Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags. Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip.
126 lines
3.6 KiB
YAML
126 lines
3.6 KiB
YAML
name: Publish
|
|
on:
|
|
workflow_run:
|
|
workflows: [ "CI" ]
|
|
types: [ "completed" ]
|
|
permissions:
|
|
contents: read
|
|
concurrency:
|
|
group: publish-${{ github.event.workflow_run.id || github.ref }}
|
|
cancel-in-progress: false
|
|
jobs:
|
|
docker-clean-metadata:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
json: ${{ steps.meta.outputs.json }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha }}
|
|
fetch-depth: 0
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
|
|
type=semver,pattern={{raw}}
|
|
|
|
docker-build:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
attestations: write
|
|
id-token: write
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- os: self-hosted
|
|
arch: amd64
|
|
- os: ubuntu-24.04-arm
|
|
arch: arm64
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha }}
|
|
fetch-depth: 0
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
|
|
type=semver,pattern={{raw}}
|
|
flavor: |
|
|
latest=auto
|
|
suffix=-${{ matrix.arch }},onlatest=true
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
|
|
- name: Build and push Docker images
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
|
|
docker-manifest:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
needs:
|
|
- docker-build
|
|
- docker-clean-metadata
|
|
runs-on: ubuntu-latest
|
|
|
|
strategy:
|
|
matrix:
|
|
image: ${{ fromJson(needs.docker-clean-metadata.outputs.json).tags }}
|
|
|
|
steps:
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Create and push manifest
|
|
run: |
|
|
docker manifest create ${{ matrix.image }} ${{ matrix.image }}-amd64 ${{ matrix.image }}-arm64
|
|
docker manifest push ${{ matrix.image }}
|