Runtime CI Guide
The CI templates under `runtime/ci` are the canonical build-and-push workflows for the container images used by this runtime.
The CI templates under runtime/ci are the canonical build-and-push workflows for the container images used by this runtime.
Providers
- GitHub Actions:
runtime/ci/github-actions/*.yml - Azure Pipelines:
runtime/ci/azure-pipelines/*.yml
Both providers follow the same model:
- Login to
gitea.perspective-v.com(Docker images live undergitea.perspective-v.com/perspective-v/<image>) - Build with Buildx
- Push
latest - Push immutable
v1.0.<run> - Keep Docker schema v2 compatible media types with
oci-mediatypes=false - Disable provenance and SBOM on the registry output path
Required Registry Secrets
The registry is now Gitea. REGISTRY_USERNAME is a Gitea username (e.g. a
dedicated ci-bot user) and REGISTRY_PASSWORD is a Gitea access token with
scope write:package (used as the login password). See
stack-gitea-guide.md for token creation.
GitHub Actions
REGISTRY_USERNAMEREGISTRY_PASSWORD
Azure Pipelines
REGISTRY_USERNAMEREGISTRY_PASSWORD
Feed Secrets By Service Type
npm and NuGet feeds are now served by Gitea. Feed URLs point at the Gitea package API and the feed token is the same style of Gitea access token used for the registry (a single token can cover Docker, npm and NuGet).
identityandgraph:NUGET_FEED_URL→https://gitea.perspective-v.com/api/packages/perspective-v/nuget/index.jsonNUGET_FEED_TOKEN(Gitea access token)
console:NPM_FEED_URL→https://gitea.perspective-v.com/api/packages/perspective-v/npm/NPM_FEED_TOKEN(or legacyNPM_FEED_API_KEY) — a Gitea access token
dbskc,nishatcolony, and generic static or API services:- registry secrets only unless the Dockerfile requires a private package source
Template Matrix
build-and-push-single-image.yml- fallback for a new service
- default trigger:
main
build-and-push-identity.yml- trigger:
deploy/identity - includes NuGet feed arguments
- trigger:
build-and-push-graph.yml- trigger:
deploy/graph - includes NuGet feed arguments
- trigger:
build-and-push-console.yml- trigger:
deploy/console - includes npm feed arguments and fallback handling for legacy secret names
- trigger:
build-and-push-dbskc.yml- trigger:
deploy/dbskc
- trigger:
build-and-push-nishatcolony.yml- trigger:
deploy/nishatcolony
- trigger:
Add A Service To CI
- Pick the closest template under
runtime/ci. - Copy it into the application repository.
- Set:
- registry host (
gitea.perspective-v.com) and namespace (perspective-v) - image name
- Dockerfile path
- build context
- branch trigger
- registry host (
- Add the required registry secrets (Gitea username + access token).
- Add package-feed secrets if the service restore step needs them.
- Run the pipeline and confirm the image lands in
gitea.perspective-v.com/perspective-v/<image>. - Deploy the image with the matching runtime service launcher.
Required Build Settings
Keep these settings unchanged unless registry compatibility is no longer required:
GitHub Actions
provenance: false
sbom: false
outputs: type=image,push=true,oci-mediatypes=falseAzure Pipelines
docker buildx build \
--provenance=false \
--sbom=false \
--output type=image,push=true,oci-mediatypes=falseAfter A Successful Build
Update or confirm the image reference in the matching service env file, then redeploy with the runtime launcher.
Examples:
./runtime/scripts/services/identity.sh pull
./runtime/scripts/services/identity.sh restart
./runtime/scripts/services/dbskc.sh pull
./runtime/scripts/services/dbskc.sh restart