oci
This module provides functionality for packaging directories into OCIartifacts and pushing them to container registries using the Flux CLI.
It is designed for Flux GitOps workflows where Kubernetes manifests,
Kustomize overlays, or other configuration are stored as OCI artifacts.
Installation
dagger install github.com/stuttgart-things/dagger/oci@v0.136.1Entrypoint
Return Type
Oci Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
func (m *MyModule) Example() *dagger.Oci {
return dag.
Oci()
}@function
def example() -> dagger.Oci:
return (
dag.oci()
)@func()
example(): Oci {
return dag
.oci()
}Types
Oci 🔗
Oci builds and pushes OCI artifacts using the Flux CLI
baseImage() 🔗
Base image to use for the Flux container
Return Type
String ! Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
base-imagefunc (m *MyModule) Example(ctx context.Context) string {
return dag.
Oci().
Baseimage(ctx)
}@function
async def example() -> str:
return await (
dag.oci()
.baseimage()
)@func()
async example(): Promise<string> {
return dag
.oci()
.baseImage()
}pushArtifact() 🔗
PushArtifact builds and pushes an OCI artifact from a directory to a container registry
Return Type
String !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| src | Directory ! | - | Source directory containing the artifact files |
| artifact | String ! | - | OCI artifact address (e.g., oci://ghcr.io/org/repo:tag) |
| registry | String ! | - | Registry URL for authentication (e.g., ghcr.io) |
| username | String ! | - | Registry username |
| password | Secret ! | - | Registry password |
| source | String | - | Source URL metadata (e.g., git remote URL) |
| revision | String | - | Revision metadata (e.g., branch@sha1:commit) |
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
push-artifact --src DIR_PATH --artifact string --registry string --username string --password env:MYSECRETfunc (m *MyModule) Example(ctx context.Context, src *dagger.Directory, artifact string, registry string, username string, password *dagger.Secret) string {
return dag.
Oci().
Pushartifact(ctx, src, artifact, registry, username, password)
}@function
async def example(src: dagger.Directory, artifact: str, registry: str, username: str, password: dagger.Secret) -> str:
return await (
dag.oci()
.pushartifact(src, artifact, registry, username, password)
)@func()
async example(src: Directory, artifact: string, registry: string, username: string, password: Secret): Promise<string> {
return dag
.oci()
.pushArtifact(src, artifact, registry, username, password)
}pushArtifacts() 🔗
PushArtifacts builds and pushes OCI artifacts from multiple directories to a container registry. Each directory name is appended to the base artifact address as a tag.
Return Type
String !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| src | Directory ! | - | Source directory containing subdirectories, each becoming an OCI artifact |
| artifact | String ! | - | Base OCI artifact address without tag (e.g., oci://ghcr.io/org/repo) |
| tag | String ! | - | Tag to use for all artifacts |
| registry | String ! | - | Registry URL for authentication (e.g., ghcr.io) |
| username | String ! | - | Registry username |
| password | Secret ! | - | Registry password |
| source | String | - | Source URL metadata (e.g., git remote URL) |
| revision | String | - | Revision metadata (e.g., branch@sha1:commit) |
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
push-artifacts --src DIR_PATH --artifact string --tag string --registry string --username string --password env:MYSECRETfunc (m *MyModule) Example(ctx context.Context, src *dagger.Directory, artifact string, tag string, registry string, username string, password *dagger.Secret) string {
return dag.
Oci().
Pushartifacts(ctx, src, artifact, tag, registry, username, password)
}@function
async def example(src: dagger.Directory, artifact: str, tag: str, registry: str, username: str, password: dagger.Secret) -> str:
return await (
dag.oci()
.pushartifacts(src, artifact, tag, registry, username, password)
)@func()
async example(src: Directory, artifact: string, tag: string, registry: string, username: string, password: Secret): Promise<string> {
return dag
.oci()
.pushArtifacts(src, artifact, tag, registry, username, password)
}registryService() 🔗
RegistryService starts a local OCI registry (zot) with TLS as a Dagger service container. A self-signed certificate is generated for the registry hostname. Useful for testing OCI artifact pushes without requiring external registry credentials.
Return Type
Service !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| image | String | "ghcr.io/project-zot/zot-linux-amd64:latest" | Zot registry image to use |
| port | Integer | 5000 | Port to expose the registry on |
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
registry-servicefunc (m *MyModule) Example() *dagger.Service {
return dag.
Oci().
Registryservice()
}@function
def example() -> dagger.Service:
return (
dag.oci()
.registryservice()
)@func()
example(): Service {
return dag
.oci()
.registryService()
}testPushArtifact() 🔗
TestPushArtifact starts a local zot registry with TLS and pushes a test artifact using flux to verify the push workflow. No external registry credentials are required.
Return Type
String !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| registryImage | String | "ghcr.io/project-zot/zot-linux-amd64:latest" | Zot registry image to use |
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
test-push-artifactfunc (m *MyModule) Example(ctx context.Context) string {
return dag.
Oci().
Testpushartifact(ctx)
}@function
async def example() -> str:
return await (
dag.oci()
.testpushartifact()
)@func()
async example(): Promise<string> {
return dag
.oci()
.testPushArtifact()
}testPushArtifacts() 🔗
TestPushArtifacts starts a local zot registry with TLS and pushes multiple test artifacts using flux to verify the batch push workflow. No external registry credentials are required.
Return Type
String !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| registryImage | String | "ghcr.io/project-zot/zot-linux-amd64:latest" | Zot registry image to use |
Example
dagger -m github.com/stuttgart-things/dagger/oci@0fa0bcf2a2108690c837262c9ad569af7e07a60b call \
test-push-artifactsfunc (m *MyModule) Example(ctx context.Context) string {
return dag.
Oci().
Testpushartifacts(ctx)
}@function
async def example() -> str:
return await (
dag.oci()
.testpushartifacts()
)@func()
async example(): Promise<string> {
return dag
.oci()
.testPushArtifacts()
}