Skip to content

feat: mirror images between GHCR and the OpenShift registry #271

Description

@conbrad

Problem

Teams publish images to one registry, either GHCR (via builder) or the OpenShift internal registry (via BuildConfigs), and their deployments pull from it at runtime. Whichever registry they use becomes a runtime dependency: if it's unreachable, every pod restart, scale-up and CronJob run fails with ImagePullBackOff, even though nothing was being deployed.

  • GHCR-only images fail on Silver when GHCR or GitHub is degraded. bcgov/wps hit this risk with an image that moved to GHCR and gained a manual-only fallback.
  • OpenShift-only images can't be pulled outside the cluster, so local development, outside contributors and other clusters have to rebuild.

Builds themselves already depend on GitHub (triggers, git clone), so the gap is redundancy for pulls, not builds. bcgov/wps currently mirrors by hand with oc image mirror in bcgov/wps#5899.

Proposal

A mirror action that copies a built image between GHCR and the OpenShift registry, in either direction, and is called right after the build:

  1. Copy by digest, both directions. GHCR → image-registry.apps.<cluster>.devops.gov.bc.ca/<namespace>/<image>:<tag>, or the reverse. The destination digest must match the sourcethe identical image.
  2. Keep multi-arch indexes intact. Copy the whole manifest list (e.g. oc image mirror --keep-manifest-list, or skopeo copy --all) instead of picking one platform. Document whey and ImageStreams accept manifest lists (importMode: PreserveOriginal).
  3. Never block a deploy. A failed mirror raises acceeds, since the primary copy already exists. Opt-instrict mode for teams that want it to fail.
  4. Handle OpenShift auth. Take a token or servicee registry immediately before the copy. Short-livedTokenRequest tokens can expire during a long build.
  5. Document the deploy side. Deployments pull frory by default, with a single image parameter to switch to the mirror during an outage.

Acceptance

  • Mirrors GHCR → OpenShift and OpenShift → GHCR, with matching digests verified after the copy
  • Multi-arch indexes are copied whole, with a tesnux/arm64`
  • Failure is a warning by default; strict mode is opt-in
  • Logs in to the registry just before the copy, s issue
  • README covers required permissions (packages: write, OpenShift push access to the target namespace) and the deploy-side switch for outages
  • Follow-up (separate PR): bcgov/wps replaces its hand-rolled oc image mirror steps with the action

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions