From d99fc7e9cba676522af62dbaf68c62c645074dcc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Carlos=20D=2E=20=C3=81lvaro?= Date: Mon, 28 Sep 2020 08:05:49 +0200 Subject: [PATCH] ci:cd/ Improve GitHub Actions workflow (#34) * ci/cd: Add dependabot.yml * ci/cd: Update build-and-test.yml script * ci/cd: Update publish.yml script * doc: Update README.md --- .github/dependabot.yml | 7 ++ .github/workflows/build-and-test.yml | 113 +++++++++++++++++++++++ .github/workflows/check-pr.yml | 77 ---------------- .github/workflows/publish.yml | 129 +++++++++++++-------------- README.md | 6 +- 5 files changed, 187 insertions(+), 145 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/build-and-test.yml delete mode 100644 .github/workflows/check-pr.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2c7d170 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,7 @@ +version: 2 +updates: + # Maintain dependencies for GitHub Actions + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "daily" diff --git a/.github/workflows/build-and-test.yml b/.github/workflows/build-and-test.yml new file mode 100644 index 0000000..b28e9f5 --- /dev/null +++ b/.github/workflows/build-and-test.yml @@ -0,0 +1,113 @@ +name: Build and test Docker image + +on: + pull_request: + branches: + - master + +env: + IMAGE_NAME: localhost:5000/cdalvaro/docker-salt-master:ci + REGISTRY_PATH: ${{ github.workspace }}/registry + CACHE_PATH: /tmp/.buildx-docker-salt-master-cache + +jobs: + build: + name: Build + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v2 + + - name: Set up QEMU + uses: docker/setup-qemu-action@v1 + + - name: Start Docker registry + run: | + docker run -d -p 5000:5000 -v ${REGISTRY_PATH}:/var/lib/registry --name registry registry:2 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v1 + with: + driver-opts: network=host + + - name: Cache Docker layers + uses: actions/cache@v2 + with: + path: ${{ env.CACHE_PATH }} + key: ${{ runner.os }}-buildx-${{ github.sha }} + restore-keys: | + ${{ runner.os }}-buildx- + + - name: Build docker-salt-master image + uses: docker/build-push-action@v2 + with: + context: . + file: ./Dockerfile + platforms: linux/amd64,linux/arm64 + cache-from: type=local,src=${{ env.CACHE_PATH }} + cache-to: type=local,dest=${{ env.CACHE_PATH }} + push: true + tags: ${{ env.IMAGE_NAME }} + + - name: Stop Docker registry + run: docker stop registry + + - name: Upload Docker registry data for testing + uses: actions/upload-artifact@v2 + with: + name: docker-registry-data + path: ${{ env.REGISTRY_PATH }}/ + + test: + name: Test + runs-on: ubuntu-latest + needs: build + strategy: + matrix: + platform: [linux/amd64, linux/arm64] + env: + DOCKER_CLI_EXPERIMENTAL: enabled + steps: + - name: Download Docker registry data from build job + uses: actions/download-artifact@v2 + with: + name: docker-registry-data + path: ${{ env.REGISTRY_PATH }} + + - name: Enable Docker experimental + run: | + # Enable docker daemon experimental support. + echo '{"experimental": true}' | sudo tee /etc/docker/daemon.json + sudo systemctl restart docker + # Install QEMU multi-architecture support for docker buildx. + docker run --rm --privileged multiarch/qemu-user-static --reset -p yes + + - name: Start Docker registry + run: | + docker run -d -p 5000:5000 -v ${REGISTRY_PATH}:/var/lib/registry --name registry registry:2 + + - name: Docker inspect + run: docker buildx imagetools inspect ${IMAGE_NAME} + + - name: Import Docker images + run: docker pull --platform ${{ matrix.platform }} ${IMAGE_NAME} + + - name: Launch docker container + run: docker run --rm -d --name saltstack_master ${IMAGE_NAME} + + - name: Show container info + run: docker container ls + + - name: Wait for salt-master bootup + run: sleep 20 + + - name: Show salt versions + run: docker exec saltstack_master salt --versions + + - name: Test image calling healthcheck + run: docker exec saltstack_master /usr/local/sbin/healthcheck + + - name: