Skip to content

M12.1: dual-publish releases to Docker Hub - #8

Merged
pgousdal merged 2 commits into
mainfrom
work/m12.1-dockerhub-dual-publish
Sep 6, 2026
Merged

pgousdal merged 2 commits into
mainfrom
work/m12.1-dockerhub-dual-publish

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Ports the qualified dual-registry release model from Ploos-AS/soju to soju-web.

  • publish one multiarch build to GHCR and Docker Hub
  • lock Docker Hub destination to ploos1/soju-web
  • require DOCKERHUB_USERNAME=ploos1 and DOCKERHUB_TOKEN
  • exact-digest qualification for both registries
  • require digest parity across GHCR and Docker Hub
  • keyless Cosign signing and verification for both registry references
  • preserve GHCR build attestation and existing /healthz runtime qualification
  • extend post-release audit to both registries

No release tag will be created until CI is green and this PR is merged.

@pgousdal
pgousdal merged commit 9c6ae21 into main Sep 6, 2026
2 checks passed
@pgousdal
pgousdal deleted the work/m12.1-dockerhub-dual-publish branch September 6, 2026 08:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant