All checks were successful
Build Container / build (push) Successful in 13s
## Summary - Add Dagger Python module (`.dagger/`) with `build` and `publish` functions for container images - Replace Docker buildx + skopeo composite action with `dagger call publish` in `build-container.yaml` - BuildKit's native push is compatible with Zot — **skopeo workaround eliminated** - Add Dagger CLI (v0.19.11) to forgejo-runner Dockerfile, bump runner to v2.6.0 - Bootstrap step in workflow curl-installs dagger if not in runner (for first build on v2.5.1 runner) - Delete old `.forgejo/actions/build-push-image/` composite action - Add GPLv3 LICENSE ## Verified locally - `dagger call build --src=. --container-name=nettest` — builds ✓ - `dagger call publish --src=. --container-name=nettest --version=dagger-test` — pushed to Zot ✓ - `dagger call build --src=. --container-name=forgejo-runner` — new runner image builds ✓ - Dagger CLI accessible inside built runner image ✓ ## Deployment sequence (after merge) 1. `mise run container-tag-and-release forgejo-runner v2.6.0` — old runner bootstraps dagger via curl, builds new runner 2. `argocd app sync forgejo-runner` — runner restarts with v2.6.0 (dagger baked in) 3. `mise run container-tag-and-release nettest v0.13.0` — end-to-end test of new pipeline 4. `mise run container-list` — verify tags ## Not included (future phases) - Phase 2: docs build + Forgejo packages migration - Phase 3: runner simplification (remove skopeo, Node.js, etc.) - Phase 4: future workflows Reviewed-on: https://forge.ops.eblu.me/eblume/blumeops/pulls/156
89 lines
3 KiB
YAML
89 lines
3 KiB
YAML
# Generic container build workflow
|
|
# Triggers on tags matching: <container>-v<version>
|
|
# Builds from containers/<container>/Dockerfile if it exists
|
|
#
|
|
# Uses Dagger to build and push images to the Zot registry.
|
|
#
|
|
# Examples:
|
|
# nettest-v1.0.0 -> builds containers/nettest/
|
|
# devpi-v2.1.0 -> builds containers/devpi/
|
|
# foo-v1.0.0 -> skips if containers/foo/ doesn't exist
|
|
name: Build Container
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- '*-v[0-9]*'
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: k8s
|
|
steps:
|
|
- name: Parse tag
|
|
id: parse
|
|
run: |
|
|
TAG="${GITHUB_REF_NAME}"
|
|
echo "Tag: $TAG"
|
|
|
|
# Extract container name (everything before -v)
|
|
# e.g., "nettest-v1.0.0" -> "nettest", "my-app-v2.0.0" -> "my-app"
|
|
CONTAINER="${TAG%-v[0-9]*}"
|
|
VERSION="${TAG#"${CONTAINER}"-}"
|
|
|
|
echo "container=$CONTAINER" >> "$GITHUB_OUTPUT"
|
|
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
|
|
echo "Container: $CONTAINER"
|
|
echo "Version: $VERSION"
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Check if container exists
|
|
id: check
|
|
run: |
|
|
CONTAINER="${{ steps.parse.outputs.container }}"
|
|
CONTEXT="containers/$CONTAINER"
|
|
|
|
if [ -f "$CONTEXT/Dockerfile" ]; then
|
|
echo "Found $CONTEXT/Dockerfile"
|
|
echo "exists=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "No Dockerfile found at $CONTEXT/Dockerfile"
|
|
echo "exists=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Skip if container not found
|
|
if: steps.check.outputs.exists != 'true'
|
|
run: |
|
|
echo "========================================"
|
|
echo "Container not found: ${{ steps.parse.outputs.container }}"
|
|
echo "========================================"
|
|
echo ""
|
|
echo "Tag '${{ github.ref_name }}' does not match any container in containers/"
|
|
echo ""
|
|
echo "Available containers:"
|
|
find containers -maxdepth 1 -mindepth 1 -type d -exec basename {} \; 2>/dev/null | sort | while read -r name; do
|
|
echo " - $name"
|
|
done || echo " (none)"
|
|
echo ""
|
|
echo "Skipping build."
|
|
|
|
- name: Ensure Dagger CLI
|
|
if: steps.check.outputs.exists == 'true'
|
|
run: |
|
|
# Bootstrap: install dagger if not already in the runner image.
|
|
# Remove once all runners include dagger (Phase 3).
|
|
if ! command -v dagger &>/dev/null; then
|
|
echo "Dagger not found, installing..."
|
|
curl -fsSL https://dl.dagger.io/dagger/install.sh | DAGGER_VERSION=0.19.11 sh
|
|
mv ./bin/dagger /usr/local/bin/dagger && rmdir ./bin
|
|
fi
|
|
dagger version
|
|
|
|
- name: Publish
|
|
if: steps.check.outputs.exists == 'true'
|
|
run: |
|
|
dagger call publish \
|
|
--src=. \
|
|
--container-name=${{ steps.parse.outputs.container }} \
|
|
--version=${{ steps.parse.outputs.version }}
|