diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml new file mode 100644 index 0000000..453d0cf --- /dev/null +++ b/.github/workflows/docker-publish.yml @@ -0,0 +1,69 @@ +name: Docker Build & Push + +on: + push: + branches: [main] + tags: ["v*"] + pull_request: + branches: [main] + +env: + REGISTRY: gitea.alterminal.com + IMAGE_NAME: ${{ github.repository }} + +jobs: + build-and-push: + runs-on: ubuntu-latest + + steps: + - name: Checkout + uses: actions/checkout@v4 + + # The Gitea runner runs this job in a `node` container which has no + # Docker CLI. The docker daemon socket is mounted, so we only need the + # client (`docker login` / `docker` CLI) to authenticate and build. + - name: Install Docker CLI + run: | + apt-get update + apt-get install -y --no-install-recommends docker.io + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + with: + driver: docker + + # Gitea Actions' automatic GITEA_TOKEN/GITHUB_TOKEN cannot publish to the + # container registry. A Personal Access Token is required instead: + # - secrets.PUSH_PACKAGE_USERNAME: a user that can push to this org's packages + # - secrets.PUSH_PACKAGE_PASSWORD: that user's PAT with write:package scope + # (Same arrangement as alterminal/bear .github/workflows/docker-publish.yml.) + - name: Log in to Gitea Container Registry + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ secrets.PUSH_PACKAGE_USERNAME }} + password: ${{ secrets.PUSH_PACKAGE_PASSWORD }} + + # 本專案版本以 git tag(v0.0.1 …)為準:推送 v* tag 時產生 + # X.Y.Z / X.Y / X 版本標籤;推送 main 另帶 branch 與 sha 標籤。 + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=semver,pattern={{version}} + type=semver,pattern={{major}}.{{minor}} + type=semver,pattern={{major}} + type=ref,event=branch + type=ref,event=pr + type=sha,format=long + + - name: Build and push + uses: docker/build-push-action@v6 + with: + context: . + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }}