ci: build and publish the image on every push to main
Build docker image and push to registry.bitdeals.org / build (push) Failing after 4m25s

The registry account available on the testnet hosts is pull-only (403 on a
blob upload even for an existing repository), so publishing goes the same way
every other BitDeals image does: the Gitea runner builds and pushes with the
CI credentials. Tags mirror the family — an immutable <version>.<sha7>, a
moving <version>, and :latest for compose and Watchtower.

The version is read out of the Dockerfile ARG rather than repeated here: a tag
that can disagree with the code inside is worse than no tag.
This commit is contained in:
2026-08-06 12:01:13 +00:00
parent a5f9d13ca4
commit 7a7ecfb303
3 changed files with 58 additions and 0 deletions
+48
View File
@@ -0,0 +1,48 @@
name: Build docker image and push to registry.bitdeals.org
run-name: docker build and docker push
on:
push:
branches:
- main
jobs:
build:
runs-on: ubuntu-latest
env:
COMMIT: ${{ gitea.sha }}
REGISTRY: 10.0.3.111:5000
IMAGE: electrumx
USER: ${{ secrets.DOCKER_USERNAME }}
PASS: ${{ secrets.DOCKER_PASSWORD }}
steps:
- name: Checkout repository code
uses: actions/checkout@v6
# The version tag comes from the Dockerfile rather than from a second
# copy here: the ARG is what the build actually installs, and a tag that
# can disagree with the code inside is worse than no tag.
- name: Resolve the ElectrumX version from the Dockerfile
run: |
v=$(sed -n 's/^ARG ELECTRUMX_VERSION=//p' docker/Dockerfile)
test -n "$v" || { echo "ELECTRUMX_VERSION not found in docker/Dockerfile" >&2; exit 1; }
echo "VERSION=$v" >> "$GITHUB_ENV"
# Three tags: the immutable one to deploy by, the moving version tag for
# people reading `docker images`, and :latest for Watchtower and compose.
- name: Build image
run: |
docker build . \
--file docker/Dockerfile \
--label "git-commit=$COMMIT" \
--tag "${REGISTRY}/${IMAGE}:${VERSION}.${COMMIT::7}" \
--tag "${REGISTRY}/${IMAGE}:${VERSION}" \
--tag "${REGISTRY}/${IMAGE}:latest"
- name: Docker login
run: docker login --username "$USER" --password "$PASS" "$REGISTRY"
- name: Push images
run: |
docker push "${REGISTRY}/${IMAGE}:${VERSION}.${COMMIT::7}"
docker push "${REGISTRY}/${IMAGE}:${VERSION}"
docker push "${REGISTRY}/${IMAGE}:latest"
+5
View File
@@ -60,6 +60,11 @@ Anything after the image name is passed on to `electrumx_server`.
## build and publish
A push to `main` builds and publishes the image (`.gitea/workflows/build.yaml`),
tagging it three ways: `<version>.<sha7>` to deploy by, `<version>` to read, and
`latest` for compose and Watchtower. By hand, when the registry credentials are
at hand:
```sh
docker build . --file docker/Dockerfile --tag registry.bitdeals.org/electrumx
docker push registry.bitdeals.org/electrumx
+5
View File
@@ -60,6 +60,11 @@ docker run -d \
## сборка и публикация
Пуш в `main` собирает и публикует образ (`.gitea/workflows/build.yaml`) с тремя
тегами: `<версия>.<sha7>` — для развёртывания, `<версия>` — для чтения глазами,
`latest` — для compose и Watchtower. Вручную, если под рукой есть учётные данные
registry:
```sh
docker build . --file docker/Dockerfile --tag registry.bitdeals.org/electrumx
docker push registry.bitdeals.org/electrumx