disk, violating CLAUDE.md rule 8 (ADR before implementation).

- ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint
  program + cilium/ebpf Go loader; 37× warm-cache clip-open latency
  improvement; opt-in via VMAFX_EBPF_BYPASS=1.
- ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl,
  five test cases covering the full operator/node/trainer stack.
- ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and
  vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12,
  uid 65532, amd64+arm64, cosign + syft SBOM.
- ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted"
  baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment.

Also adds four index rows to docs/adr/README.md.

Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any
open PRs; flagged in the PR description for maintainer awareness.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…-0815)

Adds docker/Dockerfile.operator (distroless/static-debian12, pure-Go CGO_ENABLED=0,
multi-arch amd64+arm64 via BuildKit native cross-compilation) for cmd/vmafx-operator.
Wires both the operator and the existing docker/Dockerfile.node to a new release CI
workflow (.github/workflows/docker-publish-operator-node.yml) that fires on v* tags
and workflow_dispatch, builds linux/amd64+linux/arm64, signs via cosign keyless OIDC,
and attests CycloneDX SBOMs for both ghcr.io/vmafx/vmafx-operator and
ghcr.io/vmafx/vmafx-node.

- docker/Dockerfile.operator: go-builder → distroless/static-debian12 (nonroot uid 65532)
- .github/workflows/docker-publish-operator-node.yml: build-operator + build-node +
  smoke-test + all-images aggregator gate; mirrors docker-publish-production.yml pattern
- docs/adr/0815-operator-node-distroless-dockerfiles.md: decision record
- docs/backends/operator.md: user-facing runbook (pull, verify, run, env vars, upgrade)
- changelog.d/added/0815-operator-node-distroless-dockerfiles.md: fragment

ADR-0815. Closes follow-up from PR #152 (vmafx-operator skeleton, ADR-0714).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the worktree-agent-ad6e3b565a001d2e6 branch from e477368 to a8a08ed Compare June 3, 2026 14:34
@lusoris
lusoris marked this pull request as ready for review June 3, 2026 14:34
Copilot AI review requested due to automatic review settings June 3, 2026 14:34
@lusoris
lusoris merged commit 267531c into master Jun 3, 2026
@lusoris
lusoris deleted the worktree-agent-ad6e3b565a001d2e6 branch June 3, 2026 14:35
@lusoris
lusoris removed the request for review from Copilot June 3, 2026 14:55
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant