# Single pipeline: verify → build → push. # One workflow per push, one concurrency group per branch. name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ci-${{ github.ref }} cancel-in-progress: true env: REGISTRY: forgejo.riotpiao.com IMAGE: forgejo.riotpiao.com/rock/api-gateway jobs: verify: name: Vet, test, build runs-on: golang steps: - name: Install Node.js for actions runtime run: apt-get update && apt-get install -y nodejs - uses: actions/checkout@v4 - name: go vet run: go vet ./... - name: go test -race run: go test ./... -race - name: Static build (smoke) run: CGO_ENABLED=0 go build -trimpath -o gateway ./cmd/gateway push: name: Build and push image needs: verify if: github.ref == 'refs/heads/main' && github.event_name == 'push' runs-on: golang steps: - name: Install Docker CLI and Node.js run: | apt-get update apt-get install -y --no-install-recommends docker.io nodejs git rm -rf /var/lib/apt/lists/* - uses: actions/checkout@v4 - name: Get short SHA id: sha run: | SHORT_SHA=$(git rev-parse --short HEAD) echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT - name: Registry login run: | echo "${REGISTRY_PAT}" | docker login "${REGISTRY}" \ --username rock --password-stdin env: REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - name: Build image run: | docker build \ --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:latest" \ . - name: Push image run: | docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:latest" echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" - name: Prune unused images run: | docker image prune -a --force 2>&1 | tail -3 || true