Skip to content

ci: refactor GitHub Actions and Docker build-push-action settings #11

ci: refactor GitHub Actions and Docker build-push-action settings

ci: refactor GitHub Actions and Docker build-push-action settings #11

name: docker_publish
on:
push:
branches:
- 'master'
tags:
- '*'
workflow_dispatch:
# Sets the permissions granted to the GITHUB_TOKEN for the actions in this job.
permissions:
contents: read
packages: write
jobs:
docker-latest:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: 'true'
- name: Setup docker
id: setup
uses: ./.github/workflows/docker-reused-setup-steps
with:
DOCKERHUB_ORGANIZATION_NAME : ${{ secrets.DOCKERHUB_ORGANIZATION_NAME }}
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
tag: latest
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./Dockerfile
push: true
target: final
tags: ${{ steps.setup.outputs.tags }}
labels: ${{ steps.setup.outputs.labels }}
build-args: |
VERSION=latest
RELEASE=${{ github.run_number }}
platforms: linux/amd64,linux/arm64
# Cache to regietry instead of gha to avoid the capacity limit.
cache-from: type=registry,ref=ghcr.io/recorder-moe/azure-uploader:cache
cache-to: type=registry,ref=ghcr.io/recorder-moe/azure-uploader:cache,mode=max
sbom: true
provenance: true