Publish pulls the tested builder image instead of building it on every run (#850)

A builder droplet starts with no images, so publish.yml built
omarchy-pkg-builder from the Dockerfile each time: about 100 s of
pacstrap, keyring setup and toolchain install, to run gpg, repo-add,
bsdtar and rclone for about 14 s.

builder-images.yml already publishes the tested image for the current
build inputs to ghcr.io/omacom/omarchy-pkg-builder under bin/builder-image
key. Pull that, check its org.omarchy.builder.key label, and tag it as the
local name the rest of the step uses.

Build as before when no image carries the key, which is what a merge
that changes build/ sees until the refresh it triggered has finished.

Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
This commit is contained in:
Emir BeganovićandRyan Hughes authored and GitHub committed 2026-10-08 14:57:21 -04:00
1 parent 48d6217ff7
commit 5d9783b85e
1 file changed
+20 -2
+20 -2
View File
@@ -280,8 +280,26 @@ jobs:
cat publish-record.json
exit 0
fi
docker image inspect omarchy-pkg-builder:latest-x86_64-edge >/dev/null 2>&1 \
|| docker buildx build --load -t omarchy-pkg-builder:latest-x86_64-edge --build-arg MIRROR=edge build
# A builder droplet starts with no images, so building this one here
# cost every publish about 100 s (and 20 s more to start a container
# from it) for the 14 s of signing and upload it is needed for.
# builder-images.yml already publishes the tested image for exactly
# these build inputs under their key; pull that. Build only when no
# image carries the key: a merge that changed build/ publishes
# before the refresh it triggered has finished.
builder=omarchy-pkg-builder:latest-x86_64-edge
if ! docker image inspect "$builder" >/dev/null 2>&1; then
key=$(bin/builder-image key --arch x86_64 --mirror edge)
published="ghcr.io/omacom/omarchy-pkg-builder:$key"
if docker pull --quiet "$published" &&
[[ $(docker image inspect "$published" --format '{{index .Config.Labels "org.omarchy.builder.key"}}') == "$key" ]]; then
docker tag "$published" "$builder"
echo "==> Builder image: pulled $published"
else
echo "==> Builder image: none published for $key, building it"
docker buildx build --load -t "$builder" --build-arg MIRROR=edge build
fi
fi
# Group the merge's files by the (channel, architecture) slot each
# belongs to. A package's files live under build-output/edge/<built