-
-
Notifications
You must be signed in to change notification settings - Fork 6
121 lines (102 loc) · 3.63 KB
/
deploy.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
name: Deploy to Docker Hub
on:
# Build and deploy the image on pushes to master branch
push:
branches:
- master
- main
workflow_dispatch:
# Build and deploy the image nightly (to ensure we pick up any security updates)
schedule:
- cron: "0 10 * * *"
jobs:
deploy_dockerhub_single_arch:
name: Deploy to DockerHub
runs-on: ubuntu-latest
strategy:
matrix:
docker-platform:
- linux/amd64
# Set job-wide environment variables
# - REPO: repo name on dockerhub
# - IMAGE: image name on dockerhub
env:
REPO: mikenye
IMAGE: postfix
PUSH: true
steps:
# Check out our code
-
name: Checkout
uses: actions/checkout@v2
# Hit an issue where arm builds would fail with cURL errors regarding intermediary certificates when downloading from github (ie: deploy-s6-overlay).
# After many hours of troubleshooting, the workaround is to pre-load the image's rootfs with the CA certificates from the runner.
# This problem may go away in future.
-
name: Copy CA Certificates from GitHub Runner to Image rootfs
run: |
ls -la /etc/ssl/certs/
mkdir -p ./rootfs/etc/ssl/certs
mkdir -p ./rootfs/usr/share/ca-certificates/mozilla
cp --no-dereference /etc/ssl/certs/*.crt ./rootfs/etc/ssl/certs
cp --no-dereference /etc/ssl/certs/*.pem ./rootfs/etc/ssl/certs
cp --no-dereference /usr/share/ca-certificates/mozilla/*.crt ./rootfs/usr/share/ca-certificates/mozilla
# Set up QEMU for multi-arch builds
-
name: Set up QEMU
uses: docker/setup-qemu-action@v1
# Log into docker hub (so we can push images)
-
name: Login to DockerHub
uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
# Set up buildx for multi platform builds
-
name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@v1
# Get archictecture suffix
-
name: Get image architecture suffix
run: |
echo "ARCH_TAG=$(echo '${{ matrix.docker-platform }}' | cut -d '/' -f2- | tr -s '/' '_')" >> $GITHUB_ENV
# Show archictecture suffix
-
name: Show image architecture suffix
run: |
echo "Architecture suffix: ${{ env.ARCH_TAG }}"
# Build "latest"
-
name: Build & Push - latest
uses: docker/build-push-action@v2
with:
context: .
file: ./Dockerfile
no-cache: true
platforms: ${{ matrix.docker-platform }}
push: ${{ env.PUSH }}
tags: ${{ env.REPO }}/${{ env.IMAGE }}:latest
# Get version from "latest"
-
name: Get latest image version
run: |
docker pull "${{ env.REPO }}/${{ env.IMAGE }}:latest"
echo "VERSION_TAG=$(docker run --rm --entrypoint cat "${{ env.REPO }}/${{ env.IMAGE }}:latest" /CONTAINER_VERSION)" >> $GITHUB_ENV
# Show version from "latest"
-
name: Show latest image version
run: |
echo "${{ env.REPO }}/${{ env.IMAGE }}:latest contains version: ${{ env.VERSION_TAG }}"
# Build version specific
-
name: Build & Push - version specific
uses: docker/build-push-action@v2
with:
context: .
file: ./Dockerfile
no-cache: true
platforms: ${{ matrix.docker-platform }}
push: ${{ env.PUSH }}
tags: ${{ env.REPO }}/${{ env.IMAGE }}:${{ env.VERSION_TAG }}