test merging manifests #2
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Docker Bake Build and Push 2 | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| branches: [ main ] | |
| workflow_dispatch: | |
| env: | |
| REGISTRY: ghcr.io/nersc/interactem | |
| jobs: | |
| prepare: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| outputs: | |
| tag: ${{ steps.meta.outputs.tag }} | |
| services: ${{ steps.services.outputs.services }} | |
| all-images: ${{ steps.services.outputs.all-images }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Extract metadata | |
| id: meta | |
| run: | | |
| TAG=$(git rev-parse --short=6 HEAD) | |
| echo "tag=${TAG}" >> $GITHUB_OUTPUT | |
| echo "Generated tag: ${TAG}" | |
| - name: Define services | |
| id: services | |
| run: | | |
| # Extract services from the prod group in docker-bake.hcl | |
| SERVICES=$(docker buildx bake prod --print | jq -cr '[.group.prod.targets[]]') | |
| echo "Services found: ${SERVICES}" | |
| echo "services=${SERVICES}" >> $GITHUB_OUTPUT | |
| # Create combined list including base image for merge-manifests | |
| ALL_IMAGES=$(echo ${SERVICES} | jq -c '. + ["interactem"]') | |
| echo "All images (including base): ${ALL_IMAGES}" | |
| echo "all-images=${ALL_IMAGES}" >> $GITHUB_OUTPUT | |
| working-directory: ./docker | |
| build-base: | |
| needs: prepare | |
| strategy: | |
| matrix: | |
| include: | |
| - platform: amd64 | |
| runner: ubuntu-24.04 | |
| docker-platform: linux/amd64 | |
| - platform: arm64 | |
| runner: ubuntu-24.04-arm | |
| docker-platform: linux/arm64 | |
| runs-on: ${{ matrix.runner }} | |
| permissions: | |
| contents: read | |
| packages: write # Need write for cache | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GHCR_PAT }} | |
| - name: Build base image | |
| id: bake | |
| uses: docker/bake-action@v6 | |
| with: | |
| source: . | |
| files: ./docker/docker-bake.hcl | |
| targets: base | |
| set: | | |
| *.platform=${{ matrix.docker-platform }} | |
| *.output=type=oci,dest=/tmp/base-${{ matrix.platform }}.tar | |
| *.tags=${{ env.REGISTRY }}/interactem:${{ needs.prepare.outputs.tag }} | |
| *.tags=${{ env.REGISTRY }}/interactem:latest | |
| env: | |
| TAG: ${{ needs.prepare.outputs.tag }} | |
| CACHE_PLATFORM: ${{ matrix.platform }} | |
| - name: Upload base image artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: base-image-${{ matrix.platform }} | |
| path: /tmp/base-${{ matrix.platform }}.tar | |
| if-no-files-found: error | |
| retention-days: 1 | |
| build-services: | |
| needs: [prepare, build-base] | |
| strategy: | |
| matrix: | |
| platform: | |
| - { name: amd64, runner: ubuntu-24.04, docker: linux/amd64 } | |
| - { name: arm64, runner: ubuntu-24.04-arm, docker: linux/arm64 } | |
| service: ${{ fromJson(needs.prepare.outputs.services) }} | |
| runs-on: ${{ matrix.platform.runner }} | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GHCR_PAT }} | |
| - name: Build ${{ matrix.service }} image | |
| id: bake | |
| uses: docker/bake-action@v6 | |
| with: | |
| source: . | |
| files: ./docker/docker-bake.hcl | |
| targets: ${{ matrix.service }} | |
| set: | | |
| *.platform=${{ matrix.platform.docker }} | |
| *.output=type=oci,dest=/tmp/${{ matrix.service }}-${{ matrix.platform.name }}.tar | |
| *.tags=${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} | |
| *.tags=${{ env.REGISTRY }}/${{ matrix.service }}:latest | |
| env: | |
| TAG: ${{ needs.prepare.outputs.tag }} | |
| CACHE_PLATFORM: ${{ matrix.platform.name }} | |
| - name: Upload service image artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: ${{ matrix.service }}-image-${{ matrix.platform.name }} | |
| path: /tmp/${{ matrix.service }}-${{ matrix.platform.name }}.tar | |
| if-no-files-found: error | |
| retention-days: 1 | |
| push-images: | |
| needs: [prepare, build-base, build-services] | |
| if: github.event_name != 'pull_request' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| packages: write | |
| strategy: | |
| matrix: | |
| service: ${{ fromJson(needs.prepare.outputs.all-images) }} | |
| steps: | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GHCR_PAT }} | |
| - name: Download image artifacts | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: /tmp/images | |
| pattern: ${{ matrix.service == 'interactem' && 'base' || matrix.service }}-image-* | |
| merge-multiple: true | |
| - name: Push multi-platform image | |
| run: | | |
| # Load and push amd64 image | |
| docker load -i /tmp/images/${{ matrix.service == 'interactem' && 'base' || matrix.service }}-amd64.tar | |
| docker push ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} | |
| docker push ${{ env.REGISTRY }}/${{ matrix.service }}:latest | |
| # Load and push arm64 image | |
| docker load -i /tmp/images/${{ matrix.service == 'interactem' && 'base' || matrix.service }}-arm64.tar | |
| docker push ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} | |
| docker push ${{ env.REGISTRY }}/${{ matrix.service }}:latest | |
| # Create and push multi-platform manifest | |
| docker buildx imagetools create \ | |
| -t ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} \ | |
| -t ${{ env.REGISTRY }}/${{ matrix.service }}:latest \ | |
| ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}-amd64 \ | |
| ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }}-arm64 | |
| - name: Inspect image | |
| run: | | |
| docker buildx imagetools inspect ${{ env.REGISTRY }}/${{ matrix.service }}:${{ needs.prepare.outputs.tag }} |