mirror of
https://github.com/calibrain/shelfmark.git
synced 2026-10-05 22:05:50 +01:00
183 lines
7.0 KiB
YAML
183 lines
7.0 KiB
YAML
name: Create and publish Docker images
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
schedule:
|
|
# Nightly at 03:17 UTC — only builds if there are new commits on main
|
|
# since the last successful run (see check-changes job).
|
|
- cron: '17 3 * * *'
|
|
workflow_dispatch:
|
|
permissions: read-all
|
|
|
|
env:
|
|
REGISTRY: ghcr.io
|
|
IMAGE_NAME: ${{ github.repository_owner }}/shelfmark
|
|
jobs:
|
|
check-changes:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
should_build: ${{ steps.check.outputs.should_build }}
|
|
steps:
|
|
- name: Check for new commits since last successful build
|
|
id: check
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
CURRENT_SHA: ${{ github.sha }}
|
|
REPO: ${{ github.repository }}
|
|
run: |
|
|
# Always build on tag pushes and manual dispatch.
|
|
if [[ "$EVENT_NAME" != "schedule" ]]; then
|
|
echo "Event is $EVENT_NAME — building unconditionally."
|
|
echo "should_build=true" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
# Scheduled run: only build if HEAD differs from the last successful build on main.
|
|
LAST_SHA=$(gh api "/repos/${REPO}/actions/workflows/build-and-publish-docker-image.yml/runs?branch=main&status=success&per_page=1" --jq '.workflow_runs[0].head_sha' 2>/dev/null || true)
|
|
echo "Last successful build SHA: ${LAST_SHA:-<none>}"
|
|
echo "Current HEAD SHA: ${CURRENT_SHA}"
|
|
if [[ -z "$LAST_SHA" || "$LAST_SHA" != "$CURRENT_SHA" ]]; then
|
|
echo "New commits detected — building."
|
|
echo "should_build=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "No new commits since last successful build — skipping."
|
|
echo "should_build=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
build-and-push-images:
|
|
needs: check-changes
|
|
if: needs.check-changes.outputs.should_build == 'true'
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
attestations: write
|
|
id-token: write
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- target: shelfmark
|
|
- target: shelfmark-lite
|
|
image_name_suffix: "-lite"
|
|
steps:
|
|
- name: Get current date
|
|
id: date
|
|
run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Log in to the Container registry
|
|
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Extract metadata for ${{ matrix.target }} image
|
|
id: meta
|
|
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
|
|
with:
|
|
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}${{ matrix.image_name_suffix }}
|
|
tags: |
|
|
type=raw,value=dev,enable={{is_default_branch}}
|
|
type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/') }}
|
|
type=semver,pattern={{version}}
|
|
type=semver,pattern={{major}}.{{minor}}
|
|
type=sha
|
|
type=ref,event=tag
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
|
|
|
|
- name: Build and push ${{ matrix.target }} Docker image
|
|
id: push
|
|
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
|
|
with:
|
|
platforms: linux/amd64,linux/arm64
|
|
context: .
|
|
target: ${{ matrix.target }}
|
|
push: ${{ github.event_name != 'pull_request' }}
|
|
build-args: |
|
|
BUILD_VERSION=${{ steps.date.outputs.date }}-${{ github.sha }}
|
|
RELEASE_VERSION=${{ github.ref_name }}
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
|
|
- name: Generate artifact attestation for ${{ matrix.target }} image
|
|
if: github.event_name != 'pull_request'
|
|
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
|
with:
|
|
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}${{ matrix.image_name_suffix }}
|
|
subject-digest: ${{ steps.push.outputs.digest }}
|
|
push-to-registry: true
|
|
|
|
# Create aliases for backwards compatibility
|
|
create-aliases:
|
|
needs: build-and-push-images
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name != 'pull_request'
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
env:
|
|
# Legacy name for backwards compatibility (hardcoded so it works after rename)
|
|
LEGACY_NAME: calibre-web-automated-book-downloader
|
|
steps:
|
|
- name: Log in to registry
|
|
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
|
|
|
|
- name: Create legacy aliases
|
|
run: |
|
|
# Current image names (follows repo name)
|
|
STANDARD="${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}"
|
|
LITE="${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}-lite"
|
|
|
|
# Legacy image names (hardcoded for backwards compatibility)
|
|
LEGACY="${{ env.REGISTRY }}/${{ github.repository_owner }}/${{ env.LEGACY_NAME }}"
|
|
LEGACY_TOR="${LEGACY}-tor"
|
|
LEGACY_EXTBP="${LEGACY}-extbp"
|
|
|
|
SHA_SHORT=$(echo "${{ github.sha }}" | cut -c1-7)
|
|
|
|
# Helper function to create alias with all standard tags
|
|
create_alias() {
|
|
local SOURCE=$1
|
|
local ALIAS=$2
|
|
|
|
# Always create SHA tag
|
|
docker buildx imagetools create -t "${ALIAS}:sha-${SHA_SHORT}" "${SOURCE}:sha-${SHA_SHORT}"
|
|
|
|
if [[ "${{ github.ref }}" == refs/tags/v* ]]; then
|
|
VERSION="${{ github.ref_name }}"
|
|
VERSION_NUM="${VERSION#v}"
|
|
MINOR="${VERSION_NUM%.*}"
|
|
|
|
docker buildx imagetools create -t "${ALIAS}:latest" "${SOURCE}:latest"
|
|
docker buildx imagetools create -t "${ALIAS}:${VERSION_NUM}" "${SOURCE}:${VERSION_NUM}"
|
|
docker buildx imagetools create -t "${ALIAS}:${MINOR}" "${SOURCE}:${MINOR}"
|
|
docker buildx imagetools create -t "${ALIAS}:${VERSION}" "${SOURCE}:${VERSION}"
|
|
else
|
|
docker buildx imagetools create -t "${ALIAS}:dev" "${SOURCE}:dev"
|
|
fi
|
|
}
|
|
|
|
# Create legacy aliases pointing to current images
|
|
# calibre-web-automated-book-downloader → standard image
|
|
create_alias "${STANDARD}" "${LEGACY}"
|
|
|
|
# calibre-web-automated-book-downloader-tor → standard image
|
|
create_alias "${STANDARD}" "${LEGACY_TOR}"
|
|
|
|
# calibre-web-automated-book-downloader-extbp → lite image
|
|
create_alias "${LITE}" "${LEGACY_EXTBP}"
|