Skip to content

test merging manifests #2

test merging manifests

test merging manifests #2

Workflow file for this run

name: Docker Bake Build and Push 2
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
workflow_dispatch:
env:
REGISTRY: ghcr.io/nersc/interactem
jobs:
prepare:
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
tag: ${{ steps.meta.outputs.tag }}
services: ${{ steps.services.outputs.services }}
all-images: ${{ steps.services.outputs.all-images }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Extract metadata
id: meta
run: |
TAG=$(git rev-parse --short=6 HEAD)
echo "tag=${TAG}" >> $GITHUB_OUTPUT
echo "Generated tag: ${TAG}"
- name: Define services
id: services
run: |
# Extract services from the prod group in docker-bake.hcl
SERVICES=$(docker buildx bake prod --print | jq -cr '[.group.prod.targets[]]')
echo "Services found: ${SERVICES}"
echo "services=${SERVICES}" >> $GITHUB_OUTPUT
# Create combined list including base image for merge-manifests
ALL_IMAGES=$(echo ${SERVICES} | jq -c '. + ["interactem"]')
echo "All images (including base): ${ALL_IMAGES}"
echo "all-images=${ALL_IMAGES}" >> $GITHUB_OUTPUT
working-directory: ./docker
build-base:
needs: prepare
strategy:
matrix:
include:
- platform: amd64
runner: ubuntu-24.04
docker-platform: linux/amd64
- platform: arm64
runner: ubuntu-24.04-arm
docker-platform: linux/arm64
runs-on: ${{ matrix.runner }}
permissions:
contents: read
packages: write # Need write for cache
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GHCR_PAT }}
- name: Build base image
id: bake
uses: docker/bake-action@v6
with:
source: .
files: ./docker/docker-bake.hcl
targets: base
set: |
*.platform=${{ matrix.docker-platform }}
*.output=type=oci,dest=/tmp/base-${{ matrix.platform }}.tar
*.tags=${{ env.REGISTRY }}/interactem:${{ needs.prepare.outputs.tag }}
*.tags=${{ env.REGISTRY }}/interactem:latest
env:
TAG: ${{ needs.prepare.outputs.tag }}
CACHE_PLATFORM: ${{ matrix.platform }}
- name: Upload base image artifact
uses: actions/upload-artifact@v4
with:
name: base-image-${{ matrix.platform }}
path: /tmp/base-${{ matrix.platform }}.tar
if-no-files-found: error
retention-days: 1
build-services:
needs: [prepare, build-base]
strategy:
matrix:
platform:
- { name: amd64, runner: ubuntu-24.04, docker: linux/amd64 }
- { name: arm64, runner: ubuntu-24.04-arm, docker: linux/arm64 }
service: ${{ fromJson(needs.prepare.outputs.services) }}
runs-on: ${{ matrix.platform.runner }}
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GHCR_PAT }}
- name: Build ${{ matrix.service }} image
id: bake
uses: docker/bake-action@v6
with:
source: .
files: ./docker/docker-bake.hcl
targets: ${{ matrix.service }}
set: |
*.platform=${{ matrix.platform.docker }}
*.output=type=oci,dest=/tmp/${{ matrix.service }}-${{ matrix.platform.name }}.tar
*.tags=${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}
*.tags=${{ env.REGISTRY }}/${{ matrix.service }}:latest
env:
TAG: ${{ needs.prepare.outputs.tag }}
CACHE_PLATFORM: ${{ matrix.platform.name }}
- name: Upload service image artifact
uses: actions/upload-artifact@v4
with:
name: ${{ matrix.service }}-image-${{ matrix.platform.name }}
path: /tmp/${{ matrix.service }}-${{ matrix.platform.name }}.tar
if-no-files-found: error
retention-days: 1
push-images:
needs: [prepare, build-base, build-services]
if: github.event_name != 'pull_request'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
matrix:
service: ${{ fromJson(needs.prepare.outputs.all-images) }}
steps:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GHCR_PAT }}
- name: Download image artifacts
uses: actions/download-artifact@v4
with:
path: /tmp/images
pattern: ${{ matrix.service == 'interactem' && 'base' || matrix.service }}-image-*
merge-multiple: true
- name: Push multi-platform image
run: |
# Load and push amd64 image
docker load -i /tmp/images/${{ matrix.service == 'interactem' && 'base' || matrix.service }}-amd64.tar
docker push ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}
docker push ${{ env.REGISTRY }}/${{ matrix.service }}:latest
# Load and push arm64 image
docker load -i /tmp/images/${{ matrix.service == 'interactem' && 'base' || matrix.service }}-arm64.tar
docker push ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}
docker push ${{ env.REGISTRY }}/${{ matrix.service }}:latest
# Create and push multi-platform manifest
docker buildx imagetools create \
-t ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} \
-t ${{ env.REGISTRY }}/${{ matrix.service }}:latest \
${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}-amd64 \
${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}-arm64
- name: Inspect image
run: |
docker buildx imagetools inspect ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}