Split CI and publish workflows

This supersedes 7d183b9 ("Run CI for pull requests"), which mixed validation and publishing in one workflow and regressed docker-manifest by dropping the package-write permission it needs to publish the manifest.

Split the workflows so CI handles pull requests, branch pushes, tags, and manual runs, while publishing stays focused on Docker delivery with the manifest permission fixed explicitly at the job level.
This commit is contained in:
Slavi Pantaleev
2026-04-20 22:08:07 +03:00
parent 7d183b91d1
commit 2b1bdbd3d2
2 changed files with 31 additions and 19 deletions

26
.github/workflows/ci.yml vendored Normal file
View File

@@ -0,0 +1,26 @@
name: CI
on:
workflow_dispatch:
pull_request:
branches: [ "main" ]
push:
branches:
- "**"
tags: [ "v*" ]
permissions:
contents: read
pull-requests: read
concurrency:
group: ci-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
test-and-clippy:
name: Unit testing and linting
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@1.93.0
- name: Install SQLite3
run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev
- run: cargo test --all-features
- run: cargo clippy

View File

@@ -1,30 +1,15 @@
name: CI
name: Publish
on:
pull_request:
branches: [ "main" ]
push:
branches: [ "main" ]
tags: [ "v*" ]
permissions:
contents: read
pull-requests: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
group: publish-${{ github.ref }}
cancel-in-progress: false
jobs:
test-and-clippy:
name: Unit testing and linting
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@1.93.0
- name: Install SQLite3
run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev
- run: cargo test --all-features
- run: cargo clippy
docker-clean-metadata:
if: github.event_name == 'push'
runs-on: ubuntu-latest
outputs:
json: ${{ steps.meta.outputs.json }}
@@ -40,7 +25,6 @@ jobs:
type=semver,pattern={{raw}}
docker-build:
if: github.event_name == 'push'
permissions:
contents: read
packages: write
@@ -86,7 +70,9 @@ jobs:
labels: ${{ steps.meta.outputs.labels }}
docker-manifest:
if: github.event_name == 'push'
permissions:
contents: read
packages: write
needs:
- docker-build
- docker-clean-metadata