Webhook icon
If icon
Pull icon
ImageLs icon
Assert icon
Get icon
Set icon
Log icon
Script icon
Process icon
Fail icon
DiscordIncomingWebhook icon

Container image size regression guard

Webhook-triggered container size gate. Compare against an approved KV baseline, enforce percent and MB limits, and fail promotion on regression.

Categories
Infrastructure

A central, provider-agnostic quality gate for container images. Any ci system (GitHub Actions, GitLab CI, Jenkins, CircleCI, etc.) POST the pushed image to a kestra webhook. The flow pull the artifact, measure it with ImageLs, and compares the size to an approved baseline in KV. The baseline is an explicit reference (reset_baseline=true), not the previous execution. Regressions fail the execution; discord is notified once via the errors block with the full report.

How it works

  1. Webhook receives {"image": "ghcr.io/my-org/my-app:abc123"} from any CI.
  2. optional Pull, then ImageLs and Assert.
  3. reset_baseline=true saves json metadata (image, size_bytes, approved_at).
  4. otherwise assess compares current size against the baseline using both max_increase_percent and max_increase_mb.
  5. On breach: Fail with a report; errors sends one discord alert.

Example

Approved baseline: 184 MB. Limits: +10%, +50 MB.

  • :abc123 at 190 MB (+3.3%, +6 MB) -> PASS
  • :def456 at 240 MB (+30.4%, +56 MB) -> FAIL

Prerequisites

  • Worker with Docker daemon access.
  • Registry access when pull_image=true.

Secrets

  • WEBHOOK_KEY: webhook trigger key.
  • DISCORD_WEBHOOK_URL: failure notifications.

Quick start

  1. Add secrets; set baseline_key and repository per image repo.
  2. Approve the first baseline with reset_baseline=true.
  3. POST {"image": "ghcr.io/my-org/my-app:abc123"} after push from any CI.
  4. Gate promotion on Success.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.