Skip to content

*: add butane container image build - #2255

Closed
prestist wants to merge 1 commit into
coreos:mainfrom
prestist:butane-container
Closed

prestist wants to merge 1 commit into
coreos:mainfrom
prestist:butane-container

Conversation

@prestist

@prestist prestist commented Aug 12, 2026 •

Copy link
Copy Markdown
Collaborator

Add CI to build and push the quay.io/coreos/butane container image from the ignition repo, now that Butane has been merged here (#2235).

  • Dockerfile.butane -- New Dockerfile for the butane container (adapted from the old butane/Dockerfile, uses fedora-minimal as runtime base)
  • build_for_container -- Updated to also build the butane binary alongside ignition-validate
  • .github/workflows/container-butane.yml -- New workflow to build and push quay.io/coreos/butane on pushes to main and tags (mirrors the existing container.yml for ignition-validate)
  • butane/Dockerfile -- Removed (referenced old standalone import paths)
  • butane/build_for_container -- Removed (referenced old standalone import paths)

The container-butane.yml workflow is not template-managed (unlike container.yml which comes from repo-templates). This is because the template only supports one container per workflow. A separate workflow for butane is the simplest approach.

Add Dockerfile.butane and a container-butane.yml workflow to build
and push the quay.io/coreos/butane container image. Update
build_for_container to also build the butane binary.

Remove the old butane/Dockerfile and butane/build_for_container
which referenced the standalone butane repo's import paths.
@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The shared container build now produces the Butane binary. The Dockerfile packages it from /ignition. A new GitHub Actions workflow builds and publishes architecture-specific Butane images for pushes, tags, and pull requests.

Changes

Butane container pipeline

Layer / File(s) Summary
Butane container build path
build_for_container, Dockerfile.butane, butane/build_for_container
The shared build script now builds a versioned Butane binary. Dockerfile.butane uses /ignition and packages the resulting binary. The previous Butane-specific build script was removed.
Container publishing workflow
.github/workflows/container-butane.yml
The workflow builds and pushes amd64 and arm64 images for pushes and version tags. Pull requests build only amd64 images. Full history and tags are restored before the shared container action runs.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant Repository
  participant SharedContainerAction
  participant ContainerRegistry
  GitHubActions->>Repository: Checkout full history and tags
  GitHubActions->>SharedContainerAction: Build Butane container
  SharedContainerAction->>ContainerRegistry: Push amd64 and arm64 images
Loading

Possibly related PRs

  • coreos/ignition#2253: Both changes integrate Butane with Ignition’s shared build and release pipeline, including container artifacts.
🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Commit Message Convention ✅ Passed The PR has one non-merge commit, *: add butane container image build; it uses a valid subsystem, starts with lowercase imperative add, and has no trailing period.
Title check ✅ Passed The title uses the required subsystem format and an imperative, lowercase description that matches the container image build changes.
Description check ✅ Passed The description directly explains the CI workflow, container files, build script changes, and obsolete file removals.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Binary size report (bin/amd64/ignition)

Size
Base (main) 33MiB
PR (#2255) 33MiB
Delta +0B (0.00%)

@prestist

Copy link
Copy Markdown
Collaborator Author

Closing as it actually seems more proper to keep this in repo-templates.

@prestist prestist closed this Aug 12, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/container-butane.yml:
- Line 34: Update the build-container action reference in the workflow to
replace the mutable main tag with a reviewed, full-length immutable commit SHA,
preserving the existing publishing step and QUAY_AUTH usage.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 76822bd2-96c6-4994-8449-28de1da61494

📥 Commits

Reviewing files that changed from the base of the PR and between 3ec5322 and e2a5958.

