0ec101aebd
- Split single build job into 4 jobs: lint, build, test, push - SHA-pin all actions for supply chain security - Use ChristopherHX artifact actions (Gitea-compatible) - Add tests/test.sh with Docker bridge gateway networking - Test GET /install.php returns DokuWiki setup wizard
83 lines
2.3 KiB
YAML
83 lines
2.3 KiB
YAML
name: Docker Build and Push
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [master]
|
|
push:
|
|
branches: [master]
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
|
|
jobs:
|
|
lint:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
|
|
|
|
- name: Hadolint
|
|
uses: hadolint/hadolint-action@54c9adbab1582c2ef04b2016b760714a4bfde3cf # v3.1.0
|
|
with:
|
|
dockerfile: Dockerfile
|
|
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
|
|
|
|
- name: Build image
|
|
run: docker build -t ci-image:${{ github.sha }} .
|
|
|
|
- name: Save image
|
|
run: docker save -o image.tar ci-image:${{ github.sha }}
|
|
|
|
- name: Upload artifact
|
|
uses: https://github.com/ChristopherHX/gitea-upload-artifact@62ac910c5d3dfa85c7cb2df15afe2e342b2407c2 # main
|
|
with:
|
|
name: docker-image
|
|
path: image.tar
|
|
retention-days: 1
|
|
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
needs: [lint, build]
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
|
|
|
|
- name: Download artifact
|
|
uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 # main
|
|
with:
|
|
name: docker-image
|
|
|
|
- name: Load image
|
|
run: docker load < image.tar
|
|
|
|
- name: Run tests
|
|
run: bash tests/test.sh ci-image:${{ github.sha }}
|
|
|
|
push:
|
|
runs-on: ubuntu-latest
|
|
needs: test
|
|
if: github.event_name != 'pull_request'
|
|
steps:
|
|
- name: Download artifact
|
|
uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 # main
|
|
with:
|
|
name: docker-image
|
|
|
|
- name: Load image
|
|
run: docker load < image.tar
|
|
|
|
- name: Login to Docker Hub
|
|
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
|
|
- name: Tag and push
|
|
run: |
|
|
docker tag ci-image:${{ github.sha }} jcabillot/dokuwiki:latest
|
|
docker push jcabillot/dokuwiki:latest
|