Publish only after successful CI

Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags.

Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip.
This commit is contained in:
Slavi Pantaleev
2026-04-20 22:09:37 +03:00
parent 2b1bdbd3d2
commit e978d3cb2f

View File

@@ -1,19 +1,31 @@
name: Publish
on:
push:
branches: [ "main" ]
tags: [ "v*" ]
workflow_run:
workflows: [ "CI" ]
types: [ "completed" ]
permissions:
contents: read
concurrency:
group: publish-${{ github.ref }}
group: publish-${{ github.event.workflow_run.id || github.ref }}
cancel-in-progress: false
jobs:
docker-clean-metadata:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
runs-on: ubuntu-latest
outputs:
json: ${{ steps.meta.outputs.json }}
steps:
- name: Checkout
uses: actions/checkout@v6
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 0
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v6
@@ -21,10 +33,17 @@ jobs:
images: |
ghcr.io/${{ github.repository }}
tags: |
type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
type=semver,pattern={{raw}}
docker-build:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
permissions:
contents: read
packages: write
@@ -43,6 +62,9 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 0
- name: Log in to the GitHub Container registry
uses: docker/login-action@v4
with:
@@ -54,7 +76,7 @@ jobs:
uses: docker/metadata-action@v6
with:
tags: |
type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
type=semver,pattern={{raw}}
flavor: |
latest=auto
@@ -70,6 +92,13 @@ jobs:
labels: ${{ steps.meta.outputs.labels }}
docker-manifest:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
permissions:
contents: read
packages: write