Create and push syndicated tags during builds - #2239
Merged
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: ef3e1f6f-f17d-4cc9-8466-aa0b5e21dbdf
mthalman
reviewed
Sep 17, 2026
mthalman
left a comment
Member
There was a problem hiding this comment.
What about signing? ImageSigningService calls GetAllDigests:
But that implementation does not handle syndication:
docker-tools/src/ImageBuilder/ImageInfoHelper.cs
Lines 70 to 82 in 8f2d2aa
That means that digests addressed by aspire/dashboard would be signed but not digests at dotnet/aspire-dashboard.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: ef3e1f6f-f17d-4cc9-8466-aa0b5e21dbdf
Member
Author
mthalman
approved these changes
Sep 17, 2026
lbussell
enabled auto-merge (squash)
September 17, 2026 21:27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Aspire Dashboard images will be syndicated for a period of time. When attempting to publish syndicated aspire dashboard images, the post-build stage failed with:
In this instance,
dotnet/nightly/aspire-dashboardis the syndicated version of the image.The manifest list creation task attempts to create the syndicated manifest lists, but since the syndicated platform-specific tags haven't been created yet, it fails.
Historically, here is how syndication worked:
Prior to #2030 (aka the last time we had working syndication):
After #2030:
With the changes from this PR:
You may be wondering, "Why not have the Build/Post-Build stages operate only on primary tags, and just create syndicated tags as part of publishing?"
This approach is appealing, but the current manifest/syndication model is on a tag-specific basis. This means that platforms may participate selectively in syndication.
If an image has platforms
[A, B, C], but only platforms[A, B]are syndicated with shared syndicated tags, then that necessitates a new manifest list[A, B]be created. Thus, we must create it during Build/Post-Build and not during Publishing (so that it can get signed, etc.).I would like to simplify the syndication model to image-level instead of tag-level, but I will leave that as follow-up work. This PR is required to unblock syndication of Aspire Dashboard images.