name: Build DockerHub on: push: branches: - '*' tags: - '*' paths: - '**.sh' - "Dockerfile" - '.github/workflows/dockerhub.yml' # A dispatch on a tag ref rebuilds that tag's own image; the weekly # schedule (default branch only) dispatches the latest release tag so a # pinned version tag picks up Alpine package security updates (issue 7209). # master never publishes anything but latest. schedule: - cron: '17 3 * * 1' workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.ref }} cancel-in-progress: true env: DOCKER_IMAGE: neilpang/acme.sh jobs: CheckToken: runs-on: ubuntu-latest outputs: hasToken: ${{ steps.step_one.outputs.hasToken }} env: DOCKER_PASSWORD : ${{ secrets.DOCKER_PASSWORD }} steps: - name: Set the value id: step_one run: | if [ "$DOCKER_PASSWORD" ] ; then echo "hasToken=true" >>$GITHUB_OUTPUT else echo "hasToken=false" >>$GITHUB_OUTPUT fi - name: Check the value run: echo ${{ steps.step_one.outputs.hasToken }} build: runs-on: ubuntu-latest needs: CheckToken if: "github.event_name != 'schedule' && contains(needs.CheckToken.outputs.hasToken, 'true')" permissions: contents: read packages: write steps: - name: checkout code uses: actions/checkout@v7 with: persist-credentials: false - name: Set up QEMU uses: docker/setup-qemu-action@v4 - name: Extract Docker metadata id: meta uses: docker/metadata-action@v6 with: images: ${DOCKER_IMAGE} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v4 - name: login to docker hub run: | echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u "${{ secrets.DOCKER_USERNAME }}" --password-stdin - name: login to ghcr run: | echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u "${{ github.actor }}" --password-stdin - name: build and push the image run: | if [[ $GITHUB_REF == refs/tags/* ]]; then DOCKER_IMAGE_TAG=${GITHUB_REF#refs/tags/} fi if [[ $GITHUB_REF == refs/heads/* ]]; then DOCKER_IMAGE_TAG=${GITHUB_REF#refs/heads/} if [[ $DOCKER_IMAGE_TAG == master ]]; then DOCKER_IMAGE_TAG=latest AUTO_UPGRADE=1 fi fi echo "DOCKER_IMAGE_TAG=${DOCKER_IMAGE_TAG}" >>"$GITHUB_ENV" DOCKER_LABELS=() while read -r label; do DOCKER_LABELS+=(--label "${label}") done <<<"${DOCKER_METADATA_OUTPUT_LABELS}" docker buildx build \ --tag ${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \ "${DOCKER_LABELS[@]}" \ --output "type=image,push=true" \ --build-arg AUTO_UPGRADE=${AUTO_UPGRADE} \ --platform linux/arm64/v8,linux/amd64,linux/arm/v6,linux/arm/v7,linux/386,linux/ppc64le,linux/s390x . - name: mirror the image to ghcr (best-effort) run: | docker buildx imagetools create \ --tag ghcr.io/${{ github.repository }}:${DOCKER_IMAGE_TAG} \ ${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \ || echo "::warning::GHCR mirror failed; Docker Hub publish unaffected" rebuild: # weekly: dispatch this workflow on the latest release tag so the tag # rebuilds its own image from its own commit and its own workflow file runs-on: ubuntu-latest if: github.event_name == 'schedule' permissions: contents: read actions: write env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} steps: - name: dispatch a rebuild of the latest release tag run: | tag="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq .tag_name)" if [ -z "$tag" ]; then echo "::error::cannot resolve the latest release tag" exit 1 fi echo "dispatching a rebuild of ${tag}" # A tag cut before this job existed carries a workflow file with no # workflow_dispatch trigger; the API rejects the dispatch with 422. # That is expected (nothing to rebuild there), so only a different # error fails the job. if ! out="$(gh workflow run dockerhub.yml --repo "${GITHUB_REPOSITORY}" --ref "${tag}" 2>&1)"; then echo "$out" case "$out" in *"does not have 'workflow_dispatch' trigger"*) echo "::warning::${tag} predates the dispatch trigger; skipping the rebuild" ;; *) exit 1 ;; esac fi