This supersedes 7d183b9 ("Run CI for pull requests"), which mixed validation and publishing in one workflow and regressed docker-manifest by dropping the package-write permission it needs to publish the manifest.
Split the workflows so CI handles pull requests, branch pushes, tags, and manual runs, while publishing stays focused on Docker delivery with the manifest permission fixed explicitly at the job level.
97 lines
2.5 KiB
YAML
97 lines
2.5 KiB
YAML
name: Publish
|
|
on:
|
|
push:
|
|
branches: [ "main" ]
|
|
tags: [ "v*" ]
|
|
permissions:
|
|
contents: read
|
|
concurrency:
|
|
group: publish-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
jobs:
|
|
docker-clean-metadata:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
json: ${{ steps.meta.outputs.json }}
|
|
steps:
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
|
|
type=semver,pattern={{raw}}
|
|
|
|
docker-build:
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
attestations: write
|
|
id-token: write
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- os: self-hosted
|
|
arch: amd64
|
|
- os: ubuntu-24.04-arm
|
|
arch: arm64
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
|
|
type=semver,pattern={{raw}}
|
|
flavor: |
|
|
latest=auto
|
|
suffix=-${{ matrix.arch }},onlatest=true
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
|
|
- name: Build and push Docker images
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
|
|
docker-manifest:
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
needs:
|
|
- docker-build
|
|
- docker-clean-metadata
|
|
runs-on: ubuntu-latest
|
|
|
|
strategy:
|
|
matrix:
|
|
image: ${{ fromJson(needs.docker-clean-metadata.outputs.json).tags }}
|
|
|
|
steps:
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Create and push manifest
|
|
run: |
|
|
docker manifest create ${{ matrix.image }} ${{ matrix.image }}-amd64 ${{ matrix.image }}-arm64
|
|
docker manifest push ${{ matrix.image }}
|