From e978d3cb2faab9793524d58d74d20fbd00d0f041 Mon Sep 17 00:00:00 2001 From: Slavi Pantaleev Date: Mon, 20 Apr 2026 22:09:37 +0300 Subject: [PATCH] Publish only after successful CI Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags. Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip. --- .github/workflows/publish.yml | 41 ++++++++++++++++++++++++++++++----- 1 file changed, 35 insertions(+), 6 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index bfa8836..89807d3 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,19 +1,31 @@ name: Publish on: - push: - branches: [ "main" ] - tags: [ "v*" ] + workflow_run: + workflows: [ "CI" ] + types: [ "completed" ] permissions: contents: read concurrency: - group: publish-${{ github.ref }} + group: publish-${{ github.event.workflow_run.id || github.ref }} cancel-in-progress: false jobs: docker-clean-metadata: + if: | + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.event == 'push' && + ( + github.event.workflow_run.head_branch == 'main' || + startsWith(github.event.workflow_run.head_branch || '', 'v') + ) runs-on: ubuntu-latest outputs: json: ${{ steps.meta.outputs.json }} steps: + - name: Checkout + uses: actions/checkout@v6 + with: + ref: ${{ github.event.workflow_run.head_sha }} + fetch-depth: 0 - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v6 @@ -21,10 +33,17 @@ jobs: images: | ghcr.io/${{ github.repository }} tags: | - type=raw,value=latest,enable=${{ github.ref_name == 'main' }} + type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }} type=semver,pattern={{raw}} docker-build: + if: | + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.event == 'push' && + ( + github.event.workflow_run.head_branch == 'main' || + startsWith(github.event.workflow_run.head_branch || '', 'v') + ) permissions: contents: read packages: write @@ -43,6 +62,9 @@ jobs: steps: - name: Checkout uses: actions/checkout@v6 + with: + ref: ${{ github.event.workflow_run.head_sha }} + fetch-depth: 0 - name: Log in to the GitHub Container registry uses: docker/login-action@v4 with: @@ -54,7 +76,7 @@ jobs: uses: docker/metadata-action@v6 with: tags: | - type=raw,value=latest,enable=${{ github.ref_name == 'main' }} + type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }} type=semver,pattern={{raw}} flavor: | latest=auto @@ -70,6 +92,13 @@ jobs: labels: ${{ steps.meta.outputs.labels }} docker-manifest: + if: | + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.event == 'push' && + ( + github.event.workflow_run.head_branch == 'main' || + startsWith(github.event.workflow_run.head_branch || '', 'v') + ) permissions: contents: read packages: write