26 Commits

Author SHA1 Message Date
jcabillot d89f16cfe2 Merge pull request 'CI: standardize workflows - tests mandatory, remove :latest push on master' (#10) from fix/workflow-standard into master
Main Release / hadolint (push) Successful in 7s
Main Release / test (push) Successful in 16s
Main Release / build (push) Successful in 14s
Main Release / tag (push) Successful in 12s
Tag Release / hadolint (push) Successful in 7s
Tag Release / test (push) Successful in 17s
Tag Release / build-push (push) Failing after 1m34s
Reviewed-on: #10
2026-06-13 17:37:42 -04:00
cloudix_mcp_server 4dc2cec24d ci: standardize tag.yaml - add test mandatory step, add -latest suffix tag
PR Checks / hadolint (pull_request) Successful in 5s
PR Checks / build-test (pull_request) Successful in 32s
2026-06-13 16:27:38 -04:00
cloudix_mcp_server 629029bdf6 ci: standardize cron.yaml - add test mandatory step, remove :latest push 2026-06-13 16:27:29 -04:00
cloudix_mcp_server a7b418e7a3 ci: standardize main.yaml - tests mandatory, remove :latest push on master 2026-06-13 16:27:18 -04:00
jcabillot 399c978553 Merge pull request 'refactor(ci): migrate to split Gitea Actions workflows' (#9) from fix/refactor-ci-pipelines into master
Main Release / hadolint (push) Successful in 7s
Main Release / test (push) Successful in 15s
Main Release / tag (push) Successful in 11s
Main Release / build-push (push) Successful in 2m6s
Reviewed-on: #9
2026-06-12 20:54:52 -04:00
cloudix_mcp_server 81663ba8e8 fix: rewrite cron.yaml with proper YAML (was base64-encoded)
PR Checks / build-test (pull_request) Successful in 19s
PR Checks / hadolint (pull_request) Successful in 6s
2026-06-12 20:24:39 -04:00
cloudix_mcp_server b31856d228 fix: rewrite tag.yaml with proper YAML (was base64-encoded) 2026-06-12 20:24:32 -04:00
cloudix_mcp_server 542f86b6cd fix: rewrite main.yaml with proper YAML (was base64-encoded)
PR Checks / hadolint (pull_request) Successful in 10s
PR Checks / build-test (pull_request) Successful in 21s
2026-06-12 20:24:25 -04:00
cloudix_mcp_server b2c0103b27 fix(ci): rewrite pr.yaml with parallel pattern
PR Checks / hadolint (pull_request) Successful in 6s
PR Checks / build-test (pull_request) Successful in 31s
2026-06-12 19:38:25 -04:00
cloudix_mcp_server bbecb203c9 feat(ci): add tag release workflow 2026-06-12 17:01:33 -04:00
cloudix_mcp_server 7947430ef1 feat(ci): add nightly cron rebuild workflow 2026-06-12 17:01:26 -04:00
cloudix_mcp_server d1c4b85c64 feat(ci): add PR workflow with lint and test jobs 2026-06-12 17:01:22 -04:00
cloudix_mcp_server 1e9e827b43 feat(ci): add main workflow for push to master 2026-06-12 17:01:20 -04:00
cloudix_mcp_server ef6c7b1b3e refactor(ci): replace single docker-build workflow with split workflow files 2026-06-12 17:00:50 -04:00
jcabillot bee9a79f62 Merge pull request 'ci: add automatic semver tagging on merge to master' (#8) from feat/semver-tag-action into master
Docker Build and Push / lint (push) Successful in 8s
Docker Build and Push / build (push) Failing after 2m8s
Docker Build and Push / test (push) Has been skipped
Docker Build and Push / push (push) Has been skipped
Reviewed-on: #8
2026-06-12 13:40:07 -04:00
cloudix_mcp_server 79c2ae6814 ci: add automatic semver tagging on merge to master
Docker Build and Push / lint (pull_request) Successful in 9s
Docker Build and Push / build (pull_request) Successful in 1m38s
Docker Build and Push / test (pull_request) Successful in 41s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-12 13:21:21 -04:00
cloudix_mcp_server 24edaad520 ci: add automatic semver tagging on merge to master 2026-06-12 13:20:44 -04:00
jcabillot 5083ea89e8 Merge pull request 'fix(renovate): unquote FROM to enable docker image lookup' (#5) from chore/renovate into master
Docker Build and Push / lint (push) Successful in 12s
Docker Build and Push / build (push) Successful in 1m11s
Docker Build and Push / test (push) Successful in 22s
Docker Build and Push / push (push) Successful in 24s
Reviewed-on: #5
2026-06-09 08:37:00 -04:00
Sagent fb2bfb019a fix(renovate): remove quotes from FROM to enable docker image detection
Docker Build and Push / lint (pull_request) Successful in 6s
Docker Build and Push / build (pull_request) Successful in 1m31s
