Publish Docker images to public registry

This commit is contained in:
2026-08-22 18:04:18 +01:00
parent a38d77ed23
commit 48ca873fe2
5 changed files with 31 additions and 6 deletions
+5 -1
View File
@@ -90,11 +90,15 @@ curl http://localhost:8000/api/v1/status | jq .version
### Docker images ### Docker images
Images are pushed to `docker.dcglab.co.uk/kb/engine` with tags: Images are pushed to `docker.dcglab.co.uk/public/kb/engine` with tags:
- `engine-v2.0.6-nvidia` / `engine-v2.0.6-cpu` — versioned - `engine-v2.0.6-nvidia` / `engine-v2.0.6-cpu` — versioned
- `latest-nvidia` / `latest-cpu` — latest release - `latest-nvidia` / `latest-cpu` — latest release
The release script authenticates to the registry using the
`DOCKER_DCGLAB_CI_USERNAME` and `DOCKER_DCGLAB_CI_PASSWORD` environment
variables.
Override the registry and org via environment variables: Override the registry and org via environment variables:
```bash ```bash
+1 -1
View File
@@ -20,7 +20,7 @@ docker run -d --name kb-mcp \
-e KB_API_KEY=your-engine-key \ -e KB_API_KEY=your-engine-key \
-e KB_MCP_API_KEY=your-agent-key \ -e KB_MCP_API_KEY=your-agent-key \
--restart unless-stopped \ --restart unless-stopped \
docker.dcglab.co.uk/kb/mcp:latest docker.dcglab.co.uk/public/kb/mcp:latest
``` ```
## MCP tools ## MCP tools
+2 -2
View File
@@ -33,7 +33,7 @@ docker run -d --name kb-engine \
-e KB_DEVICE=auto \ -e KB_DEVICE=auto \
-e KB_API_KEY=your-secret-key \ -e KB_API_KEY=your-secret-key \
--restart unless-stopped \ --restart unless-stopped \
docker.dcglab.co.uk/kb/engine:latest-nvidia docker.dcglab.co.uk/public/kb/engine:latest-nvidia
# CPU only (no GPU required — smaller image) # CPU only (no GPU required — smaller image)
docker run -d --name kb-engine \ docker run -d --name kb-engine \
@@ -42,7 +42,7 @@ docker run -d --name kb-engine \
-e KB_MODEL=all-MiniLM-L6-v2 \ -e KB_MODEL=all-MiniLM-L6-v2 \
-e KB_API_KEY=your-secret-key \ -e KB_API_KEY=your-secret-key \
--restart unless-stopped \ --restart unless-stopped \
docker.dcglab.co.uk/kb/engine:latest-cpu docker.dcglab.co.uk/public/kb/engine:latest-cpu
``` ```
Or use a compose file from the repo: Or use a compose file from the repo:
+1 -1
View File
@@ -65,7 +65,7 @@ The project SHALL provide Docker Compose files for single-command deployment. Co
#### Scenario: Pre-built image deployment #### Scenario: Pre-built image deployment
- **WHEN** an admin wants to use a pre-built engine image without building from source - **WHEN** an admin wants to use a pre-built engine image without building from source
- **THEN** the engine release notes SHALL include the exact `docker pull` command with the versioned tag (e.g. `docker.dcglab.co.uk/kb/engine:engine-v2.1.0-nvidia`) - **THEN** the engine release notes SHALL include the exact `docker pull` command with the versioned tag (e.g. `docker.dcglab.co.uk/public/kb/engine:engine-v2.1.0-nvidia`)
#### Scenario: MCP allowed hosts in Compose #### Scenario: MCP allowed hosts in Compose
- **WHEN** the kb-mcp service is defined in a Compose file - **WHEN** the kb-mcp service is defined in a Compose file
+22 -1
View File
@@ -20,7 +20,7 @@ VERSION_FILE="$ENGINE_DIR/VERSION"
# attestation manifests, making the image an OCI image index. The Registry v2 # attestation manifests, making the image an OCI image index. The Registry v2
# host at docker.dcglab.co.uk rejects those with a 500 on manifest PUT. # host at docker.dcglab.co.uk rejects those with a 500 on manifest PUT.
REGISTRY="${REGISTRY:-docker.dcglab.co.uk}" REGISTRY="${REGISTRY:-docker.dcglab.co.uk}"
IMAGE_ORG="${IMAGE_ORG:-}" IMAGE_ORG="${IMAGE_ORG:-public}"
IMAGE_BASE="${REGISTRY}${IMAGE_ORG:+/${IMAGE_ORG}}/kb" IMAGE_BASE="${REGISTRY}${IMAGE_ORG:+/${IMAGE_ORG}}/kb"
# Push retries — see push_image() below # Push retries — see push_image() below
@@ -106,6 +106,16 @@ run() {
fi fi
} }
registry_login() {
echo " $ docker login $REGISTRY --username \$DOCKER_DCGLAB_CI_USERNAME --password-stdin"
[[ "$DRY_RUN" == true ]] && return 0
printf '%s' "$DOCKER_DCGLAB_CI_PASSWORD" |
docker login "$REGISTRY" \
--username "$DOCKER_DCGLAB_CI_USERNAME" \
--password-stdin
}
# Push one image tag, retrying on transient registry failures. # Push one image tag, retrying on transient registry failures.
# #
# The engine images carry a ~5.6GB torch layer. Uploading it intermittently # The engine images carry a ~5.6GB torch layer. Uploading it intermittently
@@ -165,6 +175,17 @@ echo ""
echo "==> Pre-flight checks" echo "==> Pre-flight checks"
if [[ "$DRY_RUN" == false ]]; then if [[ "$DRY_RUN" == false ]]; then
if [[ -z "${DOCKER_DCGLAB_CI_USERNAME:-}" ]]; then
echo "Error: DOCKER_DCGLAB_CI_USERNAME is required" >&2
exit 1
fi
if [[ -z "${DOCKER_DCGLAB_CI_PASSWORD:-}" ]]; then
echo "Error: DOCKER_DCGLAB_CI_PASSWORD is required" >&2
exit 1
fi
registry_login
if git -C "$SCRIPT_DIR" rev-parse "$GIT_TAG" &>/dev/null; then if git -C "$SCRIPT_DIR" rev-parse "$GIT_TAG" &>/dev/null; then
echo "Error: tag $GIT_TAG already exists" echo "Error: tag $GIT_TAG already exists"
exit 1 exit 1