Skip to content

ci: publish release images and Helm chart to ghcr.io on PRIVACY-* tags - #996

Merged
idan-starkware merged 1 commit into
mainfrom
feat/docker-helm-publish-workflows
Sep 28, 2026
Merged

idan-starkware merged 1 commit into
mainfrom
feat/docker-helm-publish-workflows

Conversation

@idan-starkware

@idan-starkware idan-starkware commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • docker-publish.yml (new): on PRIVACY-* tags, builds multi-arch (amd64/arm64) discovery-service and proof-interceptor images and pushes them to ghcr.io/starkware-libs/starknet-privacy/<image>:<tag>. A manual dispatch pushes test-<sha> only.
  • helm-publish.yml (new): on PRIVACY-* tags, packages the chart (version taken from Chart.yaml, appVersion = the git tag) and pushes it to oci://ghcr.io/starkware-libs/starknet-privacy/charts/privacy-starknet. ghcr has no immutable tags, so an already-published version is skipped (with a summary telling you to bump Chart.yaml) instead of being overwritten.
  • discovery-service-docker.yaml / proof-interceptor-docker.yaml no longer run on tags, so each release tag has only one writer. They still build on PRs and main.

transaction-prover is already published on PRIVACY-* tags by starkware-libs/sequencer (starknet_transaction_prover_docker_publish.yml).

After merge (manual, one time)

  • After the first chart push, set the starknet-privacy/charts/privacy-starknet package visibility to Public. infra-tools only logs in to *-docker.pkg.dev, so ArgoCD envs pull ghcr charts anonymously.

Consuming from starkware-envs-production

  helm:
    oci_registry: oci://ghcr.io/starkware-libs/starknet-privacy/charts/privacy-starknet
    oci_version: 0.3.0

Test plan

  • actionlint clean on all touched workflows
  • helm lint + helm package --version 0.3.0 --app-version PRIVACY-0.14.3-RC.8 locally
  • Next PRIVACY-* tag: images + chart appear on ghcr; helm pull works while logged out

🤖 Generated with Claude Code


This change is Reviewable

- docker-publish.yml: multi-arch discovery-service and proof-interceptor
  images, tagged with the git tag verbatim.
- helm-publish.yml: privacy-starknet chart as an OCI artifact at
  ghcr.io/starkware-libs/starknet-privacy/charts, version from Chart.yaml,
  appVersion from the tag; skips versions already published.
- discovery-service/proof-interceptor docker workflows no longer run on
  tags, so release tags have a single writer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@idan-starkware
idan-starkware force-pushed the feat/docker-helm-publish-workflows branch from 6023309 to 4b13e47 Compare September 28, 2026 11:50
@idan-starkware
idan-starkware merged commit f9256c5 into main Sep 28, 2026
14 checks passed
@idan-starkware
idan-starkware deleted the feat/docker-helm-publish-workflows branch September 28, 2026 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants