Add compose.prebuilt.yaml overlay for prebuilt GHCR images (#548)

Adds an overlay for dev/docker-compose that resets the `build:` block
of every locally-built component and points it at the matching prebuilt
image from GHCR, so developers can run the stack without local builds.
Image tag defaults to "main" and is overridable via BUTTERCUP_IMAGE_TAG.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: allow Docker Compose !reset/!override tags in YAML check

The static-checks YAML step uses yaml.safe_load_all, which rejects the
Compose-specific !reset/!override merge tags used by
compose.prebuilt.yaml. Register no-op constructors for those tags so
compose overlays validate without masking real YAML errors elsewhere.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Riccardo Schirone
2026-05-18 16:15:53 +02:00
committed by GitHub
parent cc94bdf05b
commit 761dc6c13f
3 changed files with 70 additions and 0 deletions
+3
View File
@@ -40,6 +40,9 @@ jobs:
python3 -c "
import yaml
from pathlib import Path
# Docker Compose merge tags are valid in compose files but unknown to safe_load
for _t in ('!reset', '!override'):
yaml.SafeLoader.add_constructor(_t, lambda loader, node: None)
for f in Path('.').rglob('*.yaml'):
if 'deployment/k8s' not in str(f):
list(yaml.safe_load_all(f.read_text()))
+13
View File
@@ -18,11 +18,24 @@ cd dev/docker-compose && docker-compose --profile graphdb up -d
cd dev/docker-compose && docker-compose down
```
### Using prebuilt images (skip local builds)
`compose.prebuilt.yaml` is an overlay that replaces every locally-built
component with its prebuilt image from GHCR, so nothing is built locally:
```bash
cd dev/docker-compose && docker compose -f compose.yaml -f compose.prebuilt.yaml up -d
# Pin a specific image tag (defaults to "main"):
BUTTERCUP_IMAGE_TAG=<branch-or-tag> docker compose -f compose.yaml -f compose.prebuilt.yaml up -d
```
## Configuration
- `env.template` - Template for environment variables (copy to `.env` and customize)
- `env.dev.compose` - Development-specific environment configuration
- `compose.yaml` - Main compose file with all services
- `compose.prebuilt.yaml` - Overlay that pulls prebuilt GHCR images instead of building locally
## Notes
+54
View File
@@ -0,0 +1,54 @@
# Overlay for compose.yaml that pulls the prebuilt component images from GHCR
# instead of building them locally. It only overrides the services that have a
# `build:` block, resetting it and pointing at the published image.
#
# Usage (from dev/docker-compose):
# docker compose -f compose.yaml -f compose.prebuilt.yaml up -d
#
# Override the image tag (defaults to "main"):
# BUTTERCUP_IMAGE_TAG=<branch-or-tag> docker compose -f compose.yaml -f compose.prebuilt.yaml up -d
services:
program-model:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-program-model:${BUTTERCUP_IMAGE_TAG:-main}
coverage-bot:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-fuzzer:${BUTTERCUP_IMAGE_TAG:-main}
build-bot:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-fuzzer:${BUTTERCUP_IMAGE_TAG:-main}
tracer-bot:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-fuzzer:${BUTTERCUP_IMAGE_TAG:-main}
fuzzer-bot:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-fuzzer:${BUTTERCUP_IMAGE_TAG:-main}
task-downloader:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-orchestrator:${BUTTERCUP_IMAGE_TAG:-main}
task-server:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-orchestrator:${BUTTERCUP_IMAGE_TAG:-main}
scheduler:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-orchestrator:${BUTTERCUP_IMAGE_TAG:-main}
seed-gen:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-seed-gen:${BUTTERCUP_IMAGE_TAG:-main}
patcher:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-patcher:${BUTTERCUP_IMAGE_TAG:-main}
buttercup-ui:
build: !reset null
image: ghcr.io/trailofbits/buttercup/buttercup-orchestrator:${BUTTERCUP_IMAGE_TAG:-main}