prop-base:latest is required by the production Dockerfile's final stage but was only built when Dockerfile.base changed. The registry can GC unused images. Remove paths filter so the image is always kept fresh.
88 lines
3.1 KiB
YAML
88 lines
3.1 KiB
YAML
name: Build base image
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
schedule:
|
|
- cron: '0 6 * * 0'
|
|
workflow_dispatch:
|
|
|
|
env:
|
|
REGISTRY: git.mcintire.me
|
|
OWNER: graham
|
|
IMAGE_NAME: prop-base
|
|
DOCKER_CLI_VERSION: '28.5.2'
|
|
BUILDX_VERSION: '0.35.0'
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
build-and-push:
|
|
name: Build and push base image
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install Docker CLI and buildx
|
|
run: |
|
|
set -euo pipefail
|
|
curl -fsSL --retry 3 --retry-delay 2 \
|
|
"https://download.docker.com/linux/static/stable/x86_64/docker-${DOCKER_CLI_VERSION}.tgz" \
|
|
| tar xz --strip-components=1 -C /usr/local/bin docker/docker
|
|
# Docker 23+ routes `docker build` through buildx. The static tarball
|
|
# ships only the CLI, so the plugin has to be installed separately or
|
|
# DOCKER_BUILDKIT=1 fails with "buildx component is missing".
|
|
mkdir -p "$HOME/.docker/cli-plugins"
|
|
curl -fsSL --retry 3 --retry-delay 2 \
|
|
-o "$HOME/.docker/cli-plugins/docker-buildx" \
|
|
"https://github.com/docker/buildx/releases/download/v${BUILDX_VERSION}/buildx-v${BUILDX_VERSION}.linux-amd64"
|
|
chmod +x "$HOME/.docker/cli-plugins/docker-buildx"
|
|
docker version
|
|
docker buildx version
|
|
|
|
- name: Build and push
|
|
env:
|
|
REGISTRY_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
IMAGE="${REGISTRY}/${OWNER}/${IMAGE_NAME}"
|
|
WGRIB2=$(grep -oP '^ARG WGRIB2_VERSION=\K.*' Dockerfile.base | head -1)
|
|
G2C=$(grep -oP '^ARG G2C_VERSION=\K.*' Dockerfile.base | head -1)
|
|
SHA_TAG="wgrib2-${WGRIB2}-g2c-${G2C}-${GITHUB_SHA::7}"
|
|
# ISO year+week, so the weekly cron re-executes the apt layers for
|
|
# Debian security updates but same-week reruns reuse the cache.
|
|
# This previously travelled via an `extra_args` input the build action
|
|
# never declared, and additionally contained a `$(date ...)` that a
|
|
# `with:` value never evaluates. It was doubly dead.
|
|
CACHE_BUST=$(date -u +%G-W%V)
|
|
|
|
echo "$REGISTRY_TOKEN" | docker login "$REGISTRY" -u "$OWNER" --password-stdin
|
|
|
|
DOCKER_BUILDKIT=1 docker build \
|
|
--file Dockerfile.base \
|
|
--build-arg "CACHE_BUST=${CACHE_BUST}" \
|
|
--build-arg BUILDKIT_INLINE_CACHE=1 \
|
|
--cache-from "${IMAGE}:latest" \
|
|
--tag "${IMAGE}:${SHA_TAG}" \
|
|
--tag "${IMAGE}:latest" \
|
|
.
|
|
|
|
docker push "${IMAGE}:${SHA_TAG}"
|
|
docker push "${IMAGE}:latest"
|
|
|
|
{
|
|
echo "### Base image pushed"
|
|
echo ""
|
|
echo "- \`${IMAGE}:${SHA_TAG}\`"
|
|
echo "- \`${IMAGE}:latest\`"
|
|
echo "- cache-bust: \`${CACHE_BUST}\`"
|
|
} >> "$GITHUB_STEP_SUMMARY"
|
|
|
|
docker image rm "${IMAGE}:${SHA_TAG}" "${IMAGE}:latest" 2>/dev/null || true
|
|
docker logout "$REGISTRY" || true
|