Skip to content

Keep smoke diagnostics stable #11

Keep smoke diagnostics stable

Keep smoke diagnostics stable #11

Workflow file for this run

name: container
on:
pull_request:
push:
branches:
- main
- 'release/**'
tags:
- 'v*'
concurrency:
group: container-${{ github.ref }}
cancel-in-progress: false
permissions:
contents: read
packages: write
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Static validation
run: sh tests/static.sh
- name: Build test image
run: docker build --pull --tag cloudbot:test .
- name: Smoke test
run: sh scripts/smoke-test.sh cloudbot:test
publish-edge-or-tag:
if: github.event_name == 'push' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v'))
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/ploos-as/cloudbot
tags: |
type=raw,value=edge,enable=${{ github.ref == 'refs/heads/main' }}
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') }}
- uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: |
VERSION=${{ steps.meta.outputs.version }}
cache-from: type=gha
cache-to: type=gha,mode=max
provenance: mode=max
sbom: true
publish-release-candidate:
if: startsWith(github.ref, 'refs/heads/release/v')
needs: test
runs-on: ubuntu-latest
outputs:
tag: ${{ steps.version.outputs.tag }}
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@v4
- name: Resolve and validate release version
id: version
shell: bash
run: |
set -euo pipefail
tag="${GITHUB_REF_NAME#release/}"
version="${tag#v}"
minor="${version%.*}"
test "$tag" = "v$(cat VERSION)"
test -s "docs/releases/${tag}.md"
echo "tag=${tag}" >> "$GITHUB_OUTPUT"
echo "version=${version}" >> "$GITHUB_OUTPUT"
echo "minor=${minor}" >> "$GITHUB_OUTPUT"
- name: Ensure release tag does not already exist
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAG: ${{ steps.version.outputs.tag }}
run: |
if gh api "repos/${GITHUB_REPOSITORY}/git/ref/tags/${TAG}" >/dev/null 2>&1; then
echo "Tag ${TAG} already exists" >&2
exit 1
fi
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/ploos-as/cloudbot
tags: |
type=raw,value=${{ steps.version.outputs.version }}
type=raw,value=${{ steps.version.outputs.minor }}
type=raw,value=latest
- uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: |
VERSION=${{ steps.version.outputs.version }}
cache-from: type=gha
cache-to: type=gha,mode=max
provenance: mode=max
sbom: true
finalize-release-candidate:
if: startsWith(github.ref, 'refs/heads/release/v')
needs: publish-release-candidate
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- name: Create immutable Git tag
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAG: ${{ needs.publish-release-candidate.outputs.tag }}
run: |
gh api --method POST "repos/${GITHUB_REPOSITORY}/git/refs" \
-f ref="refs/tags/${TAG}" \
-f sha="${GITHUB_SHA}"
- name: Create GitHub release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAG: ${{ needs.publish-release-candidate.outputs.tag }}
run: |
gh release create "${TAG}" \
--verify-tag \
--title "CloudBot container ${TAG}" \
--notes-file "docs/releases/${TAG}.md"
release-from-tag:
if: startsWith(github.ref, 'refs/tags/v')
needs: publish-edge-or-tag
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- name: Validate release notes
run: test -s "docs/releases/${GITHUB_REF_NAME}.md"
- name: Create GitHub release if missing
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh release view "${GITHUB_REF_NAME}" >/dev/null 2>&1 || \
gh release create "${GITHUB_REF_NAME}" \
--verify-tag \
--title "CloudBot container ${GITHUB_REF_NAME}" \
--notes-file "docs/releases/${GITHUB_REF_NAME}.md"