Docker Build and Push / test (pull_request) Successful in 34s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-09 02:15:26 +00:00
jcabillot a6638c5ef1 Merge pull request 'Update hadolint/hadolint-action action to v3.3.0' (#4) from renovate/hadolint-hadolint-action-3.x into master
Docker Build and Push / lint (push) Successful in 8s
Docker Build and Push / build (push) Successful in 1m21s
Docker Build and Push / test (push) Successful in 20s
Docker Build and Push / push (push) Successful in 33s
Reviewed-on: #4
2026-06-08 17:28:48 -04:00
renovate f3897ba4b0 Update hadolint/hadolint-action action to v3.3.0
Docker Build and Push / lint (pull_request) Successful in 6s
Docker Build and Push / build (pull_request) Successful in 1m11s
Docker Build and Push / test (pull_request) Successful in 21s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-08 20:51:57 +00:00
jcabillot 0386665e2a Merge pull request 'feat: add lint, build, test, push pipeline with SHA-pinned actions' (#3) from feat/gitea-actions-v2 into master
Docker Build and Push / lint (push) Successful in 10s
Docker Build and Push / build (push) Successful in 1m20s
Docker Build and Push / test (push) Successful in 25s
Docker Build and Push / push (push) Successful in 23s
Reviewed-on: #3
2026-06-08 16:47:23 -04:00
Sagent 4d33657ea1 fix: replace echo with printf to avoid SC2028
Docker Build and Push / lint (pull_request) Successful in 5s
Docker Build and Push / build (pull_request) Successful in 1m23s
Docker Build and Push / test (pull_request) Successful in 22s
Docker Build and Push / push (pull_request) Has been skipped
2026-06-08 20:40:51 +00:00
Sagent d9b462b6e8 fix: unquote EXPOSE to satisfy hadolint parser
Docker Build and Push / lint (pull_request) Failing after 8s
Docker Build and Push / build (pull_request) Successful in 1m22s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
2026-06-08 19:53:15 +00:00
Sagent a1d6f90967 feat: add lint, build, test, push pipeline with SHA-pinned actions
Docker Build and Push / lint (pull_request) Failing after 9s
Docker Build and Push / build (pull_request) Successful in 2m7s
Docker Build and Push / test (pull_request) Has been skipped
Docker Build and Push / push (pull_request) Has been skipped
- Split single build job into 4 jobs: lint, build, test, push
- SHA-pin all actions for supply chain security
- Use ChristopherHX artifact actions (Gitea-compatible)
- Add tests/test.sh with Docker bridge gateway networking
- Add hadolint ignore for apt/brace patterns
2026-06-08 19:41:56 +00:00
jcabillot c065123d90 feat: add Gitea Actions workflow
Docker Build and Push / build (push) Successful in 1m1s
feat: add Gitea Actions workflow
2026-05-29 16:23:11 -04:00
7 changed files with 261 additions and 52 deletions
+53
View File
@@ -0,0 +1,53 @@
name: Nightly Rebuild
on:
schedule:
- cron: '0 0 * * *'
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build-push:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
fetch-depth: 0
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- id: get-latest-tag
run: |
TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "")
echo "tag=$TAG" >> $GITHUB_OUTPUT
- id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6
with:
images: jcabillot/php-apache
tags: |
type=raw,value=${{ steps.get-latest-tag.outputs.tag }}-latest,enable=${{ steps.get-latest-tag.outputs.tag != '' }}
- uses: docker/build-push-action@f9f3042f7e2789586610d7f5c8f03e5195baf # v7.2.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
-46
View File
@@ -1,46 +0,0 @@
name: Docker Build and Push
on:
pull_request:
branches: [master]
push:
branches: [master]
schedule:
- cron: '0 0 * * *'
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Login to Docker Hub
if: github.event_name != 'pull_request'
uses: docker/login-action@v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Docker metadata
id: meta
uses: docker/metadata-action@v6
with:
images: jcabillot/phpapache
tags: |
#type=ref,event=branch
#type=ref,event=pr
#type=sha
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/master' }}
- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
+49
View File
@@ -0,0 +1,49 @@
name: Main Release
on:
push:
branches: [master]
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t jcabillot/php-apache:${{ github.sha }} .
