Add prune-registry.sh: keeps the moving tag and newest versioned tag per distro plus their cosign signature tags, deletes the rest via the Gitea packages API. Wire it into the prune job (uses REGISTRY_TOKEN).
155 lines
5.4 KiB
YAML
155 lines
5.4 KiB
YAML
name: Build containers
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
pull_request:
|
|
branches: ["main"]
|
|
push:
|
|
branches: ["main"]
|
|
schedule:
|
|
# Weekly, Mondays 04:00 UTC.
|
|
- cron: "0 4 * * 1"
|
|
|
|
jobs:
|
|
build:
|
|
name: ${{ matrix.image }} (${{ matrix.distro }})
|
|
runs-on: ${{ matrix.runner }}
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
# To build another image, add images/<name>/{manifest.yaml,build.conf}
|
|
# and a matching matrix entry here.
|
|
matrix:
|
|
include:
|
|
- image: fedora-cosmic
|
|
distro: "44"
|
|
arch: x86_64
|
|
runner: job-v2
|
|
- image: fedora-cosmic
|
|
distro: rawhide
|
|
arch: x86_64
|
|
runner: job-v2
|
|
|
|
container:
|
|
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
|
|
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
|
|
|
|
env:
|
|
IMAGE: ${{ matrix.image }}
|
|
DISTRO: ${{ matrix.distro }}
|
|
ARCH: ${{ matrix.arch }}
|
|
REGISTRY: git.plabble.org/misthios
|
|
GITEA_URL: https://git.plabble.org
|
|
GITEA_REPO: Misthios/bootc-images
|
|
|
|
steps:
|
|
- name: Install build tools
|
|
run: |
|
|
set -xeuo pipefail
|
|
dnf install -y nodejs jq curl git createrepo_c
|
|
dnf install -y skopeo
|
|
dnf install -y cosign || true
|
|
if ! command -v cosign >/dev/null; then
|
|
case "$(uname -m)" in
|
|
x86_64) cosign_arch=amd64 ;;
|
|
aarch64) cosign_arch=arm64 ;;
|
|
*) echo "Unsupported arch for cosign"; exit 1 ;;
|
|
esac
|
|
curl -fsSL -o /usr/local/bin/cosign \
|
|
"https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}"
|
|
chmod +x /usr/local/bin/cosign
|
|
fi
|
|
|
|
- name: Configure containers storage
|
|
run: |
|
|
if [ -f /usr/share/containers/storage.conf ]; then
|
|
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
|
|
fi
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Log in to registry
|
|
env:
|
|
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
|
run: |
|
|
set -xeuo pipefail
|
|
mkdir -p ~/.docker
|
|
registry_host="${REGISTRY%%/*}"
|
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
|
--password-stdin --authfile /tmp/auth.json "${registry_host}"
|
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
|
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
|
|
|
- name: Build image
|
|
env:
|
|
KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }}
|
|
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
|
|
|
- name: Push and sign image
|
|
if: github.event_name != 'pull_request'
|
|
env:
|
|
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
|
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
|
run: |
|
|
set -xeuo pipefail
|
|
export STORAGE_DRIVER=vfs
|
|
buildid="$(cat .buildid)"
|
|
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
|
tag="${DISTRO}.${buildid}"
|
|
|
|
skopeo copy --authfile /tmp/auth.json \
|
|
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}"
|
|
skopeo copy --authfile /tmp/auth.json \
|
|
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}"
|
|
|
|
printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key
|
|
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}"
|
|
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}"
|
|
rm -f private.key
|
|
|
|
- name: Generate changelog and publish release
|
|
if: github.event_name != 'pull_request'
|
|
env:
|
|
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
|
run: |
|
|
buildid="$(cat .buildid)"
|
|
pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt"
|
|
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}"
|
|
|
|
prune:
|
|
name: Prune old releases
|
|
runs-on: job-v2
|
|
needs: build
|
|
# Run even if some matrix builds failed (e.g. rawhide churn), so their old
|
|
# releases still get cleaned up.
|
|
if: ${{ always() && github.event_name != 'pull_request' }}
|
|
container:
|
|
image: "quay.io/fedora-ostree-desktops/buildroot:44"
|
|
options: "--security-opt=label=disable --privileged --user 0:0"
|
|
env:
|
|
GITEA_URL: https://git.plabble.org
|
|
GITEA_REPO: Misthios/bootc-images
|
|
steps:
|
|
- name: Install tools
|
|
run: dnf install -y nodejs jq curl skopeo
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
- name: Prune old releases
|
|
env:
|
|
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
|
run: ./prune-releases.sh fedora-cosmic
|
|
- name: Prune old registry tags
|
|
env:
|
|
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
|
run: |
|
|
set -xeuo pipefail
|
|
authfile=/tmp/prune-auth.json
|
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
|
--password-stdin --authfile "${authfile}" git.plabble.org
|
|
AUTHFILE="${authfile}" ./prune-registry.sh fedora-cosmic Misthios 44 rawhide
|