Repository navigation
181 lines (160 loc) · 5.62 KB
/
Copy pathpublish.yml
File metadata and controls
181 lines (160 loc) · 5.62 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
name: docker publish
on:
push:
tags:
- '*'
workflow_dispatch:
inputs:
usd_version:
description: 'OpenUSD version to build (e.g. 26.05). Passed as --build-arg USD_VERSION and used to checkout v<USD_VERSION> from PixarAnimationStudios/OpenUSD.'
required: true
default: '26.05'
type: string
image_tag:
description: 'Image tag to publish (defaults to the OpenUSD version above).'
required: false
default: ''
type: string
tag_latest:
description: 'Also publish the image as :latest.'
required: false
default: false
type: boolean
env:
REGISTRY: ghcr.io
jobs:
setup:
runs-on: ubuntu-latest
outputs:
usd_version: ${{ steps.derive.outputs.usd_version }}
image_tag: ${{ steps.derive.outputs.image_tag }}
image_name: ${{ steps.derive.outputs.image_name }}
tag_latest: ${{ steps.derive.outputs.tag_latest }}
steps:
- name: derive build parameters
id: derive
run: |
set -euo pipefail
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
usd_version="${{ inputs.usd_version }}"
image_tag="${{ inputs.image_tag }}"
tag_latest="${{ inputs.tag_latest }}"
else
ref="${GITHUB_REF#refs/tags/}"
usd_version="${ref#v}"
image_tag="$ref"
tag_latest="true"
fi
if [[ -z "$image_tag" ]]; then
image_tag="$usd_version"
fi
image_name="$(echo "${{ github.repository_owner }}/python-usd" | tr '[:upper:]' '[:lower:]')"
echo "usd_version=$usd_version" >> "$GITHUB_OUTPUT"
echo "image_tag=$image_tag" >> "$GITHUB_OUTPUT"
echo "image_name=$image_name" >> "$GITHUB_OUTPUT"
echo "tag_latest=$tag_latest" >> "$GITHUB_OUTPUT"
echo "Building OpenUSD v${usd_version} -> ${{ env.REGISTRY }}/${image_name}:${image_tag} (latest=${tag_latest})"
build:
needs: setup
strategy:
fail-fast: false
matrix:
include:
- platform: linux/amd64
runner: ubuntu-latest
- platform: linux/arm64
runner: ubuntu-24.04-arm
runs-on: ${{ matrix.runner }}
timeout-minutes: 360
permissions:
contents: read
packages: write
steps:
- name: prepare platform pair
run: |
platform="${{ matrix.platform }}"
echo "PLATFORM_PAIR=${platform//\//-}" >> "$GITHUB_ENV"
- name: checkout code
uses: actions/checkout@v4
- name: setup buildx
uses: docker/setup-buildx-action@v3
- name: login to GHCR
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: build and push by digest
id: build
uses: docker/build-push-action@v6
with:
context: .
file: Dockerfile
platforms: ${{ matrix.platform }}
build-args: |
USD_VERSION=${{ needs.setup.outputs.usd_version }}
labels: |
org.opencontainers.image.title=python-usd
org.opencontainers.image.version=${{ needs.setup.outputs.image_tag }}
org.opencontainers.image.revision=${{ github.sha }}
org.opencontainers.image.source=https://github.com/${{ github.repository }}
outputs: type=image,name=${{ env.REGISTRY }}/${{ needs.setup.outputs.image_name }},push-by-digest=true,name-canonical=true,push=true
- name: export digest
run: |
mkdir -p /tmp/digests
digest="${{ steps.build.outputs.digest }}"
touch "/tmp/digests/${digest#sha256:}"
- name: upload digest
uses: actions/upload-artifact@v4
with:
name: digests-${{ env.PLATFORM_PAIR }}
path: /tmp/digests/*
if-no-files-found: error
retention-days: 1
merge:
needs: [setup, build]
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: download digests
uses: actions/download-artifact@v4
with:
path: /tmp/digests
pattern: digests-*
merge-multiple: true
- name: setup buildx
uses: docker/setup-buildx-action@v3
- name: login to GHCR
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: assemble tag args
id: tags
run: |
set -euo pipefail
image="${{ env.REGISTRY }}/${{ needs.setup.outputs.image_name }}"
tags=("version-${{ needs.setup.outputs.image_tag }}" "${{ needs.setup.outputs.image_tag }}")
if [[ "${{ needs.setup.outputs.tag_latest }}" == "true" ]]; then
tags+=("latest")
fi
args=""
for t in "${tags[@]}"; do
args+=" -t ${image}:${t}"
done
echo "args=${args}" >> "$GITHUB_OUTPUT"
- name: create multi-arch manifest
working-directory: /tmp/digests
run: |
set -euo pipefail
image="${{ env.REGISTRY }}/${{ needs.setup.outputs.image_name }}"
# shellcheck disable=SC2046
docker buildx imagetools create ${{ steps.tags.outputs.args }} \
$(printf "${image}@sha256:%s " *)
- name: inspect
run: |
docker buildx imagetools inspect \
${{ env.REGISTRY }}/${{ needs.setup.outputs.image_name }}:${{ needs.setup.outputs.image_tag }}