Repository navigation
Conversation
The managed-images promote lane already builds, validates, attests, and stages ghcr.io/nvidia/nemoclaw/hermes-sandbox in the same six-candidate cohort barrier as openclaw-sandbox, and the durable cohort contract already records all three agents. Only the consumer pointers were OpenClaw-only, so Hermes never received a :<revision> or :<release> tag and downstream Hermes images had to rebuild agents/hermes/Dockerfile from a version-matched checkout (#11228). Generalize both pointer sites to a shipped_agents list of openclaw and hermes: the staging step records each shipped agent's consumer aliases in its exact per-platform contract, and the pointer step validates every shipped agent's contract and exact cohort bytes before moving any pointer, then creates and byte-verifies each agent's aliases. Deep Agents Code intentionally stays cohort-only. The publication tests execute the actual workflow bash and now prove the Hermes pointer moves only after all cohort aliases stage, that a barrier failure moves no pointer for either agent, and that Deep Agents Code receives no consumer pointer. The Hermes plugin guide documents starting custom images FROM the published complete image instead of reproducing the managed Dockerfile. Signed-off-by: Zac Wang <zacw@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (4)
Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review. 📝 WalkthroughWalkthroughThe managed-image workflow now promotes OpenClaw and Hermes commit and release aliases from exact cohort manifests. Deep Agents Code remains cohort-only. Tests cover both shipped agents, and Hermes documentation uses the complete published image with a digest pin. ChangesManaged image promotion
Sequence Diagram(s)sequenceDiagram
participant Workflow as managed-images workflow
participant Manifest as cohort manifest
participant Registry as image registry
Workflow->>Manifest: validate OpenClaw and Hermes references
Workflow->>Registry: promote commit and release aliases
Workflow->>Registry: verify exact alias bytes
Suggested reviewers: Priority: ➖ Normal Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The Hermes alias promotion, validation barriers, tests, and documentation are aligned with the managed-image publication contract. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 unsupported.) ✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
|
🌿 Preview your docs: https://nvidia-preview-pr-11310.docs.buildwithfern.com/nemoclaw |
|
Closing the same-repository qualification replay because the original contributor PR #11298 was approved and merged as |
Outcome
NemoClaw publishes Hermes revision and release aliases from the same validated managed-image cohort as OpenClaw. Downstream Hermes images can resolve a release alias and pin its digest without rebuilding the NemoClaw Hermes Dockerfile.
Reason
The workflow already builds, validates, attests, and publishes the complete Hermes image under cohort tags. The missing consumer aliases make that supported image difficult to discover and use from downstream custom images.
Related issues
Resolves #11228.
Replays #11298 on a same-repository branch so trusted CI can qualify the contribution. The commit retains Zac Wang as its author.
Changes
Verification
npx vitest run test/inference/managed/managed-image-publication-promotion.test.ts test/inference/managed/managed-image-publication-workflow.test.ts— 39 tests passed.npm run docs— passed with zero errors.NODE_OPTIONS=--max-old-space-size=8192 npm run validate:pr— passed after installing and building both current-main package workspaces required by the fresh checkout.Review notes
The accepted product decision is recorded on #11228. NemoClaw managed-image and release maintainers own the release aliases and first-release validation.
This PR changes
.github/workflows/managed-images.yaml. The completed nine-category security review found no credential, authorization, dependency, cryptography, sandbox, or policy regression. Both agents are validated before publication. GHCR cannot update two image repositories atomically, so a registry failure can leave an earlier alias moved; rerunning the same release job reconciles every alias to the same immutable cohort.Live pointer promotion runs only from trusted
mainor release-tag workflows. The first shipping release must inspect the published Hermes manifest and run managed-image activation against the published release alias.Signed-off-by: Aaron Erickson aerickson@nvidia.com
Summary by CodeRabbit
New Features
Documentation
Tests