Cleanup + run: | + docker stop saltstack_master registry + docker image rm ${IMAGE_NAME} diff --git a/.github/workflows/check-pr.yml b/.github/workflows/check-pr.yml deleted file mode 100644 index 08f725c..0000000 --- a/.github/workflows/check-pr.yml +++ /dev/null @@ -1,77 +0,0 @@ -name: Check PR - -on: - pull_request: - branches: - - master - -env: - IMAGE_NAME: cdalvaro/docker-salt-master - IMAGE_TAG: ci - -jobs: - build: - name: Build image - runs-on: ubuntu-latest - timeout-minutes: 45 - steps: - - name: Set env variables - run: | - echo ::set-env name=CACHE_FROM::"${{ env.IMAGE_NAME }}:latest" - echo ::set-env name=DOCKER_IMAGE::"${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" - - - name: Checkout repository - uses: actions/checkout@v2 - - - name: Cache lastest image - run: docker pull ${CACHE_FROM} - - - name: Build Docker image - run: | - docker build \ - --build-arg VCS_REF="${GITHUB_SHA::7}" \ - --build-arg BUILD_DATE="$(date +"%Y-%m-%d %H:%M:%S%:z")" \ - --cache-from ${CACHE_FROM} \ - --tag "${DOCKER_IMAGE}" . - - - name: Save docker image - run: | - mkdir -p docker/ - docker save -o docker/docker-image.tar "${DOCKER_IMAGE}" - - - name: Upload image for test job - uses: actions/upload-artifact@v2 - with: - name: docker-image - path: docker/docker-image.tar - - test: - name: Test image - needs: build - runs-on: ubuntu-latest - env: - CONTAINER_NAME: salt_master_ci - steps: - - name: Download docker image from build job - uses: actions/download-artifact@v2 - with: - name: docker-image - path: docker/ - - - name: Load docker image from build job - run: docker load -i docker/docker-image.tar - - - name: Launch docker container - run: docker run --rm -d --name "${CONTAINER_NAME}" "${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" - - - name: Show container info - run: docker container ls - - - name: Wait for salt-master bootup - run: sleep 60 - - - name: Show salt versions - run: docker exec "${CONTAINER_NAME}" salt --versions - - - name: Test image calling healthcheck - run: docker exec "${CONTAINER_NAME}" /usr/local/sbin/healthcheck diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 45d5ed8..bb9bb79 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,4 +1,4 @@ -name: Publish +name: Publish Docker image on: push: @@ -11,81 +11,80 @@ on: env: GITHUB_REF_NAME: ${{ github.event.release.tag_name }} IMAGE_NAME: cdalvaro/docker-salt-master - PLATFORMS: linux/amd64 linux/arm64 - DOCKER_CLI_EXPERIMENTAL: enabled + PLATFORMS: linux/amd64,linux/arm64 + CACHE_PATH: /tmp/.buildx-docker-salt-master-cache + EXTRA_REGISTRIES: ghcr.io quay.io jobs: - build-and-publish: - name: Build and publish + publish: + name: Publish runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v2 - - name: Enable Docker experimental - run: | - # Enable docker daemon experimental support. - echo '{"experimental": true}' | sudo tee /etc/docker/daemon.json - sudo systemctl restart docker - # Install QEMU multi-architecture support for docker buildx. - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes + - name: Set up QEMU + uses: docker/setup-qemu-action@v1 - - name: Instantiate docker buildx builder - run: | - docker buildx create --use - docker buildx inspect --bootstrap + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v1 - - name: Cache latest images - continue-on-error: true + - name: Cache Docker layers + uses: actions/cache@v2 + with: + path: ${{ env.CACHE_PATH }} + key: ${{ runner.os }}-buildx-${{ github.sha }} + restore-keys: | + ${{ runner.os }}-buildx- + + - name: Login to Docker Container Registry + uses: docker/login-action@v1 + with: + username: ${{ github.repository_owner }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Login to GitHub Container Registry + uses: docker/login-action@v1 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.CR_PAT }} + + - name: Login to Quay.io Container Registry + uses: docker/login-action@v1 + with: + registry: quay.io + username: ${{ secrets.QUAYIO_USERNAME }} + password: ${{ secrets.QUAYIO_PASSWORD }} + + - name: Prepare metadata + id: metadata run: | - for PLATFORM in ${PLATFORMS}; do - docker pull --platform "${PLATFORM}" "${IMAGE_NAME}:latest" + # Tags + DOCKER_IMAGE="${IMAGE_NAME}:${GITHUB_REF_NAME:-latest}" + TAGS="${DOCKER_IMAGE}" + for registry in ${EXTRA_REGISTRIES}: do + TAGS="${TAGS},${registry}/${DOCKER_IMAGE}" done - - name: Log in to Docker Hub - run: | - echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u="${{ secrets.DOCKER_USERNAME }}" --password-stdin + # Build args + VCS_REF="${GITHUB_SHA::8}" + CREATED_ON="$(date +"%Y-%m-%d %H:%M:%S%:z")" - - name: Build and push Docker image - run: | - docker buildx build \ - --platform "${PLATFORMS// /,}" \ - --cache-from "${IMAGE_NAME}:latest" \ - --push --progress plain \ - --build-arg=VCS_REF="${GITHUB_SHA::7}" \ - --build-arg=BUILD_DATE="$(date +"%Y-%m-%d %H:%M:%S%:z")" \ - --tag="${IMAGE_NAME}:${GITHUB_REF_NAME:-latest}" . + echo ::set-output name=tags::${TAGS} + echo ::set-output name=vcs_ref::${VCS_REF} + echo ::set-output name=created_on::${CREATED_ON} - test: - name: Test - runs-on: ubuntu-latest - needs: build-and-publish - steps: - - name: Enable Docker experimental - run: | - # Enable docker daemon experimental support. - echo '{"experimental": true}' | sudo tee /etc/docker/daemon.json - sudo systemctl restart docker - # Install QEMU multi-architecture support for docker buildx. - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes - - - name: Test images - env: - CONTAINER_NAME: salt_master_test - run: | - IMAGE_TAG="${GITHUB_REF_NAME:-latest}" - DOCKER_IMAGE="${IMAGE_NAME}:${IMAGE_TAG}" - for PLATFORM in ${PLATFORMS}; do - echo "Testing docker image ${DOCKER_IMAGE} on platform ${PLATFORM} ..." - # test - docker pull -q --platform "${PLATFORM}" "${DOCKER_IMAGE}" - docker run --rm -d --name "${CONTAINER_NAME}" "${DOCKER_IMAGE}" - docker container ls - sleep 20 - docker exec "${CONTAINER_NAME}" salt --versions - echo "healthcheck" - docker exec "${CONTAINER_NAME}" /usr/local/sbin/healthcheck - # cleanup - docker stop ${CONTAINER_NAME} - docker image rm "${DOCKER_IMAGE}" - done + - name: Build + uses: docker/build-push-action@v2 + with: + context: . + file: ./Dockerfile + platforms: ${{ env.PLATFORMS }} + build-args: | + VCS_REF=${{ steps.metadata.outputs.vcs_ref }} + BUILD_DATE=${{ steps.metadata.outputs.created_on }} + cache-from: type=local,src=${{ env.CACHE_PATH }} + cache-to: type=local,dest=${{ env.CACHE_PATH }} + push: true + tags: ${{ steps.metadata.outputs.tags }} diff --git a/README.md b/README.md index 28da1fb..6a09b89 100644 --- a/README.md +++ b/README.md @@ -56,10 +56,10 @@ These images are also available from [Quay.io](https://quay.io/repository/cdalva docker pull quay.io/cdalvaro/docker-salt-master:latest ``` -and from [GitHub Packages](https://github.com/cdalvaro/docker-salt-master/packages): +and from [GitHub Container Registry](https://github.com/cdalvaro/docker-salt-master/packages): ```sh -docker pull docker.pkg.github.com/cdalvaro/docker-salt-master/docker-salt-master:latest +docker pull ghcr.io/cdalvaro/docker-salt-master:latest ``` Alternatively, you can build the image locally. @@ -509,7 +509,7 @@ Where `salt-service` is one of: `salt-master` os `salt-api` (if `SALT_API_SERVIC [ubuntu_badge]: https://img.shields.io/badge/ubuntu-focal--20200720-E95420.svg?style=flat&logo=Ubuntu [ubuntu_hub_docker]: https://hub.docker.com/_/ubuntu/ "Ubuntu Image" -[github_publish_badge]: https://github.com/cdalvaro/docker-salt-master/workflows/Publish/badge.svg +[github_publish_badge]: https://github.com/cdalvaro/docker-salt-master/workflows/Publish%20Docker%20image/badge.svg [github_publish_workflow]: https://github.com/cdalvaro/docker-salt-master/actions?query=workflow%3A%22Publish%22 [docker_size_badge]: https://img.shields.io/docker/image-size/cdalvaro/docker-salt-master/latest?logo=docker&color=2496ED