Files
2026-08-27 10:46:36 +02:00

98 lines
3.6 KiB
YAML

# =============================================================================
# Gitea Actions workflow: build a Docker image and push it to Harbor.
#
# Place this file in your application repository at:
# .gitea/workflows/build-and-push.yaml
#
# Required repo/org Actions secrets (Settings -> Actions -> Secrets):
# HARBOR_REGISTRY e.g. harbor.example.com
# HARBOR_USERNAME e.g. robot$ci
# HARBOR_PASSWORD the robot account token
#
# Optional repo/org Actions variables (Settings -> Actions -> Variables):
# HARBOR_PROJECT Harbor project name (default: "library")
# IMAGE_NAME image name (default: repository name)
# =============================================================================
name: build-and-push
on:
push:
branches:
- main
tags:
- "v*"
workflow_dispatch:
jobs:
build-and-push:
# Uses the label advertised by the act_runner on k3s.
runs-on: ubuntu-22.04
env:
HARBOR_PROJECT: ${{ vars.HARBOR_PROJECT || 'library' }}
IMAGE_NAME: ${{ vars.IMAGE_NAME || gitea.event.repository.name }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Compute image tags
id: meta
run: |
REGISTRY="${{ secrets.HARBOR_REGISTRY }}"
IMAGE="${REGISTRY}/${HARBOR_PROJECT}/${IMAGE_NAME}"
SHA_TAG="${GITHUB_SHA::12}"
echo "image=${IMAGE}" >> "$GITHUB_OUTPUT"
echo "sha_tag=${SHA_TAG}" >> "$GITHUB_OUTPUT"
# Use the git tag as the version when the ref is a tag, else 'latest'.
if [[ "${GITHUB_REF}" == refs/tags/* ]]; then
echo "version=${GITHUB_REF_NAME}" >> "$GITHUB_OUTPUT"
else
echo "version=latest" >> "$GITHUB_OUTPUT"
fi
- name: Log in to Harbor
uses: docker/login-action@v3
with:
registry: ${{ secrets.HARBOR_REGISTRY }}
username: ${{ secrets.HARBOR_USERNAME }}
password: ${{ secrets.HARBOR_PASSWORD }}
- name: Build and push
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
push: true
tags: |
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }}
- name: Summary
run: |
echo "Pushed:"
echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}"
echo " ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.sha_tag }}"
# =============================================================================
# Alternative: rootless builds (no privileged DinD sidecar)
# -----------------------------------------------------------------------------
# If you cannot run a privileged DinD sidecar, build with Kaniko instead.
# Replace the "Build and push" step (and drop the Buildx/login steps) with a
# container step running the Kaniko executor. Kaniko logs in to Harbor via a
# generated docker config:
#
# - name: Build and push with Kaniko
# uses: https://github.com/int128/kaniko-action@v1
# with:
# push: true
# tags: ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}
# registry: ${{ secrets.HARBOR_REGISTRY }}
# username: ${{ secrets.HARBOR_USERNAME }}
# password: ${{ secrets.HARBOR_PASSWORD }}
#
# In that case the act_runner does not need the DinD sidecar; the Kaniko
# executor image performs the build inside the job container.
# =============================================================================