AEROSIM-TS-49
Publish immutable images to Harbor
Gitea Actions publishes both validated source-revision images to Harbor only after required engineering gates pass.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-52
- Component
- Gitea Actions — Harbor publication workflow
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
After exact-head validation succeeds on the default branch, authenticate to Harbor from Gitea secrets, build and push both images under full source-SHA tags, resolve their registry digests, and publish image-set.json correlating source SHA to both digests. Primary files: .gitea/workflows/publish-images.yaml, scripts/publish-images.mjs, tests/ci/publish-images-workflow.test.mjs.
Implementation contract
Implementation artifacts
- .gitea/workflows/publish-images.yaml
- scripts/publish-images.mjs
- tests/ci/publish-images-workflow.test.mjs
Inputs
- Successful FT51 exact-head ci-result.json for the same candidate SHA
- HARBOR_REGISTRY, HARBOR_PROJECT, HARBOR_USERNAME, and HARBOR_PASSWORD secret references
Outputs
- Harbor repositories aerosim/nebula:<full-sha> and aerosim/singularity:<full-sha>
- image-set.json {sourceRevision,nebulaDigest,singularityDigest,publishedAt}
Failure boundaries
- Do not log in or push when validation is missing, failed, or references another SHA.
- Fail the workflow if credentials are absent, either push fails, a returned digest is malformed, or only one image is published; do not emit a complete image-set.
Excluded scope
- The workflow does not use kubectl, Argo CD credentials, mutable latest tags, or direct commits to an environment branch.
Verification steps
- node --test tests/ci/publish-images-workflow.test.mjs
- Run mocked Harbor cases for both success, first-push failure, second-push failure, digest mismatch, absent credential, and stale ci-result SHA.
Traceability
Dependencies
- AEROSIM-TS-48Canonical ID: TASK-0048
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #102 implemented immutable image publication; forward fixes #107 and #108 repaired the integration database endpoint and publication browser runtime. Current integrated application test head 5f57f5b7059c47d7d2632748eeb687f3e9376a72 contains all three merge chains. Exact-head Actions runs 4080 and 4081 passed tasks 3101, 3102, 3103, and 3104: required validation, full validation, two-image build, Harbor publication, registry digest readback, and image-set upload. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.