# ============================================================================= # Gitea Actions workflow: build a Docker image and push it to Harbor. # # Place this file in your application repository at: # .gitea/workflows/build-and-push.yaml # # Required repo/org Actions secrets (Settings -> Actions -> Secrets): # HARBOR_REGISTRY e.g. harbor.example.com # HARBOR_USERNAME e.g. robot$ci # HARBOR_PASSWORD the robot account token # # Optional repo/org Actions variables (Settings -> Actions -> Variables): # HARBOR_PROJECT Harbor project name (default: "library") # IMAGE_NAME image name (default: repository name) # ============================================================================= name: build-and-push on: push: branches: - main tags: - "v*" workflow_dispatch: jobs: build-and-push: # Uses the label advertised by the act_runner on k3s. runs-on: ubuntu-22.04 env: HARBOR_PROJECT: ${{ vars.HARBOR_PROJECT || 'library' }} IMAGE_NAME: ${{ vars.IMAGE_NAME || gitea.event.repository.name }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Compute image tags id: meta run: | REGISTRY="${{ secrets.HARBOR_REGISTRY }}" IMAGE="${REGISTRY}/${HARBOR_PROJECT}/${IMAGE_NAME}" SHA_TAG="${GITHUB_SHA::12}" echo "image=${IMAGE}" >> "$GITHUB_OUTPUT" echo "sha_tag=${SHA_TAG}" >> "$GITHUB_OUTPUT" # Use the git tag as the version when the ref is a tag, else 'latest'. if [[ "${GITHUB_REF}" == refs/tags/* ]]; then echo "version=${GITHUB_REF_NAME}" >> "$GITHUB_OUTPUT" else echo "version=latest" >> "$GITHUB_OUTPUT" fi - name: Log in to Harbor uses: docker/login-action@v3 with: registry: ${{ secrets.HARBOR_REGISTRY }} username: ${{ secrets.HARBOR_USERNAME }} password: ${{ secrets.HARBOR_PASSWORD }} - name: Build and push uses: docker/build-push-action@v6 with: context: . file: ./Dockerfile push: true tags: | ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }} ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }} - name: Summary run: | echo "Pushed:" echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }}" # ============================================================================= # Alternative: rootless builds (no privileged DinD sidecar) # ----------------------------------------------------------------------------- # If you cannot run a privileged DinD sidecar, build with Kaniko instead. # Replace the "Build and push" step (and drop the Buildx/login steps) with a # container step running the Kaniko executor. Kaniko logs in to Harbor via a # generated docker config: # # - name: Build and push with Kaniko # uses: https://github.com/int128/kaniko-action@v1 # with: # push: true # tags: ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }} # registry: ${{ secrets.HARBOR_REGISTRY }} # username: ${{ secrets.HARBOR_USERNAME }} # password: ${{ secrets.HARBOR_PASSWORD }} # # In that case the act_runner does not need the DinD sidecar; the Kaniko # executor image performs the build inside the job container. # =============================================================================