Split the monolithic docker-build/release/test workflows into the shared _ci-common.yaml + trigger-specific files used on web/mydl: - pr.yaml -> PR checks (hadolint + build smoke test) - main.yaml -> CI + local build + git semver tag (PAT, triggers tag.yaml) - tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push) - cron.yaml -> nightly rebuild of :vX.Y.Z-latest - _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache Docker pushes to :latest on every merge are replaced by versioned, tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the tag push actually triggers tag.yaml - GITHUB_TOKEN would not.
47 lines
1.5 KiB
YAML
47 lines
1.5 KiB
YAML
name: Main Release
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches: [main]
|
|
jobs:
|
|
ci:
|
|
uses: ./.gitea/workflows/_ci-common.yaml
|
|
secrets: inherit
|
|
build:
|
|
needs: [ci]
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
|
|
- name: Build (cached)
|
|
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
|
with:
|
|
context: .
|
|
file: pkg/Dockerfile
|
|
push: false
|
|
load: true
|
|
tags: jcabillot/mcp-ics:${{ github.sha }}
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|
|
tag:
|
|
needs: [build]
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
with:
|
|
fetch-depth: 0
|
|
- name: Configure git auth
|
|
run: |
|
|
git remote set-url origin "https://x-access-token:${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}@scm.cabillot.eu/perso/mcp-ics.git"
|
|
- name: Bump version and push tag
|
|
uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}
|
|
DEFAULT_BUMP: patch
|
|
RELEASE_BRANCHES: main
|
|
WITH_V: true
|
|
GIT_API_TAGGING: false
|