Repository navigation
Run Linux CI in the shared Docker image - #625
Merged
Merged
Conversation
aidangarske
commented
Oct 7, 2026
Member
- Linux CI installed dependencies at runtime despite having a dedicated image.
- Move all 40 Linux workload jobs to ghcr.io/wolfssl/wolftpm-ci:v1.1.
- Confine apt commands to the Dockerfile and remove the apt retry action.
- Keep simulator startup, tests, and cleanup within one step.
- Run SPDM builds and tests in Docker while preserving Harden Runner monitoring.
- Preserve native Windows and macOS matrix jobs.
- Publish v1.1 and verify anonymous pulls and installed tooling.
There was a problem hiding this comment.
🔵 Needs a closer look
The broad migration needs verified image publication, anonymous access, and successful representative container and native-platform runs before human approval.
0 open findings
What changed in this PR
Moves wolfTPM’s Linux CI workloads to the shared v1.1 image, reducing runtime dependency installation while retaining native Windows and macOS jobs.
Changes:
- Expands the image’s tooling and adds publication checks.
- Migrates Linux workflows and separates image-specific dependency caches.
- Consolidates simulator startup, testing, and cleanup; runs SPDM in Docker with host monitoring.
| File | Description |
|---|---|
| scripts/ci/spdm.sh | Adds containerized SPDM build and test orchestration. |
| .github/workflows/zephyr.yml | Uses baked Zephyr tooling. |
| .github/workflows/wolfssl-versions-pqc.yml | Updates image and cache version. |
| .github/workflows/wolfhal-build.yml | Containerizes wolfHAL builds. |
| .github/workflows/spdm-test.yml | Runs SPDM through Docker with host monitoring. |
| .github/workflows/smoke-test.yml | Containerizes smoke checks and scopes simulator cleanup. |
| .github/workflows/semgrep.yml | Uses baked Semgrep. |
| .github/workflows/seal-test.yml | Containerizes seal tests and consolidates server lifetime. |
| .github/workflows/sbom.yml | Uses image-provided SBOM tooling. |
| .github/workflows/sanitizer.yml | Uses privileged containers for sanitizer tests. |
| .github/workflows/rust-test.yml | Uses baked Rust tooling and scoped simulator lifetime. |
| .github/workflows/release-checks.yml | Migrates release checks and versions caches. |
| .github/workflows/publish-ci-image.yml | Checks tooling before publishing and verifies anonymous access. |
| .github/workflows/pqc-examples.yml | Containerizes examples and consolidates simulator cleanup. |
| .github/workflows/pqc-build-matrix.yml | Containerizes PQC build matrices. |
| .github/workflows/multi-compiler.yml | Uses baked compiler versions. |
| .github/workflows/make-test-swtpm.yml | Consolidates simulator-backed tests and distribution checks. |
| .github/workflows/fwtpm-test.yml | Migrates Linux tests while retaining native macOS. |
| .github/workflows/fuzz.yml | Moves fuzzing into a privileged container. |
| .github/workflows/freestanding-build.yml | Containerizes freestanding builds. |
| .github/workflows/coverity-scan-fixes.yml | Containerizes Coverity checks and versions caches. |
| .github/workflows/codespell.yml | Invokes baked codespell directly. |
| .github/workflows/codeql.yml | Containerizes CodeQL builds. |
| .github/workflows/cmake-build.yml | Containerizes Linux builds while retaining native Windows. |
| .github/docker/wolftpm-ci/Dockerfile | Adds shared compilers, scanners, SDKs, and emulator tooling. |
| .github/actions/setup-wolfssl/action.yml | Separates wolfSSL caches by image version. |
| .github/actions/setup-wolfcose/action.yml | Separates wolfCOSE caches by image version. |
| .github/actions/setup-ibmswtpm/action.yml | Separates simulator caches by image version. |
| .github/actions/apt-retry/action.yml | Removes runtime apt installation action. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
dgarske
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.