ci: publish the docsgpt-sandbox image

deployment/k8s/deployments/sandbox-deploy.yaml pulls arc53/docsgpt-sandbox,
which has never been pushed anywhere: Compose builds the runner from the
checkout (`build: ./sandbox`), but Kubernetes cannot build, so enabling code
execution on a cluster failed on an image that does not exist.

Build and push it like the other two images: `develop` on a push to main that
touches deployment/sandbox, and `<version>` plus `latest` when the release
workflow calls it. Release and develop live in one file here rather than two,
because the runner changes rarely and the only difference is which tags move.
The tag comes from the inputs and the release payload, not from
`github.event_name`, which is `push` when backend-release calls this.
This commit is contained in:
Alex committed 2026-09-12 22:06:27 +01:00
1 parent 01dfe473d3
commit fc5992c5d4
3 files changed
+189 -2

No files matched your search

@@ -21,6 +21,12 @@
# sibling kernels or bypass the session cap). The gateway fails closed if the
# token is unset.
#
# The image is built from deployment/sandbox and published as
# arc53/docsgpt-sandbox (also ghcr.io/arc53/docsgpt-sandbox) by the release
# workflow, with `develop` tracking main. It is pulled here by the floating
# `latest` tag: pin it to a release tag if you would rather not pick up a new
# runner runtime on a pod restart.
#
# On Linux prod, schedule this onto a gVisor `runsc` RuntimeClass for kernel
# isolation (uncomment `runtimeClassName` once the node has it installed).
#