Skip to content

chore(ci): sign container images#1256

Merged
webern merged 1 commit intomainfrom
matt.brigg/signed-images
Mar 23, 2026
Merged

chore(ci): sign container images#1256
webern merged 1 commit intomainfrom
matt.brigg/signed-images

Conversation

@webern
Copy link
Contributor

@webern webern commented Mar 23, 2026

Add a ddsign invocation to internal docker build workflows to sign the images.

Summary

Use ddsign to sign the images we are building in the build-ci and build-smp workflows.

Change Type

  • Bug fix
  • New feature
  • Non-functional (chore, refactoring, docs)
  • Performance

How did you test this PR?

✅ I ran the internal Build CI helper images (build, SMP) pipeline and both generate-build-ci-image and generate-general-ci-image both passed.

References

@webern webern requested a review from a team as a code owner March 23, 2026 14:00
@dd-octo-sts dd-octo-sts bot added the area/ci CI/CD, automated testing, etc. label Mar 23, 2026
@pr-commenter
Copy link

pr-commenter bot commented Mar 23, 2026

Binary Size Analysis (Agent Data Plane)

Target: 22c49c4 (baseline) vs e630876 (comparison) diff
Analysis Type: Stripped binaries (debug symbols excluded)
Baseline Size: 26.17 MiB
Comparison Size: 26.17 MiB
Size Change: +0 B (+0.00%)
Pass/Fail Threshold: +5%
Result: PASSED ✅

Changes by Module

Module File Size Symbols

Detailed Symbol Changes

    FILE SIZE        VM SIZE    
 --------------  -------------- 
  [ = ]       0  [ = ]       0    TOTAL

@pr-commenter
Copy link

pr-commenter bot commented Mar 23, 2026

Regression Detector (Agent Data Plane)

Regression Detector Results

Run ID: 25ec9344-d329-4a40-92a0-14a69e4f327b

Baseline: 22c49c4
Comparison: a99778d
Diff

Optimization Goals: ✅ No significant changes detected

Experiments ignored for regressions

Regressions in experiments with settings containing erratic: true are ignored.

perf experiment goal Δ mean % Δ mean % CI trials links
otlp_ingest_logs_5mb_memory memory utilization +1.19 [+0.46, +1.93] 1 (metrics) (profiles) (logs)
otlp_ingest_logs_5mb_throughput ingress throughput -0.02 [-0.16, +0.11] 1 (metrics) (profiles) (logs)
otlp_ingest_logs_5mb_cpu % cpu utilization -1.38 [-6.52, +3.77] 1 (metrics) (profiles) (logs)

Fine details of change detection per experiment

perf experiment goal Δ mean % Δ mean % CI trials links
dsd_uds_100mb_3k_contexts_cpu % cpu utilization +1.93 [-4.40, +8.26] 1 (metrics) (profiles) (logs)
otlp_ingest_logs_5mb_memory memory utilization +1.19 [+0.46, +1.93] 1 (metrics) (profiles) (logs)
dsd_uds_512kb_3k_contexts_cpu % cpu utilization +1.01 [-57.19, +59.21] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_transform_5mb_cpu % cpu utilization +0.48 [-1.74, +2.69] 1 (metrics) (profiles) (logs)
dsd_uds_500mb_3k_contexts_cpu % cpu utilization +0.48 [-0.96, +1.91] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_5mb_memory memory utilization +0.46 [+0.20, +0.72] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_filtering_5mb_cpu % cpu utilization +0.38 [-2.17, +2.92] 1 (metrics) (profiles) (logs)
quality_gates_rss_dsd_medium memory utilization +0.29 [+0.10, +0.47] 1 (metrics) (profiles) (logs)
quality_gates_rss_dsd_low memory utilization +0.21 [+0.02, +0.40] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_filtering_5mb_memory memory utilization +0.20 [-0.14, +0.54] 1 (metrics) (profiles) (logs)
dsd_uds_1mb_3k_contexts_memory memory utilization +0.16 [-0.01, +0.33] 1 (metrics) (profiles) (logs)
quality_gates_rss_dsd_ultraheavy memory utilization +0.08 [-0.04, +0.20] 1 (metrics) (profiles) (logs)
dsd_uds_10mb_3k_contexts_memory memory utilization +0.05 [-0.13, +0.23] 1 (metrics) (profiles) (logs)
otlp_ingest_metrics_5mb_throughput ingress throughput +0.02 [-0.11, +0.16] 1 (metrics) (profiles) (logs)
dsd_uds_100mb_3k_contexts_throughput ingress throughput +0.01 [-0.02, +0.04] 1 (metrics) (profiles) (logs)
dsd_uds_512kb_3k_contexts_memory memory utilization +0.00 [-0.17, +0.17] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_5mb_throughput ingress throughput +0.00 [-0.02, +0.02] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_filtering_5mb_throughput ingress throughput +0.00 [-0.02, +0.02] 1 (metrics) (profiles) (logs)
dsd_uds_1mb_3k_contexts_throughput ingress throughput -0.00 [-0.06, +0.06] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_transform_5mb_throughput ingress throughput -0.00 [-0.02, +0.02] 1 (metrics) (profiles) (logs)
dsd_uds_10mb_3k_contexts_throughput ingress throughput -0.01 [-0.14, +0.13] 1 (metrics) (profiles) (logs)
dsd_uds_512kb_3k_contexts_throughput ingress throughput -0.01 [-0.06, +0.04] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_ottl_transform_5mb_memory memory utilization -0.02 [-0.28, +0.23] 1 (metrics) (profiles) (logs)
otlp_ingest_logs_5mb_throughput ingress throughput -0.02 [-0.16, +0.11] 1 (metrics) (profiles) (logs)
quality_gates_rss_dsd_heavy memory utilization -0.02 [-0.15, +0.11] 1 (metrics) (profiles) (logs)
quality_gates_rss_idle memory utilization -0.11 [-0.14, -0.08] 1 (metrics) (profiles) (logs)
dsd_uds_100mb_3k_contexts_memory memory utilization -0.27 [-0.45, -0.08] 1 (metrics) (profiles) (logs)
dsd_uds_500mb_3k_contexts_memory memory utilization -0.27 [-0.44, -0.10] 1 (metrics) (profiles) (logs)
dsd_uds_500mb_3k_contexts_throughput ingress throughput -0.32 [-0.45, -0.19] 1 (metrics) (profiles) (logs)
otlp_ingest_metrics_5mb_cpu % cpu utilization -0.54 [-7.87, +6.79] 1 (metrics) (profiles) (logs)
otlp_ingest_logs_5mb_cpu % cpu utilization -1.38 [-6.52, +3.77] 1 (metrics) (profiles) (logs)
otlp_ingest_traces_5mb_cpu % cpu utilization -1.46 [-3.69, +0.77] 1 (metrics) (profiles) (logs)
dsd_uds_10mb_3k_contexts_cpu % cpu utilization -2.43 [-33.63, +28.77] 1 (metrics) (profiles) (logs)
dsd_uds_1mb_3k_contexts_cpu % cpu utilization -3.59 [-57.37, +50.19] 1 (metrics) (profiles) (logs)
otlp_ingest_metrics_5mb_memory memory utilization -4.75 [-5.01, -4.49] 1 (metrics) (profiles) (logs)

