Skip to content

feat(events-processor): add Dockerfile.staging for hardened build path - #804

Merged
IxDay merged 1 commit into
mainfrom
feat/events-processor-wolfi-hardened-ghcr
Sep 18, 2026
Merged

IxDay merged 1 commit into
mainfrom
feat/events-processor-wolfi-hardened-ghcr

Conversation

@IxDay

@IxDay IxDay commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Restores the hardened staging build for events-processor, FROMing the Wolfi/apko bases now published by getlago/lago-packages to GHCR.

ARG BUILD_IMAGE=ghcr.io/getlago/events-processor-build:latest
ARG RUNTIME_IMAGE=ghcr.io/getlago/events-processor-base:latest

Why this is a new PR and not #800 reopened

#800 cannot be reopened. Its branch was force-pushed onto main at the moment it was closed, so it now contains no changes and GitHub refuses to reopen a PR with an empty diff.

Unlike lago-front#4318 — where a pinned review preserved the pre-push commit — nothing in #800's timeline references its original head, so that version is genuinely gone. This is adapted from the copy in lago-deploy#3331, which is the same work.

Why the Dockerfile lives here

lago-deploy#3331 put this file in the private lago-deploy repo, stating:

Lives here (private lago-deploy) rather than alongside events-processor/Dockerfile in the public lago monorepo so ECR URLs, the AWS account id, and the apko base image references stay out of the OSS-facing surface.

Sound while the bases were in ECR; obsolete now. The bases are public on GHCR, so there is no account id or private registry reference to hide, and pulling them needs no credentials.

Build logic unchanged

The paired workflow already sets the build context to events-processor/, so COPY . /app/ resolves exactly as before — only the Dockerfile's location and the two ARG defaults change. The Rust FFI dependency is still pinned to LAGO_EXPRESSION_REF=v0.2.0 to match the production ./Dockerfile; bump both together.

Companion changes

Not in this PR

events-processor/Dockerfile is untouched and continues to serve production builds.

Restores the hardened staging build for events-processor, FROMing the
Wolfi/apko bases now published by getlago/lago-packages to GHCR.

This supersedes #800 rather than continuing it. That branch was force-pushed
onto main before being closed, so it holds no changes and GitHub will not
reopen it. Unlike lago-front#4318 no review was pinned to the pre-push commit,
so the original is unrecoverable; this is adapted from the copy that lives in
lago-deploy#3331.

That copy sat in the private lago-deploy repo specifically to keep ECR URLs
and the AWS account id out of a public repository. The bases are public on
GHCR now, so the Dockerfile can live beside the code it builds, as lago-api's
already does.

Build logic is unchanged — the context is still this directory, so COPY paths
behave exactly as before. The sibling ./Dockerfile still serves production.
@IxDay
IxDay merged commit 5308258 into main Sep 18, 2026
1 check passed
@IxDay
IxDay deleted the feat/events-processor-wolfi-hardened-ghcr branch September 18, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants