build-image #8
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: build-image | |
| # Build the Leadbay MCP HTTP-server Docker image and push it to the container | |
| # registry, so the self-hosted k3s deployment in leadbay/infra can run it. The | |
| # image is tagged with the full commit SHA — Argo CD Image Updater in the infra | |
| # repo watches for the newest 40-char-SHA tag and bumps the workload's | |
| # kustomization automatically (see infra apps/eu/_apps/mcp-updater.yaml). | |
| # | |
| # Runs independently of release.yml (npm publish + Fly deploy). Triggers on the | |
| # same release tags so a published version always has a matching image, and can | |
| # be dispatched manually. | |
| # | |
| # Auth — uses the SAME registry vars/secrets the backend repo uses, so if these | |
| # are set at the org level there may be nothing extra to configure here: | |
| # vars.DOCKER_REGISTRY_HOSTNAME → e.g. "leadbay.azurecr.io" | |
| # secrets.DOCKER_REGISTRY_USERNAME → registry push user / SP id | |
| # secrets.DOCKER_REGISTRY_PASSWORD → its password | |
| # The image repository is fixed to "mcp" (infra pulls leadbay.azurecr.io/mcp). | |
| on: | |
| push: | |
| tags: | |
| - "mcp-v*.*.*" | |
| - "v*.*.*" | |
| workflow_dispatch: | |
| inputs: | |
| ref: | |
| description: "Git ref (branch/tag/SHA) to build" | |
| required: false | |
| default: "" | |
| concurrency: | |
| # Never let two builds push competing tags for the same commit concurrently. | |
| group: build-image-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| build-push: | |
| name: Build + push MCP image | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ github.event.inputs.ref || github.ref }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to Azure Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ vars.DOCKER_REGISTRY_HOSTNAME }} | |
| username: ${{ secrets.DOCKER_REGISTRY_USERNAME }} | |
| password: ${{ secrets.DOCKER_REGISTRY_PASSWORD }} | |
| - name: Resolve image tags | |
| id: tags | |
| run: | | |
| set -euo pipefail | |
| # Resolve the SHA from the actually-checked-out commit, NOT github.sha: | |
| # on a workflow_dispatch with a custom `ref`, github.sha points at the | |
| # run's ref, not the built commit — which would tag the image with a | |
| # SHA whose contents it doesn't contain (Argo CD would then deploy the | |
| # wrong revision). git rev-parse HEAD is always the built commit. | |
| SHA="$(git rev-parse HEAD)" | |
| SERVER="${{ vars.DOCKER_REGISTRY_HOSTNAME }}" | |
| # Full 40-char commit SHA — the tag format Argo CD Image Updater | |
| # matches (regexp:^[0-9a-f]{40}$). Also push :latest for humans. | |
| echo "sha_tag=${SERVER}/mcp:${SHA}" >> "$GITHUB_OUTPUT" | |
| echo "latest_tag=${SERVER}/mcp:latest" >> "$GITHUB_OUTPUT" | |
| - name: Build and push | |
| uses: docker/build-push-action@v6 | |
| with: | |
| # Build context is the repo root (the Dockerfile expects the monorepo). | |
| context: . | |
| file: ./Dockerfile | |
| push: true | |
| tags: | | |
| ${{ steps.tags.outputs.sha_tag }} | |
| ${{ steps.tags.outputs.latest_tag }} | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| - name: Summary | |
| run: | | |
| echo "Pushed:" >> "$GITHUB_STEP_SUMMARY" | |
| echo "- \`${{ steps.tags.outputs.sha_tag }}\`" >> "$GITHUB_STEP_SUMMARY" | |
| echo "- \`${{ steps.tags.outputs.latest_tag }}\`" >> "$GITHUB_STEP_SUMMARY" | |
| echo "" >> "$GITHUB_STEP_SUMMARY" | |
| echo "Argo CD Image Updater (leadbay/infra) will bump the mcp workload to the SHA tag." >> "$GITHUB_STEP_SUMMARY" |