Skip to content

agent: exclude SSH (port 22) from capture #7

agent: exclude SSH (port 22) from capture

agent: exclude SSH (port 22) from capture #7

Workflow file for this run

# Build and push the ipcap container images to GHCR as multi-arch manifests
# (linux/amd64 for the game vulnbox + linux/arm64 for ARM boxes / RPi testing),
# so the collector and the vulnbox agent both deploy by `docker compose pull`
# with no build anywhere at deploy time.
name: images
on:
push:
branches: [main]
tags: ["v*"]
workflow_dispatch:
permissions:
contents: read
packages: write
jobs:
build:
runs-on: ubuntu-latest
strategy:
matrix:
include:
- image: ipcap # collector
dockerfile: deploy/Dockerfile
- image: ipcap-agent # vulnbox agent (capture+listen+tls, eCapture baked in)
dockerfile: deploy/Dockerfile.agent
steps:
- uses: actions/checkout@v4
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/madrhacks/${{ matrix.image }}
tags: |
type=raw,value=latest,enable={{is_default_branch}}
type=sha,format=short
type=ref,event=tag
- uses: docker/build-push-action@v6
with:
context: .
file: ${{ matrix.dockerfile }}
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: VERSION=${{ github.sha }}
cache-from: type=gha,scope=${{ matrix.image }}
cache-to: type=gha,mode=max,scope=${{ matrix.image }}