-
Notifications
You must be signed in to change notification settings - Fork 19
155 lines (135 loc) · 4.56 KB
/
docker.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
name: docker build
on:
push:
branches:
- develop
- main
tags:
- "v*"
workflow_dispatch:
env:
REGISTRY_IMAGE: nzbgetcom/nzbget
jobs:
build:
strategy:
fail-fast: false
matrix:
include:
- platform: linux/amd64
runner: ubuntu-24.04
- platform: linux/arm/v7
runner: ubuntu-24.04
- platform: linux/arm64
runner: ubuntu-24.04
runs-on: ${{ matrix.runner }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Prepare
id: prepare
run: |
platform=${{ matrix.platform }}
echo "platform-slug=${platform//\//-}" >> $GITHUB_OUTPUT
- name: Login to Docker Hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and push by digest
id: build
uses: docker/build-push-action@v6
env:
DOCKER_BUILD_SUMMARY: false
with:
context: .
file: docker/Dockerfile
platforms: ${{ matrix.platform }}
provenance: false
outputs: "type=image,oci-mediatypes=false,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true"
build-args: |
"NZBGET_RELEASE=${{ github.ref_name }}"
"MAKE_JOBS=4"
- name: Export digest
run: |
rm -rf digests
mkdir -p digests
digest="${{ steps.build.outputs.digest }}"
touch "digests/${digest#sha256:}"
- name: Upload digest
uses: actions/upload-artifact@v4
with:
name: digests-${{ steps.prepare.outputs.platform-slug }}
path: digests/*
if-no-files-found: error
retention-days: 1
merge:
runs-on: ubuntu-24.04
needs: build
permissions:
packages: write
steps:
- name: Download digests
uses: actions/download-artifact@v4
with:
path: digests
pattern: digests-*
merge-multiple: true
- name: Login to Docker Hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Generate image tag
id: gen-tag
run: |
case $GITHUB_REF_NAME in
develop)
TAG="testing"
;;
main)
TAG="latest"
;;
refs/tags/*)
TAG="${GITHUB_REF/refs\/tags\//}"
;;
*)
TAG="${GITHUB_REF_NAME/\//-}"
;;
esac
echo "tag=$TAG" >> $GITHUB_OUTPUT
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Create manifest list, push and inspect
run: |
cd digests
docker manifest create ${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }} $(printf -- '--amend ${{ env.REGISTRY_IMAGE }}@sha256:%s ' *)
docker manifest push ${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }}
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }}
if [[ "$GITHUB_REF_NAME" == "develop" ]] || [[ "$GITHUB_REF_NAME" == "main" ]] || [[ $GITHUB_REF == 'refs/tags/'* ]]; then
docker buildx imagetools create -t ghcr.io/${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }} ${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }}
docker buildx imagetools inspect ghcr.io/${{ env.REGISTRY_IMAGE }}:${{ steps.gen-tag.outputs.tag }}
fi
- name: Update Docker Hub Description
if: github.ref_name == 'main'
uses: peter-evans/dockerhub-description@v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
repository: ${{ env.REGISTRY_IMAGE }}
readme-filepath: ./docker/README.md
- name: Cleanup ghcr.io from outdated images
uses: miklinux/ghcr-cleanup-action@v1
with:
token: ${{ secrets.GITHUB_TOKEN }}
package-owner: nzbgetcom
package-name: nzbget
delete-orphans: true
dry-run: false