From bfee7f30c8e2495c2d9377bde88a51892dcb35b5 Mon Sep 17 00:00:00 2001 From: Andrei Jiroh Halili Date: Fri, 14 Jun 2024 03:00:24 +0800 Subject: [PATCH] build(mkdocs-material): import dockerfile and entrypoint script from website repo Also setup a singleton GHA workflow file for all the builds. --- .github/workflows/docker-buildops.yml | 125 ++++++++++++++++++++++++++ docker/mkdocs-material/Dockerfile | 86 ++++++++++++++++++ docker/mkdocs-material/README.md | 22 +++++ docker/mkdocs-material/entrypoint.sh | 12 +++ 4 files changed, 245 insertions(+) create mode 100644 .github/workflows/docker-buildops.yml create mode 100644 docker/mkdocs-material/Dockerfile create mode 100644 docker/mkdocs-material/README.md create mode 100644 docker/mkdocs-material/entrypoint.sh diff --git a/.github/workflows/docker-buildops.yml b/.github/workflows/docker-buildops.yml new file mode 100644 index 0000000..2650c3f --- /dev/null +++ b/.github/workflows/docker-buildops.yml @@ -0,0 +1,125 @@ +name: Docker Image Builds + +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. + +on: + schedule: + - cron: '30 0 * * *' + - cron: '30 12 * * *' + push: + pull_request: + branches: [ "main" ] + +env: + # github.repository as / + IMAGE_NAME_PREFIX: ${{ github.repository }} + +permissions: + contents: read + packages: write + # This is used to complete the identity challenge + # with sigstore/fulcio when running outside of PRs. + id-token: write + +jobs: + mkdocs-material: + name: Custom image on Material for Mkdocs + runs-on: ubuntu-latest + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Lint Dockerfile + uses: hadolint/hadolint-action@v3.1.0 + with: + dockerfile: docker/mkdocs-material/Dockerfile + + # Workaround: https://github.com/docker/build-push-action/issues/461 + - name: Setup Docker buildx + uses: docker/setup-buildx-action@v2 + with: + buildkitd-flags: --debug + + # Login against a Docker registry except on PR + # https://github.com/docker/login-action + - name: Log into GHCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v2 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ github.token }} + - name: Log into RHQCR + if: github.event_name != 'pull_request' + uses: docker/login-action@v2 + with: + registry: quay.io + username: ${{ secrets.RHQCR_BOT_USERNAME }} + password: ${{ secrets.RHQCR_BOT_TOKEN }} + - name: Login into GLCR on mau.dev + if: github.event_name != 'pull_request' + uses: docker/login-action@v2 + with: + registry: dock.mau.dev + username: ${{ secrets.LAB_USERNAME }} + password: ${{ secrets.LAB_MAUDEV_TOKEN }} + + # Install the cosign tool except on PR + # https://github.com/sigstore/cosign-installer + - name: Install cosign + if: github.event_name != 'pull_request' + uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 #v3.5.0 + with: + cosign-release: 'v2.2.4' + + # Extract metadata (tags, labels) for Docker + # https://github.com/docker/metadata-action + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v4 + with: + images: | + ghcr.io/${{ env.IMAGE_NAME_PREFIX }}/mkdocs-material + dock.mau.dev/${{ env.IMAGE_NAME_PREFIX }}/mkdocs-material + quay.io/ajhalili2006/mkdocs-material-build-ci + tags: | + type=raw,value=latest,enable={{is_default_branch}} + type=sha,enable=true,priority=100,prefix=commit-,suffix=,format=long + type=schedule,pattern=nightly + type=schedule,prefix=nightly-,pattern={{date 'YYYYMMDDhhmmss'}} + type=raw,prefix=branch-,value={{branch}} + + # Build and push Docker image with Buildx (don't push on PR) + # https://github.com/docker/build-push-action + - name: Build and push Docker image + id: build-and-push + uses: docker/build-push-action@v4.1.1 + with: + context: docker/mkdocs-material + #file: Dockerfile + # workaround: https://github.com/moby/buildkit/issues/2713#issuecomment-1068540101 + push: true + #load: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + cache-from: type=gha,scope=buildkit-mkdocs-material + cache-to: type=gha,mode=max,scope=buildkit-mkdocs-material + + # Sign the resulting Docker image digest except on PRs. + # This will only write to the public Rekor transparency log when the Docker + # repository is public to avoid leaking data. If you would like to publish + # transparency data even for private images, pass --force to cosign below. + # https://github.com/sigstore/cosign + - name: Sign the published Docker image + if: ${{ github.event_name != 'pull_request' }} + env: + # https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable + TAGS: ${{ steps.meta.outputs.tags }} + DIGEST: ${{ steps.build-and-push.outputs.digest }} + # This step uses the identity token to provision an ephemeral certificate + # against the sigstore community Fulcio instance. + run: echo "${TAGS}" | xargs -I {} cosign sign --yes --force {}@${DIGEST} \ No newline at