Skip to content

Build&publish the base container to GHCR + point to it from action #58

Description

Activity

self-assigned this
on Mar 25, 2021

richard-engineering commented on Oct 16, 2023

@richard-engineering

More needed now that 2FA is being enforced as the build times are quite long.

webknjaz commented on Oct 16, 2023

@webknjaz
MemberAuthor

What does it have to do with 2FA?

richard-engineering commented on Oct 16, 2023

@richard-engineering

This Github Action is officially recommended by the official PyPI docs linked to by the article on 2FA enforcement. Previously prior to 2FA enforcement uploading could be done via username/password (eg via flit publish) in CI which is a rather quick process. It's unfortunate that the recommended reference solution linked in the documentation can take up to 5+ minutes to build. Putting this on GHCR would avoid the need to build the images.

webknjaz commented on Oct 16, 2023

@webknjaz
MemberAuthor

Using API tokens still works, it hasn't gone anywhere. Putting shared username+password pairs online was always problematic, and everyone should've switched to scoped API tokens like 5 years ago.

shenxianpeng commented on Apr 21, 2024

@shenxianpeng
Contributor

To speed up user workflows, another option is using composite action, it is faster than building Dockerfile, probably the same as pulling a prepared docker image from GHCR.

Composite action will drop using docker to make GitHub action simpler, and it would support non-Linux OS.

I can draft a PR kindly for your review If you would like to have a look.

webknjaz commented on Apr 21, 2024

@webknjaz
MemberAuthor

No, there are legit reasons for not doing that. I don't want to encourage antipatterns, for example. And the level of control/side effects is unacceptable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions