Cordium documentation · Latest
Building Container Images
Workspaces can build and push OCI container images with rootless Podman, without a Docker daemon and without any privileged access to the host (read more here). This example uses an ephemeral, auto-stopping Workspace to build an image from a repository's Dockerfile, push it to GitHub Container Registry, and print its digest.
The Template
The registry token is a Secret of the payments Space with the write:packages scope. The image, tag and Dockerfile are variables, so that the same Template can build any image of the Space's repositories:
Here are a few notes about this Template:
sudodoes not preserve the environment, which is why the token is piped topodman loginrather than read by it from$REGISTRY_TOKEN.REFcan be a branch, a tag or a commit, which is fetched and checked out before the build. The repository URL is written as${{vars.REPO}}, without spaces, since URLs are validated before the variables are substituted (read more here).The image is built from the repository's own Dockerfile and context. Image builds use the Workspace's CPU, memory and storage, so size the limits for your largest image.
The run fails if any step fails, and the pushed digest appears in the Workspace's logs.
Since REGISTRY_TOKEN is an environment variable, it is readable by every process running in the Workspace, including the build's RUN steps of an untrusted Dockerfile. Only build images from repositories that you trust with this token, use a token that can only push to the intended packages, and prefer short-lived tokens where your registry supports them.
Using the Image in Workspaces
Images pushed this way can be used as the image of other Templates and Workspaces, which is an alternative to pre-builds for heavy toolchains that change rarely (read more here):