Skip to content

feat(examples): publish the self-dev image to GHCR - #138

Merged
martinothamar merged 3 commits into
mainfrom
agentctl/self-dev-image
Oct 6, 2026
Merged

martinothamar merged 3 commits into
mainfrom
agentctl/self-dev-image

Conversation

@martinothamar

@martinothamar martinothamar commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Publishes the self-development Agent's image to GHCR, the way altinn-studio publishes its Agent images, and adds development tools to it.

  • Workflow agentctl-self-dev-image.yml builds agentctl/examples/self-dev for linux/amd64 and linux/arm64 with a registry build cache. Pull requests only build it and smoke-test the tools the Agent's instructions and skills use. main, including a manual run on main, also publishes ghcr.io/digdir/digdir-agents/agent-self-dev as latest and sha-<commit>.
  • Manifests: the default, nested and worktree variants use the published image. The new nested-build variant builds it from the checkout, for changes to the image itself. Codex is optional, so the Agent is created on a host without a Codex login, and the mediated GitHub token also reaches gist.github.com.
  • Tools: cargo-deny and cargo-about (the versions CI and the release workflow run), actionlint and yq as checksum-verified release binaries; shellcheck, btop, sqlite3, socat, tcpdump, hyperfine, python3, and what checking libkrunfw's kernel configuration needs (bc, bison, flex, libelf-dev, python3-pyelftools) from Ubuntu.
  • The self-dev README, the harness test plan and the changelog are updated, and CODEOWNERS covers every agentctl-*.yml workflow with one pattern.

Image size

linux/amd64, built locally from main (4de497a) and this pull request (0da18e2):

main This PR Difference
Uncompressed 3.05 GB 3.13 GB +81 MB (+2.7%)
Compressed (gzip of docker save, about what a pull downloads) 1.35 GB 1.38 GB +33 MB (+2.4%)

After merging, the first main build creates the package. It has to be public, because Agents pull it without credentials, and the default variants cannot start until latest exists.

agentctl-self-dev-image.yml builds the self-development Agent's image
for linux/amd64 and linux/arm64, as altinn-studio does for its Agent
images. Pull requests only build it and smoke-test the tools the Agent's
instructions and skills use; main, including a manual run on main, also
publishes it as ghcr.io/digdir/digdir-agents/agent-self-dev, tagged
latest and sha-<commit>.

The default, nested and worktree variants use the published image; the
new nested-build variant builds it from the checkout. CODEOWNERS covers
every agentctl-*.yml workflow with one pattern.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 85cca0b0-f82b-48b1-95b9-edbd774f09c1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The self-development image includes shellcheck and btop from Ubuntu,
and actionlint and yq as pinned, checksum-verified release binaries;
the smoke test checks the new linters. Codex is optional, so the Agent
is created on a host without a Codex login, and the mediated GitHub
token also reaches gist.github.com, as in altinn-studio's Agents.
cargo-deny, the version CI runs, and cargo-about, the version the
release workflow runs, come as checksum-verified release binaries, so
the repository's dependency, license and notices checks run inside the
Agent. Ubuntu packages add what checking libkrunfw's kernel
configuration needs (bc, bison, flex, libelf-dev, python3-pyelftools),
sqlite3, socat and tcpdump for agentd's database, sockets and Sandbox
traffic, hyperfine for measurements, and python3 explicitly for the
notices script.
@martinothamar
martinothamar merged commit 6ec8cc1 into main Oct 6, 2026
16 checks passed
@martinothamar
martinothamar deleted the agentctl/self-dev-image branch October 6, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant