name: Docker Build & Push on: push: branches: [main] tags: ["v*"] pull_request: branches: [main] env: REGISTRY: gitea.alterminal.com IMAGE_NAME: ${{ github.repository }} jobs: build-and-push: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 # The Gitea runner runs this job in a `node` container which has no # Docker CLI. The docker daemon socket is mounted, so we only need the # client (`docker login` / `docker` CLI) to authenticate and build. - name: Install Docker CLI run: | apt-get update apt-get install -y --no-install-recommends docker.io - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: driver: docker # Gitea Actions' automatic GITEA_TOKEN/GITHUB_TOKEN cannot publish to the # container registry. A Personal Access Token is required instead: # - secrets.PUSH_PACKAGE_USERNAME: a user that can push to this org's packages # - secrets.PUSH_PACKAGE_PASSWORD: that user's PAT with write:package scope # (Same arrangement as alterminal/bear .github/workflows/docker-publish.yml.) - name: Log in to Gitea Container Registry if: github.event_name != 'pull_request' uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ secrets.PUSH_PACKAGE_USERNAME }} password: ${{ secrets.PUSH_PACKAGE_PASSWORD }} # 本專案版本以 git tag(v0.0.1 …)為準:推送 v* tag 時產生 # X.Y.Z / X.Y / X 版本標籤;推送 main 另帶 branch 與 sha 標籤。 - name: Extract Docker metadata id: meta uses: docker/metadata-action@v5 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | type=semver,pattern={{version}} type=semver,pattern={{major}}.{{minor}} type=semver,pattern={{major}} type=ref,event=branch type=ref,event=pr type=sha,format=long - name: Build and push uses: docker/build-push-action@v6 with: context: . push: ${{ github.event_name != 'pull_request' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }}