31 Commits

Author SHA1 Message Date
jcabillot 84781175fa Merge pull request 'chore(deps): update actions/checkout action to v7' (#11) from renovate/actions-checkout-7.x into master
Main Release / hadolint (push) Successful in 7s
Main Release / test (push) Successful in 15s
Main Release / build (push) Successful in 18s
Main Release / tag (push) Successful in 13s
Tag Release / hadolint (push) Successful in 10s
Tag Release / test (push) Successful in 20s
Tag Release / build-push (push) Successful in 2m12s
Reviewed-on: #11
2026-06-18 16:23:52 -04:00
renovate 31f736933b chore(deps): update actions/checkout action to v7
PR Checks / hadolint (pull_request) Successful in 7s
PR Checks / build-test (pull_request) Successful in 13s
2026-06-18 15:18:22 +00:00
jcabillot 613924e099 Merge pull request 'chore: convert to standard htpasswd 4-workflow pattern' (#10) from fix/workflow-standard into master
Main Release / hadolint (push) Successful in 9s
Main Release / test (push) Successful in 1m9s
Main Release / build (push) Successful in 1m6s
Main Release / tag (push) Successful in 12s
Tag Release / hadolint (push) Successful in 6s
Tag Release / test (push) Successful in 15s
Tag Release / build-push (push) Successful in 1m27s
Reviewed-on: #10
2026-06-13 19:48:32 -04:00
cloudix_mcp_server 69623f8353 fix: correct all SHAs in tag.yaml
PR Checks / build-test (pull_request) Successful in 1m11s
PR Checks / hadolint (pull_request) Successful in 8s
2026-06-13 19:20:29 -04:00
cloudix_mcp_server 30f7ec5280 fix: correct SHAs in pr.yaml 2026-06-13 19:20:27 -04:00
cloudix_mcp_server 68da2ceec7 fix: correct SHAs in main.yaml
PR Checks / hadolint (pull_request) Failing after 3s
PR Checks / build-test (pull_request) Failing after 2s
2026-06-13 19:20:24 -04:00
cloudix_mcp_server 6a29224322 fix: correct all SHAs in cron.yaml
PR Checks / hadolint (pull_request) Failing after 2s
PR Checks / build-test (pull_request) Failing after 26s
2026-06-13 19:20:16 -04:00
cloudix_mcp_server 4ceb61ea3f chore: convert tag to htpasswd 4-workflow pattern
PR Checks / hadolint (pull_request) Failing after 4s
PR Checks / build-test (pull_request) Failing after 22s
Standardise tag workflow: hadolint → test → build-push.
Image from original metadata (jcabillot/dl). Tags: ref/event=tag, tag-latest.
2026-06-13 17:47:27 -04:00
cloudix_mcp_server 6a8aec8bde chore: convert pr to htpasswd 4-workflow pattern
Standardise PR workflow: hadolint → build-test.
2026-06-13 17:47:21 -04:00
cloudix_mcp_server 895d3f8aa9 chore: convert main to htpasswd 4-workflow pattern
Standardise main workflow: hadolint → test → build → tag.
Image from original metadata (jcabillot/dl). Git URL: scm.cabillot.eu/web/dl.git.
2026-06-13 17:47:08 -04:00
cloudix_mcp_server 630b85ad8b chore: convert cron to htpasswd 4-workflow pattern
Standardise cron workflow: hadolint → test → build-push.
Keep original nightly schedule (0 0 * * *) and nightly+sha tag metadata.
2026-06-13 17:46:53 -04:00
jcabillot 665dee3563 Merge pull request 'feat(ci): refactor pipelines — hadolint, PR checks, tag releases, nightly rebuild' (#9) from fix/refactor-ci-pipelines into master
Tag Release / tag (push) Failing after 9s
Main / build-and-push (push) Successful in 1m40s
Reviewed-on: #9
2026-06-12 16:45:19 -04:00
cloudix_mcp_server dd4795327a fix(ci): correct labels variable syntax in cron.yaml
PR Checks / lint (pull_request) Successful in 6s
PR Checks / test (pull_request) Successful in 1m8s
2026-06-12 16:40:54 -04:00
cloudix_mcp_server 96db4c613f chore(ci): remove old combined workflow in favor of split pipelines 2026-06-12 16:40:40 -04:00
cloudix_mcp_server 85725d47c5 feat(ci): add nightly rebuild workflow 2026-06-12 16:40:25 -04:00
cloudix_mcp_server d49634163f feat(ci): add tag release workflow 2026-06-12 16:40:21 -04:00
cloudix_mcp_server 0d7f7c5560 feat(ci): add main pipeline — build & push on push to master 2026-06-12 16:40:18 -04:00
cloudix_mcp_server d71e9eb20b feat(ci): add PR checks workflow — hadolint lint + build + test 2026-06-12 16:40:13 -04:00
jcabillot 890a05cc0d Merge pull request 'ci: add automatic semver tagging on merge to master' (#8) from feat/semver-tag-action into master
Docker Build and Push / lint (push) Successful in 6s
Docker Build and Push / build (push) Successful in 2m36s
Docker Build and Push / test (push) Successful in 24s
Docker Build and Push / push (push) Failing after 57s
Reviewed-on: #8
2026-06-12 13:39:51 -04:00
cloudix_mcp_server 7998e5fbdf ci: add automatic semver tagging on merge to master
Docker Build and Push / lint (pull_request) Successful in 8s
Docker Build and Push / build (pull_request) Successful in 2m51s
Docker Build and Push / test (pull_request) Successful in 27s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-12 13:22:09 -04:00
jcabillot 0be4e572b6 Merge pull request 'Migrate Renovate config' (#7) from renovate/migrate-config into master
Docker Build and Push / lint (push) Successful in 8s
Docker Build and Push / build (push) Successful in 1m2s
Docker Build and Push / test (push) Successful in 29s
Docker Build and Push / push (push) Successful in 31s
Reviewed-on: #7
2026-06-09 14:13:14 -04:00
renovate bbe80cef3f Migrate config renovate.json
Docker Build and Push / lint (pull_request) Successful in 7s
Docker Build and Push / build (pull_request) Failing after 10m31s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
2026-06-09 18:03:07 +00:00
jcabillot 6ab4850645 Merge pull request 'chore: improve renovate dependency detection' (#5) from chore/renovate into master
Docker Build and Push / lint (push) Successful in 8s
Docker Build and Push / build (push) Successful in 1m27s
Docker Build and Push / test (push) Successful in 23s
Docker Build and Push / push (push) Successful in 41s
Reviewed-on: #5
2026-06-09 13:47:53 -04:00
Sagent 539a1f4f05 chore: remove redundant configs now handled globally
Docker Build and Push / lint (pull_request) Successful in 6s
Docker Build and Push / build (pull_request) Failing after 2m54s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
2026-06-09 13:40:13 +00:00
Sagent 2610922b3d chore: improve renovate dependency detection
Docker Build and Push / lint (pull_request) Successful in 8s
Docker Build and Push / build (pull_request) Failing after 6m10s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
- Disable gitlabci manager (legacy CI, migrated to Gitea Actions)
- Add custom regexManager to detect jcabillot/phpapache base image version from ARG VERSION
2026-06-09 02:20:05 +00:00
jcabillot 13f92438ff Merge pull request 'Update hadolint/hadolint-action action to v3.3.0' (#4) from renovate/hadolint-hadolint-action-3.x into master
Docker Build and Push / lint (push) Successful in 9s
Docker Build and Push / build (push) Successful in 1m57s
Docker Build and Push / test (push) Successful in 29s
Docker Build and Push / push (push) Successful in 27s
Reviewed-on: #4
2026-06-08 16:27:01 -04:00
renovate 0927f1abf1 Update hadolint/hadolint-action action to v3.3.0
Docker Build and Push / lint (pull_request) Successful in 13s
Docker Build and Push / build (pull_request) Successful in 2m7s
Docker Build and Push / test (pull_request) Successful in 24s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-08 19:50:56 +00:00
jcabillot a7b66a83f2 Merge pull request 'feat: add lint, build, test, push pipeline with SHA-pinned actions' (#3) from feat/gitea-actions-v2 into master
Docker Build and Push / lint (push) Successful in 1m34s
Docker Build and Push / build (push) Successful in 3m16s
Docker Build and Push / test (push) Successful in 29s
Docker Build and Push / push (push) Successful in 1m3s
Reviewed-on: #3
2026-06-08 15:37:42 -04:00
Sagent 106da2aef4 fix: add hadolint ignore for apt pinning and brace expansion
Docker Build and Push / lint (pull_request) Successful in 7s
Docker Build and Push / build (pull_request) Successful in 1m27s
Docker Build and Push / test (pull_request) Successful in 34s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-08 19:17:30 +00:00
Sagent ff0286e02d feat: add lint, build, test, push pipeline with SHA-pinned actions
Docker Build and Push / lint (pull_request) Failing after 7s
Docker Build and Push / build (pull_request) Successful in 2m10s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
- Split single build job into 4 jobs: lint, build, test, push
- SHA-pin all actions for supply chain security
- Use ChristopherHX artifact actions (Gitea-compatible)
- Add tests/test.sh with Docker bridge gateway networking
- Test GET / returns jQuery File Upload HTML
2026-06-08 19:11:35 +00:00
jcabillot f88fb6ebab feat: add Gitea Actions workflow
Docker Build and Push / build (push) Successful in 1m36s
feat: add Gitea Actions workflow
2026-05-29 16:23:23 -04:00
8 changed files with 259 additions and 46 deletions
+50
View File
@@ -0,0 +1,50 @@
name: Nightly Rebuild
on:
schedule:
- cron: '0 0 * * *'
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build-push:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
fetch-depth: 0
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6
with:
images: jcabillot/dl
tags: |
type=raw,value=nightly
type=sha
- uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
-46
View File
@@ -1,46 +0,0 @@
name: Docker Build and Push
on:
pull_request:
branches: [master]
push:
branches: [master]
schedule:
- cron: '0 0 * * *'
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Login to Docker Hub
if: github.event_name != 'pull_request'
uses: docker/login-action@v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Docker metadata
id: meta
uses: docker/metadata-action@v6
with:
images: jcabillot/dl
tags: |
#type=ref,event=branch
#type=ref,event=pr
#type=sha
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/master' }}
- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
+49
View File
@@ -0,0 +1,49 @@
name: Main Release
on:
push:
branches: [master]
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t jcabillot/dl:${{ github.sha }} .