📒 Files selected for processing (4)
  • .github/workflows/container-butane.yml
  • Dockerfile.butane
  • build_for_container
  • butane/build_for_container
💤 Files with no reviewable changes (1)
  • butane/build_for_container
📜 Review details
⏰ Context from checks skipped due to timeout. (9)
  • GitHub Check: Build butane container image
  • GitHub Check: Test ignition-validate (1.26.x, macos-latest)
  • GitHub Check: Test ignition-validate (1.26.x, windows-latest)
  • GitHub Check: Test (1.25.x)
  • GitHub Check: Check binary size
  • GitHub Check: Build container image
  • GitHub Check: Test (1.26.x)
  • GitHub Check: tmt-tests
  • GitHub Check: Shellcheck
⚠️ CI failures not shown inline (2)

GitHub Actions: Release notes / 0_Require release note.txt: *: add butane container image build

Conclusion: failure

View job details

##[group]Run set -euo pipefail
 �[36;1mset -euo pipefail�[0m
 �[36;1mif [ -n "skip-notes" ]; then�[0m
 �[36;1m    # Don't trust the label list in the event metadata, since runs�[0m
 �[36;1m    # can be scheduled out of order and the list might be stale.�[0m
 �[36;1m    label=$(curl --no-progress-meter \�[0m
 �[36;1m        -H "Accept: application/vnd.github+json" \�[0m
 �[36;1m        -H "Authorization: token ***" \�[0m
 �[36;1m        "https://api.github.com/repos/coreos/ignition/pulls/2255" |�[0m
 �[36;1m        jq '.labels[] | select(.name == "skip-notes")')�[0m
 �[36;1m    if [ -n "${label}" ]; then�[0m
 �[36;1m        echo "PR has skip-notes label; skipping"�[0m
 �[36;1m        exit 0�[0m
 �[36;1m    fi�[0m
 �[36;1mfi�[0m
 �[36;1mdiffinfo=$(curl --no-progress-meter \�[0m
 �[36;1m    -H "Accept: application/vnd.github+json" \�[0m
 �[36;1m    -H "Authorization: token ***" \�[0m
 �[36;1m    "https://api.github.com/repos/coreos/ignition/compare/3ec532290ec952d00401e5aa7f5abad41aada6d4...e2a5958f6130e167c520481f3d92032e4010be8f" |�[0m
 �[36;1m    jq '.files[] | select(.filename == "docs/release-notes.md")')�[0m
 �[36;1mif [ -z "${diffinfo}" ]; then�[0m
 �[36;1m    echo "Found no changes to docs/release-notes.md."�[0m
 �[36;1m    if [ -n "skip-notes" ]; then�[0m
 �[36;1m        echo "To ignore, add skip-notes label to PR."�[0m
 �[36;1m    fi�[0m
 �[36;1m    exit 1�[0m
 �[36;1mfi�[0m
 �[36;1mecho "Found change to docs/release-notes.md."�[0m
 shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
 ##[endgroup]
 Found no changes to docs/release-notes.md.
 To ignore, add skip-notes label to PR.
 ##[error]Process completed with exit code 1.

GitHub Actions: Release notes / Require release note: *: add butane container image build

