terdut-server was the only one of the three release-managed repos with no image scanning at all. riksdata and rd-web have had a scan-image job since they were set up; everything published here up to and including v0.9.3 went out without a CVE check. It scans the pushed image rather than a locally built one, for the same reason the siblings do: trivy cannot read a local image on this runner, since Talos has no docker socket and the dind sidecar shares no filesystem with the job. So it runs after image rather than gating it, and a red scan unpublishes nothing. What it means is narrower and worth stating plainly: do not bump the wrapper chart in Ryuvia/charts to that version. Checked before wiring it in rather than after. v0.9.3 scans clean at HIGH,CRITICAL with unfixed findings ignored, so this does not turn the pipeline red on arrival, and the same command exits 1 on an image that does have findings — a gate that cannot fail is not a gate. One platform is scanned, not both. The image is FROM scratch, so there are no OS packages and trivy sees a single target: the Go binary and its module graph. linux/amd64 and linux/arm64 are that same module set built for a different GOARCH, so a finding in one is a finding in both. On an image with a base layer that reasoning would not hold. Still no govulncheck and no gitleaks here, which riksdata and rd-web run in a separate CI job. This is the only security scanning terdut-server has. Claude-Session: https://claude.ai/code/session_01S7R4gWTz5wh5xCY4nCSJjN
1.8 KiB
Release
Say "Release" (or "Release X.Y.Z") and the release skill runs it: commit, push, tag,
wait for the pipeline, then open the wrapper-chart PR against Ryuvia/charts. It stops
there — merging and the Flux reconcile stay manual, deliberately.
Preconditions and the plan, without side effects:
~/.claude/skills/release/scripts/release-preflight # state + suggested version
~/.claude/skills/release/scripts/release-preflight vX.Y.Z # validate that release
Config is .release.conf here plus make release-vars. The process itself lives in
~/.claude/skills/release/; why it is shaped this way is in README.md §Releasing.
Two things about this repo specifically:
- The image is scanned after it is published, not before.
scan-imageruns trivy against the pushed image, because trivy cannot read a locally built one on this runner. A red scan therefore unpublishes nothing — it means: do not bump the wrapper chart inRyuvia/chartsto this version. Added 2026-09-02; every release up to and including v0.9.3 was published with no CVE check at all. - The wrapper chart has two
tag:lines — the app image and the python backup sidecar — sochart-bumpneeds--image "$IMAGE"to know which one moves.
Checks
make fmt lint test helm-lint is what the pipeline runs — ci.yaml and release.yaml
call these targets rather than restating them, the way riksdata and rd-web do. A green gate
here and a green pipeline are the same code, not two descriptions of it. test adds -race,
which the workflows do not have to ask for since they call the target; see the comment on it
for why.
make release (build + push the multi-arch image, package + push the chart) is what
release.yaml invokes. Do not run it by hand — it refuses VERSION=dev for that reason, and
publishing happens by pushing a tag.