Skip to content

ci(rstudio): add isolated native release workflow - #7

Merged
man4ish merged 1 commit into
mainfrom
hardening/rstudio-multiarch
Oct 3, 2026
Merged

man4ish merged 1 commit into
mainfrom
hardening/rstudio-multiarch

Conversation

@man4ish

@man4ish man4ish commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

docker-publish-specialized.yml's build matrix hardcodes both vscode and rstudio under one shared workflow_dispatch version input, so dispatching it to release RStudio would also rebuild and push ghcr.io/omnibioai/omnibioai-vscode under an unrelated version number -- an unauthorized side effect on a service that is already RELEASE VERIFIED and FROZEN under its own separate version lineage.

  • Adds publish-rstudio.yml, scoped to exactly ghcr.io/omnibioai/omnibioai-rstudio, mirroring the proven publish-jupyter.yml structure: native linux/amd64/linux/arm64 builds (no QEMU), independent OCI-index verification, per-architecture runtime smoke (RStudio Server, R, 19/19 packages, library(monocle3) + exact monocle3/BPCells/speedglm pin verification, workspace write, graceful shutdown), gated latest promotion.
  • docker-publish-specialized.yml is left untouched.
  • Adds test-rstudio-workflow-scope.sh, a static regression test (verified against a vscode-reference mutation) proving the new workflow has no vscode reference, no matrix/strategy block, and no second production image target.

Test plan

  • actionlint clean on publish-rstudio.yml
  • YAML parses
  • test-rstudio-workflow-scope.sh passes; verified it fails against a vscode-reference mutation
  • test-monocle3-pin.sh unaffected, still passes
  • git diff --check clean

🤖 Generated with Claude Code

docker-publish-specialized.yml's build matrix hardcodes both vscode and
rstudio under one shared workflow_dispatch version input, so dispatching
it to release RStudio would also rebuild and push
ghcr.io/omnibioai/omnibioai-vscode under an unrelated version number --
an unauthorized side effect on a service that is already RELEASE
VERIFIED and FROZEN under its own separate version lineage.

Adds publish-rstudio.yml, a dedicated workflow scoped to exactly
ghcr.io/omnibioai/omnibioai-rstudio, mirroring the proven
publish-jupyter.yml structure: native linux/amd64 (ubuntu-24.04) and
native linux/arm64 (ubuntu-24.04-arm) builds, no QEMU; an
assemble-and-verify job that independently inspects the resulting OCI
index (platform count, digest consistency, per-architecture
org.opencontainers.image.* labels via the correctly-cased
.Image.Config.Labels, and exact SBOM/provenance subject-binding to each
architecture's own digest); per-architecture runtime smoke (RStudio
Server sign-in page, R runtime, all 19 target packages, library(monocle3)
plus exact monocle3/BPCells/speedglm pin verification, workspace write,
graceful shutdown); and latest promotion gated strictly behind both smoke
jobs succeeding. docker-publish-specialized.yml itself is left untouched.

Adds test-rstudio-workflow-scope.sh, a static regression test (verified
against a vscode-reference mutation) proving the new workflow contains no
vscode reference, no matrix/strategy block, and no second production
image target.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit d77bf75 into main Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant