ci: add GHCR publish workflow (Phase 6) - #8
Open
OneByJorah wants to merge 20 commits into
Open
Conversation
Bumps [python-multipart](https://github.com/Kludex/python-multipart) from 0.0.14 to 0.0.31. - [Release notes](https://github.com/Kludex/python-multipart/releases) - [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md) - [Commits](Kludex/python-multipart@0.0.14...0.0.31) --- updated-dependencies: - dependency-name: python-multipart dependency-version: 0.0.31 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.0.1 to 1.2.2. - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.0.1...v1.2.2) --- updated-dependencies: - dependency-name: python-dotenv dependency-version: 1.2.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ure, and tech stack
Co-authored-by: OneByJorah <OneByJorah@users.noreply.github.com>
- Added Dockerfile with multi-stage build - Added .env.example with placeholder values - Updated README with deployment instructions
- Create api/models.py with all 11 ORM model classes matching db/schema.sql - Add get_db() FastAPI dependency for session management - Update api/app.py with lifespan handler for table creation on startup - Fix api/routes/training.py imports to use models module - Add missing imports: logging, UploadFile, File Fixes CRITICAL: app would fail to import due to missing model definitions
- Add import logging, UploadFile, File to training.py - Fix model imports to use api.models module - Add import for Question model (used in list_questions endpoint) Fixes CRITICAL: NameError on logging.getLogger() and UploadFile/File
- Remove two RUN pip install commands that installed packages before COPY requirements.txt, making them wasted build layers - Reorder: apt-get first, then COPY requirements.txt, then pip install -r - This halves build time and reduces image layers Fixes CRITICAL: redundant package installations doubling build time
…entials - Add healthcheck stanza to all 4 services (ollama, qdrant, minio, training-api) - Change ollama and qdrant from ports: to expose: (internal only) - Add depends_on with condition: service_healthy for proper startup ordering - Change MINIO_ROOT_PASSWORD and SECRET_KEY to required vars (:? syntax) - Remove deprecated version field (Compose v2) Fixes CRITICAL: no health checks, unnecessary port exposure, default credentials
- Add WARNING comments about changing default credentials - Add note about generating a strong SECRET_KEY - Keep backward-compatible defaults for local dev Fixes CRITICAL: default credentials without warnings
…e tree - Replace PostgreSQL badge with SQLite badge (actual default database) - Fix architecture tree: db/ is "SQLite schema definition", not "models & migrations" - Update tech stack: "SQLite (PostgreSQL upgrade path)" for accuracy Fixes DEGRADED: misleading PostgreSQL references in README
- Create app user/group (uid/gid 1001) and switch to non-root USER - Add .dockerignore to exclude unnecessary files from build context - Chown /app and /uploads for the app user Fixes DEGRADED: services running as root in containers, no .dockerignore
- Add @app.middleware("http") for security headers:
X-Content-Type-Options, X-Frame-Options, CSP, X-XSS-Protection, Referrer-Policy
- Add CORSMiddleware with restrictive defaults (no origins, GET only)
- Add lifespan handler for database table creation on startup
Fixes CRITICAL: missing security headers on all API responses
Fixes DEGRADED: no CORS configuration
- Add reports/ to .gitignore to prevent pipeline artifacts from being tracked - Create j1.yaml with project classification and metadata Fixes DEGRADED: reports/ not excluded from git tracking
- Update remote URL to OneByJorah/LearnForge - Update README: title, clone URL, directory tree - Update Makefile PROJECT variable - Update j1.yaml repo field - Update INTENT.md: repo ref, description, ecosystem diagram, tree, notes - Update api/app.py: FastAPI title, service name in root endpoint - Update api/models.py: module docstring - Update docs/deploy.md: title, clone URL - Update docs/skill-authors.md: title
… to ghcr.io on push to default branch / tags,\nusing the built-in GITHUB_TOKEN (packages: write). Auto-generated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-generated workflow that builds and publishes the repo's image(s) to
ghcr.io/onebyjorah/*on push to the default branch and on version tags. Uses the built-inGITHUB_TOKEN(packages: write) — no PAT required. Part of the J1 standardization pipeline (Phase 6).