ci: align pipeline on web/mydl pattern
CI Shared Jobs / hadolint (pull_request) Successful in 3m43s
CI Shared Jobs / build-test (pull_request) Failing after 4m10s
PR Checks / ci (pull_request) Failing after 4m20s

Split the monolithic docker-build/release/test workflows into the shared
_ci-common.yaml + trigger-specific files used on web/mydl:

- pr.yaml       -> PR checks (hadolint + build smoke test)
- main.yaml     -> CI + local build + git semver tag (PAT, triggers tag.yaml)
- tag.yaml      -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push)
- cron.yaml     -> nightly rebuild of :vX.Y.Z-latest
- _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache

Docker pushes to :latest on every merge are replaced by versioned,
tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the
tag push actually triggers tag.yaml - GITHUB_TOKEN would not.
This commit is contained in:
OpenCode Cabillot committed 2026-10-08 20:29:23 +00:00
1 parent e2a8cd7e90
commit b71e470511
7 files changed
+151 -63

No files matched your search

+46
View File
@@ -0,0 +1,46 @@
name: Main Release
on:
workflow_dispatch:
push:
branches: [main]
jobs:
ci:
uses: ./.gitea/workflows/_ci-common.yaml
secrets: inherit
build:
needs: [ci]
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
- name: Build (cached)
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: pkg/Dockerfile
push: false
load: true
tags: jcabillot/mcp-ics:${{ github.sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
tag:
needs: [build]
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Configure git auth
run: |
git remote set-url origin "https://x-access-token:${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}@scm.cabillot.eu/perso/mcp-ics.git"
- name: Bump version and push tag
uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0
env:
GITHUB_TOKEN: ${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}
DEFAULT_BUMP: patch
RELEASE_BRANCHES: main
WITH_V: true
GIT_API_TAGGING: false