Initial commit: image registry structure and node-agent
Lint / lint (push) Failing after 34s
Build Images / ${{ fromJSON(needs.select.outputs.images) }} (push) Canceled after 7m37s
Build Images / Select images (push) Successful in 17s

Set up this repo as a base image registry. Each image is self-contained in
its own directory under images/ (Dockerfile + README.md + optional test.sh);
CI discovers them by glob, so adding an image needs no workflow changes.
template/ is the skeleton to copy.

The Makefile is the single entry point for both local work and CI, so a green
`make all` locally means a green pipeline.

Workflows:
  * lint.yaml  — layout check, hadolint, shellcheck
  * build.yaml — diffs against the base commit to build only the images that
    changed, smoke-tests each one before anything is published, then pushes.
    Releases are per-image tags (<image>/vX.Y.Z); main publishes :edge.

First image, node-agent: node:22-alpine plus a GNU userland (Alpine ships
BusyBox, whose applets take narrower flags than scripts and models expect),
helm, kubectl, jq, yq, bind-tools, curl, git, ripgrep, fd and friends.
Nothing is version-pinned — rebuilding is how upstream updates land, and the
published tag is what pins things for consumers.

Its smoke test asserts the deployment contract as well as tool presence: the
image must work non-root, with a read-only root filesystem and all
capabilities dropped, which is how ToolHive runs it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
2026-08-09 11:40:29 -04:00
co-authored by Claude Opus 5
commit 1878df96ac
14 changed files with 762 additions and 0 deletions
+29
View File
@@ -0,0 +1,29 @@
# syntax=docker/dockerfile:1
# Skeleton for a new image. Copy this directory to images/<name>/ and edit.
#
# Conventions worth keeping:
# * leave upstream tags and package versions unpinned, so a rebuild picks up
# updates — the published image tag is what pins things for consumers
# * keep the ARG/LABEL block last, so changing build metadata does not
# invalidate the layers above it
#
# To build on top of an image already published here, replace the FROM with:
# FROM gitea.libretechconsulting.com/rmcguire/node-agent:latest
FROM alpine:3
# hadolint ignore=DL3018
RUN apk add --no-cache bash ca-certificates
CMD ["bash"]
ARG VERSION=dev
ARG REVISION=unknown
ARG CREATED=unknown
LABEL org.opencontainers.image.title="CHANGEME" \
org.opencontainers.image.description="CHANGEME" \
org.opencontainers.image.source="https://gitea.libretechconsulting.com/rmcguire/images" \
org.opencontainers.image.base.name="docker.io/library/alpine:3" \
org.opencontainers.image.version="${VERSION}" \
org.opencontainers.image.revision="${REVISION}" \
org.opencontainers.image.created="${CREATED}"