Add CI workflow for building and publishing Kubernetes Agent Docker images and Helm chart
Migrates the Kubernetes Agent build pipeline from TeamCity to GitHub Actions. Builds three multi-arch Docker images in parallel, creates manifests, and publishes a Helm chart to OCI registry.
Workflow structure
build-publish-kubernetes-agent.yml
├── resolve-tag ← GitVersion (identical to build-api-docker.yml)
├── build-tentacle ← squid-tentacle (amd64 + arm64 matrix)
├── build-watchdog ← squid-watchdog (amd64 + arm64 matrix)
├── build-nfs-server ← nfs-server (amd64 + arm64 matrix)
├── manifest ← multi-arch manifest for all three images
└── helm ← helm package + push to OCI registry
Key decisions
-
Separate credentials: Uses
SQUID_DOCKER_USERNAME/SQUID_DOCKER_PASSWORD/SQUID_DOCKER_HUB— distinct from the API workflow'sDOCKER_*since these push to a different Docker Hub org -
Version consistency:
resolve-tagis identical tobuild-api-docker.yml(GitVersion 6.xfullSemVer,+→-replacement) -
Chart packaging: Copies chart to
/tmpbeforesed-ingversion/appVersionto avoid mutating the working tree
Required repository configuration
| Type | Name | Purpose |
|---|---|---|
| Variable | SQUID_DOCKER_HUB |
Docker Hub org/namespace for agent images |
| Secret | SQUID_DOCKER_USERNAME |
Docker Hub username |
| Secret | SQUID_DOCKER_PASSWORD |
Docker Hub password/token |