143 lines
4.8 KiB
YAML
143 lines
4.8 KiB
YAML
|
|
name: Build DockerHub
|
|
on:
|
|
push:
|
|
branches:
|
|
- '*'
|
|
tags:
|
|
- '*'
|
|
paths:
|
|
- '**.sh'
|
|
- "Dockerfile"
|
|
- '.github/workflows/dockerhub.yml'
|
|
# A dispatch on a tag ref rebuilds that tag's own image; the weekly
|
|
# schedule (default branch only) dispatches the latest release tag so a
|
|
# pinned version tag picks up Alpine package security updates (issue 7209).
|
|
# master never publishes anything but latest.
|
|
schedule:
|
|
- cron: '17 3 * * 1'
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
DOCKER_IMAGE: neilpang/acme.sh
|
|
|
|
jobs:
|
|
CheckToken:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
hasToken: ${{ steps.step_one.outputs.hasToken }}
|
|
env:
|
|
DOCKER_PASSWORD : ${{ secrets.DOCKER_PASSWORD }}
|
|
steps:
|
|
- name: Set the value
|
|
id: step_one
|
|
run: |
|
|
if [ "$DOCKER_PASSWORD" ] ; then
|
|
echo "hasToken=true" >>$GITHUB_OUTPUT
|
|
else
|
|
echo "hasToken=false" >>$GITHUB_OUTPUT
|
|
fi
|
|
- name: Check the value
|
|
run: echo ${{ steps.step_one.outputs.hasToken }}
|
|
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
needs: CheckToken
|
|
if: "github.event_name != 'schedule' && contains(needs.CheckToken.outputs.hasToken, 'true')"
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
steps:
|
|
- name: checkout code
|
|
uses: actions/checkout@v7
|
|
with:
|
|
persist-credentials: false
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@v4
|
|
- name: Extract Docker metadata
|
|
id: meta
|
|
uses: docker/metadata-action@v6
|
|
with:
|
|
images: ${DOCKER_IMAGE}
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v4
|
|
- name: login to docker hub
|
|
run: |
|
|
echo "${{ secrets.DOCKER_PASSWORD }}" | docker login -u "${{ secrets.DOCKER_USERNAME }}" --password-stdin
|
|
- name: login to ghcr
|
|
run: |
|
|
echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u "${{ github.actor }}" --password-stdin
|
|
- name: build and push the image
|
|
run: |
|
|
if [[ $GITHUB_REF == refs/tags/* ]]; then
|
|
DOCKER_IMAGE_TAG=${GITHUB_REF#refs/tags/}
|
|
fi
|
|
|
|
if [[ $GITHUB_REF == refs/heads/* ]]; then
|
|
DOCKER_IMAGE_TAG=${GITHUB_REF#refs/heads/}
|
|
|
|
if [[ $DOCKER_IMAGE_TAG == master ]]; then
|
|
DOCKER_IMAGE_TAG=latest
|
|
AUTO_UPGRADE=1
|
|
fi
|
|
fi
|
|
|
|
echo "DOCKER_IMAGE_TAG=${DOCKER_IMAGE_TAG}" >>"$GITHUB_ENV"
|
|
|
|
DOCKER_LABELS=()
|
|
while read -r label; do
|
|
DOCKER_LABELS+=(--label "${label}")
|
|
done <<<"${DOCKER_METADATA_OUTPUT_LABELS}"
|
|
|
|
docker buildx build \
|
|
--tag ${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \
|
|
"${DOCKER_LABELS[@]}" \
|
|
--output "type=image,push=true" \
|
|
--build-arg AUTO_UPGRADE=${AUTO_UPGRADE} \
|
|
--platform linux/arm64/v8,linux/amd64,linux/arm/v6,linux/arm/v7,linux/386,linux/ppc64le,linux/s390x .
|
|
- name: mirror the image to ghcr (best-effort)
|
|
run: |
|
|
docker buildx imagetools create \
|
|
--tag ghcr.io/${{ github.repository }}:${DOCKER_IMAGE_TAG} \
|
|
${DOCKER_IMAGE}:${DOCKER_IMAGE_TAG} \
|
|
|| echo "::warning::GHCR mirror failed; Docker Hub publish unaffected"
|
|
|
|
rebuild:
|
|
# weekly: dispatch this workflow on the latest release tag so the tag
|
|
# rebuilds its own image from its own commit and its own workflow file
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'schedule'
|
|
permissions:
|
|
contents: read
|
|
actions: write
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
steps:
|
|
- name: dispatch a rebuild of the latest release tag
|
|
run: |
|
|
tag="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq .tag_name)"
|
|
if [ -z "$tag" ]; then
|
|
echo "::error::cannot resolve the latest release tag"
|
|
exit 1
|
|
fi
|
|
echo "dispatching a rebuild of ${tag}"
|
|
# A tag cut before this job existed carries a workflow file with no
|
|
# workflow_dispatch trigger; the API rejects the dispatch with 422.
|
|
# That is expected (nothing to rebuild there), so only a different
|
|
# error fails the job.
|
|
if ! out="$(gh workflow run dockerhub.yml --repo "${GITHUB_REPOSITORY}" --ref "${tag}" 2>&1)"; then
|
|
echo "$out"
|
|
case "$out" in
|
|
*"does not have 'workflow_dispatch' trigger"*)
|
|
echo "::warning::${tag} predates the dispatch trigger; skipping the rebuild"
|
|
;;
|
|
*)
|
|
exit 1
|
|
;;
|
|
esac
|
|
fi
|