diff --git a/.github/workflows/docker-buildops.yml b/.github/workflows/docker-buildops.yml index 4d0c0b1..44cb440 100644 --- a/.github/workflows/docker-buildops.yml +++ b/.github/workflows/docker-buildops.yml @@ -8,10 +8,6 @@ on: paths: - docker/** - .github/workflows/docker-buildops.yml - pull_request: - branches: [ "main" ] - paths: - - docker/** env: IMAGE_NAME_PREFIX: ${{ github.repository }} @@ -23,22 +19,9 @@ permissions: attestations: write jobs: - lint: - runs-on: ubuntu-latest - steps: - - name: Checkout repository - uses: actions/checkout@v4 - - name: Lint Dockerfile - uses: hadolint/hadolint-action@v3.1.0 - with: - dockerfile: Dockerfile - recursive: true - trusted-registries: quay.io, ghcr.io,docker.io,dock.mau.dev,index.docker.io,registry-1.docker.io - continue-on-error: true mkdocs-material: name: Custom image on Material for Mkdocs runs-on: ubuntu-latest - needs: [ lint ] steps: - name: Checkout repository uses: actions/checkout@v4 @@ -142,10 +125,202 @@ jobs: subject-name: index.docker.io/ajhalili2006/mkdocs-material subject-digest: ${{ steps.build.outputs.digest }} push-to-registry: true + devenv-base: + name: "base devenv image" + runs-on: ubuntu-latest + outputs: + baseImageTags: ${{steps.meta.outputs.tags}} + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Load secrets with dotenvx + uses: andreijiroh-dev/dotenvx-action@v0.3.0 + if: github.event_name != 'pull_request' + id: dotenvx + with: + path: .env.ci + key: ${{ secrets.DOTENV_PRIVATE_KEY_CI }} + + # Workaround: https://github.com/docker/build-push-action/issues/461 + - name: Setup Docker buildx + uses: docker/setup-buildx-action@v3 + with: + buildkitd-flags: --debug + + # Login against a Docker registry except on PR + # https://github.com/docker/login-action + - name: Log into Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ steps.dotenvx.outputs.DOCKER_USERNAME }} + password: ${{ steps.dotenvx.outputs.DOCKER_PASSWORD }} + - name: Log into GHCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ steps.dotenvx.outputs.GHCR_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GHCR_BOT_PASSWORD }} + - name: Log into RHQCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: quay.io + username: ${{ steps.dotenvx.outputs.RHQCR_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.RHQCR_BOT_PASSWORD }} + - name: Login into GLCR on mau.dev + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: dock.mau.dev + username: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_PASSWORD }} + + # Extract metadata (tags, labels) for Docker + # https://github.com/docker/metadata-action + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/devenv/base + dock.mau.dev/${{ env.IMAGE_NAME_PREFIX }}/devenv/base + quay.io/andreijiroh-dev/devenv-base + index.docker.io/ajhalili2006/devenv-base + tags: | + type=raw,value=latest,enable={{is_default_branch}} + type=sha,enable=true,priority=100,prefix=commit-,suffix=,format=long + type=schedule,pattern=nightly + type=schedule,prefix=nightly-,pattern={{date 'YYYYMMDDhhmmss'}} + type=raw,prefix=branch-,value={{branch}} + + # Build and push Docker image with Buildx (don't push on PR) + # https://github.com/docker/build-push-action + - name: Build and push Docker image + id: build + uses: docker/build-push-action@v6 + with: + context: docker/mkdocs-material + # workaround: https://github.com/moby/buildkit/issues/2713#issuecomment-1068540101 + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + pull: true + provenance: mode=max + sbom: true + - name: Generate image attestation for GHCR + uses: actions/attest-build-provenance@v1 + with: + subject-name: ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/devenv/base + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + - name: Generate image attestation for RHQCR + uses: actions/attest-build-provenance@v1 + with: + subject-name: quay.io/andreijiroh-dev/devenv-base + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + - name: Generate image attestation for Docker Hub + uses: actions/attest-build-provenance@v1 + with: + subject-name: index.docker.io/ajhalili2006/devenv-base + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + devenv-cloudshell: + name: "Google Cloud Shell custom image" + needs: [devenv-base] + runs-on: ubuntu-latest + continue-on-error: true + steps: + - name: Maximize build space + uses: easimon/maximize-build-space@master + with: + root-reserve-mb: 512 + swap-size-mb: 1024 + remove-dotnet: 'true' + remove-android: 'true' + remove-haskell: 'true' + remove-docker-images: 'true' + remove-codeql: 'true' + - name: Check free space after cleanup + run: | + echo "Free space:" + df -h + + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Load secrets with dotenvx + uses: andreijiroh-dev/dotenvx-action@v0.3.0 + if: github.event_name != 'pull_request' + id: dotenvx + with: + path: .env.ci + key: ${{ secrets.DOTENV_PRIVATE_KEY_CI }} + + # Workaround: https://github.com/docker/build-push-action/issues/461 + - name: Setup Docker buildx + uses: docker/setup-buildx-action@v3 + with: + buildkitd-flags: --debug + + # Login against a Docker registry except on PR + # https://github.com/docker/login-action + - name: Log into GHCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ steps.dotenvx.outputs.GHCR_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GHCR_BOT_PASSWORD }} + - name: Login into GLCR on mau.dev + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: dock.mau.dev + username: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_USERNAME }} + password: ${{ steps.dotenvx.outputs.GLCR_MAUDEV_BOT_PASSWORD }} + + # Extract metadata (tags, labels) for Docker + # https://github.com/docker/metadata-action + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/devenv/cloudshell + dock.mau.dev/${{ env.IMAGE_NAME_PREFIX }}/devenv/cloudshell + tags: | + type=raw,value=latest,enable={{is_default_branch}} + type=sha,enable=true,priority=100,prefix=commit-,suffix=,format=long + type=schedule,pattern=nightly + type=schedule,prefix=nightly-,pattern={{date 'YYYYMMDDhhmmss'}} + type=raw,prefix=branch-,value={{branch}} + + # Build and push Docker image with Buildx (don't push on PR) + # https://github.com/docker/build-push-action + - name: Build and push Docker image + id: build + uses: docker/build-push-action@v6 + with: + context: docker/mkdocs-material + # workaround: https://github.com/moby/buildkit/issues/2713#issuecomment-1068540101 + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + pull: true + provenance: mode=max + sbom: true + - name: Generate image attestation for GHCR + uses: actions/attest-build-provenance@v1 + with: + subject-name: ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/devenv/base + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true pkgops-alpine: name: "Alpine Linux - aports package maintainer image" runs-on: ubuntu-latest - needs: [ lint ] steps: - name: Checkout repository uses: actions/checkout@v4 diff --git a/.github/workflows/lint-and-test.yml b/.github/workflows/lint-and-test.yml new file mode 100644 index 0000000..7f6d594 --- /dev/null +++ b/.github/workflows/lint-and-test.yml @@ -0,0 +1,21 @@ +name: Linters and Tests + +on: + pull_request: + branches: [ "main" ] + paths: + - docker/** + +jobs: + hadolint: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + - name: Lint Dockerfile + uses: hadolint/hadolint-action@v3.1.0 + with: + dockerfile: Dockerfile + recursive: true + trusted-registries: quay.io, ghcr.io,docker.io,dock.mau.dev,index.docker.io,registry-1.docker.io + continue-on-error: true \ No newline at end of file