summaryrefslogtreecommitdiffstats
path: root/image-builder/registry-gc.sh
AgeCommit message (Collapse)AuthorFilesLines
14 daysrelease 1.1.2v1.1.2Danilo M.1-1/+1
Also records the host config the chain depends on. The schedule and the storage layout existed only on the VM, so a rebuilt host would have lost both, and the README's inline copy of the schedule had already drifted from what actually runs. crontab.example is byte-identical to the deployed crontab; fstab.example carries the two-disk layout and the dockerd mount-namespace trap that makes moving the registry store non-obvious. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10image-builder: add safe registry GC and stop OCI-index breakageDanilo M.1-0/+192
The registry never reclaims blobs, so its store grows until the disk fills and the nightly builds fail with "no space left on device". Add registry-gc.sh, run weekly (Sunday 08:00), plus a daily dangling-image prune. registry-gc.sh refuses to run while a build is active, stops the registry for a stable blob graph, deletes only untagged manifests (-m) and their blobs, restarts via an EXIT trap, and verifies a tag still pulls. distribution 2.8.x GC does not follow OCI image indexes, so -m deletes their child manifests (distribution#3178). Default BuildKit provenance made every pushed tag an OCI index, which made -m destructive. Build scripts now pass --provenance=false (plain schema2), and registry-gc.sh refuses to run if any tag is still an index.