name: Build & Push Portfolio Image on: push: branches: - main jobs: build-push: runs-on: golang container: image: docker:27-cli volumes: - /docker-certs/client:/docker-certs/client:ro env: DOCKER_HOST: tcp://localhost:2376 DOCKER_TLS_VERIFY: "1" DOCKER_CERT_PATH: /docker-certs/client REGISTRY: forgejo.riotpiao.com IMAGE: forgejo.riotpiao.com/rock/portfolio steps: - name: Install git run: apk add --no-cache git nodejs - name: Checkout code uses: actions/checkout@v4 - name: Get short SHA id: sha run: | SHORT_SHA=$(git rev-parse --short HEAD) echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT - name: Registry login run: | echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \ --username "${REGISTRY_USER}" --password-stdin env: REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }} REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }} - name: Delete old latest image run: | # Delete old :latest tag from Forgejo registry via API curl -s -X DELETE \ -u "${REGISTRY_USER}:${REGISTRY_TOKEN}" \ "https://${REGISTRY}/v2/rock/portfolio/manifests/$(curl -s -H 'Accept: application/vnd.oci.image.index.v1+json' -u "${REGISTRY_USER}:${REGISTRY_TOKEN}" "https://${REGISTRY}/v2/rock/portfolio/manifests/latest" | head -1 | grep -o 'sha256:[a-f0-9]*' || true)" \ 2>/dev/null || echo "No old latest to delete" env: REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }} REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }} - name: Build image run: | docker build --no-cache \ --build-arg COMMIT_SHA=${{ steps.sha.outputs.short_sha }} \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:latest" \ . - name: Push image run: | docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:latest" echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"