ci(release): smoke-test Docker images per-arch before pushing

Today's nightly published an arm64 image that segfaults on any
invocation (`fabro version` → SIGSEGV). The docker job only built and
pushed; the binary was never executed inside the final image layout,
so the broken arm64 manifest reached ghcr.io undetected.

Before the multi-arch push, build each platform single-arch with
load: true and run `fabro version` in the loaded image. A segfault,
missing binary, or broken entrypoint now fails the job instead of
shipping a broken image. The subsequent multi-arch push reuses buildx
cache from the per-platform builds, so the net cost is ~one short
`docker run` per arch.
This commit is contained in:
Bryan Helmkamp 2026-04-18 15:17:45 -04:00
parent a77c45207f
commit dba41c32f7
No known key found for this signature in database

View file

@ -190,6 +190,30 @@ jobs:
type=raw,value=latest,enable=${{ !contains(github.ref_name, '-') }}
type=raw,value=nightly,enable=${{ contains(github.ref_name, '-nightly.') }}
- name: Build amd64 image for smoke test
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
file: Dockerfile
platforms: linux/amd64
load: true
tags: fabro-smoke:amd64
- name: Smoke-test amd64 image
run: docker run --rm --platform linux/amd64 fabro-smoke:amd64 fabro version
- name: Build arm64 image for smoke test
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
file: Dockerfile
platforms: linux/arm64
load: true
tags: fabro-smoke:arm64
- name: Smoke-test arm64 image
run: docker run --rm --platform linux/arm64 fabro-smoke:arm64 fabro version
- id: build
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with: