docker/build-push-action now wraps single-platform images in an OCI
image index (to carry provenance attestations), so the per-arch
`*-amd64`/`*-arm64` tags are manifest lists. `docker manifest create`
refuses manifest-list sources ("X is a manifest list"). Switch to
`docker buildx imagetools create`, which flattens index sources
correctly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
125 lines
3.8 KiB
YAML
125 lines
3.8 KiB
YAML
name: Publish
|
|
on:
|
|
workflow_run:
|
|
workflows: [ "CI" ]
|
|
types: [ "completed" ]
|
|
permissions:
|
|
contents: read
|
|
concurrency:
|
|
group: publish-${{ github.event.workflow_run.id || github.ref }}
|
|
cancel-in-progress: false
|
|
jobs:
|
|
docker-clean-metadata:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
json: ${{ steps.meta.outputs.json }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha }}
|
|
fetch-depth: 0
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
|
|
type=semver,pattern={{raw}},value=${{ github.event.workflow_run.head_branch }},enable=${{ startsWith(github.event.workflow_run.head_branch || '', 'v') }}
|
|
|
|
docker-build:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
attestations: write
|
|
id-token: write
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- os: self-hosted
|
|
arch: amd64
|
|
- os: ubuntu-24.04-arm
|
|
arch: arm64
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha }}
|
|
fetch-depth: 0
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Extract metadata (tags, labels) for Docker
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
tags: |
|
|
type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'main' }}
|
|
type=semver,pattern={{raw}},value=${{ github.event.workflow_run.head_branch }},enable=${{ startsWith(github.event.workflow_run.head_branch || '', 'v') }}
|
|
flavor: |
|
|
latest=auto
|
|
suffix=-${{ matrix.arch }},onlatest=true
|
|
images: |
|
|
ghcr.io/${{ github.repository }}
|
|
|
|
- name: Build and push Docker images
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
|
|
docker-manifest:
|
|
if: |
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
(
|
|
github.event.workflow_run.head_branch == 'main' ||
|
|
startsWith(github.event.workflow_run.head_branch || '', 'v')
|
|
)
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
needs:
|
|
- docker-build
|
|
- docker-clean-metadata
|
|
runs-on: ubuntu-latest
|
|
|
|
strategy:
|
|
matrix:
|
|
image: ${{ fromJson(needs.docker-clean-metadata.outputs.json).tags }}
|
|
|
|
steps:
|
|
- name: Log in to the GitHub Container registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Create and push manifest
|
|
run: |
|
|
docker buildx imagetools create -t ${{ matrix.image }} ${{ matrix.image }}-amd64 ${{ matrix.image }}-arm64
|