Split the monolithic docker-build/release/test workflows into the shared _ci-common.yaml + trigger-specific files used on web/mydl: - pr.yaml -> PR checks (hadolint + build smoke test) - main.yaml -> CI + local build + git semver tag (PAT, triggers tag.yaml) - tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push) - cron.yaml -> nightly rebuild of :vX.Y.Z-latest - _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache Docker pushes to :latest on every merge are replaced by versioned, tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the tag push actually triggers tag.yaml - GITHUB_TOKEN would not.
47 lines
1.6 KiB
YAML
47 lines
1.6 KiB
YAML
name: Nightly Rebuild
|
|
on:
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
jobs:
|
|
ci:
|
|
uses: ./.gitea/workflows/_ci-common.yaml
|
|
secrets: inherit
|
|
build-push:
|
|
needs: [ci]
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
with:
|
|
fetch-depth: 0
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
|
|
- name: Login to Docker Hub
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
- id: get-latest-tag
|
|
name: Get latest tag
|
|
run: |
|
|
TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "")
|
|
echo "tag=$TAG" >> $GITHUB_OUTPUT
|
|
- id: meta
|
|
name: Docker metadata
|
|
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6
|
|
with:
|
|
images: jcabillot/mcp-ics
|
|
tags: |
|
|
type=raw,value=${{ steps.get-latest-tag.outputs.tag }}-latest,enable=${{ steps.get-latest-tag.outputs.tag != '' }}
|
|
- name: Build and push
|
|
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
|
with:
|
|
context: .
|
|
file: pkg/Dockerfile
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
pull: true
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|