tag:
needs: [build]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
fetch-depth: 0
- name: Configure git auth
run: |
git remote set-url origin "https://x-access-token:${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}@scm.cabillot.eu/web/dl.git"
- uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0
env:
GITHUB_TOKEN: ${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}
DEFAULT_BUMP: patch
RELEASE_BRANCHES: master
WITH_V: true
GIT_API_TAGGING: false
+22
View File
@@ -0,0 +1,22 @@
name: PR Checks
on:
pull_request:
branches: [master]
jobs:
hadolint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
build-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
+48
View File
@@ -0,0 +1,48 @@
name: Tag Release
on:
push:
tags: ['*']
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build-push:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6
with:
images: jcabillot/dl
tags: |
type=ref,event=tag
type=ref,event=tag,suffix=-latest
- uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
+1
View File
@@ -5,6 +5,7 @@ LABEL maintainer="Julien Cabillot <dockerimages@cabillot.eu>"
# Nécessaire pour le git clone plus loin
WORKDIR "/var/www"
# hadolint ignore=DL3008,DL3015,SC3009
RUN export DEBIAN_FRONTEND="noninteractive" && \
export BUILD_PACKAGES="libpng-dev git" && \
apt-get -qq update && \
+17
View File
@@ -0,0 +1,17 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"customManagers": [
{
"customType": "regex",
"description": "Detect ARG VERSION pin for jcabillot/phpapache base image",
"managerFilePatterns": [
"/^Dockerfile$/"
],
"matchStrings": [
"ARG\\s+VERSION=\"(?<currentValue>[^\"]+)\""
],
"depNameTemplate": "jcabillot/phpapache",
"datasourceTemplate": "docker"
}
]
}
+72
View File
@@ -0,0 +1,72 @@
#!/usr/bin/env bash
set -euo pipefail
IMAGE="${1:?Usage: test.sh <image>}"
CONTAINER_NAME="test-$(echo "$IMAGE" | tr ':/' '-')-$$"
PASSED=0
FAILED=0
TOTAL=0
cleanup() {
docker rm -f "$CONTAINER_NAME" >/dev/null 2>&1 || true
}
trap cleanup EXIT
assert() {
local name="$1" expected="$2" actual="$3"
TOTAL=$((TOTAL + 1))
if [ "$expected" = "$actual" ]; then
echo " PASS: $name"
PASSED=$((PASSED + 1))
else
echo " FAIL: $name (expected: '$expected', got: '$actual')"
FAILED=$((FAILED + 1))
fi
}
assert_match() {
local name="$1" pattern="$2" actual="$3"
TOTAL=$((TOTAL + 1))
if echo "$actual" | grep -qE "$pattern"; then
echo " PASS: $name"
PASSED=$((PASSED + 1))
else
echo " FAIL: $name (pattern: '$pattern', got: '$actual')"
FAILED=$((FAILED + 1))
fi
}
echo "Running container: $IMAGE"
docker run -d --name "$CONTAINER_NAME" -p 8080:8080 "$IMAGE" >/dev/null
DOCKER_GW=$(docker network inspect bridge --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')
BASE_URL="http://${DOCKER_GW}:8080"
echo "Waiting for container on ${DOCKER_GW}:8080..."
for i in $(seq 1 30); do
if curl -sf "$BASE_URL/" >/dev/null 2>&1; then
echo "Container ready after ${i}s"
break
fi
if [ "$i" -eq 30 ]; then
echo "FAIL: Container did not become ready within 30s"
docker logs "$CONTAINER_NAME"
exit 1
fi
sleep 1
done
echo ""
echo "Test: GET /"
RESPONSE=$(curl -sf -D - "$BASE_URL/")
STATUS=$(echo "$RESPONSE" | head -1 | grep -oP '\d{3}')
CONTENT_TYPE=$(echo "$RESPONSE" | grep -i 'content-type' | tr -d '\r' | cut -d: -f2- | xargs)
BODY=$(echo "$RESPONSE" | sed -n '/^\r$/,$p' | tail -n +2)
assert "HTTP status is 200" "200" "$STATUS"
assert_match "Content-Type is text/html" "text/html" "$CONTENT_TYPE"
assert_match "Body contains file upload UI" "[Ff]ile.?[Uu]pload" "$BODY"
echo ""
echo "Results: $PASSED/$TOTAL passed, $FAILED failed"
[ "$FAILED" -eq 0 ]