Bounds Checks: ✅ Passed

perf experiment bounds_check_name replicates_passed observed_value links
quality_gates_rss_dsd_heavy memory_usage 10/10 112.86MiB ≤ 140MiB (metrics) (profiles) (logs)
quality_gates_rss_dsd_low memory_usage 10/10 33.79MiB ≤ 50MiB (metrics) (profiles) (logs)
quality_gates_rss_dsd_medium memory_usage 10/10 52.79MiB ≤ 75MiB (metrics) (profiles) (logs)
quality_gates_rss_dsd_ultraheavy memory_usage 10/10 167.09MiB ≤ 200MiB (metrics) (profiles) (logs)
quality_gates_rss_idle memory_usage 10/10 21.16MiB ≤ 40MiB (metrics) (profiles) (logs)

Explanation

Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%

Performance changes are noted in the perf column of each table:

  • ✅ = significantly better comparison variant performance
  • ❌ = significantly worse comparison variant performance
  • ➖ = no significant change in performance

A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".

For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:

  1. Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.

  2. Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.

  3. Its configuration does not mark it "erratic".

@webern webern force-pushed the matt.brigg/signed-images branch from 5809a53 to 92f3e98 Compare March 23, 2026 14:41
@webern
Copy link
Contributor Author

webern commented Mar 23, 2026

@webern webern force-pushed the matt.brigg/signed-images branch from 92f3e98 to a99778d Compare March 23, 2026 15:08
@webern
Copy link
Contributor Author

webern commented Mar 23, 2026

/merge

@gh-worker-devflow-routing-ef8351
Copy link

gh-worker-devflow-routing-ef8351 bot commented Mar 23, 2026

View all feedbacks in Devflow UI.

2026-03-23 15:08:42 UTC ℹ️ Start processing command /merge


2026-03-23 15:08:49 UTC ℹ️ MergeQueue: waiting for PR to be ready

This pull request is not mergeable according to GitHub. Common reasons include pending required checks, missing approvals, or merge conflicts — but it could also be blocked by other repository rules or settings.
It will be added to the queue as soon as checks pass and/or get approvals. View in MergeQueue UI.
Note: if you pushed new commits since the last approval, you may need additional approval.
You can remove it from the waiting list with /remove command.


2026-03-23 16:55:09 UTC ℹ️ MergeQueue: merge request added to the queue

The expected merge time in main is approximately 12m (p90).


2026-03-23 16:59:02 UTC ℹ️ MergeQueue: This merge request was already merged

This pull request was merged directly.

Add a ddsign invocation to internal docker build workflows to sign the images.
@webern webern force-pushed the matt.brigg/signed-images branch from a99778d to e630876 Compare March 23, 2026 16:42
@webern webern merged commit 36c9e85 into main Mar 23, 2026
59 of 60 checks passed
@webern webern deleted the matt.brigg/signed-images branch March 23, 2026 16:59
dd-octo-sts bot pushed a commit that referenced this pull request Mar 23, 2026
Add a ddsign invocation to internal docker build workflows to sign the
images.

## Summary
<!-- Please provide a brief summary about what this PR does.
This should help the reviewers give feedback faster and with higher
quality. -->

Use ddsign to sign the images we are building in the build-ci and
build-smp workflows.

## Change Type
- [ ] Bug fix
- [ ] New feature
- [X] Non-functional (chore, refactoring, docs)
- [ ] Performance

## How did you test this PR?

✅ I ran the internal `Build CI helper images (build, SMP)` pipeline and
both `generate-build-ci-image` and `generate-general-ci-image` both
passed.

## References

<!-- Please list any issues closed by this PR. -->

<!--
- Closes: <issue link>
-->

<!-- Any other issues or PRs relevant to this PR? Feel free to list them
here. --> 36c9e85
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci CI/CD, automated testing, etc. mergequeue-status: done

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants