Conversation
Add Dockerfile.butane and a container-butane.yml workflow to build and push the quay.io/coreos/butane container image. Update build_for_container to also build the butane binary. Remove the old butane/Dockerfile and butane/build_for_container which referenced the standalone butane repo's import paths.
📝 WalkthroughWalkthroughThe shared container build now produces the Butane binary. The Dockerfile packages it from ChangesButane container pipeline
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant GitHubActions
participant Repository
participant SharedContainerAction
participant ContainerRegistry
GitHubActions->>Repository: Checkout full history and tags
GitHubActions->>SharedContainerAction: Build Butane container
SharedContainerAction->>ContainerRegistry: Push amd64 and arm64 images
Possibly related PRs
🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
Binary size report (
|
| Size | |
|---|---|
Base (main) |
33MiB |
| PR (#2255) | 33MiB |
| Delta | +0B (0.00%) |
|
Closing as it actually seems more proper to keep this in repo-templates. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/container-butane.yml:
- Line 34: Update the build-container action reference in the workflow to
replace the mutable main tag with a reviewed, full-length immutable commit SHA,
preserving the existing publishing step and QUAY_AUTH usage.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 76822bd2-96c6-4994-8449-28de1da61494
📒 Files selected for processing (4)
.github/workflows/container-butane.ymlDockerfile.butanebuild_for_containerbutane/build_for_container
💤 Files with no reviewable changes (1)
- butane/build_for_container
📜 Review details
⏰ Context from checks skipped due to timeout. (9)
- GitHub Check: Build butane container image
- GitHub Check: Test ignition-validate (1.26.x, macos-latest)
- GitHub Check: Test ignition-validate (1.26.x, windows-latest)
- GitHub Check: Test (1.25.x)
- GitHub Check: Check binary size
- GitHub Check: Build container image
- GitHub Check: Test (1.26.x)
- GitHub Check: tmt-tests
- GitHub Check: Shellcheck
⚠️ CI failures not shown inline (2)
GitHub Actions: Release notes / 0_Require release note.txt: *: add butane container image build
Conclusion: failure
##[group]Run set -euo pipefail
�[36;1mset -euo pipefail�[0m
�[36;1mif [ -n "skip-notes" ]; then�[0m
�[36;1m # Don't trust the label list in the event metadata, since runs�[0m
�[36;1m # can be scheduled out of order and the list might be stale.�[0m
�[36;1m label=$(curl --no-progress-meter \�[0m
�[36;1m -H "Accept: application/vnd.github+json" \�[0m
�[36;1m -H "Authorization: token ***" \�[0m
�[36;1m "https://api.github.com/repos/coreos/ignition/pulls/2255" |�[0m
�[36;1m jq '.labels[] | select(.name == "skip-notes")')�[0m
�[36;1m if [ -n "${label}" ]; then�[0m
�[36;1m echo "PR has skip-notes label; skipping"�[0m
�[36;1m exit 0�[0m
�[36;1m fi�[0m
�[36;1mfi�[0m
�[36;1mdiffinfo=$(curl --no-progress-meter \�[0m
�[36;1m -H "Accept: application/vnd.github+json" \�[0m
�[36;1m -H "Authorization: token ***" \�[0m
�[36;1m "https://api.github.com/repos/coreos/ignition/compare/3ec532290ec952d00401e5aa7f5abad41aada6d4...e2a5958f6130e167c520481f3d92032e4010be8f" |�[0m
�[36;1m jq '.files[] | select(.filename == "docs/release-notes.md")')�[0m
�[36;1mif [ -z "${diffinfo}" ]; then�[0m
�[36;1m echo "Found no changes to docs/release-notes.md."�[0m
�[36;1m if [ -n "skip-notes" ]; then�[0m
�[36;1m echo "To ignore, add skip-notes label to PR."�[0m
�[36;1m fi�[0m
�[36;1m exit 1�[0m
�[36;1mfi�[0m
�[36;1mecho "Found change to docs/release-notes.md."�[0m
shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
##[endgroup]
Found no changes to docs/release-notes.md.
To ignore, add skip-notes label to PR.
##[error]Process completed with exit code 1.
