89 lines
4 KiB
YAML
89 lines
4 KiB
YAML
name: Build and push Docker image (amd64, arm64 to hub.docker.com and ghcr.io)
|
|
|
|
on:
|
|
workflow_dispatch: # allows manual trigger
|
|
push: # push on branch
|
|
branches: [main, dev]
|
|
paths: # ignore changes to .md files
|
|
- "**"
|
|
- "!*.md"
|
|
# - '!.github/**'
|
|
pull_request: # runs when opened/reopned or when the head branch is updated
|
|
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
|
|
env:
|
|
BRANCH: ${{ github.head_ref || github.ref_name }} # head_ref/base_ref are only set for PRs, for branches ref_name will be used
|
|
|
|
jobs:
|
|
docker:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
- name: Set environment variables
|
|
run: |
|
|
echo "NOW=$(date -R)" >> "$GITHUB_ENV" # date -Iseconds; date +'%Y-%m-%dT%H:%M:%S'
|
|
if [[ "$BRANCH" == "main" ]]; then
|
|
echo "IMAGE_TAG=latest" >> "$GITHUB_ENV"
|
|
else
|
|
echo "IMAGE_TAG=$BRANCH" >> "$GITHUB_ENV"
|
|
fi
|
|
- name: Extract metadata for Docker (tags, labels)
|
|
id: meta
|
|
uses: docker/metadata-action@v5
|
|
with:
|
|
images: |
|
|
${{ secrets.DOCKERHUB_USERNAME }}/free-games-claimer
|
|
ghcr.io/${{ github.actor }}/free-games-claimer
|
|
tags: |
|
|
type=ref,event=branch
|
|
type=ref,event=pr
|
|
# use docker tag 'latest' for the default branch (default is to only use it for the latest git tag)
|
|
type=raw,value=latest,enable={{is_default_branch}}
|
|
labels: |
|
|
org.opencontainers.image.created={{commit_date 'YYYY-MM-DDTHH:mm:ss.SSS[Z]'}}
|
|
env:
|
|
# otherwise labels are not shown on GitHub due to multi-arch image: https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry#adding-a-description-to-multi-arch-images
|
|
# https://github.com/docker/metadata-action#annotations
|
|
DOCKER_METADATA_ANNOTATIONS_LEVELS: manifest,index
|
|
- name: Login to Docker Hub
|
|
uses: docker/login-action@v3
|
|
# if: ${{ secrets.DOCKERHUB_USERNAME != '' && secrets.DOCKERHUB_TOKEN != '' }} # does not work: Unrecognized named-value: 'secrets' - https://www.cloudtruth.com/blog/skipping-jobs-in-github-actions-when-secrets-are-unavailable-securely-inject-configuration-secrets-into-github
|
|
if: github.event_name != 'pull_request' # don't try to login since PRs don't have access to secrets and need to set them in their fork
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }} # actor is user that opened PR, was repository_owner before
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@v3
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v6
|
|
if: ${{ env.IMAGE_TAG != '' }}
|
|
with:
|
|
context: .
|
|
# push: ${{ github.event_name != 'pull_request' }}
|
|
push: ${{ secrets.DOCKERHUB_USERNAME != '' }} # here we can access secrets
|
|
# TODO speed up by building in parallel? https://docs.docker.com/build/ci/github-actions/multi-platform/#distribute-build-across-multiple-runners
|
|
platforms: linux/amd64,linux/arm64
|
|
build-args: |
|
|
COMMIT=${{ github.sha }}
|
|
BRANCH=${{ env.BRANCH }}
|
|
NOW=${{ env.NOW }}
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
annotations: ${{ steps.meta.outputs.annotations }}
|
|
# tags: |
|
|
# ${{ secrets.DOCKERHUB_USERNAME }}/free-games-claimer:${{env.IMAGE_TAG}}
|
|
# ghcr.io/${{ github.actor }}/free-games-claimer:${{env.IMAGE_TAG}}
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|