prop/.forgejo/workflows/build-base.yaml
Graham McIntire 92fb2deb5d
Some checks failed
Build base image / Build and push base image (push) Successful in 2m59s
Build and Push / Build CI test image (push) Successful in 10s
Build and Push / Build and Push Docker Image (push) Failing after 7m48s
fix: build base image on every push so prop-base:latest is always available
prop-base:latest is required by the production Dockerfile's final stage
but was only built when Dockerfile.base changed. The registry can GC
unused images. Remove paths filter so the image is always kept fresh.
2026-08-05 12:12:35 -05:00

88 lines
3.1 KiB
YAML

name: Build base image
on:
push:
branches:
- main
schedule:
- cron: '0 6 * * 0'
workflow_dispatch:
env:
REGISTRY: git.mcintire.me
OWNER: graham
IMAGE_NAME: prop-base
DOCKER_CLI_VERSION: '28.5.2'
BUILDX_VERSION: '0.35.0'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
jobs:
build-and-push:
name: Build and push base image
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Install Docker CLI and buildx
run: |
set -euo pipefail
curl -fsSL --retry 3 --retry-delay 2 \
"https://download.docker.com/linux/static/stable/x86_64/docker-${DOCKER_CLI_VERSION}.tgz" \
| tar xz --strip-components=1 -C /usr/local/bin docker/docker
# Docker 23+ routes `docker build` through buildx. The static tarball
# ships only the CLI, so the plugin has to be installed separately or
# DOCKER_BUILDKIT=1 fails with "buildx component is missing".
mkdir -p "$HOME/.docker/cli-plugins"
curl -fsSL --retry 3 --retry-delay 2 \
-o "$HOME/.docker/cli-plugins/docker-buildx" \
"https://github.com/docker/buildx/releases/download/v${BUILDX_VERSION}/buildx-v${BUILDX_VERSION}.linux-amd64"
chmod +x "$HOME/.docker/cli-plugins/docker-buildx"
docker version
docker buildx version
- name: Build and push
env:
REGISTRY_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
run: |
set -euo pipefail
IMAGE="${REGISTRY}/${OWNER}/${IMAGE_NAME}"
WGRIB2=$(grep -oP '^ARG WGRIB2_VERSION=\K.*' Dockerfile.base | head -1)
G2C=$(grep -oP '^ARG G2C_VERSION=\K.*' Dockerfile.base | head -1)
SHA_TAG="wgrib2-${WGRIB2}-g2c-${G2C}-${GITHUB_SHA::7}"
# ISO year+week, so the weekly cron re-executes the apt layers for
# Debian security updates but same-week reruns reuse the cache.
# This previously travelled via an `extra_args` input the build action
# never declared, and additionally contained a `$(date ...)` that a
# `with:` value never evaluates. It was doubly dead.
CACHE_BUST=$(date -u +%G-W%V)
echo "$REGISTRY_TOKEN" | docker login "$REGISTRY" -u "$OWNER" --password-stdin
DOCKER_BUILDKIT=1 docker build \
--file Dockerfile.base \
--build-arg "CACHE_BUST=${CACHE_BUST}" \
--build-arg BUILDKIT_INLINE_CACHE=1 \
--cache-from "${IMAGE}:latest" \
--tag "${IMAGE}:${SHA_TAG}" \
--tag "${IMAGE}:latest" \
.
docker push "${IMAGE}:${SHA_TAG}"
docker push "${IMAGE}:latest"
{
echo "### Base image pushed"
echo ""
echo "- \`${IMAGE}:${SHA_TAG}\`"
echo "- \`${IMAGE}:latest\`"
echo "- cache-bust: \`${CACHE_BUST}\`"
} >> "$GITHUB_STEP_SUMMARY"
docker image rm "${IMAGE}:${SHA_TAG}" "${IMAGE}:latest" 2>/dev/null || true
docker logout "$REGISTRY" || true