Repository navigation
web: Soften the self-signed certificate warning for proxied wildcards #974
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: 💫 Build App | |
| on: | |
| push: | |
| branches: [master] | |
| paths: | |
| - "apps/web/**" | |
| - "apps/api/**" | |
| - "Dockerfile" | |
| - "Dockerfile.builder" | |
| - "docker-bake.hcl" | |
| - ".github/workflows/build-app.yml" | |
| - ".github/actions/build-app/**" | |
| - ".github/actions/setup-go/**" | |
| - ".github/actions/k8s-deploy/**" | |
| - "deploy/k8s/**" | |
| concurrency: | |
| group: build-app-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| packages: write # push images to ghcr.io | |
| env: | |
| REF: ${{ github.ref_name }}-${{ github.run_id }} | |
| jobs: | |
| build: | |
| name: 🔨 Build and Push Images | |
| strategy: | |
| matrix: | |
| include: | |
| - platform: linux/amd64 | |
| runs-on: ubuntu-24.04 | |
| arch: amd64 | |
| - platform: linux/arm64 | |
| runs-on: ubuntu-24.04-arm | |
| arch: arm64 | |
| runs-on: ${{ matrix.runs-on }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Get short SHA | |
| id: sha | |
| run: echo "short=${GITHUB_SHA::7}" >> "$GITHUB_OUTPUT" | |
| - name: Build app artifacts | |
| id: artifacts | |
| uses: ./.github/actions/build-app | |
| with: | |
| arch: ${{ matrix.arch }} | |
| version: ${{ steps.sha.outputs.short }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| # Bake builds the app and builder images at the same time. | |
| - name: Build and push app and builder images | |
| uses: docker/bake-action@v6 | |
| env: | |
| TAG: ${{ env.REF }}-${{ matrix.arch }} | |
| MISE_VERSION: ${{ steps.artifacts.outputs.mise_version }} | |
| with: | |
| source: . | |
| files: ./docker-bake.hcl | |
| push: true | |
| provenance: false | |
| set: | | |
| *.platform=${{ matrix.platform }} | |
| deploy_prod: | |
| name: 🚀 Publish and Deploy App (PROD) | |
| runs-on: ubuntu-24.04 | |
| needs: build | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Login to registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| # The short SHA is the version stamped into the binaries, the API runs registry cleanup from that tag | |
| - name: Create and push manifests | |
| run: | | |
| for IMAGE in ghcr.io/unbindapp/unbind ghcr.io/unbindapp/unbind-builder; do | |
| for TAG in "$REF" "${GITHUB_SHA::7}" latest; do | |
| docker manifest create "$IMAGE:$TAG" \ | |
| --amend "$IMAGE:$REF-amd64" \ | |
| --amend "$IMAGE:$REF-arm64" | |
| docker manifest annotate --arch amd64 --os linux "$IMAGE:$TAG" "$IMAGE:$REF-amd64" | |
| docker manifest annotate --arch arm64 --os linux "$IMAGE:$TAG" "$IMAGE:$REF-arm64" | |
| docker manifest push "$IMAGE:$TAG" | |
| done | |
| done | |
| - name: Deploy | |
| uses: ./.github/actions/k8s-deploy | |
| with: | |
| image: ghcr.io/unbindapp/unbind:${{ env.REF }} | |
| kube_config: ${{ secrets.K3S_KUBE_CONFIG }} |