tag:
needs: [build]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
fetch-depth: 0
- name: Configure git auth
run: |
git remote set-url origin "https://x-access-token:${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}@scm.cabillot.eu/web/phpapache.git"
- uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0
env:
GITHUB_TOKEN: ${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}
DEFAULT_BUMP: patch
RELEASE_BRANCHES: master
WITH_V: true
GIT_API_TAGGING: false
+23
View File
@@ -0,0 +1,23 @@
name: PR Checks
on:
pull_request:
branches: [master]
jobs:
hadolint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
continue-on-error: true
with:
dockerfile: Dockerfile
build-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
+48
View File
@@ -0,0 +1,48 @@
name: Tag Release
on:
push:
tags: ['*']
jobs:
hadolint:
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0
with:
dockerfile: Dockerfile
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- run: docker build -t ci-image:${{ github.sha }} .
- run: bash tests/test.sh ci-image:${{ github.sha }}
build-push:
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6
with:
images: jcabillot/php-apache
tags: |
type=ref,event=tag
type=ref,event=tag,suffix=-latest
- uses: docker/build-push-action@f9f3042f7e2789586610d7f5c8f03e5195baf # v7.2.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
pull: true
+6 -6
View File
@@ -1,11 +1,12 @@
FROM "php:8.3-apache"
FROM php:8.3-apache
LABEL maintainer="Julien Cabillot <dockerimages@cabillot.eu>"
# hadolint ignore=DL3008,DL3015,SC3009
RUN export DEBIAN_FRONTEND="noninteractive" && \
sed -i'' 's/ServerSignature On/ServerSignature Off/; s/ServerTokens OS/ServerTokens Prod/' "/etc/apache2/conf-enabled/security.conf" && \
sed -i'' 's/^Listen 80$/Listen 8080/' "/etc/apache2/ports.conf" && \
sed -i'' 's/^<VirtualHost \*:80>$/<VirtualHost *:8080>/' '/etc/apache2/sites-enabled/000-default.conf' && \
echo "RemoteIPHeader X-Forwarded-For\nRemoteIPProxiesHeader X-Forwarded-By\nRemoteIPInternalProxy 10.0.0.0/8\nRemoteIPInternalProxy 192.168.0.0/16\nRemoteIPInternalProxy 172.16.0.0/12" > "${APACHE_CONFDIR}/conf-available/remoteip.conf" && \
printf 'RemoteIPHeader X-Forwarded-For\nRemoteIPProxiesHeader X-Forwarded-By\nRemoteIPInternalProxy 10.0.0.0/8\nRemoteIPInternalProxy 192.168.0.0/16\nRemoteIPInternalProxy 172.16.0.0/12\n' > "${APACHE_CONFDIR}/conf-available/remoteip.conf" && \
sed -i'' 's/\(LogFormat "%h.*combined\)/LogFormat "%a %l %u %t \\"%r\\" %>s %O \\"%{Referer}i\\" \\"%{User-Agent}i\\"" combined/' "${APACHE_CONFDIR}/apache2.conf" && \
echo 'AddType video/mp4 .mp4' >> /etc/apache2/sites-enabled/000-default.conf && \
a2enconf remoteip && \
@@ -29,7 +30,7 @@ RUN export DEBIAN_FRONTEND="noninteractive" && \
s#^(\s*CustomLog)\s+\S+#\1 /proc/self/fd/1#g; \
s#^(\s*ErrorLog)\s+\S+#\1 /proc/self/fd/2#g; \
' "/etc/apache2/sites-enabled/000-default.conf" && \
