diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 0ec5aec..e4d27b7 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -23,15 +23,17 @@ jobs: base: needs: semantic-release - runs-on: ubuntu-latest + runs-on: ${{ matrix.runner }} env: REGISTRY_IMAGE: flanksource/base-image strategy: fail-fast: false matrix: - platform: - - linux/amd64 - - linux/arm64 + include: + - platform: linux/amd64 + runner: ubuntu-latest + - platform: linux/arm64 + runner: ubuntu-arm64 steps: - name: Prepare run: | @@ -78,7 +80,67 @@ jobs: if-no-files-found: error retention-days: 1 - merge: + canary-checker: + needs: merge-base + runs-on: ${{ matrix.runner }} + env: + REGISTRY_IMAGE: flanksource/base-image-canary-checker + strategy: + fail-fast: false + matrix: + include: + - platform: linux/amd64 + runner: ubuntu-latest + - platform: linux/arm64 + runner: ubuntu-latest + steps: + - name: Prepare + run: | + platform=${{ matrix.platform }} + echo "PLATFORM_PAIR=${platform//\//-}" >> $GITHUB_ENV + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY_IMAGE }} + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Build and push by digest + id: build + uses: docker/build-push-action@v6 + with: + file: Dockerfile.canary-checker + platforms: ${{ matrix.platform }} + labels: ${{ steps.meta.outputs.labels }} + outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true + + - name: Export digest + run: | + mkdir -p /tmp/digests + digest="${{ steps.build.outputs.digest }}" + touch "/tmp/digests/${digest#sha256:}" + + - name: Upload digest + uses: actions/upload-artifact@v4 + with: + name: digests-${{ env.PLATFORM_PAIR }} + path: /tmp/digests/* + if-no-files-found: error + retention-days: 1 + + merge-base: runs-on: ubuntu-latest env: REGISTRY_IMAGE: flanksource/base-image @@ -117,39 +179,41 @@ jobs: run: | docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.meta.outputs.version }} - canary-checker: - needs: merge + merge-canary-checker: runs-on: ubuntu-latest + env: + REGISTRY_IMAGE: flanksource/base-image-canary-checker + needs: + - canary-checker steps: - - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2.7.0 - - - name: Set up QEMU - uses: docker/setup-qemu-action@v3 + - name: Download digests + uses: actions/download-artifact@v4 + with: + path: /tmp/digests + pattern: digests-* + merge-multiple: true - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY_IMAGE }} + - name: Login to Docker Hub uses: docker/login-action@v3 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_PASSWORD }} - - name: Build and push - uses: docker/build-push-action@v6 - env: - RELEASE_VERSION: ${{ needs.semantic-release.outputs.release-version }} - with: - push: true - tags: "flanksource/base-image:latest,flanksource/base-image:v${{ env.RELEASE_VERSION }}" - platforms: linux/amd64,linux/arm64 + - name: Create manifest list and push + working-directory: /tmp/digests + run: | + docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ + $(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *) - - name: Build and push - uses: docker/build-push-action@v6 - env: - RELEASE_VERSION: ${{ needs.semantic-release.outputs.release-version }} - with: - push: true - file: Dockerfile.canary-checker - tags: "flanksource/base-image-canary-checker:latest,flanksource/base-image-canary-checker:v${{ env.RELEASE_VERSION }}" - platforms: linux/amd64,linux/arm64 + - name: Inspect image + run: | + docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.meta.outputs.version }}