name: Docker on: push: # master is deliberately absent. Every tag this workflow publishes for a # release is enabled on the tag ref alone. Releases arrive here through the # v*.*.* tag that semantic-release creates. branches: - beta - develop paths: - 'webapp/**' - '!webapp/backend/pkg/version/version.go' - 'collector/**' - 'docker/**' - 'Makefile' - 'go.mod' - 'go.sum' # CHANGELOG.md lets a release commit match this filter on its own terms. # semantic-release tags a chore(release) commit touching only CHANGELOG.md # and version.go, and version.go is excluded above. - 'CHANGELOG.md' tags: - 'v*.*.*' workflow_dispatch: inputs: tag_suffix: description: 'Non-stable tag suffix (latest is reserved for release tags)' required: true default: 'develop' concurrency: group: docker-build-${{ github.ref }} cancel-in-progress: true env: REGISTRY: ghcr.io IMAGE_NAME: ${{ github.repository }} jobs: validate_dispatch: name: Validate manual image tag runs-on: ubuntu-latest steps: - name: Reject stable tag override env: TAG_SUFFIX: ${{ inputs.tag_suffix }} run: | if [[ "$TAG_SUFFIX" == "latest" ]]; then echo "Stable image tags are published only from release tag refs." >&2 exit 1 fi image_matrix: name: Validate Docker image matrix runs-on: ubuntu-latest permissions: contents: read outputs: all: ${{ steps.matrix.outputs.all }} steps: - name: Checkout uses: actions/checkout@v7.0.1 - name: Test Docker image matrix run: bash docker/tests/image-matrix_test.sh - name: Export Docker image matrix id: matrix run: echo "all=$(jq -c . docker/image-matrix.json)" >> "$GITHUB_OUTPUT" build: name: Build ${{ matrix.image }} needs: [validate_dispatch, image_matrix] runs-on: ubuntu-latest timeout-minutes: 30 permissions: contents: read packages: write strategy: fail-fast: false matrix: include: ${{ fromJSON(needs.image_matrix.outputs.all) }} steps: - name: Checkout repository uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Populate frontend version information if: matrix.frontend == true run: cd webapp/frontend && ./git.version.sh - name: Set up QEMU uses: docker/setup-qemu-action@v4 with: platforms: ${{ matrix.qemu }} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v4 - name: Log into registry ${{ env.REGISTRY }} if: github.event_name != 'pull_request' uses: docker/login-action@v4 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract Docker metadata id: meta uses: docker/metadata-action@v6 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} flavor: | latest=false tags: | # Manual trigger type=raw,value=${{ inputs.tag_suffix }}-${{ matrix.image }},enable=${{ github.event_name == 'workflow_dispatch' }} # Branch builds type=raw,value=latest-${{ matrix.image }},enable=${{ startsWith(github.ref, 'refs/tags/v') && github.event_name != 'workflow_dispatch' }} type=raw,value=beta-${{ matrix.image }},enable=${{ github.ref == 'refs/heads/beta' && github.event_name != 'workflow_dispatch' }} type=raw,value=develop-${{ matrix.image }},enable=${{ github.ref == 'refs/heads/develop' && github.event_name != 'workflow_dispatch' }} type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') && github.event_name != 'workflow_dispatch' && matrix.default_image == true }} type=raw,value=beta,enable=${{ github.ref == 'refs/heads/beta' && github.event_name != 'workflow_dispatch' && matrix.default_image == true }} type=raw,value=develop,enable=${{ github.ref == 'refs/heads/develop' && github.event_name != 'workflow_dispatch' && matrix.default_image == true }} # Version tags type=semver,pattern={{version}}-${{ matrix.image }} type=semver,pattern={{major}}.{{minor}}-${{ matrix.image }} type=semver,pattern={{major}}-${{ matrix.image }},enable=${{ !startsWith(github.ref, 'refs/tags/v0.') }} type=semver,pattern={{version}},enable=${{ matrix.default_image == true }} type=semver,pattern={{major}}.{{minor}},enable=${{ matrix.default_image == true }} type=semver,pattern={{major}},enable=${{ matrix.default_image == true && !startsWith(github.ref, 'refs/tags/v0.') }} - name: Build and push Docker image uses: docker/build-push-action@v7 with: platforms: ${{ matrix.platforms }} context: . file: ${{ matrix.dockerfile }} push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha,scope=${{ matrix.cache_scope }} cache-to: type=gha,mode=max,scope=${{ matrix.cache_scope }}