Files
bootc-images/.gitea/workflows/build.yaml
T
Misthios a789cb6669
Build containers / fedora-cosmic (rawhide) (push) Failing after 47s
Build containers / fedora-cosmic (44) (push) Successful in 11m4s
Build containers / Prune old releases (push) Failing after 21s
ci: prune old container registry tags too
Add prune-registry.sh: keeps the moving tag and newest versioned tag per
distro plus their cosign signature tags, deletes the rest via the Gitea
packages API. Wire it into the prune job (uses REGISTRY_TOKEN).
2026-09-27 20:03:12 +02:00

155 lines
5.4 KiB
YAML

name: Build containers
on:
workflow_dispatch:
pull_request:
branches: ["main"]
push:
branches: ["main"]
schedule:
# Weekly, Mondays 04:00 UTC.
- cron: "0 4 * * 1"
jobs:
build:
name: ${{ matrix.image }} (${{ matrix.distro }})
runs-on: ${{ matrix.runner }}
strategy:
fail-fast: false
# To build another image, add images/<name>/{manifest.yaml,build.conf}
# and a matching matrix entry here.
matrix:
include:
- image: fedora-cosmic
distro: "44"
arch: x86_64
runner: job-v2
- image: fedora-cosmic
distro: rawhide
arch: x86_64
runner: job-v2
container:
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
env:
IMAGE: ${{ matrix.image }}
DISTRO: ${{ matrix.distro }}
ARCH: ${{ matrix.arch }}
REGISTRY: git.plabble.org/misthios
GITEA_URL: https://git.plabble.org
GITEA_REPO: Misthios/bootc-images
steps:
- name: Install build tools
run: |
set -xeuo pipefail
dnf install -y nodejs jq curl git createrepo_c
dnf install -y skopeo
dnf install -y cosign || true
if ! command -v cosign >/dev/null; then
case "$(uname -m)" in
x86_64) cosign_arch=amd64 ;;
aarch64) cosign_arch=arm64 ;;
*) echo "Unsupported arch for cosign"; exit 1 ;;
esac
curl -fsSL -o /usr/local/bin/cosign \
"https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}"
chmod +x /usr/local/bin/cosign
fi
- name: Configure containers storage
run: |
if [ -f /usr/share/containers/storage.conf ]; then
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
fi
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Log in to registry
env:
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: |
set -xeuo pipefail
mkdir -p ~/.docker
registry_host="${REGISTRY%%/*}"
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
--password-stdin --authfile /tmp/auth.json "${registry_host}"
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
- name: Build image
env:
KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }}
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
- name: Push and sign image
if: github.event_name != 'pull_request'
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
run: |
set -xeuo pipefail
export STORAGE_DRIVER=vfs
buildid="$(cat .buildid)"
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
tag="${DISTRO}.${buildid}"
skopeo copy --authfile /tmp/auth.json \
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}"
skopeo copy --authfile /tmp/auth.json \
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}"
printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}"
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}"
rm -f private.key
- name: Generate changelog and publish release
if: github.event_name != 'pull_request'
env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: |
buildid="$(cat .buildid)"
pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt"
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}"
prune:
name: Prune old releases
runs-on: job-v2
needs: build
# Run even if some matrix builds failed (e.g. rawhide churn), so their old
# releases still get cleaned up.
if: ${{ always() && github.event_name != 'pull_request' }}
container:
image: "quay.io/fedora-ostree-desktops/buildroot:44"
options: "--security-opt=label=disable --privileged --user 0:0"
env:
GITEA_URL: https://git.plabble.org
GITEA_REPO: Misthios/bootc-images
steps:
- name: Install tools
run: dnf install -y nodejs jq curl skopeo
- name: Checkout
uses: actions/checkout@v4
- name: Prune old releases
env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: ./prune-releases.sh fedora-cosmic
- name: Prune old registry tags
env:
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: |
set -xeuo pipefail
authfile=/tmp/prune-auth.json
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
--password-stdin --authfile "${authfile}" git.plabble.org
AUTHFILE="${authfile}" ./prune-registry.sh fedora-cosmic Misthios 44 rawhide