end of file diff --git a/docker/mkdocs-material/Dockerfile b/docker/mkdocs-material/Dockerfile new file mode 100644 index 0000000..17324b4 --- /dev/null +++ b/docker/mkdocs-material/Dockerfile @@ -0,0 +1,86 @@ +# syntax=docker/dockerfile:1 +FROM python:3.12-alpine AS buildkit +# Instead of using Alpine base image and then installing Python from pkgs.al.o, +# we'll go with the official images instead. + +ENV PACKAGES=/usr/local/lib/python3.11/site-packages PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/root/.local/bin PYTHONDONTWRITEBYTECODE=1 +LABEL org.opencontainers.image.description="GitLab CI image for a custom mkdocs-material Docker image, alongside tools @ajhalili2006 use." + +# Since hadolint isn't in the package repos for Alpine yet, we'll copying from the offical +# Docker image instead. +COPY --from=ghcr.io/hadolint/hadolint:latest-alpine /bin/hadolint /usr/bin/hadolint + +# Load up our custom entrypoint script +COPY entrypoint.sh /usr/local/bin/entrypoint.sh +RUN chmod +x /usr/local/bin/entrypoint.sh + +# https://squidfunk.github.io/mkdocs-material/setup/setting-up-social-cards/#linux but for Alpine +# Also installs Doppler CLI for accessing secrets securely within CI +# hadolint ignore=DL3018,DL3013 +RUN apk add --no-cache \ + cairo-dev \ + freetype-dev \ + libffi-dev \ + jpeg-dev \ + libpng-dev \ + zlib-dev \ + bash \ + coreutils \ + shellcheck \ + gcc \ + libffi-dev \ + musl-dev \ + git \ + git-email \ + git-lfs \ + git-fast-import \ + openssh \ + gnupg \ + curl \ + wget \ + rsync \ + libstdc++ \ + && curl -Ls --tlsv1.2 --proto "=https" --retry 3 https://cli.doppler.com/install.sh \ + | sh -s --debug + +# Copy build artifacts from official node image into here +ENV YARN_VERSION 1.22.22 +COPY --from=node:20-alpine /opt/yarn-v$YARN_VERSION /opt/yarn-v$YARN_VERSION +COPY --from=node:20-alpine /usr/local/bin/node /usr/local/bin/node +COPY --from=node:20-alpine /usr/local/lib/node_modules/ /usr/local/lib/node_modules/ +COPY --from=node:20-alpine /usr/local/include/node/ /usr/local/include/node/ + +RUN ln -s /usr/local/bin/node /usr/local/bin/nodejs \ + && ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \ + && ln -s /usr/local/lib/node_modules/npm/bin/npx-cli.js /usr/local/bin/npx \ + && ln -s /usr/local/lib/node_modules/corepack/dist/corepack.js /usr/local/bin/corepack \ + && ln -s /opt/yarn-v$YARN_VERSION/bin/yarn /usr/local/bin/yarn \ + && corepack enable + +# See https://www.jeffgeerling.com/blog/2023/how-solve-error-externally-managed-environment-when-installing-pip3 +# for context behind removing the EXTERNALLY-MANAGED file on distribution-built CPython binary releases. +# Since we're using the official Python Docker image, we don't need to worry about that. +RUN pip install --no-cache \ + mkdocs-material \ + mkdocs-git-committers-plugin-2 \ + mkdocs-git-revision-date-localized-plugin \ + mkdocs-minify-plugin \ + mkdocs-redirects \ + mkdocs-rss-plugin \ + pillow \ + cairosvg \ + pipenv \ + pipx + +# Trust directory, required for git >= 2.35.2 +# Follows the docs for the Docker-based site build setup +RUN git config --global --add safe.directory /docs &&\ + git config --global --add safe.directory /site + +# Expose MkDocs development server port +EXPOSE 8000 + +WORKDIR /docs + +ENTRYPOINT [ "/usr/local/bin/entrypoint.sh" ] +CMD [ "mkdocs", "serve", "--dev-addr=0.0.0.0:8000" ] diff --git a/docker/mkdocs-material/README.md b/docker/mkdocs-material/README.md new file mode 100644 index 0000000..47704ce --- /dev/null +++ b/docker/mkdocs-material/README.md @@ -0,0 +1,22 @@ +# Custom `mkdocs-material` CI image + +Builds on Alpine edge, mostly used by @ajhalili2006 to deploy builds over GitLab CI. + +## Usage + +See the tags list on [GitHub][ghcr], [GitLab][maudev] or [Red Hat Quay Container Registry Cloud][quay] + +[ghcr]: https://github.com/andreijiroh-dev/docker-images/pkgs/container/docker-images%2Fmkdocs-material/versions +[quay]: https://quay.io/repository/ajhalili2006/mkdocs-material-build-ci?tab=tags +[maudev]: https://mau.dev/andreijiroh-dev/docker-images + +```yaml +# in GitLab CI config... +image: + name: dock.mau.dev/andreijiroh-dev/docker-images/mkdocs-material +``` + +```dockerfile +# ...or via your custom Docker image +FROM ghcr.io/ajhalili2006/website/build-ci:latest +``` diff --git a/docker/mkdocs-material/entrypoint.sh b/docker/mkdocs-material/entrypoint.sh new file mode 100644 index 0000000..97188ec --- /dev/null +++ b/docker/mkdocs-material/entrypoint.sh @@ -0,0 +1,12 @@ +#!/usr/bin/env bash + +if [[ $DEBUG != "" ]]; then + set -x +fi +COMMAND=$* + +if [[ $1 = "serve" ]] || [[ $1 == "build" ]] || [[ $1 == "gh-deploy" ]] || [[ $1 == "new" ]] || [[ $1 == "--help" ]] || [[ $1 == "mkdocs" ]]; then + exec "mkdocs $COMMAND" +else + exec "$COMMAND" +fi -- 2.51.2