name: Publish on: workflow_run: workflows: [ "CI" ] types: [ "completed" ] permissions: contents: read concurrency: group: publish-${{ github.event.workflow_run.id || github.ref }} cancel-in-progress: false jobs: docker-clean-metadata: if: | github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && ( github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch || '', 'v') ) runs-on: ubuntu-latest outputs: json: ${{ steps.meta.outputs.json }} steps: - name: Checkout uses: actions/checkout@v6 with: ref: ${{ github.event.workflow_run.head_sha }} fetch-depth: 0 - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v6 with: images: | ghcr.io/${{ github.repository }} tags: | type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }} type=semver,pattern={{raw}},value=${{ github.event.workflow_run.head_branch }},enable=${{ startsWith(github.event.workflow_run.head_branch || '', 'v') }} docker-build: if: | github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && ( github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch || '', 'v') ) permissions: contents: read packages: write attestations: write id-token: write strategy: matrix: include: - os: self-hosted arch: amd64 - os: ubuntu-24.04-arm arch: arm64 runs-on: ${{ matrix.os }} steps: - name: Checkout uses: actions/checkout@v6 with: ref: ${{ github.event.workflow_run.head_sha }} fetch-depth: 0 - name: Log in to the GitHub Container registry uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v6 with: tags: | type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }} type=semver,pattern={{raw}},value=${{ github.event.workflow_run.head_branch }},enable=${{ startsWith(github.event.workflow_run.head_branch || '', 'v') }} flavor: | latest=auto suffix=-${{ matrix.arch }},onlatest=true images: | ghcr.io/${{ github.repository }} - name: Build and push Docker images uses: docker/build-push-action@v7 with: push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} docker-manifest: if: | github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && ( github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch || '', 'v') ) permissions: contents: read packages: write needs: - docker-build - docker-clean-metadata runs-on: ubuntu-latest strategy: matrix: image: ${{ fromJson(needs.docker-clean-metadata.outputs.json).tags }} steps: - name: Log in to the GitHub Container registry uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Create and push manifest run: | docker buildx imagetools create -t ${{ matrix.image }} ${{ matrix.image }}-amd64 ${{ matrix.image }}-arm64