Conclusion: failure

View job details

##[group]Run set -euo pipefail
 �[36;1mset -euo pipefail�[0m
 �[36;1mif [ -n "skip-notes" ]; then�[0m
 �[36;1m    # Don't trust the label list in the event metadata, since runs�[0m
 �[36;1m    # can be scheduled out of order and the list might be stale.�[0m
 �[36;1m    label=$(curl --no-progress-meter \�[0m
 �[36;1m        -H "Accept: application/vnd.github+json" \�[0m
 �[36;1m        -H "Authorization: token ***" \�[0m
 �[36;1m        "https://api.github.com/repos/coreos/ignition/pulls/2255" |�[0m
 �[36;1m        jq '.labels[] | select(.name == "skip-notes")')�[0m
 �[36;1m    if [ -n "${label}" ]; then�[0m
 �[36;1m        echo "PR has skip-notes label; skipping"�[0m
 �[36;1m        exit 0�[0m
 �[36;1m    fi�[0m
 �[36;1mfi�[0m
 �[36;1mdiffinfo=$(curl --no-progress-meter \�[0m
 �[36;1m    -H "Accept: application/vnd.github+json" \�[0m
 �[36;1m    -H "Authorization: token ***" \�[0m
 �[36;1m    "https://api.github.com/repos/coreos/ignition/compare/3ec532290ec952d00401e5aa7f5abad41aada6d4...e2a5958f6130e167c520481f3d92032e4010be8f" |�[0m
 �[36;1m    jq '.files[] | select(.filename == "docs/release-notes.md")')�[0m
 �[36;1mif [ -z "${diffinfo}" ]; then�[0m
 �[36;1m    echo "Found no changes to docs/release-notes.md."�[0m
 �[36;1m    if [ -n "skip-notes" ]; then�[0m
 �[36;1m        echo "To ignore, add skip-notes label to PR."�[0m
 �[36;1m    fi�[0m
 �[36;1m    exit 1�[0m
 �[36;1mfi�[0m
 �[36;1mecho "Found change to docs/release-notes.md."�[0m
 shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
 ##[endgroup]
 Found no changes to docs/release-notes.md.
 To ignore, add skip-notes label to PR.
 ##[error]Process completed with exit code 1.
🧰 Additional context used
🧠 Learnings (2)
📓 Common learnings
Learnt from: PeaceRebel
Repo: coreos/ignition PR: 2239
File: .github/workflows/binary-size.yml:0-0
Timestamp: 2026-07-28T12:01:12.154Z
Learning: In `.github/workflows/binary-size.yml`, the workflow checks out and builds the current base SHA after building the PR revision. During the build-interface migration, the base branch may not contain the new Makefile targets, so the base build must retain its compatible `./build` invocation while the PR build can use `make ignition BIN_PATH=bin/amd64`.
📚 Learning: 2026-07-28T12:01:12.154Z
Learnt from: PeaceRebel
Repo: coreos/ignition PR: 2239
File: .github/workflows/binary-size.yml:0-0
Timestamp: 2026-07-28T12:01:12.154Z
Learning: In `.github/workflows/binary-size.yml`, the workflow checks out and builds the current base SHA after building the PR revision. During the build-interface migration, the base branch may not contain the new Makefile targets, so the base build must retain its compatible `./build` invocation while the PR build can use `make ignition BIN_PATH=bin/amd64`.

Applied to files:

  • build_for_container
  • Dockerfile.butane
  • .github/workflows/container-butane.yml
🪛 zizmor (1.29.0)
.github/workflows/container-butane.yml

[warning] 22-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🔇 Additional comments (3)
build_for_container (1)

32-34: LGTM!

Dockerfile.butane (1)

3-5: LGTM!

Also applies to: 9-9

.github/workflows/container-butane.yml (1)

1-33: LGTM!

Also applies to: 35-41

- name: Fix actions/checkout synthetic tag
run: git fetch --tags --force
- name: Build and push container
uses: coreos/actions-lib/build-container@main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- workflow ---'
sed -n '1,90p' .github/workflows/container-butane.yml

printf '%s\n' '--- action references in workflows ---'
rg -n 'coreos/actions-lib/build-container|QUAY_AUTH|uses: .*`@main`' .github/workflows

printf '%s\n' '--- remote action main ref ---'
curl -fsSL https://api.github.com/repos/coreos/actions-lib/git/ref/heads/main |
  jq '{ref, sha: .object.sha, type: .object.type}'

Repository: coreos/ignition

Length of output: 2121


Pin the publishing action to an immutable commit.

coreos/actions-lib/build-container@main is mutable and receives QUAY_AUTH to publish quay.io/coreos/butane. Replace main with a reviewed full commit SHA.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/container-butane.yml at line 34, Update the
build-container action reference in the workflow to replace the mutable main tag
with a reviewed, full-length immutable commit SHA, preserving the existing
publishing step and QUAY_AUTH usage.

Source: MCP tools

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant