Problem
Iron Bank republishes ubi9-minimal (and the traefik image we build on) under
the same mutable tag as Red Hat ships fixes. Our published *-ubi images are
built once at release time, so their CVE count only grows until the next
COSMOS release, even when a patched base is already available.
Proposal
A scheduled workflow (nightly, plus workflow_dispatch) that, for each
selected release:
- Checks out the release's git tag
- Rebuilds the 11
*-ubi images with --pull against the current Iron Bank base
- Scans the result with Trivy
- Pushes to Docker Hub and ghcr.io
Inputs (dispatch) / defaults (schedule):
versions: explicit list (6.10.0,6.9.2) or supported (latest patch of
the last N minors, N configurable)
ubi_tag: override the base tag, default = the tag in that release's .env
force: rebuild even if the base digest is unchanged
Open questions / requirements
What to rebuild
Tagging
Verification before push
After push
Operational
Enterprise
COSMOS Enterprise UBI images build on these core images, so they need the same
treatment:
Problem
Iron Bank republishes
ubi9-minimal(and the traefik image we build on) underthe same mutable tag as Red Hat ships fixes. Our published
*-ubiimages arebuilt once at release time, so their CVE count only grows until the next
COSMOS release, even when a patched base is already available.
Proposal
A scheduled workflow (nightly, plus
workflow_dispatch) that, for eachselected release:
*-ubiimages with--pullagainst the current Iron Bank baseInputs (dispatch) / defaults (schedule):
versions: explicit list (6.10.0,6.9.2) orsupported(latest patch ofthe last N minors, N configurable)
ubi_tag: override the base tag, default = the tag in that release's.envforce: rebuild even if the base digest is unchangedOpen questions / requirements
What to rebuild
ubi9-minimal, traefik, QuestDBRHEL) is unchanged since the last rebuild; record the digest in an
org.opencontainers.image.base.digestlabel and compare against it.Package updates inside the Dockerfiles can lower the CVE count even on an
unchanged base, so
force(or a periodic forced run) still has valueOPENC3_UBI_TAG=9.6), whichIron Bank may no longer refresh. Decide whether to rebuild on the
release's minor only, or allow bumping to the current minor (a base OS
change on a published version)
build_multi_arch.sh, or main's script against the tag's sourcesTagging
vX.Y.Z-ubiin place, and/or add an immutablevX.Y.Z-ubi-YYYYMMDDso users pinned to a rebuild can stay on itimmutability if enabled)
latestonly when the rebuilt version is the current latestcleanup-ghcr.ymldoesn't delete the superseded manifests thatdigest-pinned users still pull
Verification before push
don't push a regression
After push
(
post_release_trivy.yml)Operational
to a service account before a scheduled job depends on it
concurrencygroup so it can't overlap a release runEnterprise
COSMOS Enterprise UBI images build on these core images, so they need the same
treatment:
rebuild pushes (
repository_dispatchorworkflow_run), not on its ownschedule, so it always builds on the fresh core images
--pulltoo