Repository navigation
139 lines (116 loc) · 3.35 KB
/
Copy pathcontainer.yml
File metadata and controls
139 lines (116 loc) · 3.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
name: Docker Build & Publish
on:
release:
types: [published]
push:
tags: ['v*']
permissions:
contents: read
packages: write
attestations: write
id-token: write
env:
REGISTRY: ghcr.io
IMAGE_NAME: authkits/authkit.server
LOCAL_TAG: authkit-server:test
jobs:
build:
name: Build Image
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build image (local, no push)
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
load: true
tags: ${{ env.LOCAL_TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Save image artifact
run: docker save ${{ env.LOCAL_TAG }} | gzip > /tmp/image.tar.gz
- name: Upload image artifact
uses: actions/upload-artifact@v4
with:
name: docker-image
path: /tmp/image.tar.gz
retention-days: 1
test:
name: Smoke Test
runs-on: ubuntu-latest
needs: build
steps:
- name: Download image artifact
uses: actions/download-artifact@v4
with:
name: docker-image
path: /tmp
- name: Load image
run: docker load < /tmp/image.tar.gz
- name: Run container
run: docker run -d -p 8080:80 --name authkit ${{ env.LOCAL_TAG }}
- name: Wait for startup
run: sleep 15
- name: Verify container is running
run: |
STATE=$(docker inspect -f '{{.State.Running}}' authkit)
if [ "$STATE" != "true" ]; then
echo "Container is not running"
docker logs authkit
exit 1
fi
- name: Show logs
if: always()
run: docker logs authkit
- name: HTTP smoke check
run: |
curl -fsS http://localhost:8080/ -o /dev/null \
&& echo "HTTP OK" \
|| echo "No HTTP endpoint (non-fatal)"
- name: Stop container
if: always()
run: docker stop authkit || true
publish:
name: Publish to GHCR
runs-on: ubuntu-latest
needs: test
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- name: Build and push image
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
push: true
platforms: linux/amd64,linux/arm64
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
provenance: true
sbom: true