Skip to content

build-image

build-image #8

Workflow file for this run

name: build-image
# Build the Leadbay MCP HTTP-server Docker image and push it to the container
# registry, so the self-hosted k3s deployment in leadbay/infra can run it. The
# image is tagged with the full commit SHA — Argo CD Image Updater in the infra
# repo watches for the newest 40-char-SHA tag and bumps the workload's
# kustomization automatically (see infra apps/eu/_apps/mcp-updater.yaml).
#
# Runs independently of release.yml (npm publish + Fly deploy). Triggers on the
# same release tags so a published version always has a matching image, and can
# be dispatched manually.
#
# Auth — uses the SAME registry vars/secrets the backend repo uses, so if these
# are set at the org level there may be nothing extra to configure here:
# vars.DOCKER_REGISTRY_HOSTNAME → e.g. "leadbay.azurecr.io"
# secrets.DOCKER_REGISTRY_USERNAME → registry push user / SP id
# secrets.DOCKER_REGISTRY_PASSWORD → its password
# The image repository is fixed to "mcp" (infra pulls leadbay.azurecr.io/mcp).
on:
push:
tags:
- "mcp-v*.*.*"
- "v*.*.*"
workflow_dispatch:
inputs:
ref:
description: "Git ref (branch/tag/SHA) to build"
required: false
default: ""
concurrency:
# Never let two builds push competing tags for the same commit concurrently.
group: build-image-${{ github.ref }}
cancel-in-progress: false
jobs:
build-push:
name: Build + push MCP image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.inputs.ref || github.ref }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to Azure Container Registry
uses: docker/login-action@v3
with:
registry: ${{ vars.DOCKER_REGISTRY_HOSTNAME }}
username: ${{ secrets.DOCKER_REGISTRY_USERNAME }}
password: ${{ secrets.DOCKER_REGISTRY_PASSWORD }}
- name: Resolve image tags
id: tags
run: |
set -euo pipefail
# Resolve the SHA from the actually-checked-out commit, NOT github.sha:
# on a workflow_dispatch with a custom `ref`, github.sha points at the
# run's ref, not the built commit — which would tag the image with a
# SHA whose contents it doesn't contain (Argo CD would then deploy the
# wrong revision). git rev-parse HEAD is always the built commit.
SHA="$(git rev-parse HEAD)"
SERVER="${{ vars.DOCKER_REGISTRY_HOSTNAME }}"
# Full 40-char commit SHA — the tag format Argo CD Image Updater
# matches (regexp:^[0-9a-f]{40}$). Also push :latest for humans.
echo "sha_tag=${SERVER}/mcp:${SHA}" >> "$GITHUB_OUTPUT"
echo "latest_tag=${SERVER}/mcp:latest" >> "$GITHUB_OUTPUT"
- name: Build and push
uses: docker/build-push-action@v6
with:
# Build context is the repo root (the Dockerfile expects the monorepo).
context: .
file: ./Dockerfile
push: true
tags: |
${{ steps.tags.outputs.sha_tag }}
${{ steps.tags.outputs.latest_tag }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Summary
run: |
echo "Pushed:" >> "$GITHUB_STEP_SUMMARY"
echo "- \`${{ steps.tags.outputs.sha_tag }}\`" >> "$GITHUB_STEP_SUMMARY"
echo "- \`${{ steps.tags.outputs.latest_tag }}\`" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "Argo CD Image Updater (leadbay/infra) will bump the mcp workload to the SHA tag." >> "$GITHUB_STEP_SUMMARY"