diff --git a/DEVELOPER.md b/DEVELOPER.md index b2b849d..6b551f4 100644 --- a/DEVELOPER.md +++ b/DEVELOPER.md @@ -90,11 +90,15 @@ curl http://localhost:8000/api/v1/status | jq .version ### Docker images -Images are pushed to `docker.dcglab.co.uk/kb/engine` with tags: +Images are pushed to `docker.dcglab.co.uk/public/kb/engine` with tags: - `engine-v2.0.6-nvidia` / `engine-v2.0.6-cpu` — versioned - `latest-nvidia` / `latest-cpu` — latest release +The release script authenticates to the registry using the +`DOCKER_DCGLAB_CI_USERNAME` and `DOCKER_DCGLAB_CI_PASSWORD` environment +variables. + Override the registry and org via environment variables: ```bash diff --git a/MCP.md b/MCP.md index 7b74a8e..d0a6722 100644 --- a/MCP.md +++ b/MCP.md @@ -20,7 +20,7 @@ docker run -d --name kb-mcp \ -e KB_API_KEY=your-engine-key \ -e KB_MCP_API_KEY=your-agent-key \ --restart unless-stopped \ - docker.dcglab.co.uk/kb/mcp:latest + docker.dcglab.co.uk/public/kb/mcp:latest ``` ## MCP tools diff --git a/README.md b/README.md index 126f956..c5e5ed5 100644 --- a/README.md +++ b/README.md @@ -33,7 +33,7 @@ docker run -d --name kb-engine \ -e KB_DEVICE=auto \ -e KB_API_KEY=your-secret-key \ --restart unless-stopped \ - docker.dcglab.co.uk/kb/engine:latest-nvidia + docker.dcglab.co.uk/public/kb/engine:latest-nvidia # CPU only (no GPU required — smaller image) docker run -d --name kb-engine \ @@ -42,7 +42,7 @@ docker run -d --name kb-engine \ -e KB_MODEL=all-MiniLM-L6-v2 \ -e KB_API_KEY=your-secret-key \ --restart unless-stopped \ - docker.dcglab.co.uk/kb/engine:latest-cpu + docker.dcglab.co.uk/public/kb/engine:latest-cpu ``` Or use a compose file from the repo: diff --git a/openspec/specs/docker-deployment/spec.md b/openspec/specs/docker-deployment/spec.md index e1afb41..189276b 100644 --- a/openspec/specs/docker-deployment/spec.md +++ b/openspec/specs/docker-deployment/spec.md @@ -65,7 +65,7 @@ The project SHALL provide Docker Compose files for single-command deployment. Co #### Scenario: Pre-built image deployment - **WHEN** an admin wants to use a pre-built engine image without building from source -- **THEN** the engine release notes SHALL include the exact `docker pull` command with the versioned tag (e.g. `docker.dcglab.co.uk/kb/engine:engine-v2.1.0-nvidia`) +- **THEN** the engine release notes SHALL include the exact `docker pull` command with the versioned tag (e.g. `docker.dcglab.co.uk/public/kb/engine:engine-v2.1.0-nvidia`) #### Scenario: MCP allowed hosts in Compose - **WHEN** the kb-mcp service is defined in a Compose file diff --git a/release-engine.sh b/release-engine.sh index 640de67..4680388 100755 --- a/release-engine.sh +++ b/release-engine.sh @@ -20,7 +20,7 @@ VERSION_FILE="$ENGINE_DIR/VERSION" # attestation manifests, making the image an OCI image index. The Registry v2 # host at docker.dcglab.co.uk rejects those with a 500 on manifest PUT. REGISTRY="${REGISTRY:-docker.dcglab.co.uk}" -IMAGE_ORG="${IMAGE_ORG:-}" +IMAGE_ORG="${IMAGE_ORG:-public}" IMAGE_BASE="${REGISTRY}${IMAGE_ORG:+/${IMAGE_ORG}}/kb" # Push retries — see push_image() below @@ -106,6 +106,16 @@ run() { fi } +registry_login() { + echo " $ docker login $REGISTRY --username \$DOCKER_DCGLAB_CI_USERNAME --password-stdin" + [[ "$DRY_RUN" == true ]] && return 0 + + printf '%s' "$DOCKER_DCGLAB_CI_PASSWORD" | + docker login "$REGISTRY" \ + --username "$DOCKER_DCGLAB_CI_USERNAME" \ + --password-stdin +} + # Push one image tag, retrying on transient registry failures. # # The engine images carry a ~5.6GB torch layer. Uploading it intermittently @@ -165,6 +175,17 @@ echo "" echo "==> Pre-flight checks" if [[ "$DRY_RUN" == false ]]; then + if [[ -z "${DOCKER_DCGLAB_CI_USERNAME:-}" ]]; then + echo "Error: DOCKER_DCGLAB_CI_USERNAME is required" >&2 + exit 1 + fi + if [[ -z "${DOCKER_DCGLAB_CI_PASSWORD:-}" ]]; then + echo "Error: DOCKER_DCGLAB_CI_PASSWORD is required" >&2 + exit 1 + fi + + registry_login + if git -C "$SCRIPT_DIR" rev-parse "$GIT_TAG" &>/dev/null; then echo "Error: tag $GIT_TAG already exists" exit 1