ci: stop publishing foreign service images so GHCR packages attribute correctly - #50
Merged
Merged
Conversation
…rrectly The trust-pipeline-images workflow built all 9 services and pushed them to ghcr.io/hyperpolymath/<service>. docker/metadata-action auto-injects the org.opencontainers.image.source OCI label from the repo running the build, so GitHub linked every package to odds-and-sods-package-manager — even for services that have their own upstream repo. Build only OPSM-native services here (claim-forge, oikos, cerro-torre). Images for projects with their own repo are published by those repos instead, so the GHCR package -> repository link points at the real source: selur, vordr -> hyperpolymath/stapeln checky-monkey -> hyperpolymath/checky-monkey palimpsest-license -> hyperpolymath/palimpsest-license svalinn -> hyperpolymath/svalinn cicd-hyper-a is a retired name (project is hyperpolymath/hypatia) and is no longer published. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS
hyperpolymath
marked this pull request as ready for review
June 21, 2026 23:42
hyperpolymath
added a commit
that referenced
this pull request
Jun 26, 2026
## Why Follow-up to #50. Two more services were still built and pushed (now also with build-provenance attestations from #55) under odds-and-sods, mis-attributing their GHCR packages: - **`oikos`** → belongs to **`hyperpolymath/oikosbot`**; the package should be relinked there. - **`claim-forge`** → part of a private system; it must not be published as a public OPSM package (its source `services/claim-forge/` is also public in this repo — see "open items"). `docker/metadata-action` injects `org.opencontainers.image.source` from the repo running the build, so anything built here links to odds-and-sods regardless of where it really belongs. ## What Removes `oikos` and `claim-forge` from the `trust-pipeline-images` build matrix. **`cerro-torre`** is now the only service still built here — flagged in-file pending confirmation it has no upstream/private home of its own. This is self-contained: `trust-pipeline-e2e.yml` *pulls* these images (it doesn't depend on the build job), so trimming the matrix doesn't break e2e. ## Manual GHCR steps (API can't do these) - `oikos`: Package → settings → unlink (🗑) → relink to `oikosbot`. - `claim-forge`: delete the public package (and decide on the public source — see below). ## Open items / follow-ups - **claim-forge privacy** — `services/claim-forge/` is a real 229-line public Rust service in this public repo. If it's meant to be private, the *source* needs removing too, not just the package. - **cerro-torre** — confirm whether it's OPSM-native (keep building) or someone else's/private (remove). - **Deletion coupling** — `oikos`/`claim-forge`/`cicd-hyper-a` are still referenced by `trust-pipeline-e2e.yml`, `selur-compose.yml` and OPSM core. Deleting the `claim-forge`/`cicd-hyper-a` packages needs a separate pass to strip those references first, or e2e CI will fail to pull them. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS --- _Generated by [Claude Code](https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS)_ Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The GHCR container packages
selur,vordr,checky-monkey,palimpsest-license,svalinn, andcicd-hyper-aall show up under this repo's packages page even though they belong to other projects. That isn't a coincidence:.github/workflows/trust-pipeline-images.ymlbuilt all 9 services fromservices/<name>/Containerfileand pushed them toghcr.io/hyperpolymath/<name>.docker/metadata-actionautomatically injects theorg.opencontainers.image.sourceOCI label derived from the repo running the workflow (odds-and-sods-package-manager), and GitHub uses that label to link each package to a repository. So every image OPSM built got silently attributed to OPSM.Several of those services have their own upstream repos (and the vendored copies here are Rust reimplementations that don't even match the real artifacts — e.g. the real
checky-monkeyis Haskell + IPFS).What
Build only the OPSM-native services here (no upstream repo of their own):
claim-forgeoikoscerro-torreRemoved from the matrix (each published by its own repo so the GHCR link is correct):
selur,vordrhyperpolymath/stapelnchecky-monkeyhyperpolymath/checky-monkeypalimpsest-licensehyperpolymath/palimpsest-licensesvalinnhyperpolymath/svalinncicd-hyper-ahyperpolymath/hypatia) — not publishedThis is self-contained:
trust-pipeline-e2e.ymlpulls these images (it doesn't depend on the build job), so trimming the matrix doesn't break e2e.Not in this PR (follow-ups)
cicd-hyper-aoutright.svalinncurrently has noContainerfile(itsstapeln.tomlpoints to one that doesn't exist), so it can't self-build an image yet.cicd-hyper-aname (it's still referenced intrust-pipeline-e2e.yml,selur-compose.yml,stapeln.toml, and the Elixir live-E2E test) is a separate change.services/{selur,vordr,checky-monkey,palimpsest-license,svalinn}source trees now that they aren't built here.🤖 Generated with Claude Code
https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS
Generated by Claude Code