name: Build DockerHub on: push: branches: - '*' tags: - '*' paths: - '**.sh' - "Dockerfile" - '.github/workflows/dockerhub.yml' # Rebuild the latest release tag weekly so a pinned version tag picks up # Alpine package security updates (see issue 7209). schedule: - cron: '17 3 * * 1' workflow_dispatch: inputs: tag: description: 'Release tag to rebuild (empty = latest release)' required: false default: '' concurrency: group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.ref }} cancel-in-progress: true env: DOCKER_IMAGE: neilpang/acme.sh jobs: CheckToken: runs-on: ubuntu-latest outputs: hasToken: ${{ steps.step_one.outputs.hasToken }} env: DOCKER_PASSWORD : ${{ secrets.DOCKER_PASSWORD }} steps: - name: Set the value id: step_one run: | if [ "$DOCKER_PASSWORD" ] ; then echo "hasToken=true" >>$GITHUB_OUTPUT else echo "hasToken=false" >>$GITHUB_OUTPUT fi - name: Check the value run: echo ${{ steps.step_one.outputs.hasToken }} build: runs-on: ubuntu-latest needs: CheckToken if: "contains(needs.CheckToken.outputs.hasToken, 'true')" permissions: contents: read packages: write steps: - name: resolve the release tag to rebuild id: rebuild if: github.event_name != 'push' env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} INPUT_TAG: ${{ github.event.inputs.tag }} run: | tag="$INPUT_TAG" if [ -z "$tag" ]; then tag="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq .tag_name)" fi if [ -z "$tag" ]; then echo "::error::cannot resolve the release tag to rebuild" exit 1 fi echo "rebuilding release tag ${tag}" echo "tag=${tag}" >>"$GITHUB_OUTPUT" - name: checkout code uses: actions/checkout@v7 with: ref: ${{ steps.rebuild.outputs.tag }} persist-credentials: false - name: Set up QEMU uses: docker/setup-qemu-action@v4 - name: Extract Docker metadata id: meta uses: docker/metadata-action@v6 with: images: ${DOCKER_IMAGE} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v4 - name: login to docker hub run: | echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u "${{ secrets.DOCKER_USERNAME }}" --password-stdin - name: login to ghcr run: | echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u "${{ github.actor }}" --password-stdin - name: build and push the image env: REBUILD_TAG: ${{ steps.rebuild.outputs.tag }} run: | if [ -n "$REBUILD_TAG" ]; then # scheduled/manual rebuild of an existing release tag DOCKER_IMAGE_TAG=${REBUILD_TAG} elif [[ $GITHUB_REF == refs/tags/* ]]; then DOCKER_IMAGE_TAG=${GITHUB_REF#refs/tags/} elif [[ $GITHUB_REF == refs/heads/* ]]; then DOCKER_IMAGE_TAG=${GITHUB_REF#refs/heads/} if [[ $DOCKER_IMAGE_TAG == master ]]; then DOCKER_IMAGE_TAG=latest AUTO_UPGRADE=1 fi fi echo "DOCKER_IMAGE_TAG=${DOCKER_IMAGE_TAG}" >>"$GITHUB_ENV" DOCKER_LABELS=() while read -r label; do DOCKER_LABELS+=(--label "${label}") done <<<"${DOCKER_METADATA_OUTPUT_LABELS}" if [ -n "$REBUILD_TAG" ]; then # the metadata action derived version/revision from the default # branch; a later --label wins, so point them at the rebuilt tag DOCKER_LABELS+=(--label "org.opencontainers.image.version=${REBUILD_TAG}") DOCKER_LABELS+=(--label "org.opencontainers.image.revision=$(git rev-parse HEAD)") fi docker buildx build \ --tag ${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \ "${DOCKER_LABELS[@]}" \ --output "type=image,push=true" \ --build-arg AUTO_UPGRADE=${AUTO_UPGRADE} \ --platform linux/arm64/v8,linux/amd64,linux/arm/v6,linux/arm/v7,linux/386,linux/ppc64le,linux/s390x . - name: mirror the image to ghcr (best-effort) run: | docker buildx imagetools create \ --tag ghcr.io/${{ github.repository }}:${DOCKER_IMAGE_TAG} \ ${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \ || echo "::warning::GHCR mirror failed; Docker Hub publish unaffected"