You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(builder): arm64 builds with tag isolation, plus builder-merge #269
builder builds only the runner's architecture (amd64 on ubuntu-*). Developers on Apple Silicon run every image under emulation, which is slow and crash-prone for native-heavy images like GDAL. Teams that want arm64 have to leave builder and write their own build workflow. bcgov/wps did this in bcgov/wps#5899.
Two constraints shape the fix:
No QEMU. Emulating arm64 on an amd64 runner is very slow for compile-heavy builds, so arm64 has to build natively on an ARM runner (ubuntu-24.04-arm).
Deploys stay amd64. OpenShift runs amd64 only, and the deploy contract (build → image-tracker → deploy by digest) relies on the canonical tags (:<pr>, :<sha>, :test, :prod) and outputs.digest being amd64. An arm64 build must never change those or block a deploy.
Proposal
architecture input on builder. Leave it unset (or amd64) for today's behaviour. Set it to arm64 on an ARM runner and every tag, plus the tag_fallback lookup (test-arm64), gets an -arm64 suffix, so it can never overwrite a canonical tag. It must match the runner: a mismatch fails rather than emulating. The arm64 job keeps its own build cache, and nothing that deploys depends on it.
image-tracker only resolves the deploy architecture. The -arm64 images carry the same revision label as the canonical image, so without this check image-tracker's fallback scan can return an arm64 image for an amd64 deploy. A new architecture input (default amd64) means a multi-arch index must include it and a single-arch image must be it; other images are skipped. Images whose architecture is unknown are still accepted.
Optional builder-merge action. For teams that want one tag that runs natively everywhere, it combines the canonical amd64 image and the -arm64 image into a separate :<pr>-multiarch / :<sha>-multiarch tag. It never writes canonical tags.
Problem
builderbuilds only the runner's architecture (amd64 onubuntu-*). Developers on Apple Silicon run every image under emulation, which is slow and crash-prone for native-heavy images like GDAL. Teams that want arm64 have to leavebuilderand write their own build workflow. bcgov/wps did this in bcgov/wps#5899.Two constraints shape the fix:
ubuntu-24.04-arm).image-tracker→ deploy by digest) relies on the canonical tags (:<pr>,:<sha>,:test,:prod) andoutputs.digestbeing amd64. An arm64 build must never change those or block a deploy.Proposal
architectureinput onbuilder. Leave it unset (oramd64) for today's behaviour. Set it toarm64on an ARM runner and every tag, plus thetag_fallbacklookup (test-arm64), gets an-arm64suffix, so it can never overwrite a canonical tag. It must match the runner: a mismatch fails rather than emulating. The arm64 job keeps its own build cache, and nothing that deploys depends on it.image-trackeronly resolves the deploy architecture. The-arm64images carry the same revision label as the canonical image, so without this checkimage-tracker's fallback scan can return an arm64 image for an amd64 deploy. A newarchitectureinput (defaultamd64) means a multi-arch index must include it and a single-arch image must be it; other images are skipped. Images whose architecture is unknown are still accepted.builder-mergeaction. For teams that want one tag that runs natively everywhere, it combines the canonical amd64 image and the-arm64image into a separate:<pr>-multiarch/:<sha>-multiarchtag. It never writes canonical tags.Acceptance
architectureunset,builderbehaves exactly as todayarchitecture: arm64builds natively on an ARM runner, publishes only-arm64tags, falls back to<tag_fallback>-arm64, and fails on a mismatched runneroutputs.digeststay amd64image-trackernever resolves a non-amd64 image by default, including through its fallback scanbuilder-mergepublishes an amd64 + arm64-multiarchindex and leaves canonical tags unchanged-arm64tags,image-trackerresolution,builder-merge, and the per-architecture fallbackbuilder-merge, and theimage-trackerarchitectureinput