Skip to content

web: Soften the self-signed certificate warning for proxied wildcards #974

web: Soften the self-signed certificate warning for proxied wildcards

web: Soften the self-signed certificate warning for proxied wildcards #974

Workflow file for this run

name: 💫 Build App
on:
push:
branches: [master]
paths:
- "apps/web/**"
- "apps/api/**"
- "Dockerfile"
- "Dockerfile.builder"
- "docker-bake.hcl"
- ".github/workflows/build-app.yml"
- ".github/actions/build-app/**"
- ".github/actions/setup-go/**"
- ".github/actions/k8s-deploy/**"
- "deploy/k8s/**"
concurrency:
group: build-app-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
packages: write # push images to ghcr.io
env:
REF: ${{ github.ref_name }}-${{ github.run_id }}
jobs:
build:
name: 🔨 Build and Push Images
strategy:
matrix:
include:
- platform: linux/amd64
runs-on: ubuntu-24.04
arch: amd64
- platform: linux/arm64
runs-on: ubuntu-24.04-arm
arch: arm64
runs-on: ${{ matrix.runs-on }}
steps:
- uses: actions/checkout@v4
- name: Get short SHA
id: sha
run: echo "short=${GITHUB_SHA::7}" >> "$GITHUB_OUTPUT"
- name: Build app artifacts
id: artifacts
uses: ./.github/actions/build-app
with:
arch: ${{ matrix.arch }}
version: ${{ steps.sha.outputs.short }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
# Bake builds the app and builder images at the same time.
- name: Build and push app and builder images
uses: docker/bake-action@v6
env:
TAG: ${{ env.REF }}-${{ matrix.arch }}
MISE_VERSION: ${{ steps.artifacts.outputs.mise_version }}
with:
source: .
files: ./docker-bake.hcl
push: true
provenance: false
set: |
*.platform=${{ matrix.platform }}
deploy_prod:
name: 🚀 Publish and Deploy App (PROD)
runs-on: ubuntu-24.04
needs: build
steps:
- uses: actions/checkout@v4
- name: Login to registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
# The short SHA is the version stamped into the binaries, the API runs registry cleanup from that tag
- name: Create and push manifests
run: |
for IMAGE in ghcr.io/unbindapp/unbind ghcr.io/unbindapp/unbind-builder; do
for TAG in "$REF" "${GITHUB_SHA::7}" latest; do
docker manifest create "$IMAGE:$TAG" \
--amend "$IMAGE:$REF-amd64" \
--amend "$IMAGE:$REF-arm64"
docker manifest annotate --arch amd64 --os linux "$IMAGE:$TAG" "$IMAGE:$REF-amd64"
docker manifest annotate --arch arm64 --os linux "$IMAGE:$TAG" "$IMAGE:$REF-arm64"
docker manifest push "$IMAGE:$TAG"
done
done
- name: Deploy
uses: ./.github/actions/k8s-deploy
with:
image: ghcr.io/unbindapp/unbind:${{ env.REF }}
kube_config: ${{ secrets.K3S_KUBE_CONFIG }}