Dagger
Search

oci

This module provides functionality for packaging directories into OCI
artifacts and pushing them to container registries using the Flux CLI.
It is designed for Flux GitOps workflows where Kubernetes manifests,
Kustomize overlays, or other configuration are stored as OCI artifacts.

Installation

dagger install github.com/stuttgart-things/dagger/oci@v0.136.1

Entrypoint

Return Type
Oci
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
func (m *MyModule) Example() *dagger.Oci  {
	return dag.
			Oci()
}
@function
def example() -> dagger.Oci:
	return (
		dag.oci()
	)
@func()
example(): Oci {
	return dag
		.oci()
}

Types

Oci 🔗

Oci builds and pushes OCI artifacts using the Flux CLI

baseImage() 🔗

Base image to use for the Flux container

Return Type
String !
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 base-image
func (m *MyModule) Example(ctx context.Context) string  {
	return dag.
			Oci().
			Baseimage(ctx)
}
@function
async def example() -> str:
	return await (
		dag.oci()
		.baseimage()
	)
@func()
async example(): Promise<string> {
	return dag
		.oci()
		.baseImage()
}

pushArtifact() 🔗

PushArtifact builds and pushes an OCI artifact from a directory to a container registry

Return Type
String !
Arguments
NameTypeDefault ValueDescription
srcDirectory !-

Source directory containing the artifact files

artifactString !-

OCI artifact address (e.g., oci://ghcr.io/org/repo:tag)

registryString !-

Registry URL for authentication (e.g., ghcr.io)

usernameString !-

Registry username

passwordSecret !-

Registry password

sourceString -

Source URL metadata (e.g., git remote URL)

revisionString -

Revision metadata (e.g., branch@sha1:commit)

Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 push-artifact --src DIR_PATH --artifact string --registry string --username string --password env:MYSECRET
func (m *MyModule) Example(ctx context.Context, src *dagger.Directory, artifact string, registry string, username string, password *dagger.Secret) string  {
	return dag.
			Oci().
			Pushartifact(ctx, src, artifact, registry, username, password)
}
@function
async def example(src: dagger.Directory, artifact: str, registry: str, username: str, password: dagger.Secret) -> str:
	return await (
		dag.oci()
		.pushartifact(src, artifact, registry, username, password)
	)
@func()
async example(src: Directory, artifact: string, registry: string, username: string, password: Secret): Promise<string> {
	return dag
		.oci()
		.pushArtifact(src, artifact, registry, username, password)
}

pushArtifacts() 🔗

PushArtifacts builds and pushes OCI artifacts from multiple directories to a container registry. Each directory name is appended to the base artifact address as a tag.

Return Type
String !
Arguments
NameTypeDefault ValueDescription
srcDirectory !-

Source directory containing subdirectories, each becoming an OCI artifact

artifactString !-

Base OCI artifact address without tag (e.g., oci://ghcr.io/org/repo)

tagString !-

Tag to use for all artifacts

registryString !-

Registry URL for authentication (e.g., ghcr.io)

usernameString !-

Registry username

passwordSecret !-

Registry password

sourceString -

Source URL metadata (e.g., git remote URL)

revisionString -

Revision metadata (e.g., branch@sha1:commit)

Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 push-artifacts --src DIR_PATH --artifact string --tag string --registry string --username string --password env:MYSECRET
func (m *MyModule) Example(ctx context.Context, src *dagger.Directory, artifact string, tag string, registry string, username string, password *dagger.Secret) string  {
	return dag.
			Oci().
			Pushartifacts(ctx, src, artifact, tag, registry, username, password)
}
@function
async def example(src: dagger.Directory, artifact: str, tag: str, registry: str, username: str, password: dagger.Secret) -> str:
	return await (
		dag.oci()
		.pushartifacts(src, artifact, tag, registry, username, password)
	)
@func()
async example(src: Directory, artifact: string, tag: string, registry: string, username: string, password: Secret): Promise<string> {
	return dag
		.oci()
		.pushArtifacts(src, artifact, tag, registry, username, password)
}

registryService() 🔗

RegistryService starts a local OCI registry (zot) with TLS as a Dagger service container. A self-signed certificate is generated for the registry hostname. Useful for testing OCI artifact pushes without requiring external registry credentials.

Return Type
Service !
Arguments
NameTypeDefault ValueDescription
imageString "ghcr.io/project-zot/zot-linux-amd64:latest"

Zot registry image to use

portInteger 5000

Port to expose the registry on

Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 registry-service
func (m *MyModule) Example() *dagger.Service  {
	return dag.
			Oci().
			Registryservice()
}
@function
def example() -> dagger.Service:
	return (
		dag.oci()
		.registryservice()
	)
@func()
example(): Service {
	return dag
		.oci()
		.registryService()
}

testPushArtifact() 🔗

TestPushArtifact starts a local zot registry with TLS and pushes a test artifact using flux to verify the push workflow. No external registry credentials are required.

Return Type
String !
Arguments
NameTypeDefault ValueDescription
registryImageString "ghcr.io/project-zot/zot-linux-amd64:latest"

Zot registry image to use

Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 test-push-artifact
func (m *MyModule) Example(ctx context.Context) string  {
	return dag.
			Oci().
			Testpushartifact(ctx)
}
@function
async def example() -> str:
	return await (
		dag.oci()
		.testpushartifact()
	)
@func()
async example(): Promise<string> {
	return dag
		.oci()
		.testPushArtifact()
}

testPushArtifacts() 🔗

TestPushArtifacts starts a local zot registry with TLS and pushes multiple test artifacts using flux to verify the batch push workflow. No external registry credentials are required.

Return Type
String !
Arguments
NameTypeDefault ValueDescription
registryImageString "ghcr.io/project-zot/zot-linux-amd64:latest"

Zot registry image to use

Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
 test-push-artifacts
func (m *MyModule) Example(ctx context.Context) string  {
	return dag.
			Oci().
			Testpushartifacts(ctx)
}
@function
async def example() -> str:
	return await (
		dag.oci()
		.testpushartifacts()
	)
@func()
async example(): Promise<string> {
	return dag
		.oci()
		.testPushArtifacts()
}