echo "error_reporting=E_ALL\nerror_log=/proc/self/fd/2\nlog_errors=On\nexpose_php=Off" > "/usr/local/etc/php/conf.d/override.ini" && \
printf 'error_reporting=E_ALL\nerror_log=/proc/self/fd/2\nlog_errors=On\nexpose_php=Off\n' > "/usr/local/etc/php/conf.d/override.ini" && \
docker-php-ext-configure pcntl --enable-pcntl && \
docker-php-ext-install pcntl
@@ -39,8 +40,7 @@ CMD [ "docker-php-entrypoint", "apache2-foreground" ]
# C'est dommage mais il n'est pas possible de faire unexpose :
# https://github.com/moby/moby/issues/3465
EXPOSE "8080/tcp"
EXPOSE 8080/tcp
# TODO: à remettre une fois le bug corrigé
#HEALTHCHECK --interval="5s" \
# CMD curl --fail "http://localhost:8080" || exit 1
#HEALTHCHECK --interval=5s -- CMD curl --fail http://localhost:8080 || exit 1
+82
View File
@@ -0,0 +1,82 @@
#!/usr/bin/env bash
set -euo pipefail
IMAGE="${1:?Usage: test.sh <image>}"
CONTAINER_NAME="test-$(echo "$IMAGE" | tr ':/' '-')-$$"
PASSED=0
FAILED=0
TOTAL=0
cleanup() {
docker rm -f "$CONTAINER_NAME" >/dev/null 2>&1 || true
}
trap cleanup EXIT
assert() {
local name="$1" expected="$2" actual="$3"
TOTAL=$((TOTAL + 1))
if [ "$expected" = "$actual" ]; then
echo " PASS: $name"
PASSED=$((PASSED + 1))
else
echo " FAIL: $name (expected: '$expected', got: '$actual')"
FAILED=$((FAILED + 1))
fi
}
assert_in() {
local name="$1" expected="$2" actual="$3"
TOTAL=$((TOTAL + 1))
if [ "$actual" -ge "$expected" ] && [ "$actual" -lt 500 ]; then
echo " PASS: $name (got: $actual)"
PASSED=$((PASSED + 1))
else
echo " FAIL: $name (expected < 500, got: $actual)"
FAILED=$((FAILED + 1))
fi
}
assert_match() {
local name="$1" pattern="$2" actual="$3"
TOTAL=$((TOTAL + 1))
if echo "$actual" | grep -qE "$pattern"; then
echo " PASS: $name"
PASSED=$((PASSED + 1))
else
echo " FAIL: $name (pattern: '$pattern', got: '$actual')"
FAILED=$((FAILED + 1))
fi
}
echo "Running container: $IMAGE"
docker run -d --name "$CONTAINER_NAME" -p 8080:8080 "$IMAGE" >/dev/null
DOCKER_GW=$(docker network inspect bridge --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')
BASE_URL="http://${DOCKER_GW}:8080"
echo "Waiting for container on ${DOCKER_GW}:8080..."
for i in $(seq 1 30); do
if curl -sf -o /dev/null "$BASE_URL/" 2>/dev/null || [ "$(curl -s -o /dev/null -w '%{http_code}' "$BASE_URL/" 2>/dev/null)" != "000" ]; then
echo "Container ready after ${i}s"
break
fi
if [ "$i" -eq 30 ]; then
echo "FAIL: Container did not become ready within 30s"
docker logs "$CONTAINER_NAME"
exit 1
fi
sleep 1
done
echo ""
echo "Test: GET / (Apache responds on port 8080)"
RESPONSE=$(curl -s -D - "$BASE_URL/")
STATUS=$(echo "$RESPONSE" | head -1 | grep -oP '\d{3}')
SERVER=$(echo "$RESPONSE" | grep -i '^server:' | tr -d '\r' | cut -d: -f2- | xargs)
assert_in "HTTP status is valid" 200 "$STATUS"
assert_match "Server is Apache" "[Aa]pache" "$SERVER"
echo ""
echo "Results: $PASSED/$TOTAL passed, $FAILED failed"
[ "$FAILED" -eq 0 ]