diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..e15ef6f --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,120 @@ +on: + push: + branches: + - main + +env: + REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository }} + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + sourcemaps: + runs-on: ubuntu-latest + + steps: + - { uses: actions/checkout@v6.0.0 } + - { uses: denoland/setup-deno@v2.0.3, with: { cache: true } } + - { run: deno i } + - { + run: deno task build, + env: { SENTRY_TOKEN: "${{ secrets.SENTRY_TOKEN }}" }, + } + # ============================================================================= + + build: + strategy: + matrix: + platform: + - linux/amd64 + # - linux/arm64 + runs-on: ubuntu-24.04${{ matrix.platform == 'linux/arm64' && '-arm' || '' }} + + permissions: + contents: read + packages: write + + steps: + - uses: actions/checkout@v6.0.0 + - uses: docker/login-action@v3.6.0 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - run: | + PLATFORM=${{ matrix.platform }} + echo "PLATFORM_PAIR=${PLATFORM//\//-}" >> $GITHUB_ENV + + - uses: docker/metadata-action@v5.9.0 + with: { images: "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}" } + id: meta + + - run: docker context create builders + id: buildx-context + + - uses: docker/setup-buildx-action@v3.11.1 + with: { endpoint: builders, platforms: "${{ matrix.platform }}" } + + - uses: docker/build-push-action@v6.18.0 + with: + context: . + labels: ${{ steps.meta.outputs.labels }} + annotations: ${{ steps.meta.outputs.annotations }} + outputs: type=image,name=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }},push-by-digest=true,name-canonical=true,push=true,oci-mediatypes=true + cache-from: type=gha,scope=${{ github.repository }}-${{ github.ref_name }}-${{ matrix.platform }} + cache-to: type=gha,scope=${{ github.repository }}-${{ github.ref_name }}-${{ matrix.platform }} + id: build + + - name: Export digest + run: | + mkdir -p /tmp/digests + digest="${{ steps.build.outputs.digest }}" + touch "/tmp/digests/${digest#sha256:}" + + - name: Upload digest + uses: actions/upload-artifact@v5.0.0 + with: + name: digests-${{ env.PLATFORM_PAIR }} + if-no-files-found: error + path: /tmp/digests/* + retention-days: 1 + # ============================================================================= + + publish: + runs-on: ubuntu-latest + needs: build + + permissions: + contents: read + packages: write + + steps: + - uses: actions/download-artifact@v5.0.0 + with: { path: /tmp/digests, pattern: digests-*, merge-multiple: true } + - uses: docker/setup-buildx-action@v3.11.1 + + - uses: docker/login-action@v3.6.0 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - uses: docker/metadata-action@v5.9.0 + id: meta + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=raw,value=latest + type=sha + + - name: Create manifest list and push + working-directory: /tmp/digests + run: | + docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ + $(printf '${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@sha256:%s ' *) + +# =============================================================================