ghcr.io/avgeek-oss/rootset-api:<version>, ghcr.io/avgeek-oss/rootset-worker:<version> and ghcr.io/avgeek-oss/rootset-web:<version> for Linux amd64 and arm64. Migrations reuse the API image. All three images share one version and are built from the same reviewed commit.
The release workflow validates the version/tag and requires verification for that exact commit to pass before building images. It assembles the architecture manifests, verifies anonymous access, and tests installation and restart using the pulled images on both native architectures. Only after those checks pass does it publish the GitHub release with image digests and installation files. Publishing a tag does not by itself mean the release is ready for installation.
Upgrade a released installation
Read the target release notes first. Protect PostgreSQL, object storage, and the persistent application secret/encryption key using your provider’s backup tools. Download the matching Compose file, changeROOTSET_VERSION in .env, and pull before replacing running containers.
--profile local-db if you use bundled PostgreSQL. Preserve the Compose project name and volumes. docker compose down preserves named volumes; down --volumes deletes them.
