Split the monolithic docker-build/release/test workflows into the shared _ci-common.yaml + trigger-specific files used on web/mydl: - pr.yaml -> PR checks (hadolint + build smoke test) - main.yaml -> CI + local build + git semver tag (PAT, triggers tag.yaml) - tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push) - cron.yaml -> nightly rebuild of :vX.Y.Z-latest - _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache Docker pushes to :latest on every merge are replaced by versioned, tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the tag push actually triggers tag.yaml - GITHUB_TOKEN would not.
35 lines
1.1 KiB
YAML
35 lines
1.1 KiB
YAML
name: CI Shared Jobs
|
|
|
|
on:
|
|
workflow_call:
|
|
|
|
jobs:
|
|
hadolint:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
- uses: hadolint/hadolint-action@06be81baf89a55ffd0e24b8f04a4185738dd3387 # v3.5.0
|
|
with:
|
|
dockerfile: pkg/Dockerfile
|
|
failure-threshold: warning
|
|
|
|
build-test:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
|
|
- name: Build (cached)
|
|
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
|
with:
|
|
context: .
|
|
file: pkg/Dockerfile
|
|
push: false
|
|
load: true
|
|
tags: ci-image:${{ github.sha }}
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|
|
- name: Smoke test (container starts)
|
|
run: docker run --rm --name mcp-ics-smoke-$(hostname) ci-image:${{ github.sha }} python -c "import src.server"
|