image field of your tinfoil-config.yml.
For your own source code, use the Dockerfile and Build Image workflow in
tinfoil-containers-hello-world
as a starting point:
- Public source: keep the application, image-build workflow, config, and measured-release workflows in one public repository.
- Private source: keep the application and image-build workflow in a private repository. Reference the published image from a public
tinfoil-containers-templaterepository.
If the published image is private (not just the source), Tinfoil needs registry credentials to pull it at deploy time. See Private images. Public images work without any configuration.
Build and publish
- Edit your application and Dockerfile.
- Run Build Image (
build-image.yml) with an image version. It pushes the image to GHCR and prints the digest in the workflow summary. - Copy that digest into
tinfoil-config.ymland commit the config to the default branch. - Run Tinfoil Release with a new release version. Wait for both the tag-creation and measurement/publication phases to succeed before creating or updating an instance.
Image digests in the release workflow
Theimage field must pin the exact image with its SHA256 digest:
tinfoil-config.yml
<digest> with the real digest from your build or registry before publishing.
The measured-release workflow uses the committed config; it does not build the image
or fill in a placeholder digest.
