Skip to content

Fix crane install permissions in GHCR CI - #93

Open
pawelchcki wants to merge 3 commits into
mainfrom
dd/fix/devcontainer-ghcr-crane-permissions
Open

pawelchcki wants to merge 3 commits into
mainfrom
dd/fix/devcontainer-ghcr-crane-permissions

Conversation

@pawelchcki

@pawelchcki pawelchcki commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The devcontainer_to_ghcr job failed while extracting crane into /usr/local/bin, which the CI image cannot write. The fix installs it in the job workspace. A temporary PR run verified the archive checksum, extraction, and crane version in the actual GitLab CI image. The temporary PR rule has been removed.

Changes

  • Extract crane into a writable directory under CI_PROJECT_DIR and add it to the job's PATH.
  • Call the installed binary by its full path in after_script, which runs in a separate shell.
  • Restore the original default-branch-only rule after the successful CI probe.

Testing

  • GitLab devcontainer_to_ghcr passed on the temporary PR probe, which exited after crane version and before GHCR authentication or publishing.
  • Parsed the GitLab CI YAML and checked each job shell block with sh -n.
  • Confirmed the final CI file matches the original fix and checked the diff for whitespace errors.

PR by Bits - View session in Datadog

Comment @DataDog to request changes

Co-authored-by: pawelchcki <pawel.chcki@gmail.com>
@datadog-datadog-prod-us1-2

datadog-datadog-prod-us1-2 Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

View session in Datadog

Bits Code status: ✅ Done

CI Auto-fix: Disabled | Enable

Comment @DataDog to request changes

@pawelchcki
pawelchcki requested a review from a team as a code owner September 29, 2026 15:50
@pawelchcki
pawelchcki requested review from xlamorlette-datadog and removed request for a team September 29, 2026 15:50
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T15:53:14.000135Z 61759c0 PR opened
🔒 Security Review ✅ Completed 2026-09-29T15:54:51.154656Z 61759c0 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 61759c073f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +40 to +42
mkdir -p "$crane_bin_dir"
tar -xzf "$crane_archive" -C "$crane_bin_dir" crane
export PATH="$crane_bin_dir:$PATH"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Move the crane fix to the source template

This file says it is synced from DataDog/dd-repo-tools and must not be edited here. The next campaign sync can replace this local install fix, restore extraction to /usr/local/bin, and break the job again. Apply the fix to the named source template, then sync the generated file.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@datadog-datadog-prod-us1-2

This comment has been minimized.

Co-authored-by: pawelchcki <pawel.chcki@gmail.com>
@pawelchcki pawelchcki changed the title Fix crane install permissions in GHCR CI[bits] Fix crane install permissions in GHCR CI Sep 29, 2026
This reverts commit de0c40d.

Co-authored-by: pawelchcki <pawel.chcki@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants