Repository navigation
feat(docker): Dockerfile.operator + node publish CI — distroless multi-arch (ADR-0815) - #184
Merged
Merged
Conversation
lusoris
enabled auto-merge (squash)
May 29, 2026 10:26
lusoris
disabled auto-merge
May 29, 2026 11:43
lusoris
marked this pull request as draft
May 29, 2026 11:43
lusoris
force-pushed
the
worktree-agent-ad6e3b565a001d2e6
branch
from
May 29, 2026 12:12
7409de9 to
e477368
Compare
Contributor
Author
|
Contaminated (60 files) — needs reconstruction, skipping rebase per session policy |
lusoris
marked this pull request as ready for review
May 31, 2026 13:37
Contributor
Author
|
Superseded by master after merge marathon 2026-05-31. |
lusoris
marked this pull request as draft
May 31, 2026 18:50
3 of 6 tasks
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
#184/#439 (#535) Four ADR numbers referenced in open DRAFT PR bodies had no backing .md files on disk, violating CLAUDE.md rule 8 (ADR before implementation). - ADR-0779: eBPF FUSE bypass for rclone (PR #137) — probe-only tracepoint program + cilium/ebpf Go loader; 37× warm-cache clip-open latency improvement; opt-in via VMAFX_EBPF_BYPASS=1. - ADR-0783: k8s e2e integration test harness (PR #152) — kind + kuttl, five test cases covering the full operator/node/trainer stack. - ADR-0815: distroless multi-arch Dockerfiles for vmafx-operator and vmafx-node + release CI (PR #184) — gcr.io/distroless/static-debian12, uid 65532, amd64+arm64, cosign + syft SBOM. - ADR-0930: Helm chart NetworkPolicy default-deny + PSA "restricted" baseline (PR #439) — opt-in NetworkPolicy bundle, uid 65532 alignment. Also adds four index rows to docs/adr/README.md. Note: ADR-0715 and ADR-0716 do not exist and are not referenced by any open PRs; flagged in the PR description for maintainer awareness. Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…-0815) Adds docker/Dockerfile.operator (distroless/static-debian12, pure-Go CGO_ENABLED=0, multi-arch amd64+arm64 via BuildKit native cross-compilation) for cmd/vmafx-operator. Wires both the operator and the existing docker/Dockerfile.node to a new release CI workflow (.github/workflows/docker-publish-operator-node.yml) that fires on v* tags and workflow_dispatch, builds linux/amd64+linux/arm64, signs via cosign keyless OIDC, and attests CycloneDX SBOMs for both ghcr.io/vmafx/vmafx-operator and ghcr.io/vmafx/vmafx-node. - docker/Dockerfile.operator: go-builder → distroless/static-debian12 (nonroot uid 65532) - .github/workflows/docker-publish-operator-node.yml: build-operator + build-node + smoke-test + all-images aggregator gate; mirrors docker-publish-production.yml pattern - docs/adr/0815-operator-node-distroless-dockerfiles.md: decision record - docs/backends/operator.md: user-facing runbook (pull, verify, run, env vars, upgrade) - changelog.d/added/0815-operator-node-distroless-dockerfiles.md: fragment ADR-0815. Closes follow-up from PR #152 (vmafx-operator skeleton, ADR-0714). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
force-pushed
the
worktree-agent-ad6e3b565a001d2e6
branch
from
June 3, 2026 14:34
e477368 to
a8a08ed
Compare
lusoris
marked this pull request as ready for review
June 3, 2026 14:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docker/Dockerfile.operator: pure-Gocmd/vmafx-operatorbinary intogcr.io/distroless/static-debian12, runs asnonroot(uid 65532), multi-arch amd64+arm64 via BuildKit native cross-compilation (no QEMU needed — CGO_ENABLED=0)..github/workflows/docker-publish-operator-node.yml: fires onv*tags +workflow_dispatch; builds and pushesghcr.io/vmafx/vmafx-operatorandghcr.io/vmafx/vmafx-node(CPU, amd64+arm64); cosign keyless sign + syft CycloneDX SBOM attest for both; smoke-test + aggregator gate. Mirrors thedocker-publish-production.ymlpattern (ADR-0698).docker/Dockerfile.node(existing, ADR-0717) is unchanged — the workflow now wires it to release CI for the first time.Deliverables checklist (ADR-0108)
## Alternatives considered(static vs cc distroless; separate vs inline Dockerfile)docker build -f docker/Dockerfile.operator --target operator -t ghcr.io/vmafx/vmafx-operator:dev .changelog.d/added/0815-operator-node-distroless-dockerfiles.mddocs/rebase-notes.mdentry: no rebase impact — all fork-local filesReproducer
PR checklist
make lintpasses (no C/Python files touched)git push --forceto masterdocs/state.mdupdate: not applicable (no bug opened/closed)ffmpeg-patches/update: not applicable (no C-API surface changed)docs/backends/operator.mdadded🤖 Generated with Claude Code