Skip to content

feat: PR image cleanup action for GHCR #270

Description

@conbrad

Every PR leaves a <pr-number> tag on GHCR, plus an untagged version for each re-push. quickstart-openshift-helpers .pr-close.yml retags on merge but never deletes anything. Storage is free for public packages, but private packages count against org storage, and the package version lists keep growing.

Writing cleanup by hand is risky because promotion makes images share digests:

  • prod, test or latest can be the same version as a PR tag, so deleting that version deletes prod.
  • With multi-arch images (see the builder platforms issue), the per-architecture manifests are untagged children of an index. A naive "delete untagged" breaks every multi-arch tag.

Proposal

A cleanup action (new, or a cleanup mode on image-tracker) for PR-close flows:

  1. Delete PR-only versions. Delete package versions whose only tag is the PR tag.
  2. Protect promoted images. Skip any version that a protected tag (prod, test, latest, configurable) points to or references as an index child.
  3. Opt-in untagged pruning. Optionally delete untagged versions older than N days, with the same protection for index children.

Acceptance

  • Deletes PR-only versions across a list of packages
  • Never removes a version tagged or referenced byest for a multi-arch index promoted to prod
  • Untagged pruning is opt-in and never deletes index children
  • Missing packages or versions are a no-op, not a
  • Follow-up (separate PR): quickstart-openshift-helpers .pr-close.yml calls the cleanup action

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions