ci: build and publish the image on every push to main
Build docker image and push to registry.bitdeals.org / build (push) Failing after 4m25s
Build docker image and push to registry.bitdeals.org / build (push) Failing after 4m25s
The registry account available on the testnet hosts is pull-only (403 on a blob upload even for an existing repository), so publishing goes the same way every other BitDeals image does: the Gitea runner builds and pushes with the CI credentials. Tags mirror the family — an immutable <version>.<sha7>, a moving <version>, and :latest for compose and Watchtower. The version is read out of the Dockerfile ARG rather than repeated here: a tag that can disagree with the code inside is worse than no tag.
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
name: Build docker image and push to registry.bitdeals.org
|
||||
run-name: docker build and docker push
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
COMMIT: ${{ gitea.sha }}
|
||||
REGISTRY: 10.0.3.111:5000
|
||||
IMAGE: electrumx
|
||||
USER: ${{ secrets.DOCKER_USERNAME }}
|
||||
PASS: ${{ secrets.DOCKER_PASSWORD }}
|
||||
steps:
|
||||
- name: Checkout repository code
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# The version tag comes from the Dockerfile rather than from a second
|
||||
# copy here: the ARG is what the build actually installs, and a tag that
|
||||
# can disagree with the code inside is worse than no tag.
|
||||
- name: Resolve the ElectrumX version from the Dockerfile
|
||||
run: |
|
||||
v=$(sed -n 's/^ARG ELECTRUMX_VERSION=//p' docker/Dockerfile)
|
||||
test -n "$v" || { echo "ELECTRUMX_VERSION not found in docker/Dockerfile" >&2; exit 1; }
|
||||
echo "VERSION=$v" >> "$GITHUB_ENV"
|
||||
|
||||
# Three tags: the immutable one to deploy by, the moving version tag for
|
||||
# people reading `docker images`, and :latest for Watchtower and compose.
|
||||
- name: Build image
|
||||
run: |
|
||||
docker build . \
|
||||
--file docker/Dockerfile \
|
||||
--label "git-commit=$COMMIT" \
|
||||
--tag "${REGISTRY}/${IMAGE}:${VERSION}.${COMMIT::7}" \
|
||||
--tag "${REGISTRY}/${IMAGE}:${VERSION}" \
|
||||
--tag "${REGISTRY}/${IMAGE}:latest"
|
||||
|
||||
- name: Docker login
|
||||
run: docker login --username "$USER" --password "$PASS" "$REGISTRY"
|
||||
|
||||
- name: Push images
|
||||
run: |
|
||||
docker push "${REGISTRY}/${IMAGE}:${VERSION}.${COMMIT::7}"
|
||||
docker push "${REGISTRY}/${IMAGE}:${VERSION}"
|
||||
docker push "${REGISTRY}/${IMAGE}:latest"
|
||||
@@ -60,6 +60,11 @@ Anything after the image name is passed on to `electrumx_server`.
|
||||
|
||||
## build and publish
|
||||
|
||||
A push to `main` builds and publishes the image (`.gitea/workflows/build.yaml`),
|
||||
tagging it three ways: `<version>.<sha7>` to deploy by, `<version>` to read, and
|
||||
`latest` for compose and Watchtower. By hand, when the registry credentials are
|
||||
at hand:
|
||||
|
||||
```sh
|
||||
docker build . --file docker/Dockerfile --tag registry.bitdeals.org/electrumx
|
||||
docker push registry.bitdeals.org/electrumx
|
||||
|
||||
@@ -60,6 +60,11 @@ docker run -d \
|
||||
|
||||
## сборка и публикация
|
||||
|
||||
Пуш в `main` собирает и публикует образ (`.gitea/workflows/build.yaml`) с тремя
|
||||
тегами: `<версия>.<sha7>` — для развёртывания, `<версия>` — для чтения глазами,
|
||||
`latest` — для compose и Watchtower. Вручную, если под рукой есть учётные данные
|
||||
registry:
|
||||
|
||||
```sh
|
||||
docker build . --file docker/Dockerfile --tag registry.bitdeals.org/electrumx
|
||||
docker push registry.bitdeals.org/electrumx
|
||||
|
||||
Reference in New Issue
Block a user