Publish only after successful CI

Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags.

Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip.
This commit is contained in:
Slavi Pantaleev
2026-04-20 22:09:37 +03:00
parent 2b1bdbd3d2
commit e978d3cb2f

View File

@@ -1,19 +1,31 @@
name: Publish name: Publish
on: on:
push: workflow_run:
branches: [ "main" ] workflows: [ "CI" ]
tags: [ "v*" ] types: [ "completed" ]
permissions: permissions:
contents: read contents: read
concurrency: concurrency:
group: publish-${{ github.ref }} group: publish-${{ github.event.workflow_run.id || github.ref }}
cancel-in-progress: false cancel-in-progress: false
jobs: jobs:
docker-clean-metadata: docker-clean-metadata:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
runs-on: ubuntu-latest runs-on: ubuntu-latest
outputs: outputs:
json: ${{ steps.meta.outputs.json }} json: ${{ steps.meta.outputs.json }}
steps: steps:
- name: Checkout
uses: actions/checkout@v6
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 0
- name: Extract metadata (tags, labels) for Docker - name: Extract metadata (tags, labels) for Docker
id: meta id: meta
uses: docker/metadata-action@v6 uses: docker/metadata-action@v6
@@ -21,10 +33,17 @@ jobs:
images: | images: |
ghcr.io/${{ github.repository }} ghcr.io/${{ github.repository }}
tags: | tags: |
type=raw,value=latest,enable=${{ github.ref_name == 'main' }} type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
type=semver,pattern={{raw}} type=semver,pattern={{raw}}
docker-build: docker-build:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
permissions: permissions:
contents: read contents: read
packages: write packages: write
@@ -43,6 +62,9 @@ jobs:
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v6 uses: actions/checkout@v6
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 0
- name: Log in to the GitHub Container registry - name: Log in to the GitHub Container registry
uses: docker/login-action@v4 uses: docker/login-action@v4
with: with:
@@ -54,7 +76,7 @@ jobs:
uses: docker/metadata-action@v6 uses: docker/metadata-action@v6
with: with:
tags: | tags: |
type=raw,value=latest,enable=${{ github.ref_name == 'main' }} type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
type=semver,pattern={{raw}} type=semver,pattern={{raw}}
flavor: | flavor: |
latest=auto latest=auto
@@ -70,6 +92,13 @@ jobs:
labels: ${{ steps.meta.outputs.labels }} labels: ${{ steps.meta.outputs.labels }}
docker-manifest: docker-manifest:
if: |
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
(
github.event.workflow_run.head_branch == 'main' ||
startsWith(github.event.workflow_run.head_branch || '', 'v')
)
permissions: permissions:
contents: read contents: read
packages: write packages: write