ci:cd/ Improve GitHub Actions workflow (#34)
* ci/cd: Add dependabot.yml * ci/cd: Update build-and-test.yml script * ci/cd: Update publish.yml script * doc: Update README.md
This commit is contained in:
129
.github/workflows/publish.yml
vendored
129
.github/workflows/publish.yml
vendored
@@ -1,4 +1,4 @@
|
||||
name: Publish
|
||||
name: Publish Docker image
|
||||
|
||||
on:
|
||||
push:
|
||||
@@ -11,81 +11,80 @@ on:
|
||||
env:
|
||||
GITHUB_REF_NAME: ${{ github.event.release.tag_name }}
|
||||
IMAGE_NAME: cdalvaro/docker-salt-master
|
||||
PLATFORMS: linux/amd64 linux/arm64
|
||||
DOCKER_CLI_EXPERIMENTAL: enabled
|
||||
PLATFORMS: linux/amd64,linux/arm64
|
||||
CACHE_PATH: /tmp/.buildx-docker-salt-master-cache
|
||||
EXTRA_REGISTRIES: ghcr.io quay.io
|
||||
|
||||
jobs:
|
||||
build-and-publish:
|
||||
name: Build and publish
|
||||
publish:
|
||||
name: Publish
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Enable Docker experimental
|
||||
run: |
|
||||
# Enable docker daemon experimental support.
|
||||
echo '{"experimental": true}' | sudo tee /etc/docker/daemon.json
|
||||
sudo systemctl restart docker
|
||||
# Install QEMU multi-architecture support for docker buildx.
|
||||
docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v1
|
||||
|
||||
- name: Instantiate docker buildx builder
|
||||
run: |
|
||||
docker buildx create --use
|
||||
docker buildx inspect --bootstrap
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v1
|
||||
|
||||
- name: Cache latest images
|
||||
continue-on-error: true
|
||||
- name: Cache Docker layers
|
||||
uses: actions/cache@v2
|
||||
with:
|
||||
path: ${{ env.CACHE_PATH }}
|
||||
key: ${{ runner.os }}-buildx-${{ github.sha }}
|
||||
restore-keys: |
|
||||
${{ runner.os }}-buildx-
|
||||
|
||||
- name: Login to Docker Container Registry
|
||||
uses: docker/login-action@v1
|
||||
with:
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@v1
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.CR_PAT }}
|
||||
|
||||
- name: Login to Quay.io Container Registry
|
||||
uses: docker/login-action@v1
|
||||
with:
|
||||
registry: quay.io
|
||||
username: ${{ secrets.QUAYIO_USERNAME }}
|
||||
password: ${{ secrets.QUAYIO_PASSWORD }}
|
||||
|
||||
- name: Prepare metadata
|
||||
id: metadata
|
||||
run: |
|
||||
for PLATFORM in ${PLATFORMS}; do
|
||||
docker pull --platform "${PLATFORM}" "${IMAGE_NAME}:latest"
|
||||
# Tags
|
||||
DOCKER_IMAGE="${IMAGE_NAME}:${GITHUB_REF_NAME:-latest}"
|
||||
TAGS="${DOCKER_IMAGE}"
|
||||
for registry in ${EXTRA_REGISTRIES}: do
|
||||
TAGS="${TAGS},${registry}/${DOCKER_IMAGE}"
|
||||
done
|
||||
|
||||
- name: Log in to Docker Hub
|
||||
run: |
|
||||
echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u="${{ secrets.DOCKER_USERNAME }}" --password-stdin
|
||||
# Build args
|
||||
VCS_REF="${GITHUB_SHA::8}"
|
||||
CREATED_ON="$(date +"%Y-%m-%d %H:%M:%S%:z")"
|
||||
|
||||
- name: Build and push Docker image
|
||||
run: |
|
||||
docker buildx build \
|
||||
--platform "${PLATFORMS// /,}" \
|
||||
--cache-from "${IMAGE_NAME}:latest" \
|
||||
--push --progress plain \
|
||||
--build-arg=VCS_REF="${GITHUB_SHA::7}" \
|
||||
--build-arg=BUILD_DATE="$(date +"%Y-%m-%d %H:%M:%S%:z")" \
|
||||
--tag="${IMAGE_NAME}:${GITHUB_REF_NAME:-latest}" .
|
||||
echo ::set-output name=tags::${TAGS}
|
||||
echo ::set-output name=vcs_ref::${VCS_REF}
|
||||
echo ::set-output name=created_on::${CREATED_ON}
|
||||
|
||||
test:
|
||||
name: Test
|
||||
runs-on: ubuntu-latest
|
||||
needs: build-and-publish
|
||||
steps:
|
||||
- name: Enable Docker experimental
|
||||
run: |
|
||||
# Enable docker daemon experimental support.
|
||||
echo '{"experimental": true}' | sudo tee /etc/docker/daemon.json
|
||||
sudo systemctl restart docker
|
||||
# Install QEMU multi-architecture support for docker buildx.
|
||||
docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
|
||||
|
||||
- name: Test images
|
||||
env:
|
||||
CONTAINER_NAME: salt_master_test
|
||||
run: |
|
||||
IMAGE_TAG="${GITHUB_REF_NAME:-latest}"
|
||||
DOCKER_IMAGE="${IMAGE_NAME}:${IMAGE_TAG}"
|
||||
for PLATFORM in ${PLATFORMS}; do
|
||||
echo "Testing docker image ${DOCKER_IMAGE} on platform ${PLATFORM} ..."
|
||||
# test
|
||||
docker pull -q --platform "${PLATFORM}" "${DOCKER_IMAGE}"
|
||||
docker run --rm -d --name "${CONTAINER_NAME}" "${DOCKER_IMAGE}"
|
||||
docker container ls
|
||||
sleep 20
|
||||
docker exec "${CONTAINER_NAME}" salt --versions
|
||||
echo "healthcheck"
|
||||
docker exec "${CONTAINER_NAME}" /usr/local/sbin/healthcheck
|
||||
# cleanup
|
||||
docker stop ${CONTAINER_NAME}
|
||||
docker image rm "${DOCKER_IMAGE}"
|
||||
done
|
||||
- name: Build
|
||||
uses: docker/build-push-action@v2
|
||||
with:
|
||||
context: .
|
||||
file: ./Dockerfile
|
||||
platforms: ${{ env.PLATFORMS }}
|
||||
build-args: |
|
||||
VCS_REF=${{ steps.metadata.outputs.vcs_ref }}
|
||||
BUILD_DATE=${{ steps.metadata.outputs.created_on }}
|
||||
cache-from: type=local,src=${{ env.CACHE_PATH }}
|
||||
cache-to: type=local,dest=${{ env.CACHE_PATH }}
|
||||
push: true
|
||||
tags: ${{ steps.metadata.outputs.tags }}
|
||||
|
||||
Reference in New Issue
Block a user