Skip to content

ci: manual cleanup workflow for claude-code GHCR images - #84

Merged
gatezh merged 1 commit into
masterfrom
cleanup-claude-code-ghcr
Apr 25, 2026
Merged

gatezh merged 1 commit into
masterfrom
cleanup-claude-code-ghcr

Conversation

@gatezh

@gatezh gatezh commented Apr 25, 2026

Copy link
Copy Markdown
Owner

What

Adds a manually-triggered GitHub Actions workflow that prunes old container versions of the claude-code and claude-code-sandbox packages on GHCR.

Why

build-claude-code.yml runs daily and pushes three new tags per image (latest, <sha>, <YYYYMMDD>) for two architectures. Each time latest moves, the previous manifest becomes untagged but stays forever — GHCR never auto-prunes. Over months this clutters the package version list and slows API paging. Public packages have free unlimited storage on GHCR, so this is a hygiene improvement, not a cost fix.

Other images in this repo (bun, hugo-bun, hugo-bun-node, ralphex-fe, claude-bun) only rebuild on Dockerfile changes and don't have the same accumulation problem, so they're explicitly out of scope.

Changes

  • New file: .github/workflows/cleanup-claude-code-ghcr.yml
    • Trigger: workflow_dispatch only — no cron, no automatic execution
    • Inputs: retention-days (default 90), dry-run (default true)
    • Matrix over [claude-code, claude-code-sandbox] so each package is processed independently
    • Uses dataaxiom/ghcr-cleanup-action@v1, which is multi-arch-safe (it skips child manifests still referenced by tagged manifest lists)
    • exclude-tags: latest unconditionally preserves the moving latest pointer

Notes

One-time setup required before the first real run: for each of the two packages, open Package settings → Manage Actions access in the GHCR UI, add this repository, and grant Admin. Without that, the action returns 403.

Verification (post-merge, since workflow_dispatch only resolves once on master):

  1. From the Actions tab → Cleanup claude-code GHCR versions → Run workflow with defaults (dry-run on). Read both matrix job logs to confirm latest is preserved and only versions older than 90 days are listed.
  2. Re-run with the dry-run checkbox unchecked for the real prune.
  3. Sanity-check docker manifest inspect ghcr.io/gatezh/devcontainers/claude-code:latest still returns both linux/amd64 and linux/arm64 entries.

CI will only run actionlint on this PR (no Dockerfile changes); actionlint was also run locally and passes.

Adds a workflow_dispatch-only workflow that prunes old versions of the
ghcr.io/gatezh/devcontainers/claude-code and claude-code-sandbox packages.
Other packages in this repo are out of scope and unreachable from this
workflow.

Defaults are conservative: 90-day retention and dry-run=true, so the first
"Run workflow" click is always a safe preview. To actually delete, re-run
with the dry-run checkbox unchecked. `latest` is preserved unconditionally
via exclude-tags.

One-time setup: each target package must grant this repository the "Admin"
role under Package Settings -> Manage Actions access in the GHCR UI;
otherwise the action returns 403.
@gatezh
gatezh merged commit bdb0811 into master Apr 25, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant