name: Build containers on: workflow_dispatch: pull_request: branches: ["main"] push: branches: ["main"] schedule: # Weekly, Mondays 04:00 UTC. - cron: "0 4 * * 1" jobs: build: name: ${{ matrix.image }} (${{ matrix.distro }}) runs-on: ${{ matrix.runner }} strategy: fail-fast: false # To build another image, add images//{manifest.yaml,build.conf} # and a matching matrix entry here. matrix: include: - image: fedora-cosmic distro: "44" arch: x86_64 runner: job-v2 - image: fedora-cosmic distro: rawhide arch: x86_64 runner: job-v2 container: image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}" options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw" env: IMAGE: ${{ matrix.image }} DISTRO: ${{ matrix.distro }} ARCH: ${{ matrix.arch }} REGISTRY: git.plabble.org/misthios GITEA_URL: https://git.plabble.org GITEA_REPO: Misthios/bootc-images steps: - name: Install build tools run: | set -xeuo pipefail dnf install -y nodejs jq curl git createrepo_c dnf install -y skopeo dnf install -y cosign || true if ! command -v cosign >/dev/null; then case "$(uname -m)" in x86_64) cosign_arch=amd64 ;; aarch64) cosign_arch=arm64 ;; *) echo "Unsupported arch for cosign"; exit 1 ;; esac curl -fsSL -o /usr/local/bin/cosign \ "https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}" chmod +x /usr/local/bin/cosign fi - name: Configure containers storage run: | if [ -f /usr/share/containers/storage.conf ]; then sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf fi - name: Checkout uses: actions/checkout@v4 with: fetch-depth: 0 - name: Log in to registry env: REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | set -xeuo pipefail mkdir -p ~/.docker registry_host="${REGISTRY%%/*}" echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \ --password-stdin --authfile /tmp/auth.json "${registry_host}" echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \ --password-stdin --authfile ~/.docker/config.json "${registry_host}" - name: Build image env: KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }} run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}" - name: Push and sign image if: github.event_name != 'pull_request' env: COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} run: | set -xeuo pipefail export STORAGE_DRIVER=vfs buildid="$(cat .buildid)" oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive" tag="${DISTRO}.${buildid}" skopeo copy --authfile /tmp/auth.json \ "oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}" skopeo copy --authfile /tmp/auth.json \ "oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}" printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}" cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}" rm -f private.key - name: Generate changelog and publish release if: github.event_name != 'pull_request' env: RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }} run: | buildid="$(cat .buildid)" pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt" ./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}" prune: name: Prune old releases runs-on: job-v2 needs: build # Run even if some matrix builds failed (e.g. rawhide churn), so their old # releases still get cleaned up. if: ${{ always() && github.event_name != 'pull_request' }} container: image: "quay.io/fedora-ostree-desktops/buildroot:44" options: "--security-opt=label=disable --privileged --user 0:0" env: GITEA_URL: https://git.plabble.org GITEA_REPO: Misthios/bootc-images steps: - name: Install tools run: dnf install -y nodejs jq curl - name: Checkout uses: actions/checkout@v4 - name: Prune old releases env: RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }} run: ./prune-releases.sh fedora-cosmic