@@ -39,19 +39,9 @@ Local development and the official hosted editor work without any environment va
3939docker compose up -d
4040```
4141
42- The editor will be running at ** http://localhost:3000 ** . Compose pulls the official
43- image from GHCR; set ` IMAGE_TAG ` to use a release instead of ` latest ` :
44-
45- ``` bash
46- IMAGE_TAG=1.0.0 docker compose up -d
47- ```
48-
49- The ` editor ` package must be public in the ` pascalorg ` organization's GHCR packages
50- for unauthenticated deployments. After the first release, open the package settings
51- under the organization's Packages page, set its visibility to ** Public** , and connect
52- it to ` pascalorg/editor ` . Maintainers only need to configure this once.
53-
54- Saved scenes live in the ` pascal-data ` volume, so they survive ` docker compose down ` .
42+ The editor will be running at ** http://localhost:3000 ** . Compose builds from source;
43+ it does not depend on a GHCR package being available. Saved scenes live in the
44+ ` pascal-data ` volume, so they survive ` docker compose down ` .
5545
5646Docker defaults ` MINT_PASCAL_HOST_ORIGIN ` to ` http://localhost:3000 ` . Override
5747it when hosting Pascal at another origin:
@@ -65,6 +55,39 @@ a base URL that only `NEXT_PUBLIC_APP_URL` can override, and Next inlines that
6555value at build time, so remapping the port to something else makes the page
6656return 500.
6757
58+ ### GHCR bootstrap (maintainers)
59+
60+ Docker publication is separate from the npm release workflow. After a successful
61+ editor release, run the ** Docker** workflow with the existing version (for example,
62+ ` 1.0.0-beta.5 ` ). It checks out ` @pascal-app/editor@<version> ` and builds amd64 and
63+ arm64 images. Leave ` publish ` disabled for a build-only check, then enable it to
64+ publish ` ghcr.io/<owner>/<repository>:<version> ` . It never updates ` latest ` .
65+
66+ Before switching the default Compose configuration in a follow-up PR:
67+
68+ 1 . Publish a version from a completed editor release.
69+ 2 . In the organization's Packages settings, connect the package to ` pascalorg/editor `
70+ and set its visibility to ** Public** (a one-time maintainer action).
71+ 3 . Using a Docker configuration without registry credentials, inspect the manifest
72+ and pull both platforms. Replace ` <version> ` with the published version:
73+
74+ ``` bash
75+ docker buildx imagetools inspect ghcr.io/pascalorg/editor:< version>
76+ docker pull --platform linux/amd64 ghcr.io/pascalorg/editor:< version>
77+ docker pull --platform linux/arm64 ghcr.io/pascalorg/editor:< version>
78+ ```
79+
80+ 4 . Smoke-test startup and scene persistence on both architectures and record the
81+ version, digest, and results in the follow-up PR. The maintainer must approve
82+ promotion to ` latest ` and the default-Compose transition separately.
83+
84+ If a Docker build or push fails, npm releases and source-based Compose remain
85+ unchanged. Inspect GHCR for a partially uploaded version before retrying the same
86+ release tag; do not rerun npm publishing or move the Git tag. For a bad image, keep
87+ users on the source build or a previously verified image digest, and publish a
88+ corrected release version rather than silently replacing an image users may have
89+ pinned. Registry cleanup and any future ` latest ` rollback require maintainer approval.
90+
6891## CLI-managed editor
6992
7093Node.js 22.13 or newer can install a persistent local runtime, start it in the
0 commit comments