diff --git a/.gitea/workflows/build-prod.yaml b/.gitea/workflows/build-prod.yaml new file mode 100644 index 0000000..1631270 --- /dev/null +++ b/.gitea/workflows/build-prod.yaml @@ -0,0 +1,58 @@ +# Build and push on prod branch — triggered automatically when commits land on prod. +# Tag is commit short SHA: unique, immutable, maps to exactly one commit. +# Image: forgejo.riotpiao.com/rock/api-gateway: +# +# No write-back, no git push — ArgoCD Image Updater or manual deployment pulls new builds. +name: Build (prod) + +on: + push: + branches: [prod] + +env: + REGISTRY: forgejo.riotpiao.com + IMAGE: forgejo.riotpiao.com/rock/api-gateway + +jobs: + build: + name: Build and push image + runs-on: golang + container: + image: docker:27-cli + volumes: + - /docker-certs/client:/docker-certs/client:ro + env: + DOCKER_HOST: tcp://localhost:2376 + DOCKER_TLS_VERIFY: "1" + DOCKER_CERT_PATH: /docker-certs/client + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + steps: + - name: install node (required by JS-based actions) + run: apk add --no-cache nodejs git + + - uses: actions/checkout@v4 + + - name: Get short SHA + id: sha + run: | + SHORT_SHA=$(git rev-parse --short HEAD) + echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT + + - name: Registry login + run: | + echo "${GITHUB_TOKEN}" | docker login "${REGISTRY}" \ + --username rock --password-stdin + + - name: Build + run: | + docker build \ + --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ + -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ + . + + - name: Push + run: docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" + + - name: Report digest + run: | + docker inspect --format='{{index .RepoDigests 0}}' "${IMAGE}:${{ steps.sha.outputs.short_sha }}"