GitHub Actions: Release notes / Require release note: *: add butane container image build
Conclusion: failure
##[group]Run set -euo pipefail
�[36;1mset -euo pipefail�[0m
�[36;1mif [ -n "skip-notes" ]; then�[0m
�[36;1m # Don't trust the label list in the event metadata, since runs�[0m
�[36;1m # can be scheduled out of order and the list might be stale.�[0m
�[36;1m label=$(curl --no-progress-meter \�[0m
�[36;1m -H "Accept: application/vnd.github+json" \�[0m
�[36;1m -H "Authorization: token ***" \�[0m
�[36;1m "https://api.github.com/repos/coreos/ignition/pulls/2255" |�[0m
�[36;1m jq '.labels[] | select(.name == "skip-notes")')�[0m
�[36;1m if [ -n "${label}" ]; then�[0m
�[36;1m echo "PR has skip-notes label; skipping"�[0m
�[36;1m exit 0�[0m
�[36;1m fi�[0m
�[36;1mfi�[0m
�[36;1mdiffinfo=$(curl --no-progress-meter \�[0m
�[36;1m -H "Accept: application/vnd.github+json" \�[0m
�[36;1m -H "Authorization: token ***" \�[0m
�[36;1m "https://api.github.com/repos/coreos/ignition/compare/3ec532290ec952d00401e5aa7f5abad41aada6d4...e2a5958f6130e167c520481f3d92032e4010be8f" |�[0m
�[36;1m jq '.files[] | select(.filename == "docs/release-notes.md")')�[0m
�[36;1mif [ -z "${diffinfo}" ]; then�[0m
�[36;1m echo "Found no changes to docs/release-notes.md."�[0m
�[36;1m if [ -n "skip-notes" ]; then�[0m
�[36;1m echo "To ignore, add skip-notes label to PR."�[0m
�[36;1m fi�[0m
�[36;1m exit 1�[0m
�[36;1mfi�[0m
�[36;1mecho "Found change to docs/release-notes.md."�[0m
shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
##[endgroup]
Found no changes to docs/release-notes.md.
To ignore, add skip-notes label to PR.
##[error]Process completed with exit code 1.
🧰 Additional context used
🧠 Learnings (2)
📓 Common learnings
Learnt from: PeaceRebel
Repo: coreos/ignition PR: 2239
File: .github/workflows/binary-size.yml:0-0
Timestamp: 2026-07-28T12:01:12.154Z
Learning: In `.github/workflows/binary-size.yml`, the workflow checks out and builds the current base SHA after building the PR revision. During the build-interface migration, the base branch may not contain the new Makefile targets, so the base build must retain its compatible `./build` invocation while the PR build can use `make ignition BIN_PATH=bin/amd64`.
📚 Learning: 2026-07-28T12:01:12.154Z
Learnt from: PeaceRebel
Repo: coreos/ignition PR: 2239
File: .github/workflows/binary-size.yml:0-0
Timestamp: 2026-07-28T12:01:12.154Z
Learning: In `.github/workflows/binary-size.yml`, the workflow checks out and builds the current base SHA after building the PR revision. During the build-interface migration, the base branch may not contain the new Makefile targets, so the base build must retain its compatible `./build` invocation while the PR build can use `make ignition BIN_PATH=bin/amd64`.
Applied to files:
build_for_containerDockerfile.butane.github/workflows/container-butane.yml
🪛 zizmor (1.29.0)
.github/workflows/container-butane.yml
[warning] 22-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🔇 Additional comments (3)
build_for_container (1)
32-34: LGTM!Dockerfile.butane (1)
3-5: LGTM!Also applies to: 9-9
.github/workflows/container-butane.yml (1)
1-33: LGTM!Also applies to: 35-41
| - name: Fix actions/checkout synthetic tag | ||
| run: git fetch --tags --force | ||
| - name: Build and push container | ||
| uses: coreos/actions-lib/build-container@main |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
sed -n '1,90p' .github/workflows/container-butane.yml
printf '%s\n' '--- action references in workflows ---'
rg -n 'coreos/actions-lib/build-container|QUAY_AUTH|uses: .*`@main`' .github/workflows
printf '%s\n' '--- remote action main ref ---'
curl -fsSL https://api.github.com/repos/coreos/actions-lib/git/ref/heads/main |
jq '{ref, sha: .object.sha, type: .object.type}'Repository: coreos/ignition
Length of output: 2121
Pin the publishing action to an immutable commit.
coreos/actions-lib/build-container@main is mutable and receives QUAY_AUTH to publish quay.io/coreos/butane. Replace main with a reviewed full commit SHA.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/container-butane.yml at line 34, Update the
build-container action reference in the workflow to replace the mutable main tag
with a reviewed, full-length immutable commit SHA, preserving the existing
publishing step and QUAY_AUTH usage.
Source: MCP tools
Add CI to build and push the
quay.io/coreos/butanecontainer image from the ignition repo, now that Butane has been merged here (#2235).Dockerfile.butane-- New Dockerfile for the butane container (adapted from the oldbutane/Dockerfile, usesfedora-minimalas runtime base)build_for_container-- Updated to also build the butane binary alongside ignition-validate.github/workflows/container-butane.yml-- New workflow to build and pushquay.io/coreos/butaneon pushes to main and tags (mirrors the existingcontainer.ymlfor ignition-validate)butane/Dockerfile-- Removed (referenced old standalone import paths)butane/build_for_container-- Removed (referenced old standalone import paths)The
container-butane.ymlworkflow is not template-managed (unlikecontainer.ymlwhich comes from repo-templates). This is because the template only supports one container per workflow. A separate workflow for butane is the simplest approach.