The GitHub Actions job "Release Auditing" on texera.git/pr/curated-computing-unit-images has failed. Run started by GitHub user tanishqgandhi1908 (triggered by tanishqgandhi1908).
Head commit for run: 9ed9d0ed4f784d4192576a282cd674d6a57d7b5d / Tanishq Gandhi <[email protected]> feat(computing-unit): curate computing-unit images An administrator registers an image reference from a public registry, and a computing unit can then be started from it. Off by default until the UI to manage these ships. Texera reads the image's manifest and config blob -- a few kilobytes, never the layers -- to check its start command runs computing-unit-master, which means it was built FROM the Texera computing-unit image, and to resolve the digest behind the reference. A misspelled, private or unsuitable image is refused in seconds, in front of the administrator, rather than when a user's unit will not start. The row records owner/name@sha256:..., and that is what units run, so a tag its owner moves later cannot change what already ran. Nothing is copied and no registry is added: units pull the reference the same way the deployment's own image is already pulled. Uniqueness is enforced by the database, not only checked in the service. Two administrators registering the same link at the same moment both pass a read-then-write check and produce two rows for one image. A curated image was supplied by an administrator and reviewed by nobody, so a unit started from one runs as a non-root user with no privilege escalation and no capabilities. Curated images only -- the deployment's own image is its operator's choice, and one that has replaced it with an image needing root would break on upgrade. The first unit on each node waits for the image to download, about 80 seconds for a 3 GB one, while later units there start at once. Pre-pulling ready images onto nodes is a follow-up. Report URL: https://github.com/apache/texera/actions/runs/34399575967 With regards, GitHub Actions via GitBox
