ci: align pipeline on web/mydl pattern
CI Shared Jobs / hadolint (pull_request) Successful in 3m43s
CI Shared Jobs / build-test (pull_request) Failing after 4m10s
PR Checks / ci (pull_request) Failing after 4m20s

Split the monolithic docker-build/release/test workflows into the shared
_ci-common.yaml + trigger-specific files used on web/mydl:

- pr.yaml       -> PR checks (hadolint + build smoke test)
- main.yaml     -> CI + local build + git semver tag (PAT, triggers tag.yaml)
- tag.yaml      -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push)
- cron.yaml     -> nightly rebuild of :vX.Y.Z-latest
- _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache

Docker pushes to :latest on every merge are replaced by versioned,
tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the
tag push actually triggers tag.yaml - GITHUB_TOKEN would not.
This commit is contained in:
OpenCode Cabillot committed 2026-10-08 20:29:23 +00:00
1 parent e2a8cd7e90
commit b71e470511
7 files changed
+151 -63

No files matched your search

+46
View File
@@ -0,0 +1,46 @@
name: Nightly Rebuild
on:
schedule:
- cron: '0 0 * * *'
jobs:
ci:
uses: ./.gitea/workflows/_ci-common.yaml
secrets: inherit
build-push:
needs: [ci]
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
- name: Login to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- id: get-latest-tag
name: Get latest tag
run: |
TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "")
echo "tag=$TAG" >> $GITHUB_OUTPUT
- id: meta
name: Docker metadata
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6
with:
images: jcabillot/mcp-ics
tags: |
type=raw,value=${{ steps.get-latest-tag.outputs.tag }}-latest,enable=${{ steps.get-latest-tag.outputs.tag != '' }}
- name: Build and push
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: pkg/Dockerfile
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
cache-from: type=gha
cache-to: type=gha,mode=max