98 lines
3.6 KiB
YAML
98 lines
3.6 KiB
YAML
# =============================================================================
|
|||
|
|
# Gitea Actions workflow: build a Docker image and push it to Harbor.
|
||
|
|
#
|
||
|
|
# Place this file in your application repository at:
|
||
|
|
# .gitea/workflows/build-and-push.yaml
|
||
|
|
#
|
||
|
|
# Required repo/org Actions secrets (Settings -> Actions -> Secrets):
|
||
|
|
# HARBOR_REGISTRY e.g. harbor.example.com
|
||
|
|
# HARBOR_USERNAME e.g. robot$ci
|
||
|
|
# HARBOR_PASSWORD the robot account token
|
||
|
|
#
|
||
|
|
# Optional repo/org Actions variables (Settings -> Actions -> Variables):
|
||
|
|
# HARBOR_PROJECT Harbor project name (default: "library")
|
||
|
|
# IMAGE_NAME image name (default: repository name)
|
||
|
|
# =============================================================================
|
||
|
|
name: build-and-push
|
||
|
|
|
||
|
|
on:
|
||
|
|
push:
|
||
|
|
branches:
|
||
|
|
- main
|
||
|
|
tags:
|
||
|
|
- "v*"
|
||
|
|
workflow_dispatch:
|
||
|
|
|
||
|
|
jobs:
|
||
|
|
build-and-push:
|
||
|
|
# Uses the label advertised by the act_runner on k3s.
|
||
|
|
runs-on: ubuntu-22.04
|
||
|
|
env:
|
||
|
|
HARBOR_PROJECT: ${{ vars.HARBOR_PROJECT || 'library' }}
|
||
|
|
IMAGE_NAME: ${{ vars.IMAGE_NAME || gitea.event.repository.name }}
|
||
|
|
steps:
|
||
|
|
- name: Checkout
|
||
|
|
uses: actions/checkout@v4
|
||
|
|
|
||
|
|
- name: Set up Docker Buildx
|
||
|
|
uses: docker/setup-buildx-action@v3
|
||
|
|
|
||
|
|
- name: Compute image tags
|
||
|
|
id: meta
|
||
|
|
run: |
|
||
|
|
REGISTRY="${{ secrets.HARBOR_REGISTRY }}"
|
||
|
|
IMAGE="${REGISTRY}/${HARBOR_PROJECT}/${IMAGE_NAME}"
|
||
|
|
SHA_TAG="${GITHUB_SHA::12}"
|
||
|
|
echo "image=${IMAGE}" >> "$GITHUB_OUTPUT"
|
||
|
|
echo "sha_tag=${SHA_TAG}" >> "$GITHUB_OUTPUT"
|
||
|
|
# Use the git tag as the version when the ref is a tag, else 'latest'.
|
||
|
|
if [[ "${GITHUB_REF}" == refs/tags/* ]]; then
|
||
|
|
echo "version=${GITHUB_REF_NAME}" >> "$GITHUB_OUTPUT"
|
||
|
|
else
|
||
|
|
echo "version=latest" >> "$GITHUB_OUTPUT"
|
||
|
|
fi
|
||
|
|
|
||
|
|
- name: Log in to Harbor
|
||
|
|
uses: docker/login-action@v3
|
||
|
|
with:
|
||
|
|
registry: ${{ secrets.HARBOR_REGISTRY }}
|
||
|
|
username: ${{ secrets.HARBOR_USERNAME }}
|
||
|
|
password: ${{ secrets.HARBOR_PASSWORD }}
|
||
|
|
|
||
|
|
- name: Build and push
|
||
|
|
uses: docker/build-push-action@v6
|
||
|
|
with:
|
||
|
|
context: .
|
||
|
|
file: ./Dockerfile
|
||
|
|
push: true
|
||
|
|
tags: |
|
||
|
|
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}
|
||
|
|
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }}
|
||
|
|
|
||
|
|
- name: Summary
|
||
|
|
run: |
|
||
|
|
echo "Pushed:"
|
||
|
|
echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}"
|
||
|
|
echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }}"
|
||
|
|
|
||
|
|
# =============================================================================
|
||
|
|
# Alternative: rootless builds (no privileged DinD sidecar)
|
||
|
|
# -----------------------------------------------------------------------------
|
||
|
|
# If you cannot run a privileged DinD sidecar, build with Kaniko instead.
|
||
|
|
# Replace the "Build and push" step (and drop the Buildx/login steps) with a
|
||
|
|
# container step running the Kaniko executor. Kaniko logs in to Harbor via a
|
||
|
|
# generated docker config:
|
||
|
|
#
|
||
|
|
# - name: Build and push with Kaniko
|
||
|
|
# uses: https://github.com/int128/kaniko-action@v1
|
||
|
|
# with:
|
||
|
|
# push: true
|
||
|
|
# tags: ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}
|
||
|
|
# registry: ${{ secrets.HARBOR_REGISTRY }}
|
||
|
|
# username: ${{ secrets.HARBOR_USERNAME }}
|
||
|
|
# password: ${{ secrets.HARBOR_PASSWORD }}
|
||
|
|
#
|
||
|
|
# In that case the act_runner does not need the DinD sidecar; the Kaniko
|
||
|
|
# executor image performs the build inside the job container.
|
||
|
|
# =============================================================================
|