Fold build-tools into this repo

build-tools is the image the pipeline's build pod runs its shell steps in.
It was owned by devops-lib, which is an odd home: it is not library code,
it is an artefact built by hand and pushed to Harbor, exactly like the
mirrors here. devops-lib only ever referenced the result by tag, and it
still will.

Three deliberate changes from the homelab's version:

- Pushed to base-images/build-tools:1, not homelab/. That project is
  public, so build pods pull it with no credentials — the same reason the
  language images live there.

- FROM the mirrored docker:27-cli rather than Docker Hub, with that tag
  added to images.txt. Otherwise building the image that exists to remove
  a Docker Hub dependency would itself depend on Docker Hub.

- yq is pinned instead of "releases/latest". An image that resolves a
  different yq on every build is not reproducible, and that is the kind
  of drift that surfaces months later as an unexplained pipeline failure.

The README gains the build-and-push procedure: the same pod shape as the
mirror, with the registry CA mounted into dind so the push is trusted, and
DOCKER_BUILDKIT=0, since BuildKit wants to write state under /root/.docker
where the push credentials get mounted read-only.

Verified the three places that must agree do: images.txt, the README's
inlined ConfigMap copy of it, and the Dockerfile's FROM tag.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
Mukul Sharma
2026-09-13 01:12:24 +05:30
co-authored by Claude Opus 5
parent b38af45c31
commit 2f80cfe288
3 changed files with 148 additions and 4 deletions
+5
View File
@@ -25,3 +25,8 @@ python:3.12-alpine python:3.12-alpine
maven:3-eclipse-temurin-21-alpine maven:3-eclipse-temurin-21-alpine
eclipse-temurin:21-jre-alpine eclipse-temurin:21-jre-alpine
php:8.3-cli-alpine php:8.3-cli-alpine
# Not a language runtime: this is what build-tools.Dockerfile builds FROM.
# Mirrored for the same reason as everything else here — so building the
# build image does not depend on Docker Hub either. Keep the tag in step
# with the FROM line in build-tools.Dockerfile.
docker:27-cli docker:27-cli